diff --git a/.generator/schemas/v2/openapi.yaml b/.generator/schemas/v2/openapi.yaml index 4363be9d31..047f523b4e 100644 --- a/.generator/schemas/v2/openapi.yaml +++ b/.generator/schemas/v2/openapi.yaml @@ -37901,6 +37901,13 @@ components: required: - revisions type: object + EntityContextEntityType: + default: siem_entity_identity + description: The type of entity to retrieve. Only `siem_entity_identity` is currently supported. + enum: [siem_entity_identity] + example: siem_entity_identity + type: string + x-enum-varnames: [SIEM_ENTITY_IDENTITY] EntityContextPage: description: Pagination metadata for the entity context response. properties: @@ -37970,6 +37977,15 @@ components: email: user@example.com principal_id: user@example.com type: object + EntityContextRevisionsMode: + default: latest + description: |- + Which revisions to return for each entity: `latest` returns only the latest revision of each entity as of `to`, + and `all` returns every revision in the requested time range. + enum: [latest, all] + example: latest + type: string + x-enum-varnames: [LATEST, ALL] EntityData: description: Entity data. properties: @@ -92819,6 +92835,17 @@ components: x-enum-varnames: - ANY - ALL + RecentlyUpdatedEntitiesResponse: + description: Response from the recently updated entities endpoint, containing the entities with the most recent updates in the requested time range, ordered from most to least recently updated. + properties: + data: + description: The list of entities with the most recent updates, ordered from most to least recently updated. + items: + $ref: "#/components/schemas/EntityContextEntity" + type: array + required: + - data + type: object RecommendationAttributes: description: Attributes of the SPA Recommendation resource. Contains recommendations for both driver and executor components. properties: @@ -212572,6 +212599,15 @@ paths: required: false schema: type: string + - description: |- + The type of entity to retrieve. Only `siem_entity_identity` is currently supported. + Defaults to `siem_entity_identity`. + example: siem_entity_identity + in: query + name: entity_type + required: false + schema: + $ref: "#/components/schemas/EntityContextEntityType" - description: |- The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now-7d`). Defaults to `now-7d`. Ignored when `as_of` is set. @@ -212664,6 +212700,113 @@ paths: x-unstable: |- **Note**: This endpoint is in Preview and is subject to change. If you have any feedback, contact [Datadog support](https://docs.datadoghq.com/help/). + /api/v2/security_monitoring/entity_context/recently_updated: + get: + description: |- + Get the entities with the most recent updates in the Cloud SIEM entity context store. Entities are ranked + by the time of their most recent revision in the requested time range, and the top `limit` entities are + returned in that order. This endpoint is not paginated. + operationId: GetEntityContextRecentlyUpdated + parameters: + - description: A free-text query (for example, an email address or principal ID) used to filter the entities returned. + example: user@example.com + in: query + name: query + required: false + schema: + type: string + - description: |- + The type of entity to retrieve. Only `siem_entity_identity` is currently supported. + Defaults to `siem_entity_identity`. + example: siem_entity_identity + in: query + name: entity_type + required: false + schema: + $ref: "#/components/schemas/EntityContextEntityType" + - description: |- + The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now-7d`). + Defaults to `now-7d`. + in: query + name: from + required: false + schema: + default: now-7d + example: now-7d + type: string + - description: |- + The end of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now`). + Defaults to `now`. Entities are ranked by their most recent revision within `[from, to]`. + in: query + name: to + required: