コンテンツにスキップ

Investigations GraphQL API 🔗

重要

Investigations v2 API は現在 非推奨 です。代わりに Cases GraphQL API を使用してください。

注意

Taegis XDRでは、アラート および インベスティゲーション という用語が、最近 検出 および ケース に変更されました。SophosとTaegisテクノロジーのプラットフォーム統合作業が進行中のため、引き続き旧用語が参照されている場合があります。詳細については、Taegis用語の更新をご覧ください。

ノード🔗

フィールド🔗

Field Type Description Arguments
id ID

ID🔗

説明: ID スカラー型は一意の識別子を表し、オブジェクトの再取得やキャッシュのキーとしてよく使用されます。ID 型は JSON レスポンスでは String として表示されますが、人間が読めることを意図したものではありません。入力型として期待される場合、任意の文字列("4" など)または整数(4 など)の入力値が ID として受け入れられます。

クエリ🔗

フィールド🔗

Field Type Description Arguments
investigationV2 InvestigationV2 investigationV2 は単一の Investigation を取得します。 arguments: InvestigationV2Arguments
investigationsV2 InvestigationsV2 investigationsV2 は、指定された引数に一致する investigation のリストを返します。 arguments: InvestigationsV2Arguments
investigationRule InvestigationRule investigationRule は自動 investigation ルールを取得します arguments: InvestigationRuleArguments
investigationRules InvestigationRules investigationRules は、指定された引数に一致する investigation ルールのリストを返します。 arguments: InvestigationRulesArguments
investigationTemplate InvestigationTemplate investigationTemplate は自動 investigation テンプレートを取得します arguments: InvestigationTemplateArguments
investigationTemplates InvestigationTemplates investigationTemplates は、指定された引数に一致する investigation テンプレートのリストを返します。 arguments: InvestigationTemplatesArguments
exportInvestigationResources InvestigationResourceExport exportInvestigationResources は、自動 investigation リソース(ルールとテンプレート)の YAML 文字列表現を返します。
返された文字列はファイルに保存し、importInvestigationResources を使用してシステムに再インポートできます。
arguments: ExportInvestigationResourcesArguments
investigationV2Timeline InvestigationV2Timeline investigationV2Timeline は、investigation に関連して実行されたアラート、イベント、その他のアクションの順序を詳述する investigation タイムラインを返します。 arguments: InvestigationV2TimelineArguments
commentsV2 CommentsV2 commentsV2 は investigation のすべてのコメントを返します arguments: CommentsV2Arguments
investigationV2Types InvestigationV2Type investigationV2Types は、指定されたユーザーおよび現在のテナントのサービスレベルで利用可能な investigation タイプを返します
investigationV2Statuses InvestigationV2Status investigationStatuses は、指定されたユーザーおよび現在のテナントのサービスレベルで利用可能な investigation ステータスを返します arguments: InvestigationV2StatusesArguments
investigationFileV2 InvestigationFileV2 investigationFileV2 は、指定された引数に基づいて investigation に添付された単一ファイルのファイル詳細を返します。
結果には事前署名済みダウンロード URL も含まれます。
arguments: InvestigationFileV2Arguments
investigationFilesV2 InvestigationFilesV2 investigationFilesV2 は、指定された引数に一致するすべてのファイルのファイル詳細を返します。
結果には、返される各ファイルメタデータの事前署名済みダウンロード URL は含まれません。
arguments: InvestigationFilesV2Arguments
investigationsAggregation InvestigationsAggregation investigationsAggregation では investigation のデータを集計できます。
個々の investigation や investigation のリストの取得には使用できず、集計データのみに使用できます。
外部クライアントでは使用せず、Taegis UI からのみ呼び出す必要があります。
このエンドポイントは予告なくいつでも変更される可能性があるため、使用は推奨されません。
arguments: InvestigationsAggregationArguments

InvestigationsAggregationArguments🔗

フィールド🔗

Field Type Description Arguments
cql String データを集計する対象のクエリ

String🔗

説明: String スカラー型はテキストデータを表し、UTF-8 文字シーケンスとして表現されます。String 型は、GraphQL で自由形式の人間可読テキストを表すために最もよく使用されます。

InvestigationsAggregation🔗

フィールド🔗

Field Type Description Arguments
Aggregation Map

ミューテーション🔗

フィールド🔗

Field Type Description Arguments
createInvestigationV2 InvestigationV2 createInvestigationV2 は、指定された引数で新しい investigation を作成します。 input: CreateInvestigationInput
updateInvestigationV2 InvestigationV2 updateInvestigationV2 は既存の investigation を更新します。
これは PATCH スタイルのミューテーションであり、入力で送信されたフィールドのみが更新されます。
input: UpdateInvestigationV2Input
addEvidenceToInvestigation AddEvidenceToInvestigationResult addEvidenceToInvestigation は、既存の investigation にさらに証拠を追加します。
このミューテーションで追加された証拠は genesis evidence とは見なされません。
レスポンスには、サービスが investigation に追加を試みる証拠が含まれます。

investigation への証拠の追加は非同期処理です。
通常はかなり迅速に完了しますが、追加されたアラートやイベントは、非同期ジョブが完全に完了するまで返された investigation に表示されない場合があります。
investigation 型にある processing status には、処理ジョブの状態が反映されます。
ステータスが SUCCESS に設定されるとバックグラウンドジョブは完了し、investigation をリクエストすると関連する証拠が返されます。

特定の investigation に対して他のジョブが処理中に証拠の追加、削除、更新(investigation のクローズ)を行うと、ジョブはキューに入れられます。
ジョブは受信された順に処理されます。
input: AddEvidenceToInvestigationInput
removeEvidenceFromInvestigation RemoveEvidenceFromInvestigationResult removeEvidenceFromInvestigation は、既存の investigation から証拠を削除します。
レスポンスには、サービスが investigation から削除を試みる証拠が含まれます。

investigation からの証拠の削除は非同期処理です。
通常はかなり迅速に完了しますが、削除されたアラートやイベントは、非同期ジョブが完全に完了するまで investigation に関連付けられたまま残る場合があります。
investigation 型にある processing status には、処理ジョブの状態が反映されます。
ステータスが SUCCESS に設定されるとバックグラウンドジョブは完了し、investigation をリクエストすると削除されなかった証拠のみが返されます。

特定の investigation に対して他のジョブが処理中に証拠の追加、削除、更新(investigation のクローズ)を行うと、ジョブはキューに入れられます。
ジョブは受信された順に処理されます。
input: RemoveEvidenceFromInvestigationInput
closeInvestigation InvestigationV2 closeInvestigation は既存の investigation をクローズします。
investigation にアラートが関連付けられている場合、alertsResolutionStatus フィールドは必須であり、アラートは指定されたステータスに基づいて解決されます。
investigation がクローズされると、クローズ状態の間は編集したり証拠を追加したりできなくなり、アーカイブのみ可能になります。
クローズされた investigation は、クローズ後に変更が必要な場合は再オープンできます。

investigation 内の証拠の解決は非同期処理です。
通常はかなり迅速に完了しますが、アラートの解決は、非同期ジョブが完全に完了するまで更新されたステータスを反映しない場合があります。
investigation 型にある processing status には、処理ジョブの状態が反映されます。
ステータスが SUCCESS に設定されるとバックグラウンドジョブは完了し、アラートは更新されています。

