---
title: Update a severity modifier rule
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: Docs > API Reference > Security Monitoring
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Update a severity modifier rule{% #update-a-severity-modifier-rule %}
Copy pageCopied
{% tab title="v2" %}
**Note**: This endpoint is in Preview and is subject to change. If you have any feedback, contact [Datadog support](https://docs.datadoghq.com/help/).
| Datadog site      | API endpoint                                                                                            |
| ----------------- | ------------------------------------------------------------------------------------------------------- |
| ap1.datadoghq.com | PUT https://api.ap1.datadoghq.com/api/v2/security/findings/automation/severity_modifier_rules/{rule_id} |
| ap2.datadoghq.com | PUT https://api.ap2.datadoghq.com/api/v2/security/findings/automation/severity_modifier_rules/{rule_id} |
| app.datadoghq.eu  | PUT https://api.datadoghq.eu/api/v2/security/findings/automation/severity_modifier_rules/{rule_id}      |
| app.ddog-gov.com  | PUT https://api.ddog-gov.com/api/v2/security/findings/automation/severity_modifier_rules/{rule_id}      |
| us2.ddog-gov.com  | PUT https://api.us2.ddog-gov.com/api/v2/security/findings/automation/severity_modifier_rules/{rule_id}  |
| uk1.datadoghq.com | PUT https://api.uk1.datadoghq.com/api/v2/security/findings/automation/severity_modifier_rules/{rule_id} |
| app.datadoghq.com | PUT https://api.datadoghq.com/api/v2/security/findings/automation/severity_modifier_rules/{rule_id}     |
| us3.datadoghq.com | PUT https://api.us3.datadoghq.com/api/v2/security/findings/automation/severity_modifier_rules/{rule_id} |
| us5.datadoghq.com | PUT https://api.us5.datadoghq.com/api/v2/security/findings/automation/severity_modifier_rules/{rule_id} |

### Overview

Update an existing severity modifier rule by ID. This endpoint requires the `security_pipelines_write` permission.

### Arguments

#### Path Parameters

| Name                      | Type   | Description                           |
| ------------------------- | ------ | ------------------------------------- |
| rule_id [*required*] | string | The ID of the severity modifier rule. |

### Request

#### Body Data (required)



{% tab title="Model" %}

| Parent field | Field                            | Type          | Description                                                                                                                                                                                                                                                                                  |
| ------------ | -------------------------------- | ------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|              | data [*required*]           | object        | The data object for a severity modifier rule create or update request.                                                                                                                                                                                                                       |
| data         | attributes [*required*]     | object        | Attributes for creating or updating a severity modifier rule.                                                                                                                                                                                                                                |
| attributes   | action [*required*]         |  <oneOf> | The action to take when a severity modifier rule matches a finding. This is a discriminated union on `type`: `set` assigns a fixed severity, while `shift` moves the severity up or down by one rank.                                                                                        | A severity modifier rule's `rule.query` must not filter on `@severity` or on the `@severity_details.user_adjusted.*` namespace. | Use `@severity_details.adjusted.value` instead, which reflects the severity before user-defined adjustments. |
| action       | <type=set>                       | object        | Sets matched findings to a fixed severity.                                                                                                                                                                                                                                                   |
| <type=set>   | description                      | string        | An optional free-form explanation for the severity change.                                                                                                                                                                                                                                   |
| <type=set>   | severity [*required*]       | enum          | The severity to assign to matched findings. `info_none` is not supported for the `iac_misconfiguration`, `runtime_code_vulnerability`, `secret`, or `static_code_vulnerability` finding types. Allowed enum values: `info_none,low,medium,high,critical`                                     |
| <type=set>   | type [*required*]           | enum          | The type of a severity modifier rule action that sets a fixed severity. Allowed enum values: `set`                                                                                                                                                                                           |
| action       | <type=shift>                     | object        | Shifts matched findings up or down by one severity rank.                                                                                                                                                                                                                                     |
| <type=shift> | description                      | string        | An optional free-form explanation for the severity change.                                                                                                                                                                                                                                   |
| <type=shift> | severity_delta [*required*] | enum          | The direction in which to shift the severity of matched findings by one rank. Allowed enum values: `up_one,down_one`                                                                                                                                                                         |
| <type=shift> | type [*required*]           | enum          | The type of a severity modifier rule action that shifts the severity by one rank. Allowed enum values: `shift`                                                                                                                                                                               |
| attributes   | enabled                          | boolean       | Whether the severity modifier rule is enabled.                                                                                                                                                                                                                                               |
| attributes   | name [*required*]           | string        | The name of the severity modifier rule.                                                                                                                                                                                                                                                      |
| attributes   | rule [*required*]           | object        | Defines the scope of findings to which the automation rule applies.                                                                                                                                                                                                                          |
| rule         | finding_types [*required*]  | [string]      | The list of security finding types that the automation rule applies to.                                                                                                                                                                                                                      |
| rule         | query                            | string        | A search query to further filter the findings matched by this rule. The `@workflow.*` namespace and `@status` fields are not permitted. For a reference of available fields, see the [Security Findings schema documentation](https://docs.datadoghq.com/security/guide/findings-schema.md). |
| data         | type [*required*]           | enum          | The JSON:API type for severity modifier rules. Allowed enum values: `severity_modifier_rules`                                                                                                                                                                                                |