false + schema: + default: now + example: now + type: string + - description: The number of entities to return. Must be between 1 and 100. + example: 50 + in: query + name: limit + required: false + schema: + default: 50 + format: int64 + maximum: 100 + minimum: 1 + type: integer + - description: |- + Which revisions to return for each entity: `latest` returns only the latest revision of each entity as of `to`, + and `all` returns every revision in the requested time range. + example: latest + in: query + name: revisions + required: false + schema: + $ref: "#/components/schemas/EntityContextRevisionsMode" + responses: + "200": + content: + application/json: + examples: + default: + value: + data: + - attributes: + revisions: + - attributes: + accounts: + - linked-account-123 + display_name: Test User + email: user@example.com + principal_id: user@example.com + first_seen_at: "2026-04-01T00:00:00Z" + last_seen_at: "2026-05-01T00:00:00Z" + id: user@example.com + type: siem_entity_identity + schema: + $ref: "#/components/schemas/RecentlyUpdatedEntitiesResponse" + description: OK + "400": + $ref: "#/components/responses/BadRequestResponse" + "403": + $ref: "#/components/responses/NotAuthorizedResponse" + "429": + $ref: "#/components/responses/TooManyRequestsResponse" + security: + - apiKeyAuth: [] + appKeyAuth: [] + - AuthZ: + - siem_entities_read + summary: Get recently updated entity context + tags: ["Security Monitoring"] + x-permission: + operator: OR + permissions: + - siem_entities_read + x-unstable: |- + **Note**: This endpoint is in Preview and is subject to change. + If you have any feedback, contact [Datadog support](https://docs.datadoghq.com/help/). /api/v2/security_monitoring/entity_context/{id}: get: description: |- @@ -212680,6 +212823,15 @@ paths: schema: example: user@example.com type: string + - description: |- + The type of entity to retrieve. Only `siem_entity_identity` is currently supported. + Defaults to `siem_entity_identity`. + example: siem_entity_identity + in: query + name: entity_type + required: false + schema: + $ref: "#/components/schemas/EntityContextEntityType" - description: |- The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now-7d`). Defaults to `now-7d`. Ignored when `as_of` is set. diff --git a/examples/v2/security-monitoring/GetEntityContextRecentlyUpdated.py b/examples/v2/security-monitoring/GetEntityContextRecentlyUpdated.py new file mode 100644 index 0000000000..1bc558c046 --- /dev/null +++ b/examples/v2/security-monitoring/GetEntityContextRecentlyUpdated.py @@ -0,0 +1,16 @@ +""" +Get recently updated entity context returns "OK" response +""" + +from os import environ +from datadog_api_client import ApiClient, Configuration +from datadog_api_client.v2.api.security_monitoring_api import SecurityMonitoringApi + +configuration = Configuration() +configuration.access_token = environ["DD_BEARER_TOKEN"] +configuration.unstable_operations["get_entity_context_recently_updated"] = True +with ApiClient(configuration) as api_client: + api_instance = SecurityMonitoringApi(api_client) + response = api_instance.get_entity_context_recently_updated() + + print(response) diff --git a/src/datadog_api_client/configuration.py b/src/datadog_api_client/configuration.py index d3437737b1..7ea7906945 100644 --- a/src/datadog_api_client/configuration.py +++ b/src/datadog_api_client/configuration.py @@ -400,6 +400,7 @@ def __init__( "v2.export_security_monitoring_terraform_resource": False, "v2.get_content_packs_states": False, "v2.get_entity_context": False, + "v2.get_entity_context_recently_updated": False, "v2.get_entra_id_azure_app_registrations": False, "v2.get_finding": False, "v2.get_historical_job": False, diff --git a/src/datadog_api_client/v2/api/security_monitoring_api.py b/src/datadog_api_client/v2/api/security_monitoring_api.py index ff9a00e3b7..7eb69cbd9d 100644 --- a/src/datadog_api_client/v2/api/security_monitoring_api.py +++ b/src/datadog_api_client/v2/api/security_monitoring_api.py @@ -196,6 +196,9 @@ SecurityMonitoringDatasetVersionHistoryResponse, ) from datadog_api_client.v2.model.entity_context_response import EntityContextResponse +from datadog_api_client.v2.model.entity_context_entity_type import EntityContextEntityType +from datadog_api_client.v2.model.recently_updated_entities_response import RecentlyUpdatedEntitiesResponse +from datadog_api_client.v2.model.entity_context_revisions_mode import EntityContextRevisionsMode from datadog_api_client.v2.model.single_entity_context_response import SingleEntityContextResponse from datadog_api_client.v2.model.matching_signals_response import MatchingSignalsResponse from datadog_api_client.v2.model.security_monitoring_list_rules_response import SecurityMonitoringListRulesResponse @@ -1889,6 +1892,11 @@ def __init__(self, api_client=None): "attribute": "query", "location": "query", }, + "entity_type": { + "openapi_types": (EntityContextEntityType,), + "attribute": "entity_type", + "location": "query", + }, "_from": { "openapi_types": (str,), "attribute": "from", @@ -1921,6 +1929,57 @@ def __init__(self, api_client=None): api_client=api_client, ) + self._get_entity_context_recently_updated_endpoint = _Endpoint( + settings={ + "response_type": (RecentlyUpdatedEntitiesResponse,), + "auth": ["apiKeyAuth", "appKeyAuth", "AuthZ"], + "endpoint_path": "/api/v2/security_monitoring/entity_context/recently_updated", + "operation_id": "get_entity_context_recently_updated", + "http_method": "GET", + "version": "v2", + }, + params_map={ + "query": { + "openapi_types": (str,), + "attribute": "query", + "location": "query", + }, + "entity_type": { + "openapi_types": (EntityContextEntityType,), + "attribute": "entity_type", + "location": "query", + }, + "_from": { + "openapi_types": (str,), + "attribute": "from", + "location": "query", + }, + "to": { + "openapi_types": (str,), + "attribute": "to", + "location": "query", + }, + "limit": { + "validation": { + "inclusive_maximum": 100, + "inclusive_minimum": 1, + }, + "openapi_types": (int,), + "attribute": "limit", + "location": "query", + }, + "revisions": { + "openapi_types": (EntityContextRevisionsMode,), + "attribute": "revisions", + "location": "query", + }, + }, + headers_map={ + "accept": ["application/json"], + }, + api_client=api_client, + ) + self._get_entra_id_azure_app_registrations_endpoint = _Endpoint( settings={ "response_type": (SecurityMonitoringEntraIdAzureAppRegistrationsResponse,), @@ -2739,6 +2798,11 @@ def __init__(self, api_client=None): "attribute": "id", "location": "path", }, + "entity_type": { + "openapi_types": (EntityContextEntityType,), + "attribute": "entity_type", + "location": "query", + }, "_from": { "openapi_types": (str,), "attribute": "from", @@ -6382,6 +6446,7 @@ def get_entity_context( self, *, query: Union[str, UnsetType] = unset, + entity_type: Union[EntityContextEntityType, UnsetType] = unset, _from: Union[str, UnsetType] = unset, to: Union[str, UnsetType] = unset, as_of: Union[str, UnsetType] = unset, @@ -6397,6 +6462,9 @@ def get_entity_context( :param query: A free-text query (for example, an email address or principal ID) used to filter the entities returned. :type query: str, optional + :param entity_type: The type of entity to retrieve. Only ``siem_entity_identity`` is currently supported. + Defaults to ``siem_entity_identity``. + :type entity_type: EntityContextEntityType, optional :param _from: The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, ``now-7d`` ). Defaults to ``now-7d``. Ignored when ``as_of`` is set. :type _from: str, optional @@ -6417,6 +6485,9 @@ def get_entity_context( if query is not unset: kwargs["query"] = query + if entity_type is not unset: + kwargs["entity_type"] = entity_type + if _from is not unset: kwargs["_from"] = _from @@ -6434,6 +6505,61 @@ def get_entity_context( return