特定の investigation に対して他のジョブが処理中に証拠の追加、削除、更新(investigation のクローズ)を行うと、ジョブはキューに入れられます。
ジョブは受信された順に処理されます。
input: CloseInvestigationInput
createInvestigationRule InvestigationRule createInvestigationRule は、新しい自動 investigation ルールを作成するための入力を受け付けます。 input: CreateInvestigationRuleInput
updateInvestigationRule InvestigationRule updateInvestigationRule は、既存の自動 investigation ルールを更新するための入力を受け付けます。 input: UpdateInvestigationRuleInput
deleteInvestigationRule InvestigationRule deleteInvestigationRule は既存の investigation ルールを削除します。
これは完全削除です。データは復元できません。
input: DeleteInvestigationRuleInput
createInvestigationTemplate InvestigationTemplate createInvestigationTemplate は、新しい自動 investigation テンプレートを作成するための入力を受け付けます。 input: CreateInvestigationTemplateInput
updateInvestigationTemplate InvestigationTemplate updateInvestigationTemplate は、既存の自動 investigation テンプレートを更新するための入力を受け付けます。 input: UpdateInvestigationTemplateInput
deleteInvestigationTemplate InvestigationTemplate deleteInvestigationTemplate は既存の investigation テンプレートを削除します。
これは完全削除です。データは復元できません。
input: DeleteInvestigationTemplateInput
importInvestigationResources InvestigationResource importInvestigationResources は、YAML ファイルから investigation リソース(ルールとテンプレート)をインポートします。
入力 YAML 構造は、exportInvestigationResources クエリからエクスポートされた YAML 文字列から取得できます。
input: ImportInvestigationResourcesInput
addCommentToInvestigation CommentV2 addCommentToInvestigation は既存の investigation にコメントを追加します。 input: AddCommentToInvestigationInput
updateInvestigationComment CommentV2 updateInvestigationComment は investigation 上の既存のコメントを更新します。
これは PATCH スタイルのミューテーションであり、入力で送信されたフィールドのみが更新されます。
コメントを更新できるのは、そのコメントを作成したユーザーのみです。
コメントを更新して新しい @mention を追加すると新しい通知がトリガーされますが、すでにコメント内に存在する @mention には通知は送信されません。
input: UpdateInvestigationCommentInput
deleteInvestigationComment CommentV2 deleteInvestigationComment は investigation から既存のコメントを削除します。
これは完全削除です。データは復元できません。
input: DeleteInvestigationCommentInput
archiveInvestigationV2 InvestigationV2 archiveInvestigationV2 は既存の investigation をアーカイブします。
アーカイブできるのはクローズされた investigation のみです。
アーカイブされていてもクローズ状態ではない investigation が存在する場合がありますが、これらは「クローズ」要件が導入される前にアーカイブされたレガシー investigation です。
input: ArchiveInvestigationInput
unarchiveInvestigationV2 InvestigationV2 unarchiveInvestigationV2 はアーカイブされた investigation のアーカイブを解除します。 input: UnarchiveInvestigationInput
archiveInvestigationsV2 ArchivedInvestigations archiveInvestigationsV2 は既存の investigation のセットをアーカイブします。
アーカイブできるのはクローズされた investigation のみです。
レスポンスには正常にアーカイブされた investigation の id が含まれ、アーカイブできなかった investigation に対するエラーは返されません。
input: ArchiveInvestigationsInput
unarchiveInvestigationsV2 UnarchivedInvestigations unarchiveInvestigationsV2 はアーカイブされた investigation のセットのアーカイブを解除します。
レスポンスには正常にアーカイブ解除された investigation の id が含まれ、アーカイブ解除できなかった investigation に対するエラーは返されません。
input: UnarchiveInvestigationsInput
initInvestigationFileUpload InvestigationFileUpload initInvestigationFileUpload は investigation のファイルアップロードを初期化します。
レスポンスには、investigation にファイルをアップロードするために使用できる事前署名済み URL が含まれます。
input: InitInvestigationFileUploadInput
deleteInvestigationFile InvestigationFileV2 deleteInvestigationFile は investigation から既存のファイルを削除します。
これは完全削除です。データは復元できません。
input: DeleteInvestigationFileInput

CreateInvestigationInput🔗

説明: CreateInvestigationInput は、新しい investigation を作成するために使用できるフィールドを説明します。

フィールド🔗

Field Type Description Arguments
type InvestigationType investigation をどのタイプでオープンするか
タイプは、現在のユーザーおよびテナントのサービスレベルで利用可能なタイプに制限されます。
priority Int investigation の優先度。
1 - 低
2 - 中
3 - 高
4 - 重大
title String investigation のタイトル。
最大 256 文字で、それを超える部分は切り詰められます。
tags String investigation のラベル付けに役立つタグ
keyFindings String KeyFindings は investigation の詳細を説明するために使用されます
status InvestigationStatus Status は investigation の状態を表すために使用されます
ステータスは、現在のユーザーおよびテナントで利用可能なステータスに制限されます。
クローズステータスはここでは設定できません。
assigneeId String AssigneeId は investigation に割り当てられたユーザーを設定するために使用されます。
担当者は、システム内の有効なユーザー、クライアント、または @mention である必要があります。
alerts String Alerts は investigation に関連付けるアラート ID のリストです。
investigation の作成時に追加されたアラートは genesis evidence と見なされます。
alertsSearchQuery String AlertsSearchQuery は、investigation にアラートを関連付けるために使用できる CQL クエリです。
investigation に関連付けられるのは最初の 50k 件のアラートのみです。
investigation 作成時に検索クエリ経由で追加されたアラートは genesis evidence と見なされます。
events String Events は investigation に関連付けるイベント ID のリストです。
investigation の作成時に追加されたイベントは genesis evidence と見なされます。
searchQueries String SearchQueries は、investigation をオープンするために使用する保存済み検索です。
investigation の作成時に追加された検索クエリは genesis evidence と見なされます。
ここで追加された検索は証拠を関連付けるために実行されず、このフィールドは保存済み検索を investigation に関連付けるためにのみ使用されます。
serviceDeskId String serviceDeskId は、サードパーティのサービスデスクを investigation にマッピングする ID を定義するために使用されます。
これは URL または、investigation をサービスデスクチケットにリンクするために使用できるその他の識別子です。

URL 形式:
サービスデスクチケットへの完全な URL を指定し、追加パラメーター id を URL にエンコードしてください。
例: https://company.service-now.com//nav_to.do?uri=%2Fincident.do%3Fsys_id=3454676eadfedaf8e665370cbb350b&id=INC2345
serviceDeskType String serviceDeskType は、service desk id に関連して使用されるサービスデスクのタイプ/識別子を設定するために使用されます。例: SNOW, 4me
これは自由形式のテキストであり、検証されません。
ruleId ID ruleId は内部 I&R 専用のフィールドです。これに値を指定すると失敗する可能性があり、動作は未定義です。
templateId ID TemplateId は内部 I&R 専用のフィールドです。これに値を指定すると失敗する可能性があり、動作は未定義です。

Int🔗

説明: Int スカラー型は、小数を含まない符号付き整数値を表します。Int は -(2^31) から 2^31 - 1 までの値を表現できます。

UpdateInvestigationV2Input🔗

説明: UpdateInvestigationV2Input は、investigation を更新するために使用できるフィールドを説明します。 指定されていないオプションフィールドは更新されません。

フィールド🔗

Field Type Description Arguments
id ID 更新する investigation の Id
type InvestigationType investigation を更新するタイプ。
タイプは、現在のユーザーおよびテナントのサービスレベルで利用可能なタイプに制限されます。
priority Int investigation を更新する優先度。
1 - 低
2 - 中
3 - 高
4 - 重大
title String investigation を更新するタイトル
tags String investigation のラベル付けに役立つタグ
タグは追加方式ではなく、指定されたタグが investigation 上の既存のタグを置き換えます。
既存のタグを保持したい場合は、tags フィールドにそれらを含める必要があります。
tags フィールドをまったく送信しない(null)場合、タグは更新されません。
keyFindings String KeyFindings は investigation の詳細を説明するために使用されます
status InvestigationStatus Status は investigation の状態を更新するために使用されます
ステータスは、現在のユーザーおよびテナントで利用可能なステータスに制限されます。
ここではクローズされていないステータスのみをサポートし、クローズステータスはここでは更新できません。investigation は closeInvestigation ミューテーションでクローズする必要があります。
ステータスを AWAITING_ACTION に設定すると、assignee id が変更された場合に引き継ぎがトリガーされ、新しい担当者にメールが送信されます。
assigneeId String AssigneeId は investigation に割り当てられたユーザーを更新するために使用されます。
担当者は、システム内の有効なユーザー、クライアント、または @mention である必要があります。
assignee id を更新し、ステータスを AWAITING_ACTION に設定すると、assignee id が変更された場合に引き継ぎがトリガーされ、新しい担当者にメールが送信されます。
serviceDeskId String serviceDeskId は、サードパーティのサービスデスクを investigation にマッピングする ID を更新するために使用されます。
これは URL または、investigation をサービスデスクチケットにリンクするために使用できるその他の識別子です。

