Skip to main content

siem_ioc_explorer_triages

Creates, updates, deletes, gets or lists a siem_ioc_explorer_triages resource.

Overview

Namesiem_ioc_explorer_triages
TypeResource
Iddatadog.security.siem_ioc_explorer_triages

Fields

The following fields are returned by SELECT queries:

SELECT not supported for this resource, use SHOW METHODS to view available operations for the resource.

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
create_io_ctriage_stateinsertdataSet the triage state of an indicator of compromise (IoC). This creates or<br />updates the triage state for the indicator in your organization.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
sitestringThe Datadog site (region) for your organization, for example datadoghq.com, us3.datadoghq.com, us5.datadoghq.com, ap1.datadoghq.com, ap2.datadoghq.com, datadoghq.eu, ddog-gov.com. Resolved from the DD_SITE environment variable when set. Optional: defaults to datadoghq.com, or the value of the DD_SITE environment variable when set; a WHERE value overrides both.

INSERT examples

Set the triage state of an indicator of compromise (IoC). This creates or<br />updates the triage state for the indicator in your organization.

INSERT INTO datadog.security.siem_ioc_explorer_triages (
data
)
SELECT
'{{ data }}' /* required */
RETURNING
data
;