{% /tab %}

{% tab title="Example" %}

```json
{
  "data": {
    "attributes": {
      "action": {
        "description": "Lower severity for dev environment noise",
        "severity": "low",
        "type": "set"
      },
      "enabled": true,
      "name": "Downgrade misconfigurations in dev",
      "rule": {
        "finding_types": [
          "misconfiguration"
        ],
        "query": "env:prod team:platform"
      }
    },
    "type": "severity_modifier_rules"
  }
}
```

{% /tab %}

### Response

{% tab title="200" %}
Successfully updated the severity modifier rule
{% tab title="Model" %}
A single severity modifier rule response.

| Parent field | Field                            | Type          | Description                                                                                                                                                                                                                                                                                  |
| ------------ | -------------------------------- | ------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|              | data [*required*]           | object        | The data object for a severity modifier rule as returned by the API.                                                                                                                                                                                                                         |
| data         | attributes [*required*]     | object        | Attributes of a severity modifier rule as returned by the API.                                                                                                                                                                                                                               |
| attributes   | action [*required*]         |  <oneOf> | The action to take when a severity modifier rule matches a finding. This is a discriminated union on `type`: `set` assigns a fixed severity, while `shift` moves the severity up or down by one rank.                                                                                        | A severity modifier rule's `rule.query` must not filter on `@severity` or on the `@severity_details.user_adjusted.*` namespace. | Use `@severity_details.adjusted.value` instead, which reflects the severity before user-defined adjustments. |
| action       | <type=set>                       | object        | Sets matched findings to a fixed severity.                                                                                                                                                                                                                                                   |
| <type=set>   | description                      | string        | An optional free-form explanation for the severity change.                                                                                                                                                                                                                                   |
| <type=set>   | severity [*required*]       | enum          | The severity to assign to matched findings. `info_none` is not supported for the `iac_misconfiguration`, `runtime_code_vulnerability`, `secret`, or `static_code_vulnerability` finding types. Allowed enum values: `info_none,low,medium,high,critical`                                     |
| <type=set>   | type [*required*]           | enum          | The type of a severity modifier rule action that sets a fixed severity. Allowed enum values: `set`                                                                                                                                                                                           |
| action       | <type=shift>                     | object        | Shifts matched findings up or down by one severity rank.                                                                                                                                                                                                                                     |
| <type=shift> | description                      | string        | An optional free-form explanation for the severity change.                                                                                                                                                                                                                                   |
| <type=shift> | severity_delta [*required*] | enum          | The direction in which to shift the severity of matched findings by one rank. Allowed enum values: `up_one,down_one`                                                                                                                                                                         |
| <type=shift> | type [*required*]           | enum          | The type of a severity modifier rule action that shifts the severity by one rank. Allowed enum values: `shift`                                                                                                                                                                               |
| attributes   | created_at [*required*]     | int64         | The Unix timestamp in milliseconds when the rule was created.                                                                                                                                                                                                                                |
| attributes   | created_by [*required*]     | object        | The user or Datadog system who created the rule.                                                                                                                                                                                                                                             |
