Update a detection

Note: This endpoint is in preview and is subject to change. If you have any feedback, contact Datadog support.

PATCH https://api.ap1.datadoghq.com/api/v2/governance/detections/{detection_id}https://api.ap2.datadoghq.com/api/v2/governance/detections/{detection_id}https://api.datadoghq.eu/api/v2/governance/detections/{detection_id}https://api.ddog-gov.com/api/v2/governance/detections/{detection_id}https://api.us2.ddog-gov.com/api/v2/governance/detections/{detection_id}https://api.uk1.datadoghq.com/api/v2/governance/detections/{detection_id}https://api.datadoghq.com/api/v2/governance/detections/{detection_id}https://api.us3.datadoghq.com/api/v2/governance/detections/{detection_id}https://api.us5.datadoghq.com/api/v2/governance/detections/{detection_id}

Overview

Update a governance detection by its unique identifier. Only the attributes present in the request are modified, allowing a detection to be acknowledged as an exception, reopened, reassigned, or deferred for mitigation. This endpoint requires the governance_console_read permission.

Arguments

Path Parameters

Name

Type

Description

detection_id [required]

string

The unique identifier of the detection.

Request

Body Data (required)

Expand All

Field

Type

Description

data [required]

object

The data of a governance control detection update request.

attributes

object

The attributes of a governance control detection that can be updated. Only the attributes present in the request are modified.

assigned_team

string

The handle of the team the detection is assigned to. Set to an empty string to clear the assignment.

assigned_to

string

The UUID of the user the detection is assigned to. Set to an empty string to clear the assignment.

mitigate_after

date-time

The timestamp after which the detection becomes eligible for mitigation. Used to defer mitigation to a later time.

state

enum

The new state to set for the detection. Set to exception to acknowledge the detection and exclude it from active counts, or active to reopen it. Allowed enum values: exception,active

type [required]

enum

Governance control detection resource type. Allowed enum values: governance_control_detection

{
  "data": {
    "attributes": {
      "assigned_team": "platform-security",
      "assigned_to": "11111111-2222-3333-4444-555555555555",
      "mitigate_after": "2024-03-15T00:00:00Z",
      "state": "exception"
    },
    "type": "governance_control_detection"
  }
}

Response

OK

A single governance control detection.

Expand All

Field

Type

Description

data [required]

object

A governance control detection resource.

attributes [required]

object

The attributes of a governance control detection.

assigned_team

string

The identifier of the team the detection is assigned to, if any.

assigned_to

string

The identifier of the user the detection is assigned to, if any.

assignment_source [required]

enum

How the detection's current assignment was determined. Possible values are auto_resolved, manual, reassigned, and cleared. Allowed enum values: auto_resolved,manual,reassigned,cleared

control_id [required]

string

DEPRECATED: DEPRECATED: mirrors detection_type for backward compatibility; use detection_type instead.

created_at [required]

date-time

The date and time when the detection was created.

detection_type [required]

string

The type of detection, which determines what condition was detected.

display_name [required]

string

The human-readable name of the detected resource.

exception_at

date-time

The date and time when the detection was marked as an exception, if applicable.

exception_by

string

The identifier of the user who marked the detection as an exception, if applicable.

metadata

Free-form metadata associated with the detection.

mitigate_after

date-time

The date and time after which the detection is scheduled to be mitigated, if applicable.

mitigated_at

date-time

The date and time when the detection was mitigated, if applicable.

priority [required]

int64

The priority of the detection, if set.

resource_id [required]

string

The identifier of the resource the detection applies to.

resource_type [required]

string

The type of resource the detection applies to, for example api_key or dashboard.

state [required]

enum

The current state of the detection. Possible values are active, exception, mitigated, inactive, obsolete, resolved_externally, and mitigation_in_progress. Allowed enum values: active,exception,mitigated,inactive,obsolete,resolved_externally,mitigation_in_progress

id [required]

string

The unique identifier of the detection.

type [required]

enum

Governance control detection resource type. Allowed enum values: governance_control_detection

