Get content pack states

Note: This endpoint is in preview and is subject to change. If you have any feedback, contact Datadog support.

GET https://api.ap1.datadoghq.com/api/v2/security_monitoring/content_packs/stateshttps://api.ap2.datadoghq.com/api/v2/security_monitoring/content_packs/stateshttps://api.datadoghq.eu/api/v2/security_monitoring/content_packs/stateshttps://api.ddog-gov.com/api/v2/security_monitoring/content_packs/stateshttps://api.us2.ddog-gov.com/api/v2/security_monitoring/content_packs/stateshttps://api.uk1.datadoghq.com/api/v2/security_monitoring/content_packs/stateshttps://api.datadoghq.com/api/v2/security_monitoring/content_packs/stateshttps://api.us3.datadoghq.com/api/v2/security_monitoring/content_packs/stateshttps://api.us5.datadoghq.com/api/v2/security_monitoring/content_packs/states

Présentation

Récupérer les états d’activation et de configuration de tous les packs de contenu de surveillance de la sécurité. Cet endpoint renvoie des informations de statut sur chaque pack de contenu, notamment l’état d’activation, le statut d’intégration et le statut de collecte des logs. This endpoint requires any of the following permissions:

  • security_monitoring_filters_read
  • logs_read_index_data

  • OAuth apps require the security_monitoring_filters_read authorization scope to access this endpoint.

    Réponse

    OK

    Response containing content pack states.

    Expand All

    Champ

    Type

    Description

    data [required]

    [object]

    Array of content pack states.

    attributes [required]

    object

    Attributes of a content pack state.

    details [required]

     <oneOf>

    Type-specific details for a content pack state. The set of fields present depends on the content pack's type. When Cloud SIEM is inactive for the requesting organization, onboarding is returned instead of the content pack's usual type, such as logs or vulnerability.`

    <type=logs>

    object

    Details for a logs-based content pack.

    cp_activation [required]

    enum

    The activation status of a content pack. Allowed enum values: never_activated,activated,deactivated

    data_last_seen [required]

    enum

    Timestamp bucket indicating when logs were last collected. Allowed enum values: not_seen,within_24_hours,within_24_to_72_hours,over_72h_to_30d,over_30d

    filters_configured [required]

    boolean

    Whether filters (Security Filters or Index Query depending on the pricing model) are present and correctly configured to route logs into Cloud SIEM.

    integration_installed_status [required]

    enum

    The installation status of the related integration. Allowed enum values: installed,available,partially_installed,detected,error

    logs_seen_from_any_index [required]

    boolean

    Whether logs for this content pack have been seen in any Datadog index in the last 72 hours.

    siem_index_incorrect [required]

    boolean

    Whether the Cloud SIEM index configuration is incorrect (only applies to certain pricing models).

    type [required]

    enum

    The filtered data type. Allowed enum values: logs

    <type=threat_intel>

    object

    Details for a threat intelligence content pack.

    cp_activation [required]

    enum

    The activation status of a content pack. Allowed enum values: never_activated,activated,deactivated

    data_last_seen [required]

    enum

    Timestamp bucket indicating when logs were last collected. Allowed enum values: not_seen,within_24_hours,within_24_to_72_hours,over_72h_to_30d,over_30d

    integration_installed_status [required]

    enum

    The installation status of the related integration. Allowed enum values: installed,available,partially_installed,detected,error

    type [required]

    enum

    Type for threat intelligence content pack details. Allowed enum values: threat_intel

    <type=entity>

    object

    Details for an entity or identity content pack.

    cp_activation [required]

    enum

    The activation status of a content pack. Allowed enum values: never_activated,activated,deactivated

    type [required]

    enum

    Type for entity content pack details. Allowed enum values: entity

    <type=audit>

    object

    Details for an audit trail content pack.

    type [required]

    enum

    Type for audit trail content pack details. Allowed enum values: audit

    <type=appsec>

    object

    Details for an Application Security content pack.

    type [required]

    enum

    Type for Application Security content pack details. Allowed enum values: appsec

    <type=vulnerability>

    object

    Details for a vulnerability content pack.

    cp_activation [required]

    enum

    The activation status of a content pack. Allowed enum values: never_activated,activated,deactivated

    data_last_seen [required]

    enum

    Timestamp bucket indicating when logs were last collected. Allowed enum values: not_seen,within_24_hours,within_24_to_72_hours,over_72h_to_30d,over_30d

    integration_installed_status [required]

    enum

    The installation status of the related integration. Allowed enum values: installed,available,partially_installed,detected,error

    type [required]

    enum

    Type for vulnerability content pack details. Allowed enum values: vulnerability

    <type=onboarding>

    object

    Content pack details returned when Cloud SIEM is inactive for the requesting organization.