| created_by   | id [*required*]             | string        | The actor's identifier (a user UUID or a system identifier).                                                                                                                                                                                                                                 |
| created_by   | name [*required*]           | string        | The name of the actor.                                                                                                                                                                                                                                                                       |
| created_by   | type [*required*]           | enum          | Whether the actor is a user or the Datadog system. Allowed enum values: `user,system`                                                                                                                                                                                                        |
| attributes   | enabled [*required*]        | boolean       | Whether the severity modifier rule is enabled.                                                                                                                                                                                                                                               |
| attributes   | modified_at [*required*]    | int64         | The Unix timestamp in milliseconds when the rule was last modified.                                                                                                                                                                                                                          |
| attributes   | modified_by [*required*]    | object        | The user or Datadog system who last modified the rule.                                                                                                                                                                                                                                       |
| modified_by  | id [*required*]             | string        | The actor's identifier (a user UUID or a system identifier).                                                                                                                                                                                                                                 |
| modified_by  | name [*required*]           | string        | The name of the actor.                                                                                                                                                                                                                                                                       |
| modified_by  | type [*required*]           | enum          | Whether the actor is a user or the Datadog system. Allowed enum values: `user,system`                                                                                                                                                                                                        |
| attributes   | name [*required*]           | string        | The name of the severity modifier rule.                                                                                                                                                                                                                                                      |
| attributes   | rule [*required*]           | object        | Defines the scope of findings to which the automation rule applies.                                                                                                                                                                                                                          |
| rule         | finding_types [*required*]  | [string]      | The list of security finding types that the automation rule applies to.                                                                                                                                                                                                                      |
| rule         | query                            | string        | A search query to further filter the findings matched by this rule. The `@workflow.*` namespace and `@status` fields are not permitted. For a reference of available fields, see the [Security Findings schema documentation](https://docs.datadoghq.com/security/guide/findings-schema.md). |
| data         | id [*required*]             | uuid          | The ID of the severity modifier rule.                                                                                                                                                                                                                                                        |
| data         | type [*required*]           | enum          | The JSON:API type for severity modifier rules. Allowed enum values: `severity_modifier_rules`                                                                                                                                                                                                |

{% /tab %}

{% tab title="Example" %}

```json
{
  "data": {
    "attributes": {
      "action": {
        "description": "Lower severity for dev environment noise",
        "severity": "low",
        "type": "set"
      },
      "created_at": 1722439510282,
      "created_by": {
        "id": "00000000-0000-0000-0000-000000000000",
        "name": "Jane Doe",
        "type": "user"
      },
      "enabled": true,
      "modified_at": 1722439510282,
      "modified_by": {
        "id": "00000000-0000-0000-0000-000000000000",
        "name": "Jane Doe",
        "type": "user"
      },
      "name": "Downgrade misconfigurations in dev",
      "rule": {
        "finding_types": [
          "misconfiguration"
        ],
        "query": "env:prod team:platform"
      }
    },
    "id": "00000000-0000-0000-0000-000000000000",
    "type": "severity_modifier_rules"
  }
}
```

{% /tab %}

{% /tab %}

{% tab title="400" %}
Bad Request
{% tab title="Model" %}
API error response.

