Créer un nouveau filtre d’exclusion WAF avec les paramètres fournis.
Une requête correspondant à un filtre d’exclusion sera ignorée par le produit WAF Application Security.
Accédez à https://app.datadoghq.com/security/appsec/passlist pour consulter les filtres d’exclusion existants (également appelés entrées de liste d’autorisation).
This endpoint requires the appsec_protect_write permission.
Object for creating a single WAF exclusion filter.
attributes [required]
object
Attributes for creating a WAF exclusion filter.
description [required]
string
A description for the exclusion filter.
enabled [required]
boolean
Indicates whether the exclusion filter is enabled.
ip_list
[string]
The client IP addresses matched by the exclusion filter (CIDR notation is supported).
on_match
enum
The action taken when the exclusion filter matches. When set to monitor, security traces are emitted but the requests are not blocked. By default, security traces are not emitted and the requests are not blocked.
Allowed enum values: monitor
parameters
[string]
A list of parameters matched by the exclusion filter in the HTTP query string and HTTP request body. Nested parameters can be matched by joining fields with a dot character.
path_glob
string
The HTTP path glob expression matched by the exclusion filter.
rules_target
[object]
The WAF rules targeted by the exclusion filter.
rule_id
string
Target a single WAF rule based on its identifier.
tags
object
Target multiple WAF rules based on their tags.
category
string
The category of the targeted WAF rules.
type
string
The type of the targeted WAF rules.
scope
[object]
The services where the exclusion filter is deployed.
env
string
Deploy on this environment.
service
string
Deploy on this service.
type [required]
enum
Type of the resource. The value should always be exclusion_filter.
Allowed enum values: exclusion_filter
default: exclusion_filter
{"data":{"attributes":{"description":"Exclude false positives on a path","enabled":true,"parameters":["list.search.query"],"path_glob":"/accounts/*","rules_target":[{"tags":{"category":"attack_attempt","type":"lfi"}}],"scope":[{"env":"www","service":"prod"}]},"type":"exclusion_filter"}}
Response object for a single WAF exclusion filter.
Expand All
Champ
Type
Description
data
object
A JSON:API resource for an WAF exclusion filter.
attributes
object
Attributes describing a WAF exclusion filter.
description
string
A description for the exclusion filter.
enabled
boolean
Indicates whether the exclusion filter is enabled.
event_query
string
The event query matched by the legacy exclusion filter. Cannot be created nor updated.
ip_list
[string]
The client IP addresses matched by the exclusion filter (CIDR notation is supported).
metadata
object
Extra information about the exclusion filter.
added_at
date-time
The creation date of the exclusion filter.
added_by
string
The handle of the user who created the exclusion filter.
added_by_name
string
The name of the user who created the exclusion filter.
modified_at
date-time
The last modification date of the exclusion filter.
modified_by
string
The handle of the user who last modified the exclusion filter.
modified_by_name
string
The name of the user who last modified the exclusion filter.
on_match
enum
The action taken when the exclusion filter matches. When set to monitor, security traces are emitted but the requests are not blocked. By default, security traces are not emitted and the requests are not blocked.
Allowed enum values: monitor
parameters
[string]
A list of parameters matched by the exclusion filter in the HTTP query string and HTTP request body. Nested parameters can be matched by joining fields with a dot character.
path_glob
string
The HTTP path glob expression matched by the exclusion filter.
rules_target
[object]
The WAF rules targeted by the exclusion filter.
rule_id
string
Target a single WAF rule based on its identifier.
tags
object
Target multiple WAF rules based on their tags.
category
string
The category of the targeted WAF rules.
type
string
The type of the targeted WAF rules.
scope
[object]
The services where the exclusion filter is deployed.
env
string
Deploy on this environment.
service
string
Deploy on this service.
search_query
string
Generated event search query for traces matching the exclusion filter.
id
string
The identifier of the WAF exclusion filter.
type
enum
Type of the resource. The value should always be exclusion_filter.