    integration_installed_status

    enum

    The installation status of the related integration. Allowed enum values: installed,available,partially_installed,detected,error

    logs_seen_from_any_index [required]

    boolean

    Whether logs for this content pack have been seen in any Datadog index in the last 72 hours.

    type [required]

    enum

    Type for onboarding content pack details. Allowed enum values: onboarding

    status [required]

    enum

    The current operational status of a content pack. Allowed enum values: install,activate,initializing,active,warning,broken,not_configured

    id [required]

    string

    The content pack identifier.

    type [required]

    enum

    Type for content pack state object Allowed enum values: content_pack_state

    meta [required]

    object

    Metadata for content pack states.

    cloud_siem_index_incorrect [required]

    boolean

    Whether the Cloud SIEM index configuration is incorrect for the organization.

    retention_months

    int32

    The number of months that standard logs are retained for organizations on the standalone_indexed` pricing model. This field is omitted for other pricing models.

    sku [required]

    enum

    The Cloud SIEM pricing model (SKU) for the organization. Allowed enum values: per_gb_analyzed,per_event_in_siem_index_2023,add_on_2024,standalone_indexed,unknown

    {
      "data": [
        {
          "attributes": {
            "details": {
              "cp_activation": "activated",
              "data_last_seen": "within_24_hours",
              "filters_configured": true,
              "integration_installed_status": "installed",
              "logs_seen_from_any_index": true,
              "siem_index_incorrect": false,
              "type": "logs"
            },
            "status": "active"
          },
          "id": "aws-cloudtrail",
          "type": "content_pack_state"
        }
      ],
      "meta": {
        "cloud_siem_index_incorrect": false,
        "retention_months": 15,
        "sku": "add_on_2024"
      }
    }

    Forbidden

    API error response.

    Expand All

    Champ

    Type

    Description

    errors [required]

    [object]

    A list of errors.

    detail

    string

    A human-readable explanation specific to this occurrence of the error.

    meta

    object

    Non-standard meta-information about the error

    source

    object

    References to the source of the error.

    header

    string

    A string indicating the name of a single request header which caused the error.

    parameter

    string

    A string indicating which URI query parameter caused the error.

    pointer

    string

    A JSON pointer to the value in the request document that caused the error.

    status

    string

    Status code of the response.

    title

    string

    Short human-readable summary of the error.

    {
      "errors": [
        {
          "detail": "Missing required attribute in body",
          "meta": {},
          "source": {
            "header": "Authorization",
            "parameter": "limit",
            "pointer": "/data/attributes/title"
          },
          "status": "400",
          "title": "Bad Request"
        }
      ]
    }

    Not Found

    API error response.

    Expand All

    Champ

    Type

    Description

    errors [required]

    [object]

    A list of errors.

    detail

    string

    A human-readable explanation specific to this occurrence of the error.

    meta

    object

    Non-standard meta-information about the error

    source

    object

    References to the source of the error.

    header

    string

    A string indicating the name of a single request header which caused the error.

    parameter

    string

    A string indicating which URI query parameter caused the error.

    pointer

    string

    A JSON pointer to the value in the request document that caused the error.

    status

    string

    Status code of the response.

    title

    string

    Short human-readable summary of the error.

    {
      "errors": [
        {
          "detail": "Missing required attribute in body",
          "meta": {},
          "source": {
            "header": "Authorization",
            "parameter": "limit",
            "pointer": "/data/attributes/title"
          },
          "status": "400",
          "title": "Bad Request"
        }
      ]
    }

    Too many requests

    API error response.

    Expand All

    Champ

    Type

    Description

    errors [required]

    [string]

    A list of errors.

    {
      "errors": [
        "Bad Request"
      ]
    }

    Exemple de code

                      # Curl command
    curl -X GET "https://api.ap1.datadoghq.com"https://api.ap2.datadoghq.com"https://api.datadoghq.eu"https://api.ddog-gov.com"https://api.us2.ddog-gov.com"https://api.uk1.datadoghq.com"https://api.datadoghq.com"https://api.us3.datadoghq.com"https://api.us5.datadoghq.com/api/v2/security_monitoring/content_packs/states" \ -H "Accept: application/json" \ -H "DD-API-KEY: ${DD_API_KEY}" \ -H "DD-APPLICATION-KEY: ${DD_APP_KEY}"
    """
    Get content pack states returns "OK" response
    """
    
    from datadog_api_client import ApiClient, Configuration
    from datadog_api_client.v2.api.security_monitoring_api import SecurityMonitoringApi
    
    configuration = Configuration()
    configuration.unstable_operations["get_content_packs_states"] = True
    with ApiClient(configuration) as api_client:
        api_instance = SecurityMonitoringApi(api_client)
        response = api_instance.get_content_packs_states()
    
        print(response)
    