| Parent field | Field                    | Type     | Description                                                                     |
| ------------ | ------------------------ | -------- | ------------------------------------------------------------------------------- |
|              | errors [*required*] | [object] | A list of errors.                                                               |
| errors       | detail                   | string   | A human-readable explanation specific to this occurrence of the error.          |
| errors       | meta                     | object   | Non-standard meta-information about the error                                   |
| errors       | source                   | object   | References to the source of the error.                                          |
| source       | header                   | string   | A string indicating the name of a single request header which caused the error. |
| source       | parameter                | string   | A string indicating which URI query parameter caused the error.                 |
| source       | pointer                  | string   | A JSON pointer to the value in the request document that caused the error.      |
| errors       | status                   | string   | Status code of the response.                                                    |
| errors       | title                    | string   | Short human-readable summary of the error.                                      |

{% /tab %}

{% tab title="Example" %}

```json
{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}
```

{% /tab %}

{% /tab %}

{% tab title="403" %}
Forbidden
{% tab title="Model" %}
API error response.

| Field                    | Type     | Description       |
| ------------------------ | -------- | ----------------- |
| errors [*required*] | [string] | A list of errors. |

{% /tab %}

{% tab title="Example" %}

```json
{
  "errors": [
    "Bad Request"
  ]
}
```

{% /tab %}

{% /tab %}

{% tab title="404" %}
Not Found
{% tab title="Model" %}
API error response.

| Field                    | Type     | Description       |
| ------------------------ | -------- | ----------------- |
| errors [*required*] | [string] | A list of errors. |

{% /tab %}

{% tab title="Example" %}

```json
{
  "errors": [
    "Bad Request"
  ]
}
```

{% /tab %}

{% /tab %}

{% tab title="422" %}
Unprocessable Entity
{% tab title="Model" %}
API error response.

| Parent field | Field                    | Type     | Description                                                                     |
| ------------ | ------------------------ | -------- | ------------------------------------------------------------------------------- |
|              | errors [*required*] | [object] | A list of errors.                                                               |
| errors       | detail                   | string   | A human-readable explanation specific to this occurrence of the error.          |
| errors       | meta                     | object   | Non-standard meta-information about the error                                   |
| errors       | source                   | object   | References to the source of the error.                                          |
| source       | header                   | string   | A string indicating the name of a single request header which caused the error. |
| source       | parameter                | string   | A string indicating which URI query parameter caused the error.                 |
| source       | pointer                  | string   | A JSON pointer to the value in the request document that caused the error.      |
| errors       | status                   | string   | Status code of the response.                                                    |
| errors       | title                    | string   | Short human-readable summary of the error.                                      |

{% /tab %}

{% tab title="Example" %}

```json
{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}
```

{% /tab %}

{% /tab %}

{% tab title="429" %}
Too many requests
{% tab title="Model" %}
API error response.

| Field                    | Type     | Description       |
| ------------------------ | -------- | ----------------- |
| errors [*required*] | [string] | A list of errors. |

{% /tab %}

{% tab title="Example" %}

```json
{
  "errors": [
    "Bad Request"
  ]
}
```

{% /tab %}

{% /tab %}

### Code Example

##### 
                          \## default
# 
 \# Path parameters export rule_id="00000000-0000-0000-0000-000000000000" \# Curl command curl -X PUT "https://api.datadoghq.com/api/v2/security/findings/automation/severity_modifier_rules/${rule_id}" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "DD-API-KEY: ${DD_API_KEY}" \
-H "DD-APPLICATION-KEY: ${DD_APP_KEY}" \
-d @- << EOF
{
  "data": {
    "attributes": {
      "action": {
        "severity_delta": "down_one",
        "type": "shift"
      },
      "enabled": false,
      "name": "Downgrade misconfigurations in dev",
      "rule": {
        "finding_types": [
          "misconfiguration"
        ],
        "query": "env:dev"
      }
    },
    "type": "severity_modifier_rules"
  }
}
EOF 
                        
