Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
152 changes: 152 additions & 0 deletions .generator/schemas/v2/openapi.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -37901,6 +37901,13 @@ components:
required:
- revisions
type: object
EntityContextEntityType:
default: siem_entity_identity
description: The type of entity to retrieve. Only `siem_entity_identity` is currently supported.
enum: [siem_entity_identity]
example: siem_entity_identity
type: string
x-enum-varnames: [SIEM_ENTITY_IDENTITY]
EntityContextPage:
description: Pagination metadata for the entity context response.
properties:
Expand Down Expand Up @@ -37970,6 +37977,15 @@ components:
email: user@example.com
principal_id: user@example.com
type: object
EntityContextRevisionsMode:
default: latest
description: |-
Which revisions to return for each entity: `latest` returns only the latest revision of each entity as of `to`,
and `all` returns every revision in the requested time range.
enum: [latest, all]
example: latest
type: string
x-enum-varnames: [LATEST, ALL]
EntityData:
description: Entity data.
properties:
Expand Down Expand Up @@ -92819,6 +92835,17 @@ components:
x-enum-varnames:
- ANY
- ALL
RecentlyUpdatedEntitiesResponse:
description: Response from the recently updated entities endpoint, containing the entities with the most recent updates in the requested time range, ordered from most to least recently updated.
properties:
data:
description: The list of entities with the most recent updates, ordered from most to least recently updated.
items:
$ref: "#/components/schemas/EntityContextEntity"
type: array
required:
- data
type: object
RecommendationAttributes:
description: Attributes of the SPA Recommendation resource. Contains recommendations for both driver and executor components.
properties:
Expand Down Expand Up @@ -212572,6 +212599,15 @@ paths:
required: false
schema:
type: string
- description: |-
The type of entity to retrieve. Only `siem_entity_identity` is currently supported.
Defaults to `siem_entity_identity`.
example: siem_entity_identity
in: query
name: entity_type
required: false
schema:
$ref: "#/components/schemas/EntityContextEntityType"
- description: |-
The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now-7d`).
Defaults to `now-7d`. Ignored when `as_of` is set.
Expand Down Expand Up @@ -212664,6 +212700,113 @@ paths:
x-unstable: |-
**Note**: This endpoint is in Preview and is subject to change.
If you have any feedback, contact [Datadog support](https://docs.datadoghq.com/help/).
/api/v2/security_monitoring/entity_context/recently_updated:
get:
description: |-
Get the entities with the most recent updates in the Cloud SIEM entity context store. Entities are ranked
by the time of their most recent revision in the requested time range, and the top `limit` entities are
returned in that order. This endpoint is not paginated.
operationId: GetEntityContextRecentlyUpdated
parameters:
- description: A free-text query (for example, an email address or principal ID) used to filter the entities returned.
example: user@example.com
in: query
name: query
required: false
schema:
type: string
- description: |-
The type of entity to retrieve. Only `siem_entity_identity` is currently supported.
Defaults to `siem_entity_identity`.
example: siem_entity_identity
in: query
name: entity_type
required: false
schema:
$ref: "#/components/schemas/EntityContextEntityType"
- description: |-
The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now-7d`).
Defaults to `now-7d`.
in: query
name: from
required: false
schema:
default: now-7d
example: now-7d
type: string
- description: |-
The end of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now`).
Defaults to `now`. Entities are ranked by their most recent revision within `[from, to]`.
in: query
name: to
required: false
schema:
default: now
example: now
type: string
- description: The number of entities to return. Must be between 1 and 100.
example: 50
in: query
name: limit
required: false
schema:
default: 50
format: int64
maximum: 100
minimum: 1
type: integer
- description: |-
Which revisions to return for each entity: `latest` returns only the latest revision of each entity as of `to`,
and `all` returns every revision in the requested time range.
example: latest
in: query
name: revisions
required: false
schema:
$ref: "#/components/schemas/EntityContextRevisionsMode"
responses:
"200":
content:
application/json:
examples:
default:
value:
data:
- attributes:
revisions:
- attributes:
accounts:
- linked-account-123
display_name: Test User
email: user@example.com
principal_id: user@example.com
first_seen_at: "2026-04-01T00:00:00Z"
last_seen_at: "2026-05-01T00:00:00Z"
id: user@example.com
type: siem_entity_identity
schema:
$ref: "#/components/schemas/RecentlyUpdatedEntitiesResponse"
description: OK
"400":
$ref: "#/components/responses/BadRequestResponse"
"403":
$ref: "#/components/responses/NotAuthorizedResponse"
"429":
$ref: "#/components/responses/TooManyRequestsResponse"
security:
- apiKeyAuth: []
appKeyAuth: []
- AuthZ:
- siem_entities_read
summary: Get recently updated entity context
tags: ["Security Monitoring"]
x-permission:
operator: OR
permissions:
- siem_entities_read
x-unstable: |-
**Note**: This endpoint is in Preview and is subject to change.
If you have any feedback, contact [Datadog support](https://docs.datadoghq.com/help/).
/api/v2/security_monitoring/entity_context/{id}:
get:
description: |-
Expand All @@ -212680,6 +212823,15 @@ paths:
schema:
example: user@example.com
type: string
- description: |-
The type of entity to retrieve. Only `siem_entity_identity` is currently supported.
Defaults to `siem_entity_identity`.
example: siem_entity_identity
in: query
name: entity_type
required: false
schema:
$ref: "#/components/schemas/EntityContextEntityType"
- description: |-
The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now-7d`).
Defaults to `now-7d`. Ignored when `as_of` is set.
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
"""
Get recently updated entity context returns "OK" response
"""

from os import environ
from datadog_api_client import ApiClient, Configuration
from datadog_api_client.v2.api.security_monitoring_api import SecurityMonitoringApi

configuration = Configuration()
configuration.access_token = environ["DD_BEARER_TOKEN"]
configuration.unstable_operations["get_entity_context_recently_updated"] = True
with ApiClient(configuration) as api_client:
api_instance = SecurityMonitoringApi(api_client)
response = api_instance.get_entity_context_recently_updated()

print(response)
1 change: 1 addition & 0 deletions src/datadog_api_client/configuration.py
Original file line number Diff line number Diff line change
Expand Up @@ -400,6 +400,7 @@ def __init__(
"v2.export_security_monitoring_terraform_resource": False,
"v2.get_content_packs_states": False,
"v2.get_entity_context": False,
"v2.get_entity_context_recently_updated": False,
"v2.get_entra_id_azure_app_registrations": False,
"v2.get_finding": False,
"v2.get_historical_job": False,
Expand Down
Loading
Loading