URL 形式:
サービスデスクチケットへの完全な URL を指定し、追加パラメーター id を URL にエンコードしてください。
例: https://company.service-now.com//nav_to.do?uri=%2Fincident.do%3Fsys_id=3454676eadfedaf8e665370cbb350b&id=INC2345
serviceDeskType String serviceDeskType は、service desk id に関連して使用されるサービスデスクのタイプ/識別子を更新するために使用されます。例: SNOW, 4me
これは自由形式のテキストであり、検証されません。

CloseInvestigationInput🔗

説明: CloseInvestigationInput は、investigation をクローズするために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID investigation id
status InvestigationCloseStatus investigation のクローズステータス
reason String reason は、investigation をクローズする理由の短い説明を提供するために使用されます
alertsResolutionStatus AlertResolutionStatus alertsResolutionStatus は、investigation をクローズするときにアラートに設定するステータスです。
これはアラートを含む investigation では必須フィールドですが、アラートがない investigation ではオプションです。

AlertResolutionStatus🔗

説明: アラート解決ステータスの列挙型。

AddEvidenceToInvestigationInput🔗

説明: AddAlertsToInvestigationInput は、既存の investigation に証拠を追加するために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
investigationId ID 証拠を追加する investigation id
alerts String Alerts は investigation に関連付けるアラート ID のリストです
alertsSearchQuery String AlertsSearchQuery は、investigation にアラートを追加するために使用する CQL クエリです
events String Events は investigation に関連付けるイベント ID のリストです
searchQueries String SearchQueries は investigation に関連付ける保存済み検索です。
investigation の作成時に追加された検索クエリは genesis evidence と見なされます。
ここで追加された検索は証拠を関連付けるために実行されず、このフィールドは保存済み検索を investigation に関連付けるためにのみ使用されます。

RemoveEvidenceFromInvestigationInput🔗

説明: RemoveEvidenceFromInvestigationResult は、既存の investigation から証拠を削除するために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
investigationId ID investigation id
alerts String Alerts は investigation から削除するアラート ID のリストです
events String Events は investigation から削除するイベント ID のリストです
assets String Assets は investigation から削除する asset ID のリストです
searchQueries String searchQueries は investigation から削除する検索クエリのリストです

DeleteInvestigationRuleInput🔗

説明: DeleteInvestigationRuleInput は、既存の investigation ルールを削除するために使用できるフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID 更新するルールの ID

ArchiveInvestigationInput🔗

説明: ArchiveInvestigationInput は、既存の investigation をアーカイブするためのフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID アーカイブする investigation の ID

UnarchiveInvestigationInput🔗

説明: UnarchiveInvestigationInput は、既存の investigation のアーカイブを解除するためのフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID アーカイブ解除する investigation の ID

ArchiveInvestigationsInput🔗

説明: ArchiveInvestigationsInput は、既存の investigation を一括アーカイブするためのフィールドを説明します。

フィールド🔗

Field Type Description Arguments
ids ID アーカイブする investigation の ID

UnarchiveInvestigationsInput🔗

説明: UnarchiveInvestigationInput は、既存の investigation の一括アーカイブ解除のためのフィールドを説明します。

フィールド🔗

Field Type Description Arguments
ids ID アーカイブ解除する investigation の ID

ArchivedInvestigations🔗

説明: ArchivedInvestigations は、アーカイブされた investigation のセットを説明します。

フィールド🔗

Field Type Description Arguments
ids ID 正常にアーカイブされた investigation の ids

UnarchivedInvestigations🔗

説明: UnarchivedInvestigations は、アーカイブ解除された investigation のセットを説明します。

フィールド🔗

Field Type Description Arguments
ids ID 正常にアーカイブ解除された investigation の ids

InvestigationV2🔗

説明: InvestigationV2 は Taegis XDR investigation を説明します。

フィールド🔗

Field Type Description Arguments
id ID investigation の ID(一意)
shortId String shortId は人間が読める investigation の識別子です
short id は通常は順番に作成されますが、順番どおりに作成される保証はありません。
title String investigation のタイトル
keyFindings String KeyFindings は investigation の詳細を説明するために使用されます
alertsEvidence AlertEvidence AlertsEvidence は investigation に関連付けられたアラート証拠のリストです
alertsEvidenceCount Int AlertsEvidenceCount は investigation に関連付けられたアラート数です
assetsEvidence AssetEvidence AssetsEvidence は investigation に関連付けられた asset 証拠のリストです
assetsEvidenceCount Int AssetsEvidenceCount は investigation に関連付けられた asset 数です
eventsEvidence EventEvidence EventsEvidence は investigation に関連付けられたイベント証拠のリストです
eventsEvidenceCount Int EventsEvidenceCount は investigation に関連付けられたイベント数です
searchQueriesEvidence SearchQueryEvidence SearchQueriesEvidence は investigation に関連付けられた検索クエリ証拠のリストです
searchQueriesEvidenceCount Int SearchQueriesEvidenceCount は investigation に関連付けられた検索クエリ数です
priority Int investigation の優先度
type InvestigationType investigation のタイプ
status InvestigationStatus Status は investigation の現在のステータスです
tags String investigation のラベル付けに役立つタグ
contributorIds String ContributorIds は investigation に貢献したユーザー id のリストです
contributorSubjects Subject ContributorSubjects は investigation に貢献した subject のフェデレーションリストです。
これは貢献者のユーザー情報を取得するために使用できます。
すべての貢献者がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
assigneeId String AssigneeId は investigation に割り当てられたユーザー、クライアント、またはグループの id です
assigneeSubject Subject assigneeSubject は、担当者のユーザー/クライアント情報を取得するために使用できるフェデレーションフィールドです。
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
assignee id が @partner mention または @customer に設定されている場合は常に nil になります。
担当者がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
tenantId String TenantId は investigation が属するテナントの id です
tenant TenantV4 Tenant は、investigation のテナント情報を取得するために使用できるフェデレーションフィールドです。
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
テナントがフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合やテナントが別の環境に移動された場合です。
createdById String CreatedById は investigation を作成したユーザーの id です
createdBySubject Subject CreatedBySubject は、investigation の作成者のユーザー情報を取得するために使用できるフェデレーションフィールドです。
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
createdBy がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
createdAt Time CreatedAt は investigation が作成された時刻です
このフィールドは、investigation が元々ドラフト状態で作成され、その後昇格された場合に更新されます。
updatedById String UpdatedById は investigation を最後に更新したユーザーの id です
updatedBySubject Subject UpdatedBySubject は、investigation を最後に更新したユーザーの情報を取得するために使用できるフェデレーションフィールドです。
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
updatedBy がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
updatedAt Time UpdatedAt は investigation が最後に更新された時刻です
archivedAt Time ArchivedAt は investigation がアーカイブされた時刻です
このフィールドは investigation がアーカイブされている場合にのみ設定されます。
investigation のアーカイブが解除されると nil に戻されます。
closeReason String investigation をクローズするときにユーザーが指定した理由。
このフィールドは、Closed ステータスに達した investigation に対してのみ設定されます。
processingStatus InvestigationProcessingStatus processingStatus には、investigation に対して処理可能な各証拠タイプの現在のステータスが含まれます
commentsCount InvestigationCommentsCount commentsCount には investigation のコメント数が含まれます
ruleId ID ruleId は investigation をオープンしたルールの id です。investigation がルールによってオープンされた場合にのみ設定される必要があります
serviceDeskId String serviceDeskId は、サードパーティのサービスデスクを investigation にマッピングする id です。
このフィールドの利用者は、このフィールドから URL を解析して id パラメーターを取得し、そのパラメーターの値を表示値として使用できる必要があります。
serviceDeskType String serviceDeskType は、service desk id に関連して使用されるタイプ/識別子です。例: SNOW, 4me
metrics Metric metrics には、この investigation に対して収集されたデータポイントが含まれます。これらは、investigation がパートナーによってオープンされ、従来の investigation フローに従った場合にのみ設定されます。
isCreatedByPartner Boolean isCreatedByPartner は、investigation が子テナントの親テナントによって作成されたかどうかを示すフィールドです。
alerts String
assets String
events String
contributorIDs String
searchQueries String
entitiesEvidence EntityEvidence
entitiesEvidenceCount Int
assignee TDRUser
contributors TDRUser
createdBy TDRUser
updatedBy TDRUser
metric Metric