##### 

```go
// Update a severity modifier rule returns "Successfully updated the severity modifier rule" response

package main

import (
	"context"
	"encoding/json"
	"fmt"
	"os"

	"github.com/DataDog/datadog-api-client-go/v2/api/datadog"
	"github.com/DataDog/datadog-api-client-go/v2/api/datadogV2"
	"github.com/google/uuid"
)

func main() {
	// there is a valid "valid_severity_modifier_rule" in the system
	ValidSeverityModifierRuleDataID := uuid.MustParse(os.Getenv("VALID_SEVERITY_MODIFIER_RULE_DATA_ID"))

	body := datadogV2.SeverityModifierRuleUpdateRequest{
		Data: datadogV2.SeverityModifierRuleDataCreate{
			Attributes: datadogV2.SeverityModifierRuleAttributesCreate{
				Action: datadogV2.SeverityModifierRuleAction{
					SeverityModifierRuleSetAction: &datadogV2.SeverityModifierRuleSetAction{
						Description: datadog.PtrString("Lower severity for dev environment noise"),
						Severity:    datadogV2.SEVERITYMODIFIERSEVERITY_LOW,
						Type:        datadogV2.SEVERITYMODIFIERRULESETACTIONTYPE_SET,
					}},
				Enabled: datadog.PtrBool(true),
				Name:    "Downgrade misconfigurations in dev",
				Rule: datadogV2.AutomationRuleScope{
					FindingTypes: []datadogV2.SecurityFindingType{
						datadogV2.SECURITYFINDINGTYPE_MISCONFIGURATION,
					},
					Query: datadog.PtrString("env:prod team:platform"),
				},
			},
			Type: datadogV2.SEVERITYMODIFIERRULETYPE_SEVERITY_MODIFIER_RULES,
		},
	}
	ctx := datadog.NewDefaultContext(context.Background())
	configuration := datadog.NewConfiguration()
	configuration.SetUnstableOperationEnabled("v2.UpdateSecurityFindingsAutomationSeverityModifierRule", true)
	apiClient := datadog.NewAPIClient(configuration)
	api := datadogV2.NewSecurityMonitoringApi(apiClient)
	resp, r, err := api.UpdateSecurityFindingsAutomationSeverityModifierRule(ctx, ValidSeverityModifierRuleDataID, body)

	if err != nil {
		fmt.Fprintf(os.Stderr, "Error when calling `SecurityMonitoringApi.UpdateSecurityFindingsAutomationSeverityModifierRule`: %v\n", err)
		fmt.Fprintf(os.Stderr, "Full HTTP response: %v\n", r)
	}

	responseContent, _ := json.MarshalIndent(resp, "", "  ")
	fmt.Fprintf(os.Stdout, "Response from `SecurityMonitoringApi.UpdateSecurityFindingsAutomationSeverityModifierRule`:\n%s\n", responseContent)
}
```

