{
"data": [
{
"attributes": {
"createdAt": "string",
"createdByHandle": "string",
"createdByName": "string",
"createdFromRuleId": "string",
"jobDefinition": {
"calculatedFields": [
{
"expression": "@request_end_timestamp - @request_start_timestamp",
"name": "response_time"
}
],
"cases": [
{
"actions": [
{
"options": {
"duration": 0,
"flaggedIPType": "FLAGGED",
"userBehaviorName": "string"
},
"type": "string"
}
],
"condition": "string",
"name": "string",
"notifications": [],
"status": "critical"
}
],
"from": 1729843470000,
"groupSignalsBy": [
"service"
],
"index": "cloud_siem",
"message": "A large number of failed login attempts.",
"name": "Excessive number of failed attempts.",
"options": {
"anomalyDetectionOptions": {
"bucketDuration": 300,
"detectionTolerance": 5,
"instantaneousBaseline": false,
"learningDuration": "integer",
"learningPeriodBaseline": "integer"
},
"detectionMethod": "string",
"evaluationWindow": "integer",
"impossibleTravelOptions": {
"baselineUserLocations": true,
"baselineUserLocationsDuration": "integer"
},
"keepAlive": "integer",
"maxSignalDuration": "integer",
"newValueOptions": {
"forgetAfter": "integer",
"instantaneousBaseline": false,
"learningDuration": "integer",
"learningMethod": "string",
"learningThreshold": "integer"
},
"sequenceDetectionOptions": {
"stepTransitions": [
{
"child": "string",
"evaluationWindow": "integer",
"parent": "string"
}
],
"steps": [
{
"condition": "string",
"evaluationWindow": "integer",
"name": "string"
}
]
},
"thirdPartyRuleOptions": {
"defaultNotifications": [],
"defaultStatus": "critical",
"rootQueries": [
{
"groupByFields": [],
"query": "source:cloudtrail"
}
],
"signalTitleTemplate": "string"
}
},
"queries": [
{
"additionalFilters": "string",
"aggregation": "string",
"correlatedByFields": [],
"correlatedQueryIndex": "integer",
"customQueryExtension": "string",
"dataSource": "logs",
"datasetIds": [],
"distinctFields": [],
"groupByFields": [],
"hasOptionalGroupByFields": false,
"index": "string",
"indexes": [],
"metrics": [],
"name": "string",
"query": "a > 3",
"queryLanguage": "string"
}
],
"referenceTables": [
{
"checkPresence": false,
"columnName": "string",
"logFieldPath": "string",
"ruleQueryName": "string",
"tableName": "string"
}
],
"tags": [],
"thirdPartyCases": [
{
"name": "string",
"notifications": [],
"query": "string",
"status": "critical"
}
],
"to": 1729847070000,
"type": "string"
},
"jobName": "string",
"jobStatus": "string",
"modifiedAt": "string",
"progressRate": "number",
"signalOutput": false
},
"id": "string",
"type": "string"
}
],
"meta": {
"totalCount": "integer"
}
}