Boolean🔗

説明: Boolean スカラー型は true または false を表します。

InvestigationsV2🔗

説明: InvestigationsV2 は、investigation 検索のページネーションされた結果を定義します。

フィールド🔗

Field Type Description Arguments
investigations InvestigationV2 現在のページの検索条件に一致する investigation のリスト
totalCount Int 検索条件に一致する investigation の総数
aggregatedCounts AggregatedCounts AggregatedCounts には、指定されたクエリに対する investigation 全体のセットの集計データ(件数)が含まれます(ページネーションは無視されます)。
このフィールドをリクエストすると、クエリの API レスポンス時間が遅くなる場合があります。絶対に必要な場合にのみこのフィールドをリクエストしてください。
データは元のリクエストで指定されたクエリに基づいて集計されます。
metrics Metrics Metrics には、指定されたクエリに対する investigation 全体のセットの集計データが含まれます(ページネーションは無視されます)
このフィールドをリクエストすると、クエリの API レスポンス時間が遅くなる場合があります。絶対に必要な場合にのみこのフィールドをリクエストしてください。
データは元のリクエストで指定されたクエリに基づいて計算されます。

AggregatedCounts🔗

説明: AggregatedCounts には、investigation のさまざまなフィールドに対する集計 investigation 件数データが含まれます

フィールド🔗

Field Type Description Arguments
status InvestigationStatusCount status にはステータス別の investigation 件数が含まれます
type InvestigationTypeCount type にはタイプ別の investigation 件数が含まれます
priority InvestigationPriorityCount priority には優先度別の investigation 件数が含まれます
tenant InvestigationTenantCount tenant にはテナント別の investigation 件数が含まれます
assignee InvestigationAssigneeCount assignee には担当者別の investigation 件数が含まれます
creator InvestigationCreatorCount creator には作成者別の investigation 件数が含まれます
archivedCount Int openCount にはオープンな investigation の件数が含まれます

InvestigationStatusCount🔗

説明: InvestigationStatusCount には、指定されたステータスの investigation 件数が含まれます

フィールド🔗

Field Type Description Arguments
status InvestigationStatus
count Int

InvestigationPriorityCount🔗

説明: InvestigationPriorityCount には、指定された優先度の investigation 件数が含まれます

フィールド🔗

Field Type Description Arguments
priority Int
count Int

InvestigationTypeCount🔗

説明: InvestigationTypeCount には、指定されたタイプの investigation 件数が含まれます

フィールド🔗

Field Type Description Arguments
type InvestigationType
count Int

InvestigationTenantCount🔗

説明: InvestigationTenantCount には、指定されたテナントの investigation 件数が含まれます

フィールド🔗

Field Type Description Arguments
tenantId String
count Int
tenant TenantV4 Tenant は、件数のテナント情報を取得するために使用できるフェデレーションフィールドです。
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
テナントがフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合やテナントが別の環境に移動された場合です。

InvestigationCreatorCount🔗

説明: InvestigationCreatorCount には、指定された担当者の investigation 件数が含まれます

フィールド🔗

Field Type Description Arguments
creatorId String
subject Subject
count Int

InvestigationAssigneeCount🔗

説明: InvestigationAssigneeCound には、指定された作成者の investigation 件数が含まれます

フィールド🔗

Field Type Description Arguments
assigneeId String
subject Subject
count Int

Metric🔗

説明: Metric は個々の investigation のメトリクスを説明します。

フィールド🔗

Field Type Description Arguments
draftCreatedAt Time investigation が最初にドラフト状態で作成された時刻を示すタイムスタンプ。
設定されていない場合、その investigation はドラフト状態になったことがありません。
draftPromotedAt Time investigation がドラフトから他の任意の状態に移行した時刻を示すタイムスタンプ。
timeToDraftPromotion Int investigation がオープンされてからドラフトが昇格されるまでの秒数。
draftPromotedBy String investigation を昇格したユーザーまたはクライアントの id。
handedOffAt Time パートナーがお客様に investigation を通知した時刻を示すタイムスタンプ。
Secureworks/Partner のユーザーまたはクライアントが、担当者をお客様として investigation を awaiting action に設定した場合にのみ設定されます。
timeToHandOff Int investigation がオープンされてから引き継ぎが行われるまでの秒数
investigation がドラフトだった場合、これは draft promoted at から hand off までの秒数になります。
Secureworks/Partner のユーザーまたはクライアントが、担当者をお客様として investigation を awaiting action に設定した場合にのみ設定されます。
handedOffBy String investigation を引き継いだユーザーまたはクライアントの id。
Secureworks/Partner のユーザーまたはクライアントが、担当者をお客様として investigation を awaiting action に設定した場合にのみ設定されます。
acknowledgedAt Time 引き継ぎ後に investigation が最初にお客様(人間である必要があります)によって取得された時刻を示すタイムスタンプ。
引き継ぎがあった場合にのみ設定されます。
timeToAcknowledgement Int investigation が引き継がれてから人間によって確認されるまでの秒数。
引き継ぎがあった場合にのみ設定されます。
acknowledgedBy String investigation を確認したユーザー(人間である必要があります)の id。
引き継ぎがあった場合にのみ設定されます。
resolvedAt Time 引き継ぎ後に investigation がクローズされた時刻を示すタイムスタンプ。
引き継ぎがあり、かつ investigation がお客様ユーザー/クライアントによってクローズされた場合にのみ設定されます。
timeToResolution Int investigation が引き継がれてからクローズされるまでの秒数。
引き継ぎがあり、かつ investigation がお客様ユーザー/クライアントによってクローズされた場合にのみ設定されます。
resolvedBy String investigation を解決したユーザーまたはクライアントの id。
引き継ぎがあり、かつ investigation がお客様ユーザー/クライアントによってクローズされた場合にのみ設定されます。

Metrics🔗

説明: Metrics は、investigation のセットに対する集計メトリクスを説明します。

フィールド🔗

Field Type Description Arguments
meanTimeToHandoff Int 引き継ぎまでの平均時間(秒)。
meanTimeToAcknowledgement Int 確認までの平均時間(秒)。
meanTimeToResolution Int 解決までの平均時間(秒)。
meanTimeToDraftPromotion Int ドラフト昇格までの平均時間(秒)。

AddEvidenceToInvestigationResult🔗

説明: AddAlertsToInvestigationInput は、既存の investigation にアラートを追加するために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
investigationId ID 証拠を追加する investigation の id
alerts String Alerts は investigation に関連付けるアラート ID のリストです
alertsSearchQuery String alertsSearchQuery は、investigation にアラートを追加するために使用する CQL クエリです
events String Events は investigation に関連付けるイベント ID のリストです
searchQueries String SearchQueries は investigation に関連付ける保存済み検索です。
ここで追加された検索は証拠を関連付けるために実行されず、このフィールドは保存済み検索を investigation に関連付けるためにのみ使用されます。

RemoveEvidenceFromInvestigationResult🔗

説明: RemoveEvidenceFromInvestigationResult は、既存の investigation から証拠を削除するために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
investigationId ID 証拠を削除する investigation の id
alerts String Alerts は investigation から削除するアラート ID のリストです
events String Events は investigation から削除するイベント ID のリストです
assets String Assets は investigation から削除する asset ID のリストです
searchQueries String searchQueries は investigation から削除する検索クエリのリストです