Allowed enum values: exclusion_filter
default: exclusion_filter
{"data":{"attributes":{"description":"Exclude false positives on a path","enabled":true,"event_query":"string","ip_list":["198.51.100.72"],"metadata":{"added_at":"2019-09-19T10:00:00.000Z","added_by":"string","added_by_name":"string","modified_at":"2019-09-19T10:00:00.000Z","modified_by":"string","modified_by_name":"string"},"on_match":"string","parameters":["list.search.query"],"path_glob":"/accounts/*","rules_target":[{"rule_id":"dog-913-009","tags":{"category":"attack_attempt","type":"lfi"}}],"scope":[{"env":"www","service":"prod"}],"search_query":"string"},"id":"3dd-0uc-h1s","type":"exclusion_filter"}}
// Create a WAF exclusion filter returns "OK" responsepackagemainimport("context""encoding/json""fmt""os""github.com/DataDog/datadog-api-client-go/v2/api/datadog""github.com/DataDog/datadog-api-client-go/v2/api/datadogV2")funcmain(){body:=datadogV2.ApplicationSecurityWafExclusionFilterCreateRequest{Data:datadogV2.ApplicationSecurityWafExclusionFilterCreateData{Attributes:datadogV2.ApplicationSecurityWafExclusionFilterCreateAttributes{Description:"Exclude false positives on a path",Enabled:true,Parameters:[]string{"list.search.query",},PathGlob:datadog.PtrString("/accounts/*"),RulesTarget:[]datadogV2.ApplicationSecurityWafExclusionFilterRulesTarget{{Tags:&datadogV2.ApplicationSecurityWafExclusionFilterRulesTargetTags{Category:datadog.PtrString("attack_attempt"),Type:datadog.PtrString("lfi"),},},},Scope:[]datadogV2.ApplicationSecurityWafExclusionFilterScope{{Env:datadog.PtrString("www"),Service:datadog.PtrString("prod"),},},},Type:datadogV2.APPLICATIONSECURITYWAFEXCLUSIONFILTERTYPE_EXCLUSION_FILTER,},}ctx:=datadog.NewDefaultContext(context.Background())configuration:=datadog.NewConfiguration()apiClient:=datadog.NewAPIClient(configuration)api:=datadogV2.NewApplicationSecurityApi(apiClient)resp,r,err:=api.CreateApplicationSecurityWafExclusionFilter(ctx,body)iferr!=nil{fmt.Fprintf(os.Stderr,"Error when calling `ApplicationSecurityApi.CreateApplicationSecurityWafExclusionFilter`: %v\n",err)fmt.Fprintf(os.Stderr,"Full HTTP response: %v\n",r)}responseContent,_:=json.MarshalIndent(resp,""," ")fmt.Fprintf(os.Stdout,"Response from `ApplicationSecurityApi.CreateApplicationSecurityWafExclusionFilter`:\n%s\n",responseContent)}
"""
Create a WAF exclusion filter returns "OK" response
"""fromdatadog_api_clientimportApiClient,Configurationfromdatadog_api_client.v2.api.application_security_apiimportApplicationSecurityApifromdatadog_api_client.v2.model.application_security_waf_exclusion_filter_create_attributesimport(ApplicationSecurityWafExclusionFilterCreateAttributes,)fromdatadog_api_client.v2.model.application_security_waf_exclusion_filter_create_dataimport(ApplicationSecurityWafExclusionFilterCreateData,)fromdatadog_api_client.v2.model.application_security_waf_exclusion_filter_create_requestimport(ApplicationSecurityWafExclusionFilterCreateRequest,)fromdatadog_api_client.v2.model.application_security_waf_exclusion_filter_rules_targetimport(ApplicationSecurityWafExclusionFilterRulesTarget,)fromdatadog_api_client.v2.model.application_security_waf_exclusion_filter_rules_target_tagsimport(ApplicationSecurityWafExclusionFilterRulesTargetTags,)fromdatadog_api_client.v2.model.application_security_waf_exclusion_filter_scopeimport(ApplicationSecurityWafExclusionFilterScope,)fromdatadog_api_client.v2.model.application_security_waf_exclusion_filter_typeimport(ApplicationSecurityWafExclusionFilterType,)body=ApplicationSecurityWafExclusionFilterCreateRequest(data=ApplicationSecurityWafExclusionFilterCreateData(attributes=ApplicationSecurityWafExclusionFilterCreateAttributes(description="Exclude false positives on a path",enabled=True,parameters=["list.search.query",],path_glob="/accounts/*",rules_target=[ApplicationSecurityWafExclusionFilterRulesTarget(tags=ApplicationSecurityWafExclusionFilterRulesTargetTags(category="attack_attempt",type="lfi",),),],scope=[ApplicationSecurityWafExclusionFilterScope(env="www",service="prod",),],),type=ApplicationSecurityWafExclusionFilterType.EXCLUSION_FILTER,),)configuration=Configuration()withApiClient(configuration)asapi_client:api_instance=ApplicationSecurityApi(api_client)response=api_instance.create_application_security_waf_exclusion_filter(body=body)print(response)