{
  "data": {
    "attributes": {
      "assigned_team": "platform-security",
      "assigned_to": "11111111-2222-3333-4444-555555555555",
      "assignment_source": "manual",
      "control_id": "unused_api_keys",
      "created_at": "2024-03-01T12:00:00Z",
      "detection_type": "unused_api_keys",
      "display_name": "CI Deploy Key",
      "exception_at": "2024-03-05T09:00:00Z",
      "exception_by": "11111111-2222-3333-4444-555555555555",
      "metadata": {
        "region": "us-east-1"
      },
      "mitigate_after": "2024-03-15T00:00:00Z",
      "mitigated_at": "2024-03-10T15:30:00Z",
      "priority": 1,
      "resource_id": "api-key-12345",
      "resource_type": "api_key",
      "state": "active"
    },
    "id": "3f9b2c1a-8d4e-4a6b-9c2f-1e7d5a0b3c4d",
    "type": "governance_control_detection"
  }
}

Bad Request

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Unauthorized

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Forbidden

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Not Found

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Too many requests

API error response.

Expand All

Field

Type

Description

errors [required]

[string]

A list of errors.

{
  "errors": [
    "Bad Request"
  ]
}

Code Example

                  ## default
# 

# Path parameters
export detection_id="3f9b2c1a-8d4e-4a6b-9c2f-1e7d5a0b3c4d"
# Curl command
curl -X PATCH "https://api.ap1.datadoghq.com"https://api.ap2.datadoghq.com"https://api.datadoghq.eu"https://api.ddog-gov.com"https://api.us2.ddog-gov.com"https://api.uk1.datadoghq.com"https://api.datadoghq.com"https://api.us3.datadoghq.com"https://api.us5.datadoghq.com/api/v2/governance/detections/${detection_id}" \ -H "Accept: application/json" \ -H "Content-Type: application/json" \ -H "DD-API-KEY: ${DD_API_KEY}" \ -H "DD-APPLICATION-KEY: ${DD_APP_KEY}" \ -d @- << EOF { "data": { "attributes": { "assigned_to": "11111111-2222-3333-4444-555555555555", "state": "exception" }, "type": "governance_control_detection" } } EOF
"""
Update a detection returns "OK" response
"""

from datadog_api_client import ApiClient, Configuration
from datadog_api_client.v2.api.governance_console_api import GovernanceConsoleApi
from datadog_api_client.v2.model.governance_control_detection_resource_type import (
    GovernanceControlDetectionResourceType,
)
from datadog_api_client.v2.model.governance_control_detection_update_attributes import (
    GovernanceControlDetectionUpdateAttributes,
)
from datadog_api_client.v2.model.governance_control_detection_update_data import GovernanceControlDetectionUpdateData
from datadog_api_client.v2.model.governance_control_detection_update_request import (
    GovernanceControlDetectionUpdateRequest,
)
from datadog_api_client.v2.model.governance_control_detection_update_state import GovernanceControlDetectionUpdateState
from datetime import datetime
from dateutil.tz import tzutc

body = GovernanceControlDetectionUpdateRequest(
    data=GovernanceControlDetectionUpdateData(
        attributes=GovernanceControlDetectionUpdateAttributes(
            assigned_team="platform-security",
            assigned_to="11111111-2222-3333-4444-555555555555",
            mitigate_after=datetime(2024, 3, 15, 0, 0, tzinfo=tzutc()),
            state=GovernanceControlDetectionUpdateState.EXCEPTION,
        ),
        type=GovernanceControlDetectionResourceType.GOVERNANCE_CONTROL_DETECTION,
    ),
)

configuration = Configuration()
configuration.unstable_operations["update_governance_detection"] = True
with ApiClient(configuration) as api_client:
    api_instance = GovernanceConsoleApi(api_client)
    response = api_instance.update_governance_detection(detection_id="detection_id", body=body)

    print(response)

