Get a ticket creation rule

Note: This endpoint is in Preview and is subject to change. If you have any feedback, contact Datadog support.

GET https://api.ap1.datadoghq.com/api/v2/security/findings/automation/ticket_creation_rules/{rule_id}https://api.ap2.datadoghq.com/api/v2/security/findings/automation/ticket_creation_rules/{rule_id}https://api.datadoghq.eu/api/v2/security/findings/automation/ticket_creation_rules/{rule_id}https://api.ddog-gov.com/api/v2/security/findings/automation/ticket_creation_rules/{rule_id}https://api.us2.ddog-gov.com/api/v2/security/findings/automation/ticket_creation_rules/{rule_id}https://api.uk1.datadoghq.com/api/v2/security/findings/automation/ticket_creation_rules/{rule_id}https://api.datadoghq.com/api/v2/security/findings/automation/ticket_creation_rules/{rule_id}https://api.us3.datadoghq.com/api/v2/security/findings/automation/ticket_creation_rules/{rule_id}https://api.us5.datadoghq.com/api/v2/security/findings/automation/ticket_creation_rules/{rule_id}

Overview

Get the details of a ticket creation rule by ID. This endpoint requires the security_pipelines_read permission.

Arguments

Path Parameters

Name

Type

Description

rule_id [required]

string

The ID of the ticket creation rule.

Response

Successfully retrieved the ticket creation rule

A single ticket creation rule response.

Expand All

Field

Type

Description

data [required]

object

The data object for a ticket creation rule returned by the API.

attributes [required]

object

Attributes of a ticket creation rule returned by the API.

action [required]

object

The action to take when the ticket creation rule matches a finding.

assignee_id

uuid

The UUID of the default assignee for created tickets.

auto_disabled_reason

string

The reason the rule was automatically disabled by the system due to a ticketing integration error.

fields

object

Custom fields of the Jira issue to create. For the list of available fields, see Jira documentation.

max_tickets_per_day [required]

int64

The maximum number of tickets the rule may create per day. If exceeded, one final ticket will be created, explaining the limit was hit and link back to the responsible rule.

project_id [required]

uuid

The UUID of the case management project.

target [required]

enum

The ticketing system to create tickets in. Allowed enum values: jira,case_management

created_at [required]

int64

The Unix timestamp in milliseconds when the rule was created.

created_by [required]

object

The user or Datadog system who created the rule.

id [required]

string

The actor's identifier (a user UUID or a system identifier).

name [required]

string

The name of the actor.

type [required]

enum

Whether the actor is a user or the Datadog system. Allowed enum values: user,system

enabled [required]

boolean

Whether the ticket creation rule is enabled.

modified_at [required]

int64

The Unix timestamp in milliseconds when the rule was last modified.

modified_by [required]

object

The user or Datadog system who last modified the rule.

id [required]

string

The actor's identifier (a user UUID or a system identifier).

name [required]

string

The name of the actor.

type [required]

enum

Whether the actor is a user or the Datadog system. Allowed enum values: user,system

name [required]

string

The name of the ticket creation rule.

rule [required]

object

Defines the scope of findings to which the automation rule applies.

finding_types [required]

[string]

The list of security finding types that the automation rule applies to.

query

string

A search query to further filter the findings matched by this rule. The @workflow.* namespace and @status fields are not permitted. For a reference of available fields, see the Security Findings schema documentation.

id [required]

uuid

The ID of the ticket creation rule.

type [required]

enum

The JSON:API type for ticket creation rules. Allowed enum values: ticket_creation_rules

{
  "data": {
    "attributes": {
      "action": {
        "assignee_id": "22222222-2222-2222-2222-222222222222",
        "auto_disabled_reason": "Daily ticket creation limit exceeded",
        "fields": {
          "labels": [
            "security"
          ]
        },
        "max_tickets_per_day": 100,
        "project_id": "11111111-1111-1111-1111-111111111111",
        "target": "jira"
      },
      "created_at": 1722439510282,
      "created_by": {
        "id": "00000000-0000-0000-0000-000000000000",
        "name": "Jane Doe",
        "type": "user"
      },
      "enabled": true,
      "modified_at": 1722439510282,
      "modified_by": {
        "id": "00000000-0000-0000-0000-000000000000",
        "name": "Jane Doe",
        "type": "user"
      },
      "name": "Auto-create Jira tickets for critical findings",
      "rule": {
        "finding_types": [
          "misconfiguration"
        ],
        "query": "env:prod team:platform"
      }
    },
    "id": "00000000-0000-0000-0000-000000000000",
    "type": "ticket_creation_rules"
  }
}

Forbidden

API error response.