self._get_entity_context_endpoint.call_with_http_info(**kwargs) + def get_entity_context_recently_updated( + self, + *, + query: Union[str, UnsetType] = unset, + entity_type: Union[EntityContextEntityType, UnsetType] = unset, + _from: Union[str, UnsetType] = unset, + to: Union[str, UnsetType] = unset, + limit: Union[int, UnsetType] = unset, + revisions: Union[EntityContextRevisionsMode, UnsetType] = unset, + ) -> RecentlyUpdatedEntitiesResponse: + """Get recently updated entity context. + + Get the entities with the most recent updates in the Cloud SIEM entity context store. Entities are ranked + by the time of their most recent revision in the requested time range, and the top ``limit`` entities are + returned in that order. This endpoint is not paginated. + + :param query: A free-text query (for example, an email address or principal ID) used to filter the entities returned. + :type query: str, optional + :param entity_type: The type of entity to retrieve. Only ``siem_entity_identity`` is currently supported. + Defaults to ``siem_entity_identity``. + :type entity_type: EntityContextEntityType, optional + :param _from: The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, ``now-7d`` ). + Defaults to ``now-7d``. + :type _from: str, optional + :param to: The end of the time range to query, as an RFC3339 timestamp or a relative time (for example, ``now`` ). + Defaults to ``now``. Entities are ranked by their most recent revision within ``[from, to]``. + :type to: str, optional + :param limit: The number of entities to return. Must be between 1 and 100. + :type limit: int, optional + :param revisions: Which revisions to return for each entity: ``latest`` returns only the latest revision of each entity as of ``to`` , + and ``all`` returns every revision in the requested time range. + :type revisions: EntityContextRevisionsMode, optional + :rtype: RecentlyUpdatedEntitiesResponse + """ + kwargs: Dict[str, Any] = {} + if query is not unset: + kwargs["query"] = query + + if entity_type is not unset: + kwargs["entity_type"] = entity_type + + if _from is not unset: + kwargs["_from"] = _from + + if to is not unset: + kwargs["to"] = to + + if limit is not unset: + kwargs["limit"] = limit + + if revisions is not unset: + kwargs["revisions"] = revisions + + return self._get_entity_context_recently_updated_endpoint.call_with_http_info(**kwargs) + def get_entra_id_azure_app_registrations( self, ) -> SecurityMonitoringEntraIdAzureAppRegistrationsResponse: @@ -7089,6 +7215,7 @@ def get_single_entity_context( self, id: str, *, + entity_type: Union[EntityContextEntityType, UnsetType] = unset, _from: Union[str, UnsetType] = unset, to: Union[str, UnsetType] = unset, as_of: Union[str, UnsetType] = unset, @@ -7102,6 +7229,9 @@ def get_single_entity_context( :param id: The unique identifier of the entity to retrieve. :type id: str + :param entity_type: The type of entity to retrieve. Only ``siem_entity_identity`` is currently supported. + Defaults to ``siem_entity_identity``. + :type entity_type: EntityContextEntityType, optional :param _from: The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, ``now-7d`` ). Defaults to ``now-7d``. Ignored when ``as_of`` is set. :type _from: str, optional @@ -7117,6 +7247,9 @@ def get_single_entity_context( kwargs: Dict[str, Any] = {} kwargs["id"] = id + if entity_type is not unset: + kwargs["entity_type"] = entity_type + if _from is not unset: kwargs["_from"] = _from diff --git a/src/datadog_api_client/v2/model/entity_context_entity_type.py b/src/datadog_api_client/v2/model/entity_context_entity_type.py new file mode 100644 index 0000000000..50081cdd82 --- /dev/null +++ b/src/datadog_api_client/v2/model/entity_context_entity_type.py @@ -0,0 +1,35 @@ +# Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License. +# This product includes software developed at Datadog (https://www.datadoghq.com/). +# Copyright 