InvestigationTemplate🔗

説明: InvestigationTemplate には、investigation を設定するために使用される事前定義済みアトリビュートのセットが含まれます。

テンプレートは、新しい investigation をオープンするためにも、既存の investigation に適用するためにも使用できます。

フィールド🔗

Field Type Description Arguments
id ID investigation テンプレートの ID(一意)
createdById String investigation テンプレートを作成したユーザーの ID
createdBySubject Subject createdBySubject は、investigation テンプレートの作成者のユーザー情報を取得するために使用できるフェデレーションフィールドです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
createdBy がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
createdAt Time createdAt は investigation テンプレートが作成された時刻です
updatedById String investigation テンプレートを最後に更新したユーザーの ID
updatedBySubject Subject updatedBySubject は、investigation テンプレートを最後に更新したユーザーの情報を取得するために使用できるフェデレーションフィールドです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
updatedBy がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
updatedAt Time updatedAt は investigation テンプレートが最後に更新された時刻です
tenantId String investigation テンプレートが属するテナントの ID
name String テンプレート名
title String テンプレートのタイトル - テンプレートを視覚的に表示する際、このフィールドが設定されている場合は、name ではなくこれをテンプレートの表現として使用する必要があります
description String テンプレートの説明
tags String テンプレートのラベル付けに役立つタグ
investigationType String investigation をどのタイプでオープンするか
investigationPriority String investigation の優先度
investigationTitle String investigation のタイトル
investigationTags String investigation のラベル付けに役立つタグ
investigationKeyFindings String keyFindings は、investigation の詳細を入力して説明するために使用できる cel テンプレートです
investigationKeyFindingsPrompts String keyFindingsPrompts は、OpenAI からの応答に基づいて investigation の詳細を入力して説明するために使用できる cel テンプレートのセットです
investigationAssignee String Assignee は investigation に割り当てられたユーザーを設定するために使用されます
investigationAssigneeSubject Subject investigationAssigneeSubject は、investigation テンプレートの担当者のユーザー情報を取得するために使用できるフェデレーションフィールドです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
担当者がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
investigationStatus String investigation の初期ステータス
createdBy TDRUser
updatedBy TDRUser
investigationAssigneeUser TDRUser

InvestigationTemplates🔗

説明: InvestigationTemplates は、investigation テンプレート検索のページネーションされた結果を定義します。

フィールド🔗

Field Type Description Arguments
templates InvestigationTemplate 現在のページの検索条件に一致するテンプレートのリスト
totalCount Int 検索条件に一致するテンプレートの総数

CreateInvestigationTemplateInput🔗

説明: CreateInvestigationTemplateInput は、新しい investigation テンプレートを作成するために使用されるフィールドを説明します。

フィールド🔗

Field Type Description Arguments
name String 作成するテンプレート名。
文字、数字、アンダースコアのみで構成できます。
name は一度設定すると変更できません。
title String ルールのタイトル - 後で変更できます。
description String テンプレートの説明
tags String テンプレートのラベル付けに役立つタグ
investigationType String investigation をどのタイプでオープンするか
CEL によるテンプレート化をサポートするため、type enum ではなく String 型を使用します。ただし、最終的にレンダリングされた値は有効な InvestigationType である必要があります。
investigationPriority String investigation の優先度
CEL によるテンプレート化をサポートするため、int ではなく String 型を使用します。ただし、最終的にレンダリングされた値は有効な (1-4) Int である必要があります。
investigationTitle String investigation のタイトル
investigationTags String investigation のラベル付けに役立つタグ
investigationKeyFindings String investigationKeyFindings は、investigation の詳細を入力して説明するために使用できる CEL テンプレートです
investigationKeyFindingsPrompts String investigationKeyFindingsPrompts は、OpenAI からの応答に基づいて investigation の詳細を入力して説明するために使用できる CEL テンプレートのセットです
investigationAssignee String Assignee は investigation に割り当てられたユーザーを設定するために使用されます
investigationStatus String investigation をオープンする際のステータス。
CEL によるテンプレート化をサポートするため、status enum ではなく String 型を使用します。ただし、最終的にレンダリングされた値は有効な InvestigationStatus である必要があります。

UpdateInvestigationTemplateInput🔗

説明: UpdateInvestigationTemplateInput は、既存の investigation テンプレートを更新するために使用されるフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID 更新するテンプレートの ID
title String テンプレートを更新するタイトル
description String テンプレートを更新する説明
tags String テンプレートのラベル付けに使用されるタグ。
タグは追加方式ではなく、指定されたタグが investigation 上の既存のタグを置き換えます。
既存のタグを保持したい場合は、tags フィールドにそれらを含める必要があります。
tags フィールドをまったく送信しない(null)場合、タグは更新されません。
investigationType String investigation をどのタイプでオープンするか
CEL によるテンプレート化をサポートするため、type enum ではなく String 型を使用します。ただし、最終的にレンダリングされた値は有効な InvestigationType である必要があります。
investigationPriority String investigation の優先度
CEL によるテンプレート化をサポートするため、int ではなく String 型を使用します。ただし、最終的にレンダリングされた値は有効な (1-4) Int である必要があります。
investigationTitle String investigation のタイトル
investigationTags String investigation のラベル付けに役立つタグ
investigationKeyFindings String investigationKeyFindings は、investigation の詳細を入力して説明するために使用できる CEL テンプレートです
investigationKeyFindingsPrompts String investigationKeyFindingsPrompts は、OpenAI からの応答に基づいて investigation の詳細を入力して説明するために使用できる CEL テンプレートのセットです
investigationAssignee String Assignee は investigation に割り当てられたユーザーを設定するために使用されます
investigationStatus String investigation をオープンする際のステータス。
CEL によるテンプレート化をサポートするため、status enum ではなく String 型を使用します。ただし、最終的にレンダリングされた値は有効な InvestigationStatus である必要があります。

DeleteInvestigationTemplateInput🔗

説明: DeleteInvestigationTemplateInput は、既存の investigation テンプレートを削除するために使用できるフィールドを定義します。

フィールド🔗

Field Type Description Arguments
id ID 削除するテンプレートの ID

InvestigationV2Arguments🔗

説明: InvestigationV2Arguments は、investigation を検索するためのパラメーターを説明します。

フィールド🔗

Field Type Description Arguments
id ID

InvestigationsV2Arguments🔗

説明: InvestigationsV2Arguments は、investigation の検索のためのパラメーターを説明します。

フィールド🔗

Field Type Description Arguments
cql String investigation を検索するための cql 文字列
page Int 返す結果のページ - ページは 1 から始まります
perPage Int 1 ページあたりの結果数 - 最大 100
tenantServiceFilters String 検索する tenant service ラベル
orderBy PaginationOrder
searchChildrenTenants Boolean

InvestigationTemplateArguments🔗

説明: InvestigationTemplateArguments は、investigation テンプレートを見つけるためのパラメーターを説明します。 id と name はどちらもテンプレートの一意識別子です。 少なくとも 1 つのフィールドを設定する必要があり、両方を設定した場合は両方ともテンプレートに一致する必要があります。

フィールド🔗

Field Type Description Arguments
id ID
name String

InvestigationTemplatesArguments🔗

説明: InvestigationTemplatesArguments は、investigation テンプレートの検索のためのパラメーターを説明します。

フィールド🔗

Field Type Description Arguments
cql String テンプレートを検索するための cql 文字列
page Int 返す結果のページ - ページは 1 から始まります
perPage Int 1 ページあたりの結果数 - 最大 100
name String
tags String

ExportInvestigationResourcesArguments🔗

説明: ExportInvestigationResourcesResult は、investigation リソース(ルール/テンプレート)をエクスポートするために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
arguments ExportInvestigationResourcesArgument

ExportInvestigationResourcesArgument🔗

説明: ExportInvestigationResourcesArgument は、investigation リソース(ルール/テンプレート)を見つけてエクスポートするためのパラメーターを説明します。 id と name はどちらもテンプレートの一意識別子です。 少なくとも 1 つのフィールドを設定する必要があり、両方を設定した場合は両方ともテンプレートに一致する必要があります。

フィールド🔗

Field Type Description Arguments
id ID
name String
type InvestigationResourceType エクスポートするリソースのタイプ