#### Instructions

First [install the library and its dependencies](https://docs.datadoghq.com/api/latest.md?code-lang=go) and then save the example to `main.go` and run following commands:
    DD_SITE="datadoghq.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" go run "main.go"
##### 

```java
// Update a severity modifier rule returns "Successfully updated the severity modifier rule"
// response

import com.datadog.api.client.ApiClient;
import com.datadog.api.client.ApiException;
import com.datadog.api.client.v2.api.SecurityMonitoringApi;
import com.datadog.api.client.v2.model.AutomationRuleScope;
import com.datadog.api.client.v2.model.SecurityFindingType;
import com.datadog.api.client.v2.model.SeverityModifierRuleAction;
import com.datadog.api.client.v2.model.SeverityModifierRuleAttributesCreate;
import com.datadog.api.client.v2.model.SeverityModifierRuleDataCreate;
import com.datadog.api.client.v2.model.SeverityModifierRuleResponse;
import com.datadog.api.client.v2.model.SeverityModifierRuleSetAction;
import com.datadog.api.client.v2.model.SeverityModifierRuleSetActionType;
import com.datadog.api.client.v2.model.SeverityModifierRuleType;
import com.datadog.api.client.v2.model.SeverityModifierRuleUpdateRequest;
import com.datadog.api.client.v2.model.SeverityModifierSeverity;
import java.util.Collections;
import java.util.UUID;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = ApiClient.getDefaultApiClient();
    defaultClient.setUnstableOperationEnabled(
        "v2.updateSecurityFindingsAutomationSeverityModifierRule", true);
    SecurityMonitoringApi apiInstance = new SecurityMonitoringApi(defaultClient);

    // there is a valid "valid_severity_modifier_rule" in the system
    UUID VALID_SEVERITY_MODIFIER_RULE_DATA_ID = null;
    try {
      VALID_SEVERITY_MODIFIER_RULE_DATA_ID =
          UUID.fromString(System.getenv("VALID_SEVERITY_MODIFIER_RULE_DATA_ID"));
    } catch (IllegalArgumentException e) {
      System.err.println("Error parsing UUID: " + e.getMessage());
    }

    SeverityModifierRuleUpdateRequest body =
        new SeverityModifierRuleUpdateRequest()
            .data(
                new SeverityModifierRuleDataCreate()
                    .attributes(
                        new SeverityModifierRuleAttributesCreate()
                            .action(
                                new SeverityModifierRuleAction(
                                    new SeverityModifierRuleSetAction()
                                        .description("Lower severity for dev environment noise")
                                        .severity(SeverityModifierSeverity.LOW)
                                        .type(SeverityModifierRuleSetActionType.SET)))
                            .enabled(true)
                            .name("Downgrade misconfigurations in dev")
                            .rule(
                                new AutomationRuleScope()
                                    .findingTypes(
                                        Collections.singletonList(
                                            SecurityFindingType.MISCONFIGURATION))
                                    .query("env:prod team:platform")))
                    .type(SeverityModifierRuleType.SEVERITY_MODIFIER_RULES));

    try {
      SeverityModifierRuleResponse result =
          apiInstance.updateSecurityFindingsAutomationSeverityModifierRule(
              VALID_SEVERITY_MODIFIER_RULE_DATA_ID, body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println(
          "Exception when calling"
              + " SecurityMonitoringApi#updateSecurityFindingsAutomationSeverityModifierRule");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}
```

#### Instructions

First [install the library and its dependencies](https://docs.datadoghq.com/api/latest.md?code-lang=java) and then save the example to `Example.java` and run following commands:
    DD_SITE="datadoghq.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" java "Example.java"
##### 

```python
"""
Update a severity modifier rule returns "Successfully updated the severity modifier rule" response
"""

from os import environ
from datadog_api_client import ApiClient, Configuration
from datadog_api_client.v2.api.security_monitoring_api import SecurityMonitoringApi
from datadog_api_client.v2.model.automation_rule_scope import AutomationRuleScope
from datadog_api_client.v2.model.security_finding_type import SecurityFindingType
from datadog_api_client.v2.model.severity_modifier_rule_attributes_create import SeverityModifierRuleAttributesCreate
from datadog_api_client.v2.model.severity_modifier_rule_data_create import SeverityModifierRuleDataCreate
from datadog_api_client.v2.model.severity_modifier_rule_set_action import SeverityModifierRuleSetAction
from datadog_api_client.v2.model.severity_modifier_rule_set_action_type import SeverityModifierRuleSetActionType
from datadog_api_client.v2.model.severity_modifier_rule_type import SeverityModifierRuleType
from datadog_api_client.v2.model.severity_modifier_rule_update_request import SeverityModifierRuleUpdateRequest
from datadog_api_client.v2.model.severity_modifier_severity import SeverityModifierSeverity

# there is a valid "valid_severity_modifier_rule" in the system
VALID_SEVERITY_MODIFIER_RULE_DATA_ID = environ["VALID_SEVERITY_MODIFIER_RULE_DATA_ID"]

body = SeverityModifierRuleUpdateRequest(
    data=SeverityModifierRuleDataCreate(
        attributes=SeverityModifierRuleAttributesCreate(
            action=SeverityModifierRuleSetAction(
                description="Lower severity for dev environment noise",
                severity=SeverityModifierSeverity.LOW,
                type=SeverityModifierRuleSetActionType.SET,
            ),
            enabled=True,
            name="Downgrade misconfigurations in dev",
            rule=AutomationRuleScope(
                finding_types=[
                    SecurityFindingType.MISCONFIGURATION,
                ],
                query="env:prod team:platform",
            ),
        ),
        type=SeverityModifierRuleType.SEVERITY_MODIFIER_RULES,
    ),
)

configuration = Configuration()
configuration.unstable_operations["update_security_findings_automation_severity_modifier_rule"] = True
with ApiClient(configuration) as api_client:
    api_instance = SecurityMonitoringApi(api_client)
    response = api_instance.update_security_findings_automation_severity_modifier_rule(
        rule_id=VALID_SEVERITY_MODIFIER_RULE_DATA_ID, body=body
    )

    print(response)
```