Expand All

Field

Type

Description

errors [required]

[string]

A list of errors.

{
  "errors": [
    "Bad Request"
  ]
}

Not Found

API error response.

Expand All

Field

Type

Description

errors [required]

[string]

A list of errors.

{
  "errors": [
    "Bad Request"
  ]
}

Too many requests

API error response.

Expand All

Field

Type

Description

errors [required]

[string]

A list of errors.

{
  "errors": [
    "Bad Request"
  ]
}

Code Example

                  # Path parameters
export rule_id="00000000-0000-0000-0000-000000000000"
# Curl command
curl -X GET "https://api.ap1.datadoghq.com"https://api.ap2.datadoghq.com"https://api.datadoghq.eu"https://api.ddog-gov.com"https://api.us2.ddog-gov.com"https://api.uk1.datadoghq.com"https://api.datadoghq.com"https://api.us3.datadoghq.com"https://api.us5.datadoghq.com/api/v2/security/findings/automation/ticket_creation_rules/${rule_id}" \ -H "Accept: application/json" \ -H "DD-API-KEY: ${DD_API_KEY}" \ -H "DD-APPLICATION-KEY: ${DD_APP_KEY}"
"""
Get a ticket creation rule returns "Successfully retrieved the ticket creation rule" response
"""

from os import environ
from datadog_api_client import ApiClient, Configuration
from datadog_api_client.v2.api.security_monitoring_api import SecurityMonitoringApi

# there is a valid "valid_ticket_creation_rule" in the system
VALID_TICKET_CREATION_RULE_DATA_ID = environ["VALID_TICKET_CREATION_RULE_DATA_ID"]

configuration = Configuration()
configuration.unstable_operations["get_security_findings_automation_ticket_creation_rule"] = True
with ApiClient(configuration) as api_client:
    api_instance = SecurityMonitoringApi(api_client)
    response = api_instance.get_security_findings_automation_ticket_creation_rule(
        rule_id=VALID_TICKET_CREATION_RULE_DATA_ID,
    )

    print(response)

Instructions

First install the library and its dependencies and then save the example to example.py and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" python3 "example.py"
# Get a ticket creation rule returns "Successfully retrieved the ticket creation rule" response

require "datadog_api_client"
DatadogAPIClient.configure do |config|
  config.unstable_operations["v2.get_security_findings_automation_ticket_creation_rule".to_sym] = true
end
api_instance = DatadogAPIClient::V2::SecurityMonitoringAPI.new

# there is a valid "valid_ticket_creation_rule" in the system
VALID_TICKET_CREATION_RULE_DATA_ID = ENV["VALID_TICKET_CREATION_RULE_DATA_ID"]
p api_instance.get_security_findings_automation_ticket_creation_rule(VALID_TICKET_CREATION_RULE_DATA_ID)

Instructions

First install the library and its dependencies and then save the example to example.rb and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" rb "example.rb"
// Get a ticket creation rule returns "Successfully retrieved the ticket creation rule" response

package main

import (
	"context"
	"encoding/json"
	"fmt"
	"os"

	"github.com/DataDog/datadog-api-client-go/v2/api/datadog"
	"github.com/DataDog/datadog-api-client-go/v2/api/datadogV2"
	"github.com/google/uuid"
)

func main() {
	// there is a valid "valid_ticket_creation_rule" in the system
	ValidTicketCreationRuleDataID := uuid.MustParse(os.Getenv("VALID_TICKET_CREATION_RULE_DATA_ID"))

	ctx := datadog.NewDefaultContext(context.Background())
	configuration := datadog.NewConfiguration()
	configuration.SetUnstableOperationEnabled("v2.GetSecurityFindingsAutomationTicketCreationRule", true)
	apiClient := datadog.NewAPIClient(configuration)
	api := datadogV2.NewSecurityMonitoringApi(apiClient)
	resp, r, err := api.GetSecurityFindingsAutomationTicketCreationRule(ctx, ValidTicketCreationRuleDataID)

	if err != nil {
		fmt.Fprintf(os.Stderr, "Error when calling `SecurityMonitoringApi.GetSecurityFindingsAutomationTicketCreationRule`: %v\n", err)
		fmt.Fprintf(os.Stderr, "Full HTTP response: %v\n", r)
	}

	responseContent, _ := json.MarshalIndent(resp, "", "  ")
	fmt.Fprintf(os.Stdout, "Response from `SecurityMonitoringApi.GetSecurityFindingsAutomationTicketCreationRule`:\n%s\n", responseContent)
}