InvestigationRule🔗

説明: InvestigationRule には、自動 investigation ルールの設定が含まれます。

フィールド🔗

Field Type Description Arguments
id ID ルールの ID(一意)
createdById String ルールを作成したユーザーの ID
createdBySubject Subject createdBySubject は、investigation ルールの作成者のユーザー情報を取得するために使用できるフェデレーションフィールドです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
createdBy がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
createdAt Time createdAt は investigation ルールが作成された時刻です
updatedById String investigation ルールを最後に更新したユーザーの ID
updatedBySubject Subject updatedBySubject は、investigation ルールを最後に更新したユーザーの情報を取得するために使用できるフェデレーションフィールドです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
updatedBy がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
updatedAt Time updatedAt は investigation ルールが最後に更新された時刻です
tenantId String investigation ルールが属するテナントの ID
name String ルール名
title String ルールのタイトル - ルールを視覚的に表示する際、このフィールドが設定されている場合は、name ではなくこれをルールの表現として使用する必要があります
description String ルールの説明
tags String ルールのラベル付けに役立つタグ
type InvestigationRuleType Type はルールのタイプを示し、アラートの評価に使用されるものを決定します
order Int Order はルールを評価する順序を定義します。
数値が小さいほど、そのルールは早く評価されます。
ルールのフィルターが一致してアラートに適用されると、システムは他のルールの適用を試行しなくなります。
state InvestigationRuleState State はルールの処理動作を定義します
filter String QL 式として表現されたアラートフィルター
appendFilter String 追加時と作成時で異なるアラート制約(たとえばより広い条件)を定義できるオプションのフィルター
appendComment String アラートが既存の非ドラフト investigation に追加されたときに展開され、コメントが生成されるオプションのコメント
groupBy String 一致する追加のアラートを既存の investigation に追加するオプションの group by 句
groupCount Int Count は、group by 句に必要な一致数を指定するオプションです
groupDuration String Duration は、一致する investigation がクローズされた後もアラートのグループ化を継続する期間を指定するオプションです(形式は <int>[d|h|m|s] の文字列)
groupExtendOnAppend Boolean 新しく追加されたアラートが、アラートのグループ化に使用されるエンティティ/アトリビュートのセットを拡張するかどうかを示すオプションのフラグです。デフォルトは false です
searchQueries String 新しく作成された investigation に追加のアラートまたはイベントを入力するために使用されるオプションの検索クエリ
searchWindow String オプションの検索ウィンドウは、genesis alerts から検索が評価される期間を指定します
tenantFilter String 有効なサービスやルール定義と同じテナントなどのアトリビュートに基づいてテナントをフィルタリングする設定
skipAlertPrioritization Boolean アラート評価時にアラートの優先度が引き下げられているかどうかの確認をスキップする設定
template InvestigationTemplate investigation コンテンツを定義するテンプレート
comment String
excludeChildTenants Boolean
createdBy TDRUser
updatedBy TDRUser

CreateInvestigationRuleInput🔗

説明: CreateInvestigationRuleInput は、新しい investigation ルールを作成するために使用されるフィールドを説明します。

フィールド🔗

Field Type Description Arguments
name String 作成するルール名。
文字、数字、アンダースコアのみで構成できます。
name は一度設定すると変更できません。
title String ルールのタイトル - 後で変更できます。
description String ルールの説明
tags String ルールのラベル付けに役立つタグ
type InvestigationRuleType Type はルールのタイプを示し、アラートの評価方法を決定します
order Int Order はルールを評価する順序を定義します。
重複する order 値は許可されません。重複する order を持つルールを追加すると、そのルールは目的の
位置に挿入され、挿入されたルールの order 以上のすべてのルールは 1 つ繰り上がります。
state InvestigationRuleState State はルールの処理動作を定義します
filter String filter は、アラートをルールに一致させるために使用される ql/cel 式です
appendFilter String appendFilter は、追加時と作成時で異なるアラート制約(たとえばより広い条件)を定義できるオプションのフィルターです
appendComment String appendComment は、アラートが既存の非ドラフト investigation に追加されたときに展開され、コメントが生成されるオプションのコメントです
groupBy String groupBy 句は、一致する追加のアラートを既存のオープンな investigation に追加します
groupCount Int groupCount は、group by 句に必要な一致数を指定するオプションです
groupDuration String groupDuration は、一致する investigation がクローズされた後もアラートのグループ化を継続する期間を指定するオプションです(形式は <int>[h|m|s] の文字列)
groupExtendOnAppend Boolean groupExtendOnAppend は、新しく追加されたアラートが、アラートのグループ化に使用されるエンティティ/アトリビュートのセットを拡張するかどうかを示すオプションのフラグです。デフォルトは false です
searchQueries String searchQueries は、新しく作成された investigation に追加のアラートまたはイベントを入力するために使用される cql 式のオプションリストです
searchWindow String searchWindow は、searchQueries が評価される genesis alerts からのオプションの期間です
tenantFilter String tenantFilter は、有効なサービスやルール定義と同じテナントなどのアトリビュートに基づいてテナントをフィルタリングするために使用できます
skipAlertPrioritization Boolean skipAlertPrioritization は、アラート評価時にアラートの優先度が引き下げられているかどうかの確認をスキップするために使用できます
templateId ID templateId は、ルールが新しい investigation をオープンする必要があるときに使用するテンプレートの id です
responseData JSONObject ResponseData は、プレイブック向けのルール固有のコンテキスト/設定を提供します。

UpdateInvestigationRuleInput🔗

説明: UpdateInvestigationRuleInput は、既存の investigation ルールを更新するために使用できるフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID 更新するルールの ID
title String ルールのタイトル(これを変更してもルールの視覚的表現にのみ影響します)。
description String ルールの説明
tags String ルールのラベル付けに役立つタグ。
タグは追加方式ではなく、指定されたタグが investigation 上の既存のタグを置き換えます。
既存のタグを保持したい場合は、tags フィールドにそれらを含める必要があります。
tags フィールドをまったく送信しない(null)場合、タグは更新されません。
order Int Order はルールを評価する順序を定義します。
重複する order 値は許可されません。重複する order を持つルールを追加すると、そのルールは目的の
位置に挿入され、挿入されたルールの order 以上のすべてのルールは 1 つ繰り上がります。
state InvestigationRuleState State はルールの処理動作を定義します
filter String filter は、アラートをルールに一致させるために使用される ql/cel 式です
appendFilter String appendFilter は、追加時と作成時で異なるアラート制約(たとえばより広い条件)を定義できるオプションのフィルターです
appendComment String appendComment は、アラートが既存の非ドラフト investigation に追加されたときに展開され、コメントが生成されるオプションのコメントです
groupBy String groupBy 句は、一致する追加のアラートを既存のオープンな investigation に追加します
groupCount Int groupCount は、group by 句に必要な一致数を指定するオプションです
groupDuration String groupDuration は、一致する investigation がクローズされた後もアラートのグループ化を継続する期間を指定するオプションです(形式は <int>[h|m|s] の文字列)
groupExtendOnAppend Boolean groupExtendOnAppend は、新しく追加されたアラートが、アラートのグループ化に使用されるエンティティ/アトリビュートのセットを拡張するかどうかを示すオプションのフラグです。デフォルトは false です
searchQueries String searchQueries は、新しく作成された investigation に追加のアラートまたはイベントを入力するために使用される cql 式のオプションリストです
searchWindow String searchWindow は、searchQueries が評価される genesis alerts からのオプションの期間です
tenantFilter String tenantFilter は、有効なサービスやルール定義と同じテナントなどのアトリビュートに基づいてテナントをフィルタリングするために使用できます
skipAlertPrioritization Boolean skipAlertPrioritization は、アラート評価時にアラートの優先度が引き下げられているかどうかの確認をスキップするために使用できます
templateId ID templateId は、ルールが新しい investigation をオープンする必要があるときに使用するテンプレートの id です
responseData JSONObject ResponseData は、プレイブック向けのルール固有のコンテキスト/設定を提供します。