#### Instructions

First [install the library and its dependencies](https://docs.datadoghq.com/api/latest.md?code-lang=python) and then save the example to `example.py` and run following commands:
    DD_SITE="datadoghq.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" python3 "example.py"
##### 

```ruby
# Update a severity modifier rule returns "Successfully updated the severity modifier rule" response

require "datadog_api_client"
DatadogAPIClient.configure do |config|
  config.unstable_operations["v2.update_security_findings_automation_severity_modifier_rule".to_sym] = true
end
api_instance = DatadogAPIClient::V2::SecurityMonitoringAPI.new

# there is a valid "valid_severity_modifier_rule" in the system
VALID_SEVERITY_MODIFIER_RULE_DATA_ID = ENV["VALID_SEVERITY_MODIFIER_RULE_DATA_ID"]

body = DatadogAPIClient::V2::SeverityModifierRuleUpdateRequest.new({
  data: DatadogAPIClient::V2::SeverityModifierRuleDataCreate.new({
    attributes: DatadogAPIClient::V2::SeverityModifierRuleAttributesCreate.new({
      action: DatadogAPIClient::V2::SeverityModifierRuleSetAction.new({
        description: "Lower severity for dev environment noise",
        severity: DatadogAPIClient::V2::SeverityModifierSeverity::LOW,
        type: DatadogAPIClient::V2::SeverityModifierRuleSetActionType::SET,
      }),
      enabled: true,
      name: "Downgrade misconfigurations in dev",
      rule: DatadogAPIClient::V2::AutomationRuleScope.new({
        finding_types: [
          DatadogAPIClient::V2::SecurityFindingType::MISCONFIGURATION,
        ],
        query: "env:prod team:platform",
      }),
    }),
    type: DatadogAPIClient::V2::SeverityModifierRuleType::SEVERITY_MODIFIER_RULES,
  }),
})
p api_instance.update_security_findings_automation_severity_modifier_rule(VALID_SEVERITY_MODIFIER_RULE_DATA_ID, body)
```

