Récupérer les états d’activation et de configuration de tous les packs de contenu de surveillance de la sécurité.
Cet endpoint renvoie des informations de statut sur chaque pack de contenu, notamment l’état d’activation,
le statut d’intégration et le statut de collecte des logs.
This endpoint requires
any
of the following permissions:
security_monitoring_filters_read
logs_read_index_data
OAuth apps require the security_monitoring_filters_read authorization scope to access this endpoint.
Type-specific details for a content pack state. The set of fields present depends
on the content pack's type. When Cloud SIEM is inactive for the requesting organization, onboarding is returned instead of the content pack's usual type, such as logs or vulnerability.`
<type=logs>
object
Details for a logs-based content pack.
cp_activation [required]
enum
The activation status of a content pack.
Allowed enum values: never_activated,activated,deactivated
data_last_seen [required]
enum
Timestamp bucket indicating when logs were last collected.
Allowed enum values: not_seen,within_24_hours,within_24_to_72_hours,over_72h_to_30d,over_30d
filters_configured [required]
boolean
Whether filters (Security Filters or Index Query depending on the pricing model) are
present and correctly configured to route logs into Cloud SIEM.
integration_installed_status [required]
enum
The installation status of the related integration.
Allowed enum values: installed,available,partially_installed,detected,error
logs_seen_from_any_index [required]
boolean
Whether logs for this content pack have been seen in any Datadog index in the last 72 hours.
siem_index_incorrect [required]
boolean
Whether the Cloud SIEM index configuration is incorrect (only applies to certain pricing models).
type [required]
enum
The filtered data type.
Allowed enum values: logs
<type=threat_intel>
object
Details for a threat intelligence content pack.
cp_activation [required]
enum
The activation status of a content pack.
Allowed enum values: never_activated,activated,deactivated
data_last_seen [required]
enum
Timestamp bucket indicating when logs were last collected.
Allowed enum values: not_seen,within_24_hours,within_24_to_72_hours,over_72h_to_30d,over_30d
integration_installed_status [required]
enum
The installation status of the related integration.
Allowed enum values: installed,available,partially_installed,detected,error
type [required]
enum
Type for threat intelligence content pack details.
Allowed enum values: threat_intel
<type=entity>
object
Details for an entity or identity content pack.
cp_activation [required]
enum
The activation status of a content pack.
Allowed enum values: never_activated,activated,deactivated
type [required]
enum
Type for entity content pack details.
Allowed enum values: entity
<type=audit>
object
Details for an audit trail content pack.
type [required]
enum
Type for audit trail content pack details.
Allowed enum values: audit
<type=appsec>
object
Details for an Application Security content pack.
type [required]
enum
Type for Application Security content pack details.
Allowed enum values: appsec
<type=vulnerability>
object
Details for a vulnerability content pack.
cp_activation [required]
enum
The activation status of a content pack.
Allowed enum values: never_activated,activated,deactivated
data_last_seen [required]
enum
Timestamp bucket indicating when logs were last collected.
Allowed enum values: not_seen,within_24_hours,within_24_to_72_hours,over_72h_to_30d,over_30d
integration_installed_status [required]
enum
The installation status of the related integration.
Allowed enum values: installed,available,partially_installed,detected,error
type [required]
enum
Type for vulnerability content pack details.
Allowed enum values: vulnerability
<type=onboarding>
object
Content pack details returned when Cloud SIEM is inactive for the requesting organization.
integration_installed_status
enum
The installation status of the related integration.
Allowed enum values: installed,available,partially_installed,detected,error
logs_seen_from_any_index [required]
boolean
Whether logs for this content pack have been seen in any Datadog index in the last 72 hours.
type [required]
enum
Type for onboarding content pack details.
Allowed enum values: onboarding
status [required]
enum
The current operational status of a content pack.
Allowed enum values: install,activate,initializing,active,warning,broken,not_configured
id [required]
string
The content pack identifier.
type [required]
enum
Type for content pack state object
Allowed enum values: content_pack_state
meta [required]
object
Metadata for content pack states.
cloud_siem_index_incorrect [required]
boolean
Whether the Cloud SIEM index configuration is incorrect for the organization.
retention_months
int32
The number of months that standard logs are retained for organizations on the standalone_indexed` pricing model. This field is omitted for other pricing models.
sku [required]
enum
The Cloud SIEM pricing model (SKU) for the organization.
Allowed enum values: per_gb_analyzed,per_event_in_siem_index_2023,add_on_2024,standalone_indexed,unknown
"""
Get content pack states returns "OK" response
"""fromdatadog_api_clientimportApiClient,Configurationfromdatadog_api_client.v2.api.security_monitoring_apiimportSecurityMonitoringApiconfiguration=Configuration()configuration.unstable_operations["get_content_packs_states"]=TruewithApiClient(configuration)asapi_client:api_instance=SecurityMonitoringApi(api_client)response=api_instance.get_content_packs_states()print(response)
# Get content pack states returns "OK" responserequire"datadog_api_client"DatadogAPIClient.configuredo|config|config.unstable_operations["v2.get_content_packs_states".to_sym]=trueendapi_instance=DatadogAPIClient::V2::SecurityMonitoringAPI.newpapi_instance.get_content_packs_states()
// Get content pack states returns "OK" responsepackagemainimport("context""encoding/json""fmt""os""github.com/DataDog/datadog-api-client-go/v2/api/datadog""github.com/DataDog/datadog-api-client-go/v2/api/datadogV2")funcmain(){ctx:=datadog.NewDefaultContext(context.Background())configuration:=datadog.NewConfiguration()configuration.SetUnstableOperationEnabled("v2.GetContentPacksStates",true)apiClient:=datadog.NewAPIClient(configuration)api:=datadogV2.NewSecurityMonitoringApi(apiClient)resp,r,err:=api.GetContentPacksStates(ctx)iferr!=nil{fmt.Fprintf(os.Stderr,"Error when calling `SecurityMonitoringApi.GetContentPacksStates`: %v\n",err)fmt.Fprintf(os.Stderr,"Full HTTP response: %v\n",r)}responseContent,_:=json.MarshalIndent(resp,""," ")fmt.Fprintf(os.Stdout,"Response from `SecurityMonitoringApi.GetContentPacksStates`:\n%s\n",responseContent)}
// Get content pack states returns "OK" response
usedatadog_api_client::datadog;usedatadog_api_client::datadogV2::api_security_monitoring::SecurityMonitoringAPI;#[tokio::main]asyncfnmain(){letmutconfiguration=datadog::Configuration::new();configuration.set_unstable_operation_enabled("v2.GetContentPacksStates",true);letapi=SecurityMonitoringAPI::with_config(configuration);letresp=api.get_content_packs_states().await;ifletOk(value)=resp{println!("{:#?}",value);}else{println!("{:#?}",resp.unwrap_err());}}
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com"DD_API_KEY="<DD_API_KEY>"DD_APP_KEY="<DD_APP_KEY>"cargo run
/**
* Get content pack states returns "OK" response
*/import{client,v2}from"@datadog/datadog-api-client";constconfiguration=client.createConfiguration();configuration.unstableOperations["v2.getContentPacksStates"]=true;constapiInstance=newv2.SecurityMonitoringApi(configuration);apiInstance.getContentPacksStates().then((data: v2.SecurityMonitoringContentPackStatesResponse)=>{console.log("API called successfully. Returned data: "+JSON.stringify(data));}).catch((error: any)=>console.error(error));