InvestigationRules🔗

説明: InvestigationRules は、investigation ルール検索のページネーションされた結果を定義します。

フィールド🔗

Field Type Description Arguments
rules InvestigationRule
totalCount Int

InvestigationRuleArguments🔗

説明: InvestigationRuleArguments は、investigation ルールを見つけるためのパラメーターを説明します。 id と name はどちらもルールの一意識別子です。 少なくとも 1 つのフィールドを設定する必要があり、両方を設定した場合は両方ともルールに一致する必要があります。

フィールド🔗

Field Type Description Arguments
id ID
name String

InvestigationRulesArguments🔗

説明: InvestigationRulesArguments は、investigation ルールの検索のためのパラメーターを説明します。

フィールド🔗

Field Type Description Arguments
cql String テンプレートを検索するための cql 文字列
page Int 返す結果のページ - ページは 1 から始まります
perPage Int 1 ページあたりの結果数 - 最大 100
name String
tags String

InvestigationRuleState🔗

InvestigationStatus🔗

説明: InvestigationStatuses は、investigation で使用可能なステータスを定義します。

InvestigationCloseStatus🔗

説明: InvestigationCloseStatus は、investigation をクローズするために使用可能なステータスを定義します。

InvestigationV2StatusesArguments🔗

フィールド🔗

Field Type Description Arguments
currentStatus InvestigationStatus CurrentStatus は investigation の現在のステータスです。
設定されている場合、結果は現在のステータスから遷移可能なステータスのみを含むようにフィルタリングされます。
主にドラフト関連のステータスに使用されます。

InvestigationType🔗

説明: InvestigationType は、investigation で使用可能なタイプを定義します。

InvestigationProcessingState🔗

説明: InvestigationProcessingState は、investigation 証拠の処理に使用可能な状態を定義します。

ExportInvestigationResourceInput🔗

説明: ExportInvestigationResourceInput は、investigation リソースをエクスポートするために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID

ImportInvestigationResourcesInput🔗

説明: ImportInvestigationResourcesInput は、investigation リソースをインポートするために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
file Upload アップロードするファイル

InvestigationResourceExport🔗

説明: InvestigationResourceExport は、investigation リソースをエクスポートするために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
export String エクスポートドキュメント

InvestigationResource🔗

説明: InvestigationResource union は、investigation リソースを実装するすべての型を定義します。

InvestigationResourceType🔗

説明: InvestigationResourceType は、investigation リソースで使用可能なタイプを定義します。

InvestigationProcessingStatus🔗

説明: InvestigationProcessingStatus は、処理状態を持つことができる証拠と、現在の処理状態を定義します。

フィールド🔗

Field Type Description Arguments
assets InvestigationProcessingState
events InvestigationProcessingState
alerts InvestigationProcessingState

PaginationOrder🔗

説明: PaginationOrder は、結果を昇順または降順に並べ替えるために使用できる列挙型を定義します

InvestigationV2TimelineEntityType🔗

説明: InvestigationV2TimelineEntityType は、investigation タイムラインエンティティで使用可能なタイプを定義します。

InvestigationRuleType🔗

説明: InvestigationRuleType は、investigation で使用可能なタイプを定義します。 これらのタイプは、アラートの評価方法を決定するために使用されます。

InvestigationV2TimelineArguments🔗

説明: InvestigationV2TimelineArguments は、investigation タイムラインを取得するためのパラメーターを説明します。

フィールド🔗

Field Type Description Arguments
investigationId ID タイムラインを取得する investigation の ID
createdAfter String createdAfter は、指定されたタイムスタンプより後に作成されたタイムラインエントリのみにフィルタリングするためのタイムスタンプです
createdBefore String createdBefore は、指定されたタイムスタンプより前に作成されたタイムラインエントリのみにフィルタリングするためのタイムスタンプです
orderBy PaginationOrder orderBy はタイムラインエントリを並べ替える順序です
entityTypes InvestigationV2TimelineEntityType entityTypes は、指定されたタイプのタイムラインエントリのみにフィルタリングするためのエンティティタイプのリストです
page Int 返す結果のページ - ページは 1 から始まります
perPage Int 1 ページあたりの結果数 - 最大 1000

InvestigationV2Timeline🔗

説明: InvestigationV2Timeline は、investigation タイムラインリクエストのページネーションされた結果を定義します。

フィールド🔗

Field Type Description Arguments
entities InvestigationV2TimelineEntity 現在のページの検索条件に一致するタイムラインエントリのリスト
totalEntities Int 検索条件に一致するタイムラインエントリの総数

InvestigationV2TimelineEntity🔗

説明: InvestigationV2TimelineEntity は、investigation の単一タイムラインエントリのフィールドを定義します。

フィールド🔗

Field Type Description Arguments
id ID タイムラインエントリの ID(一意)
investigationId ID タイムラインエントリが関連付けられている investigation の ID
type String type はタイムラインエントリのタイプです - Event Alert
tenantId String tenantId はタイムラインが関連する investigation の tenant id です
createdAt Time createdAt はタイムラインエントリが作成された時刻です
resourceId String resourceId は監査タイムラインエンティティに関連するリソースの id です
resourceCreatedAt Time resourceCreatedAt はリソースが作成された時刻です
description String description はタイムラインエントリの短い説明です
descriptor String descriptor はエントリの側面を強調する 1~2 語の短い語句です
監査タイプには descriptor はありません
subjectId String subjectId は監査タイムラインエンティティに関連するユーザーの id です
subject Subject subject は、監査タイムラインエンティティに関連するユーザーのユーザー情報を取得するために使用できるフェデレーションフィールドです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
ユーザーがフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
isPartnerOnly Boolean isPartnerOnly は、そのタイムラインエントリがパートナーユーザーにのみ表示されるかどうかを示します
user TDRUser
entityId String
timestamp Time
userId ID
userSubject Subject

AddCommentToInvestigationInput🔗

説明: AddCommentToInvestigationInput は、investigation にコメントを追加するために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
investigationId String コメントを追加する investigation の ID
comment String comment は investigation に追加するコメントのテキストです。
コメントには、ユーザーに通知するための @mention を含めることができます。
isInternal Boolean isInternal はコメントを内部コメントとしてマークし、パートナーユーザーにのみ表示します
内部コメントを作成できるのはパートナーユーザーのみです。

UpdateInvestigationCommentInput🔗

説明: UpdateInvestigationCommentInput は、investigation 内のコメントを更新するために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
commentId String 更新するコメントの ID
comment String comment は更新するコメントのテキストです
markAsRead Boolean mark as read は、現在のユーザーに対してコメントを既読としてマークします

CommentV2🔗

説明: CommentV2 は、investigation 内のコメントのフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID コメントの ID(一意)
authorId String コメントを作成したユーザーの ID
authorSubject Subject authorSubject は、コメント作成者のユーザー情報を取得するために使用できるフェデレーションフィールドです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
author がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
createdAt Time createdAt はコメントが作成された時刻です
updatedAt Time updatedAt はコメントが最後に更新された時刻です
comment String comment はコメントのテキストです
investigationId ID investigationId はコメントが関連付けられている investigation の id です
tenantId String tenantId はコメントが関連する investigation の tenant id です
mentionsIds String mentionsIds はコメント内で言及されているユーザー id およびグループ mention のリストです
mentionsSubjects Subject mentionsSubjects はコメント内で言及されている subject のリストです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
mentions がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
readByIds String readByIds はコメントを既読としてマークしたユーザー id のリストです
readBySubjects Subject readBySubjects はコメントを既読としてマークした subject のリストです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
readBy がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
isInternal Boolean isInternal は、そのコメントが内部コメントでありパートナーユーザーにのみ表示されるかどうかを示します
author TDRUser
mentionsUsers TDRUser
readBy TDRUser

DeleteInvestigationCommentInput🔗

説明: DeleteInvestigationCommentInput は、investigation からコメントを削除するために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
commentId String