# Create a WAF exclusion filter returns "OK" responserequire"datadog_api_client"api_instance=DatadogAPIClient::V2::ApplicationSecurityAPI.newbody=DatadogAPIClient::V2::ApplicationSecurityWafExclusionFilterCreateRequest.new({data:DatadogAPIClient::V2::ApplicationSecurityWafExclusionFilterCreateData.new({attributes:DatadogAPIClient::V2::ApplicationSecurityWafExclusionFilterCreateAttributes.new({description:"Exclude false positives on a path",enabled:true,parameters:["list.search.query",],path_glob:"/accounts/*",rules_target:[DatadogAPIClient::V2::ApplicationSecurityWafExclusionFilterRulesTarget.new({tags:DatadogAPIClient::V2::ApplicationSecurityWafExclusionFilterRulesTargetTags.new({category:"attack_attempt",type:"lfi",}),}),],scope:[DatadogAPIClient::V2::ApplicationSecurityWafExclusionFilterScope.new({env:"www",service:"prod",}),],}),type:DatadogAPIClient::V2::ApplicationSecurityWafExclusionFilterType::EXCLUSION_FILTER,}),})papi_instance.create_application_security_waf_exclusion_filter(body)
// Create a WAF exclusion filter returns "OK" response
usedatadog_api_client::datadog;usedatadog_api_client::datadogV2::api_application_security::ApplicationSecurityAPI;usedatadog_api_client::datadogV2::model::ApplicationSecurityWafExclusionFilterCreateAttributes;usedatadog_api_client::datadogV2::model::ApplicationSecurityWafExclusionFilterCreateData;usedatadog_api_client::datadogV2::model::ApplicationSecurityWafExclusionFilterCreateRequest;usedatadog_api_client::datadogV2::model::ApplicationSecurityWafExclusionFilterRulesTarget;usedatadog_api_client::datadogV2::model::ApplicationSecurityWafExclusionFilterRulesTargetTags;usedatadog_api_client::datadogV2::model::ApplicationSecurityWafExclusionFilterScope;usedatadog_api_client::datadogV2::model::ApplicationSecurityWafExclusionFilterType;usestd::collections::BTreeMap;#[tokio::main]asyncfnmain(){letbody=ApplicationSecurityWafExclusionFilterCreateRequest::new(ApplicationSecurityWafExclusionFilterCreateData::new(ApplicationSecurityWafExclusionFilterCreateAttributes::new("Exclude false positives on a path".to_string(),true,).parameters(vec!["list.search.query".to_string()]).path_glob("/accounts/*".to_string()).rules_target(vec![ApplicationSecurityWafExclusionFilterRulesTarget::new().tags(ApplicationSecurityWafExclusionFilterRulesTargetTags::new().category("attack_attempt".to_string()).type_("lfi".to_string()).additional_properties(BTreeMap::from([])),)]).scope(vec![ApplicationSecurityWafExclusionFilterScope::new().env("www".to_string()).service("prod".to_string())]),ApplicationSecurityWafExclusionFilterType::EXCLUSION_FILTER,),);letconfiguration=datadog::Configuration::new();letapi=ApplicationSecurityAPI::with_config(configuration);letresp=api.create_application_security_waf_exclusion_filter(body).await;ifletOk(value)=resp{println!("{:#?}",value);}else{println!("{:#?}",resp.unwrap_err());}}
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com"DD_API_KEY="<API-KEY>"DD_APP_KEY="<APP-KEY>"cargo run
/**
* Create a WAF exclusion filter returns "OK" response
*/import{client,v2}from"@datadog/datadog-api-client";constconfiguration=client.createConfiguration();constapiInstance=newv2.ApplicationSecurityApi(configuration);constparams: v2.ApplicationSecurityApiCreateApplicationSecurityWafExclusionFilterRequest={body:{data:{attributes:{description:"Exclude false positives on a path",enabled: true,parameters:["list.search.query"],pathGlob:"/accounts/*",rulesTarget:[{tags:{category:"attack_attempt",type:"lfi",},},],scope:[{env:"www",service:"prod",},],},type:"exclusion_filter",},},};apiInstance.createApplicationSecurityWafExclusionFilter(params).then((data: v2.ApplicationSecurityWafExclusionFilterResponse)=>{console.log("API called successfully. Returned data: "+JSON.stringify(data));}).catch((error: any)=>console.error(error));