siem_ioc_explorer_triages
Creates, updates, deletes, gets or lists a siem_ioc_explorer_triages resource.
Overview
| Name | siem_ioc_explorer_triages |
| Type | Resource |
| Id | datadog.security.siem_ioc_explorer_triages |
Fields
The following fields are returned by SELECT queries:
SELECT not supported for this resource, use SHOW METHODS to view available operations for the resource.
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
create_io_ctriage_state | insert | data | Set the triage state of an indicator of compromise (IoC). This creates or<br />updates the triage state for the indicator in your organization. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
site | string | The Datadog site (region) for your organization, for example datadoghq.com, us3.datadoghq.com, us5.datadoghq.com, ap1.datadoghq.com, ap2.datadoghq.com, datadoghq.eu, ddog-gov.com. Resolved from the DD_SITE environment variable when set. Optional: defaults to datadoghq.com, or the value of the DD_SITE environment variable when set; a WHERE value overrides both. |
INSERT examples
- create_io_ctriage_state
- Manifest
Set the triage state of an indicator of compromise (IoC). This creates or<br />updates the triage state for the indicator in your organization.
INSERT INTO datadog.security.siem_ioc_explorer_triages (
data
)
SELECT
'{{ data }}' /* required */
RETURNING
data
;
# Description fields are for documentation purposes
- name: siem_ioc_explorer_triages
props:
- name: data
description: |
Data object for the triage write request.
value:
attributes:
indicator: "{{ indicator }}"
triage_state: "{{ triage_state }}"
type: "{{ type }}"