Skip to main content

monitoring_hist_signals

Creates, updates, deletes, gets or lists a monitoring_hist_signals resource.

Overview

Namemonitoring_hist_signals
TypeResource
Iddatadog.security.monitoring_hist_signals

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
idstringThe unique ID of the security signal. (example: AAAAAWgN8Xwgr1vKDQAAAABBV2dOOFh3ZzZobm1mWXJFYTR0OA)
attributesobjectThe object containing all signal attributes and their associated values.
typestringThe type of event. (default: signal, example: signal)

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
get_security_monitoring_histsignalselecthistsignal_id, regionGet a hist signal's details.
get_security_monitoring_histsignals_by_job_idselectjob_id, regionfilter[query], filter[from], filter[to], sort, page[cursor], page[limit]Get a job's hist signals.
list_security_monitoring_histsignalsselectregionfilter[query], filter[from], filter[to], sort, page[cursor], page[limit]List hist signals.
search_security_monitoring_histsignalsexecregionSearch hist signals.
convert_job_result_to_signalexecregionConvert a job result to a signal.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
histsignal_idstringThe ID of the historical signal.
job_idstringThe ID of the job.
regionstring(default: datadoghq.com)
filter[from]string (date-time)The minimum timestamp for requested security signals. (example: 2019-01-02T09:42:36.320Z)
filter[query]stringThe search query for security signals. (example: security:attack status:high)
filter[to]string (date-time)The maximum timestamp for requested security signals. (example: 2019-01-03T09:42:36.320Z)
page[cursor]stringA list of results using the cursor provided in the previous query. (example: eyJzdGFydEF0IjoiQVFBQUFYS2tMS3pPbm40NGV3QUFBQUJCV0V0clRFdDZVbG8zY3pCRmNsbHJiVmxDWlEifQ==)
page[limit]integer (int32)The maximum number of security signals in the response. (example: 25)
sortstringThe order of the security signals in results.

SELECT examples

Get a hist signal's details.

SELECT
id,
attributes,
type
FROM datadog.security.monitoring_hist_signals
WHERE histsignal_id = '{{ histsignal_id }}' -- required
AND region = '{{ region }}' -- required
;

Lifecycle Methods

Search hist signals.

EXEC datadog.security.monitoring_hist_signals.search_security_monitoring_histsignals 
@region='{{ region }}' --required
@@json=
'{
"filter": "{{ filter }}",
"page": "{{ page }}",
"sort": "{{ sort }}"
}'
;