Instructions

First install the library and its dependencies and then save the example to example.py and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" python3 "example.py"
# Update a detection returns "OK" response

require "datadog_api_client"
DatadogAPIClient.configure do |config|
  config.unstable_operations["v2.update_governance_detection".to_sym] = true
end
api_instance = DatadogAPIClient::V2::GovernanceConsoleAPI.new

body = DatadogAPIClient::V2::GovernanceControlDetectionUpdateRequest.new({
  data: DatadogAPIClient::V2::GovernanceControlDetectionUpdateData.new({
    attributes: DatadogAPIClient::V2::GovernanceControlDetectionUpdateAttributes.new({
      assigned_team: "platform-security",
      assigned_to: "11111111-2222-3333-4444-555555555555",
      mitigate_after: "2024-03-15T00:00:00Z",
      state: DatadogAPIClient::V2::GovernanceControlDetectionUpdateState::EXCEPTION,
    }),
    type: DatadogAPIClient::V2::GovernanceControlDetectionResourceType::GOVERNANCE_CONTROL_DETECTION,
  }),
})
p api_instance.update_governance_detection("detection_id", body)

Instructions

First install the library and its dependencies and then save the example to example.rb and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" rb "example.rb"
// Update a detection returns "OK" response

package main

import (
	"context"
	"encoding/json"
	"fmt"
	"os"
	"time"

	"github.com/DataDog/datadog-api-client-go/v2/api/datadog"
	"github.com/DataDog/datadog-api-client-go/v2/api/datadogV2"
)

func main() {
	body := datadogV2.GovernanceControlDetectionUpdateRequest{
		Data: datadogV2.GovernanceControlDetectionUpdateData{
			Attributes: &datadogV2.GovernanceControlDetectionUpdateAttributes{
				AssignedTeam:  datadog.PtrString("platform-security"),
				AssignedTo:    datadog.PtrString("11111111-2222-3333-4444-555555555555"),
				MitigateAfter: datadog.PtrTime(time.Date(2024, 3, 15, 0, 0, 0, 0, time.UTC)),
				State:         datadogV2.GOVERNANCECONTROLDETECTIONUPDATESTATE_EXCEPTION.Ptr(),
			},
			Type: datadogV2.GOVERNANCECONTROLDETECTIONRESOURCETYPE_GOVERNANCE_CONTROL_DETECTION,
		},
	}
	ctx := datadog.NewDefaultContext(context.Background())
	configuration := datadog.NewConfiguration()
	configuration.SetUnstableOperationEnabled("v2.UpdateGovernanceDetection", true)
	apiClient := datadog.NewAPIClient(configuration)
	api := datadogV2.NewGovernanceConsoleApi(apiClient)
	resp, r, err := api.UpdateGovernanceDetection(ctx, "detection_id", body)

	if err != nil {
		fmt.Fprintf(os.Stderr, "Error when calling `GovernanceConsoleApi.UpdateGovernanceDetection`: %v\n", err)
		fmt.Fprintf(os.Stderr, "Full HTTP response: %v\n", r)
	}

	responseContent, _ := json.MarshalIndent(resp, "", "  ")
	fmt.Fprintf(os.Stdout, "Response from `GovernanceConsoleApi.UpdateGovernanceDetection`:\n%s\n", responseContent)
}

Instructions

First install the library and its dependencies and then save the example to main.go and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" go run "main.go"
// Update a detection returns "OK" response

import com.datadog.api.client.ApiClient;
import com.datadog.api.client.ApiException;
import com.datadog.api.client.v2.api.GovernanceConsoleApi;
import com.datadog.api.client.v2.model.GovernanceControlDetectionResourceType;
import com.datadog.api.client.v2.model.GovernanceControlDetectionResponse;
import com.datadog.api.client.v2.model.GovernanceControlDetectionUpdateAttributes;
import com.datadog.api.client.v2.model.GovernanceControlDetectionUpdateData;
import com.datadog.api.client.v2.model.GovernanceControlDetectionUpdateRequest;
import com.datadog.api.client.v2.model.GovernanceControlDetectionUpdateState;
import java.time.OffsetDateTime;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = ApiClient.getDefaultApiClient();
    defaultClient.setUnstableOperationEnabled("v2.updateGovernanceDetection", true);
    GovernanceConsoleApi apiInstance = new GovernanceConsoleApi(defaultClient);