2019-Present Datadog, Inc. +from __future__ import annotations + + +from datadog_api_client.model_utils import ( + ModelSimple, + cached_property, +) + +from typing import ClassVar + + +class EntityContextEntityType(ModelSimple): + """ + The type of entity to retrieve. Only `siem_entity_identity` is currently supported. + + :param value: If omitted defaults to "siem_entity_identity". Must be one of ["siem_entity_identity"]. + :type value: str + """ + + allowed_values = { + "siem_entity_identity", + } + SIEM_ENTITY_IDENTITY: ClassVar["EntityContextEntityType"] + + @cached_property + def openapi_types(_): + return { + "value": (str,), + } + + +EntityContextEntityType.SIEM_ENTITY_IDENTITY = EntityContextEntityType("siem_entity_identity") diff --git a/src/datadog_api_client/v2/model/entity_context_revisions_mode.py b/src/datadog_api_client/v2/model/entity_context_revisions_mode.py new file mode 100644 index 0000000000..7a6e6cfff3 --- /dev/null +++ b/src/datadog_api_client/v2/model/entity_context_revisions_mode.py @@ -0,0 +1,39 @@ +# Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License. +# This product includes software developed at Datadog (https://www.datadoghq.com/). +# Copyright 2019-Present Datadog, Inc. +from __future__ import annotations + + +from datadog_api_client.model_utils import ( + ModelSimple, + cached_property, +) + +from typing import ClassVar + + +class EntityContextRevisionsMode(ModelSimple): + """ + Which revisions to return for each entity: `latest` returns only the latest revision of each entity as of `to`, + and `all` returns every revision in the requested time range. + + :param value: If omitted defaults to "latest". Must be one of ["latest", "all"]. + :type value: str + """ + + allowed_values = { + "latest", + "all", + } + LATEST: ClassVar["EntityContextRevisionsMode"] + ALL: ClassVar["EntityContextRevisionsMode"] + + @cached_property + def openapi_types(_): + return { + "value": (str,), + } + + +EntityContextRevisionsMode.LATEST = EntityContextRevisionsMode("latest") +EntityContextRevisionsMode.ALL = EntityContextRevisionsMode("all") diff --git a/src/datadog_api_client/v2/model/recently_updated_entities_response.py b/src/datadog_api_client/v2/model/recently_updated_entities_response.py new file mode 100644 index 0000000000..3ced5f3480 --- /dev/null +++ b/src/datadog_api_client/v2/model/recently_updated_entities_response.py @@ -0,0 +1,40 @@ +# Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License. +# This product includes software developed at Datadog (https://www.datadoghq.com/). +# Copyright 2019-Present Datadog, Inc. +from __future__ import annotations + +from typing import List, TYPE_CHECKING + +from datadog_api_client.model_utils import ( + ModelNormal, + cached_property, +) + + +if TYPE_CHECKING: + from datadog_api_client.v2.model.entity_context_entity import EntityContextEntity + + +class RecentlyUpdatedEntitiesResponse(ModelNormal): + @cached_property + def openapi_types(_): + from datadog_api_client.v2.model.entity_context_entity import EntityContextEntity + + return { + "data": ([EntityContextEntity],), + } + + attribute_map = { + "data": "data", + } + + def __init__(self_, data: List[EntityContextEntity], **kwargs): + """ + Response from the recently updated entities endpoint, containing the entities with the most recent updates in the requested time range, ordered from most to least recently updated. + + :param data: The list of entities with the most recent updates, ordered from most to least recently updated. + :type data: [EntityContextEntity] + """ + super().