    Instructions

    First install the library and its dependencies and then save the example to example.py and run following commands:

        
    DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" python3 "example.py"
    # Get content pack states returns "OK" response
    
    require "datadog_api_client"
    DatadogAPIClient.configure do |config|
      config.unstable_operations["v2.get_content_packs_states".to_sym] = true
    end
    api_instance = DatadogAPIClient::V2::SecurityMonitoringAPI.new
    p api_instance.get_content_packs_states()
    

    Instructions

    First install the library and its dependencies and then save the example to example.rb and run following commands:

        
    DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" rb "example.rb"
    // Get content pack states returns "OK" response
    
    package main
    
    import (
    	"context"
    	"encoding/json"
    	"fmt"
    	"os"
    
    	"github.com/DataDog/datadog-api-client-go/v2/api/datadog"
    	"github.com/DataDog/datadog-api-client-go/v2/api/datadogV2"
    )
    
    func main() {
    	ctx := datadog.NewDefaultContext(context.Background())
    	configuration := datadog.NewConfiguration()
    	configuration.SetUnstableOperationEnabled("v2.GetContentPacksStates", true)
    	apiClient := datadog.NewAPIClient(configuration)
    	api := datadogV2.NewSecurityMonitoringApi(apiClient)
    	resp, r, err := api.GetContentPacksStates(ctx)
    
    	if err != nil {
    		fmt.Fprintf(os.Stderr, "Error when calling `SecurityMonitoringApi.GetContentPacksStates`: %v\n", err)
    		fmt.Fprintf(os.Stderr, "Full HTTP response: %v\n", r)
    	}
    
    	responseContent, _ := json.MarshalIndent(resp, "", "  ")
    	fmt.Fprintf(os.Stdout, "Response from `SecurityMonitoringApi.GetContentPacksStates`:\n%s\n", responseContent)
    }
    

    Instructions

    First install the library and its dependencies and then save the example to main.go and run following commands:

        
    DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" go run "main.go"
    // Get content pack states returns "OK" response
    
    import com.datadog.api.client.ApiClient;
    import com.datadog.api.client.ApiException;
    import com.datadog.api.client.v2.api.SecurityMonitoringApi;
    import com.datadog.api.client.v2.model.SecurityMonitoringContentPackStatesResponse;
    
    public class Example {
      public static void main(String[] args) {
        ApiClient defaultClient = ApiClient.getDefaultApiClient();
        defaultClient.setUnstableOperationEnabled("v2.getContentPacksStates", true);
        SecurityMonitoringApi apiInstance = new SecurityMonitoringApi(defaultClient);
    
        try {
          SecurityMonitoringContentPackStatesResponse result = apiInstance.getContentPacksStates();
          System.out.println(result);
        } catch (ApiException e) {
          System.err.println("Exception when calling SecurityMonitoringApi#getContentPacksStates");
          System.err.println("Status code: " + e.getCode());
          System.err.println("Reason: " + e.getResponseBody());
          System.err.println("Response headers: " + e.getResponseHeaders());
          e.printStackTrace();
        }
      }
    }
    

    Instructions

    First install the library and its dependencies and then save the example to Example.java and run following commands:

        
    DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" java "Example.java"
    // Get content pack states returns "OK" response
    use datadog_api_client::datadog;
    use datadog_api_client::datadogV2::api_security_monitoring::SecurityMonitoringAPI;
    
    #[tokio::main]
    async fn main() {
        let mut configuration = datadog::Configuration::new();
        configuration.set_unstable_operation_enabled("v2.GetContentPacksStates", true);
        let api = SecurityMonitoringAPI::with_config(configuration);
        let resp = api.get_content_packs_states().await;
        if let Ok(value) = resp {
            println!("{:#?}", value);
        } else {
            println!("{:#?}", resp.unwrap_err());
        }
    }
    

    Instructions

    First install the library and its dependencies and then save the example to src/main.rs and run following commands:

        
    DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" cargo run
    /**
     * Get content pack states returns "OK" response
     */
    
    import { client, v2 } from "@datadog/datadog-api-client";
    
    const configuration = client.createConfiguration();
    configuration.unstableOperations["v2.getContentPacksStates"] = true;
    const apiInstance = new v2.SecurityMonitoringApi(configuration);
    
    apiInstance
      .getContentPacksStates()
      .then((data: v2.SecurityMonitoringContentPackStatesResponse) => {
        console.log(
          "API called successfully. Returned data: " + JSON.stringify(data)
        );
      })
      .catch((error: any) => console.error(error));
    

    Instructions

    First install the library and its dependencies and then save the example to example.ts and run following commands:

        
    DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" tsc "example.ts"