CommentVisibilityFilter🔗

説明: CommentVisibilityFilter は、コメントに使用可能なフィルターを定義します。

CommentsV2Arguments🔗

説明: CommentsV2Arguments は、investigation 内のコメントを検索するためのパラメーターを説明します。

フィールド🔗

Field Type Description Arguments
investigationId String コメントを取得する investigation の ID
orderBy PaginationOrder orderBy はコメントを createdAt タイムスタンプで並べ替える順序です
visibility CommentVisibilityFilter visibility は、コメントをその可視性(isInternal)でフィルタリングするために使用されます
page Int 返す結果のページ - ページは 1 から始まります
perPage Int 1 ページあたりの結果数 - 最大 100

CommentsV2🔗

説明: CommentsV2 は、コメント検索のページネーションされた結果を定義します。

フィールド🔗

Field Type Description Arguments
comments CommentV2 現在のページの検索条件に一致するコメントのリスト
totalCount Int 検索条件に一致するコメントの総数

InvestigationCommentsCount🔗

説明: InvestigationCommentsCount は、investigation のコメント総数と未読コメント数を定義します。

フィールド🔗

Field Type Description Arguments
total Int
unread Int

AlertEvidence🔗

説明: AlertEvidence は、investigation 内のアラート証拠のフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID 証拠エントリの ID(一意)
investigationId ID 証拠が関連する investigation の ID
tenantId String investigation/証拠の tenant id
createdAt Time 証拠が investigation に追加された時刻のタイムスタンプ
createdBy String 証拠を追加したユーザーまたはクライアントの Id。
追加された他の証拠から派生した証拠が同期プロセスによって追加された場合、このフィールドにはその証拠を追加したサービスアカウントが設定されます。
alertId String アラート id
isGenesis Boolean IsGenesis は、その証拠が investigation を最初にオープンするために使用されたかどうかを示すフラグです

EventEvidence🔗

説明: EventEvidence は、investigation 内のイベント証拠のフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID 証拠エントリの ID(一意)
investigationId ID 証拠が関連する investigation の ID
tenantId String investigation/証拠の tenant id
createdAt Time 証拠が investigation に追加された時刻のタイムスタンプ
createdBy String 証拠を追加したユーザーまたはクライアントの Id。
追加された他の証拠から派生した証拠が同期プロセスによって追加された場合、このフィールドにはその証拠を追加したサービスアカウントが設定されます。
eventId String イベント id
isGenesis Boolean IsGenesis は、その証拠が investigation を最初にオープンするために使用されたかどうかを示すフラグです

AssetEvidence🔗

説明: AssetEvidence は、investigation 内の asset 証拠のフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID 証拠エントリの ID(一意)
investigationId ID 証拠が関連する investigation の ID
tenantId String investigation/証拠の tenant id
createdAt Time 証拠が investigation に追加された時刻のタイムスタンプ
createdBy String 証拠を追加したユーザーまたはクライアントの Id。
追加された他の証拠から派生した証拠が同期プロセスによって追加された場合、このフィールドにはその証拠を追加したサービスアカウントが設定されます。
assetId String asset id

EntityEvidence🔗

説明: 非推奨: 代替はありません。entity api を呼び出してください

フィールド🔗

Field Type Description Arguments
id ID
investigationId ID
tenantId String
createdAt Time
createdBy String
entityId String

SearchQueryEvidence🔗

説明: SearchQueryEvidence は、investigation 内の検索クエリ証拠のフィールドを説明します。

フィールド🔗

Field Type Description Arguments
id ID 証拠エントリの ID(一意)
investigationId ID 証拠が関連する investigation の ID
tenantId String investigation/証拠の tenant id
createdAt Time 証拠が investigation に追加された時刻のタイムスタンプ
createdBy String 証拠を追加したユーザーまたはクライアントの Id。
追加された他の証拠から派生した証拠が同期プロセスによって追加された場合、このフィールドにはその証拠を追加したサービスアカウントが設定されます。
searchQuery String 検索クエリ
isGenesis Boolean IsGenesis は、その証拠が investigation を最初にオープンするために使用されたかどうかを示すフラグです

InvestigationV2Type🔗

説明: InvestigationV2Type は investigation タイプを定義します

フィールド🔗

Field Type Description Arguments
type InvestigationType Investigation タイプ
description String investigation タイプの説明

InvestigationV2Status🔗

説明: InvestigationV2Status は investigation ステータスを定義します

フィールド🔗

Field Type Description Arguments
status InvestigationStatus Investigation ステータス

InvestigationFileV2🔗

説明: InvestigationFileV2 は、investigation 内のファイルのフィールドを定義します。

フィールド🔗

Field Type Description Arguments
id ID ファイルの ID(一意)
investigationId ID ファイルが関連する investigation の ID
tenantId String investigation/ファイルの tenant id
createdAt Time ファイルが investigation に追加された時刻のタイムスタンプ
updatedAt Time ファイルが最後に更新された時刻のタイムスタンプ
deletedAt Time ファイルが削除された時刻のタイムスタンプ
uploadedById String uploadedById はファイルアップロードを初期化したユーザーの id です
uploadedBySubject Subject uploadedBySubject は、ファイルアップロードを初期化したユーザーのユーザー情報を取得するために使用できるフェデレーションフィールドです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
uploadedBy がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
deletedById String deletedById はファイルを削除したユーザーの id です
deletedBySubject Subject deletedBySubject は、ファイルを削除したユーザーのユーザー情報を取得するために使用できるフェデレーションフィールドです
これは利便性のためのフィールドであり、api がこのフィールドをフェデレーション経由でレンダリングできないと判断した場合は nil になります。
deletedBy がフェデレーション経由で解決できる保証はありません。たとえば、フェデレーションサービスが停止している場合や subject が削除された場合です。
name String ファイル名
path String ファイルの場所
size Int ファイルサイズ
status String ファイルの現在のアップロードステータス
metadata InvestigationFileMeta ファイルに関する追加メタデータ
downloadURL String ファイルの署名付きダウンロード url。
ファイルが削除されている場合、または単一クエリで複数ファイルが要求された場合は null になります。
uploadedBy TDRUser
deletedBy TDRUser

InvestigationFileMeta🔗

説明: InvestigationFileMeta は、investigation 内のファイルに関する追加メタデータを定義します。

フィールド🔗

Field Type Description Arguments
contentType String ファイルの content type
contentMD5 String ファイルの md5 ハッシュ

InitInvestigationFileUploadInput🔗

説明: InitInvestigationFileUploadInput は、investigation のファイルアップロードを初期化するために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
investigationId ID ファイルをアップロードする investigation の ID
name String ファイル名
size Int 想定されるファイルサイズ
contentType String 想定されるファイルの content type

InvestigationFileUpload🔗

説明: InitInvestigationFileUpload は、investigation のファイルアップロード初期化に対するレスポンスです。

フィールド🔗

Field Type Description Arguments
file InvestigationFileV2 file には、presignedUrl にアップロードされることを想定しているファイルのメタデータが含まれます
presignedUrl String presignedUrl はファイルをアップロードする URL です

InvestigationFileV2Arguments🔗

説明: InvestigationFileV2Arguments は、investigation に添付されたファイルを取得するためのパラメーターを説明します。

フィールド🔗

Field Type Description Arguments
fileId ID

InvestigationFilesV2🔗

フィールド🔗

Field Type Description Arguments
files InvestigationFileV2
totalCount Int

InvestigationFilesV2Arguments🔗

フィールド🔗

Field Type Description Arguments
cql String ファイルを検索するための cql 文字列
page Int 返す結果のページ - ページは 1 から始まります
perPage Int 1 ページあたりの結果数 - 最大 100
investigationId ID

DeleteInvestigationFileInput🔗

説明: DeleteInvestigationFileInput は、investigation からファイルを削除するために必要なフィールドを説明します。

フィールド🔗

Field Type Description Arguments
fileId ID

TenantV4🔗

フィールド🔗

Field Type Description Arguments
id ID

Subject🔗

フィールド🔗

Field Type Description Arguments
id ID

TDRUser🔗

フィールド🔗

Field Type Description Arguments
id ID

Time🔗

説明: このライブラリのデフォルトの Time 実装です。

Upload🔗

説明: ファイルアップロードの内容

JSONObject🔗

説明: JSON ペイロード

Map🔗

説明: このライブラリのデフォルトの Map 実装です