__init__(kwargs) + + self_.data = data diff --git a/src/datadog_api_client/v2/models/__init__.py b/src/datadog_api_client/v2/models/__init__.py index 54a2130d19..8912540d10 100644 --- a/src/datadog_api_client/v2/models/__init__.py +++ b/src/datadog_api_client/v2/models/__init__.py @@ -2983,11 +2983,13 @@ from datadog_api_client.v2.model.entity_attributes import EntityAttributes from datadog_api_client.v2.model.entity_context_entity import EntityContextEntity from datadog_api_client.v2.model.entity_context_entity_attributes import EntityContextEntityAttributes +from datadog_api_client.v2.model.entity_context_entity_type import EntityContextEntityType from datadog_api_client.v2.model.entity_context_page import EntityContextPage from datadog_api_client.v2.model.entity_context_response import EntityContextResponse from datadog_api_client.v2.model.entity_context_response_meta import EntityContextResponseMeta from datadog_api_client.v2.model.entity_context_revision import EntityContextRevision from datadog_api_client.v2.model.entity_context_revision_attributes import EntityContextRevisionAttributes +from datadog_api_client.v2.model.entity_context_revisions_mode import EntityContextRevisionsMode from datadog_api_client.v2.model.entity_data import EntityData from datadog_api_client.v2.model.entity_integration_config_attributes import EntityIntegrationConfigAttributes from datadog_api_client.v2.model.entity_integration_config_data import EntityIntegrationConfigData @@ -8152,6 +8154,7 @@ from datadog_api_client.v2.model.react_native_sourcemap_data import ReactNativeSourcemapData from datadog_api_client.v2.model.readiness_gate import ReadinessGate from datadog_api_client.v2.model.readiness_gate_threshold_type import ReadinessGateThresholdType +from datadog_api_client.v2.model.recently_updated_entities_response import RecentlyUpdatedEntitiesResponse from datadog_api_client.v2.model.recommendation_attributes import RecommendationAttributes from datadog_api_client.v2.model.recommendation_data import RecommendationData from datadog_api_client.v2.model.recommendation_document import RecommendationDocument @@ -14015,11 +14018,13 @@ "EntityAttributes", "EntityContextEntity", "EntityContextEntityAttributes", + "EntityContextEntityType", "EntityContextPage", "EntityContextResponse", "EntityContextResponseMeta", "EntityContextRevision", "EntityContextRevisionAttributes", + "EntityContextRevisionsMode", "EntityData", "EntityIntegrationConfigAttributes", "EntityIntegrationConfigData", @@ -17482,6 +17487,7 @@ "ReactNativeSourcemapData", "ReadinessGate", "ReadinessGateThresholdType", + "RecentlyUpdatedEntitiesResponse", "RecommendationAttributes", "RecommendationData", "RecommendationDocument", diff --git a/tests/v2/features/security_monitoring.feature b/tests/v2/features/security_monitoring.feature index a1781b2257..cf9a335e22 100644 --- a/tests/v2/features/security_monitoring.feature +++ b/tests/v2/features/security_monitoring.feature @@ -2505,6 +2505,20 @@ Feature: Security Monitoring When the request is sent Then the response status is 200 OK + @generated @skip @team:DataDog/cloud-siem + Scenario: Get recently updated entity context returns "Bad Request" response + Given operation "GetEntityContextRecentlyUpdated" enabled + And new "GetEntityContextRecentlyUpdated" request + When the request is sent + Then the response status is 400 Bad Request + + @generated @skip @team:DataDog/cloud-siem + Scenario: Get recently updated entity context returns "OK" response + Given operation "GetEntityContextRecentlyUpdated" enabled + And new "GetEntityContextRecentlyUpdated" request + When the request is sent + Then the response status is 200 OK + @skip-go @skip-java @skip-ruby @team:DataDog/cloud-siem Scenario: Get rule version history returns "OK" response Given operation "GetRuleVersionHistory" enabled diff --git a/tests/v2/features/undo.json b/tests/v2/features/undo.json index cbecf69cfc..a3ee9d72c9 100644 --- a/tests/v2/features/undo.json +++ b/tests/v2/features/undo.json @@ -8776,6 +8776,12 @@ "type": "safe" } }, + "GetEntityContextRecentlyUpdated": { + "tag": "Security Monitoring", + "undo": { + "type": "safe" + } + }, "GetSingleEntityContext": { "tag": "Security Monitoring", "undo": {