#### Instructions

First [install the library and its dependencies](https://docs.datadoghq.com/api/latest.md?code-lang=ruby) and then save the example to `example.rb` and run following commands:
    DD_SITE="datadoghq.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" rb "example.rb"
##### 

```rust
// Update a severity modifier rule returns "Successfully updated the severity
// modifier rule" response
use datadog_api_client::datadog;
use datadog_api_client::datadogV2::api_security_monitoring::SecurityMonitoringAPI;
use datadog_api_client::datadogV2::model::AutomationRuleScope;
use datadog_api_client::datadogV2::model::SecurityFindingType;
use datadog_api_client::datadogV2::model::SeverityModifierRuleAction;
use datadog_api_client::datadogV2::model::SeverityModifierRuleAttributesCreate;
use datadog_api_client::datadogV2::model::SeverityModifierRuleDataCreate;
use datadog_api_client::datadogV2::model::SeverityModifierRuleSetAction;
use datadog_api_client::datadogV2::model::SeverityModifierRuleSetActionType;
use datadog_api_client::datadogV2::model::SeverityModifierRuleType;
use datadog_api_client::datadogV2::model::SeverityModifierRuleUpdateRequest;
use datadog_api_client::datadogV2::model::SeverityModifierSeverity;

#[tokio::main]
async fn main() {
    // there is a valid "valid_severity_modifier_rule" in the system
    let valid_severity_modifier_rule_data_id =
        uuid::Uuid::parse_str(&std::env::var("VALID_SEVERITY_MODIFIER_RULE_DATA_ID").unwrap())
            .expect("Invalid UUID");
    let body = SeverityModifierRuleUpdateRequest::new(SeverityModifierRuleDataCreate::new(
        SeverityModifierRuleAttributesCreate::new(
            SeverityModifierRuleAction::SeverityModifierRuleSetAction(Box::new(
                SeverityModifierRuleSetAction::new(
                    SeverityModifierSeverity::LOW,
                    SeverityModifierRuleSetActionType::SET,
                )
                .description("Lower severity for dev environment noise".to_string()),
            )),
            "Downgrade misconfigurations in dev".to_string(),
            AutomationRuleScope::new(vec![SecurityFindingType::MISCONFIGURATION])
                .query("env:prod team:platform".to_string()),
        )
        .enabled(true),
        SeverityModifierRuleType::SEVERITY_MODIFIER_RULES,
    ));
    let mut configuration = datadog::Configuration::new();
    configuration.set_unstable_operation_enabled(
        "v2.UpdateSecurityFindingsAutomationSeverityModifierRule",
        true,
    );
    let api = SecurityMonitoringAPI::with_config(configuration);
    let resp = api
        .update_security_findings_automation_severity_modifier_rule(
            valid_severity_modifier_rule_data_id.clone(),
            body,
        )
        .await;
    if let Ok(value) = resp {
        println!("{:#?}", value);
    } else {
        println!("{:#?}", resp.unwrap_err());
    }
}
```

#### Instructions

First [install the library and its dependencies](https://docs.datadoghq.com/api/latest.md?code-lang=rust) and then save the example to `src/main.rs` and run following commands:
    DD_SITE="datadoghq.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" cargo run
##### 

```typescript
/**
 * Update a severity modifier rule returns "Successfully updated the severity modifier rule" response
 */

import { client, v2 } from "@datadog/datadog-api-client";

const configuration = client.createConfiguration();
configuration.unstableOperations[
  "v2.updateSecurityFindingsAutomationSeverityModifierRule"
] = true;
const apiInstance = new v2.SecurityMonitoringApi(configuration);

// there is a valid "valid_severity_modifier_rule" in the system
const VALID_SEVERITY_MODIFIER_RULE_DATA_ID = process.env
  .VALID_SEVERITY_MODIFIER_RULE_DATA_ID as string;

const params: v2.SecurityMonitoringApiUpdateSecurityFindingsAutomationSeverityModifierRuleRequest =
  {
    body: {
      data: {
        attributes: {
          action: {
            description: "Lower severity for dev environment noise",
            severity: "low",
            type: "set",
          },
          enabled: true,
          name: "Downgrade misconfigurations in dev",
          rule: {
            findingTypes: ["misconfiguration"],
            query: "env:prod team:platform",
          },
        },
        type: "severity_modifier_rules",
      },
    },
    ruleId: VALID_SEVERITY_MODIFIER_RULE_DATA_ID,
  };

apiInstance
  .updateSecurityFindingsAutomationSeverityModifierRule(params)
  .then((data: v2.SeverityModifierRuleResponse) => {
    console.log(
      "API called successfully. Returned data: " + JSON.stringify(data)
    );
  })
  .catch((error: any) => console.error(error));
```

#### Instructions

First [install the library and its dependencies](https://docs.datadoghq.com/api/latest.md?code-lang=typescript) and then save the example to `example.ts` and run following commands:
    DD_SITE="datadoghq.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" tsc "example.ts"
{% /tab %}