Instructions

First install the library and its dependencies and then save the example to main.go and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" go run "main.go"
// Get a ticket creation rule returns "Successfully retrieved the ticket creation rule" response

import com.datadog.api.client.ApiClient;
import com.datadog.api.client.ApiException;
import com.datadog.api.client.v2.api.SecurityMonitoringApi;
import com.datadog.api.client.v2.model.TicketCreationRuleResponse;
import java.util.UUID;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = ApiClient.getDefaultApiClient();
    defaultClient.setUnstableOperationEnabled(
        "v2.getSecurityFindingsAutomationTicketCreationRule", true);
    SecurityMonitoringApi apiInstance = new SecurityMonitoringApi(defaultClient);

    // there is a valid "valid_ticket_creation_rule" in the system
    UUID VALID_TICKET_CREATION_RULE_DATA_ID = null;
    try {
      VALID_TICKET_CREATION_RULE_DATA_ID =
          UUID.fromString(System.getenv("VALID_TICKET_CREATION_RULE_DATA_ID"));
    } catch (IllegalArgumentException e) {
      System.err.println("Error parsing UUID: " + e.getMessage());
    }

    try {
      TicketCreationRuleResponse result =
          apiInstance.getSecurityFindingsAutomationTicketCreationRule(
              VALID_TICKET_CREATION_RULE_DATA_ID);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println(
          "Exception when calling"
              + " SecurityMonitoringApi#getSecurityFindingsAutomationTicketCreationRule");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}

Instructions

First install the library and its dependencies and then save the example to Example.java and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" java "Example.java"
// Get a ticket creation rule returns "Successfully retrieved the ticket creation
// rule" response
use datadog_api_client::datadog;
use datadog_api_client::datadogV2::api_security_monitoring::SecurityMonitoringAPI;

#[tokio::main]
async fn main() {
    // there is a valid "valid_ticket_creation_rule" in the system
    let valid_ticket_creation_rule_data_id =
        uuid::Uuid::parse_str(&std::env::var("VALID_TICKET_CREATION_RULE_DATA_ID").unwrap())
            .expect("Invalid UUID");
    let mut configuration = datadog::Configuration::new();
    configuration
        .set_unstable_operation_enabled("v2.GetSecurityFindingsAutomationTicketCreationRule", true);
    let api = SecurityMonitoringAPI::with_config(configuration);
    let resp = api
        .get_security_findings_automation_ticket_creation_rule(
            valid_ticket_creation_rule_data_id.clone(),
        )
        .await;
    if let Ok(value) = resp {
        println!("{:#?}", value);
    } else {
        println!("{:#?}", resp.unwrap_err());
    }
}

Instructions

First install the library and its dependencies and then save the example to src/main.rs and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" cargo run
/**
 * Get a ticket creation rule returns "Successfully retrieved the ticket creation rule" response
 */

import { client, v2 } from "@datadog/datadog-api-client";

const configuration = client.createConfiguration();
configuration.unstableOperations[
  "v2.getSecurityFindingsAutomationTicketCreationRule"
] = true;
const apiInstance = new v2.SecurityMonitoringApi(configuration);

// there is a valid "valid_ticket_creation_rule" in the system
const VALID_TICKET_CREATION_RULE_DATA_ID = process.env
  .VALID_TICKET_CREATION_RULE_DATA_ID as string;

const params: v2.SecurityMonitoringApiGetSecurityFindingsAutomationTicketCreationRuleRequest =
  {
    ruleId: VALID_TICKET_CREATION_RULE_DATA_ID,
  };

apiInstance
  .getSecurityFindingsAutomationTicketCreationRule(params)
  .then((data: v2.TicketCreationRuleResponse) => {
    console.log(
      "API called successfully. Returned data: " + JSON.stringify(data)
    );
  })
  .catch((error: any) => console.error(error));

Instructions

First install the library and its dependencies and then save the example to example.ts and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" tsc "example.ts"