    GovernanceControlDetectionUpdateRequest body =
        new GovernanceControlDetectionUpdateRequest()
            .data(
                new GovernanceControlDetectionUpdateData()
                    .attributes(
                        new GovernanceControlDetectionUpdateAttributes()
                            .assignedTeam("platform-security")
                            .assignedTo("11111111-2222-3333-4444-555555555555")
                            .mitigateAfter(OffsetDateTime.parse("2024-03-15T00:00:00Z"))
                            .state(GovernanceControlDetectionUpdateState.EXCEPTION))
                    .type(GovernanceControlDetectionResourceType.GOVERNANCE_CONTROL_DETECTION));

    try {
      GovernanceControlDetectionResponse result =
          apiInstance.updateGovernanceDetection("3f9b2c1a-8d4e-4a6b-9c2f-1e7d5a0b3c4d", body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println("Exception when calling GovernanceConsoleApi#updateGovernanceDetection");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}

Instructions

First install the library and its dependencies and then save the example to Example.java and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" java "Example.java"
// Update a detection returns "OK" response
use chrono::{DateTime, Utc};
use datadog_api_client::datadog;
use datadog_api_client::datadogV2::api_governance_console::GovernanceConsoleAPI;
use datadog_api_client::datadogV2::model::GovernanceControlDetectionResourceType;
use datadog_api_client::datadogV2::model::GovernanceControlDetectionUpdateAttributes;
use datadog_api_client::datadogV2::model::GovernanceControlDetectionUpdateData;
use datadog_api_client::datadogV2::model::GovernanceControlDetectionUpdateRequest;
use datadog_api_client::datadogV2::model::GovernanceControlDetectionUpdateState;

#[tokio::main]
async fn main() {
    let body = GovernanceControlDetectionUpdateRequest::new(
        GovernanceControlDetectionUpdateData::new(
            GovernanceControlDetectionResourceType::GOVERNANCE_CONTROL_DETECTION,
        )
        .attributes(
            GovernanceControlDetectionUpdateAttributes::new()
                .assigned_team("platform-security".to_string())
                .assigned_to("11111111-2222-3333-4444-555555555555".to_string())
                .mitigate_after(
                    DateTime::parse_from_rfc3339("2024-03-15T00:00:00+00:00")
                        .expect("Failed to parse datetime")
                        .with_timezone(&Utc),
                )
                .state(GovernanceControlDetectionUpdateState::EXCEPTION),
        ),
    );
    let mut configuration = datadog::Configuration::new();
    configuration.set_unstable_operation_enabled("v2.UpdateGovernanceDetection", true);
    let api = GovernanceConsoleAPI::with_config(configuration);
    let resp = api
        .update_governance_detection("detection_id".to_string(), body)
        .await;
    if let Ok(value) = resp {
        println!("{:#?}", value);
    } else {
        println!("{:#?}", resp.unwrap_err());
    }
}

Instructions

First install the library and its dependencies and then save the example to src/main.rs and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" cargo run
/**
 * Update a detection returns "OK" response
 */

import { client, v2 } from "@datadog/datadog-api-client";

const configuration = client.createConfiguration();
configuration.unstableOperations["v2.updateGovernanceDetection"] = true;
const apiInstance = new v2.GovernanceConsoleApi(configuration);

const params: v2.GovernanceConsoleApiUpdateGovernanceDetectionRequest = {
  body: {
    data: {
      attributes: {
        assignedTeam: "platform-security",
        assignedTo: "11111111-2222-3333-4444-555555555555",
        mitigateAfter: new Date(2024, 3, 15, 0, 0, 0, 0),
        state: "exception",
      },
      type: "governance_control_detection",
    },
  },
  detectionId: "detection_id",
};

apiInstance
  .updateGovernanceDetection(params)
  .then((data: v2.GovernanceControlDetectionResponse) => {
    console.log(
      "API called successfully. Returned data: " + JSON.stringify(data)
    );
  })
  .catch((error: any) => console.error(error));

Instructions

First install the library and its dependencies and then save the example to example.ts and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" tsc "example.ts"