openapi: 3.0.1 info: title: Zero Networks version: 1.26.3 description: APIs for Zero Networks contact: name: Support url: https://support.zeronetworks.com email: support@zeronetworks.com servers: - url: https://portal.zeronetworks.com/v1/api description: Customer URL variables: CustomerURL: description: this value is per customer / partner default: portal paths: /active-directory/domains: {} /activities/analysis/widgets/{activityType}: {} /activities/analysis/widgets/{activityType}/{widgetId}: {} /activities/logon: {} /activities/logon/distinctField/{fieldName}: {} /activities/logon/export: {} /activities/logon/export/csv/{exportId}: {} /activities/logon/filters: {} /activities/logon/filters/user-filters: {} /activities/logon/filters/user-filters/{filterId}: {} /activities/network: {} /activities/network/distinctField/{fieldName}: {} /activities/network/export: {} /activities/network/export/csv/{exportId}: {} /activities/network/filters: {} /activities/network/filters/user-filters: {} /activities/network/filters/user-filters/{filterId}: {} /activities/rpc: {} /activities/rpc/export: {} /activities/rpc/export/csv/{exportId}: {} /activities/rpc/filters: {} /activities/rpc/filters/interface-candidates: {} /activities/rpc/filters/op-candidates: {} /activities/rpc/filters/user-filters: {} /activities/rpc/filters/user-filters/{filterId}: {} /activities/network/internet-categories-candidates: {} /activities/network/internet-sub-categories-candidates: {} /ai/learning-config: {} /ai/next-batch: {} /assets: {} /assets/{assetId}: {} /assets/{assetId}/actions: {} /assets/{assetId}/actions/activate: {} /assets/{assetId}/actions/activate-break-glass: {} /assets/{assetId}/actions/deactivate-break-glass: {} /assets/{assetId}/actions/inactivate: {} /assets/{assetId}/actions/mirror: {} /assets/{assetId}/actions/os-type: {} /assets/{assetId}/actions/outbound-restriction: {} /assets/{assetId}/actions/deployments-cluster: {} /assets/{assetId}/actions/preferred-deployment: {} /assets/{assetId}/actions/protect: {} /assets/{assetId}/actions/protect/validate: {} /assets/{assetId}/actions/quarantine: {} /assets/{assetId}/actions/queue: {} /assets/{assetId}/actions/retry-health: {} /assets/{assetId}/actions/type: {} /assets/{assetId}/actions/unprotect: {} /assets/{assetId}/actions/unprotect/validate: {} /assets/{assetId}/activities/logon: {} /assets/{assetId}/activities/logon/distinctField/{fieldName}: {} /assets/{assetId}/activities/logon/export: {} /assets/{assetId}/activities/logon/export/csv/{exportId}: {} /assets/{assetId}/activities/logon/filters: {} /assets/{assetId}/activities/logon/filters/user-filters: {} /assets/{assetId}/activities/logon/filters/user-filters/{filterId}: {} /assets/{assetId}/activities/network: {} /assets/{assetId}/activities/network/distinctField/{fieldName}: {} /assets/{assetId}/activities/network/export: {} /assets/{assetId}/activities/network/export/csv/{exportId}: {} /assets/{assetId}/activities/network/filters: {} /assets/{assetId}/activities/network/filters/user-filters: {} /assets/{assetId}/activities/network/filters/user-filters/{filterId}: {} /assets/{assetId}/activities/rpc: {} /assets/{assetId}/activities/rpc/export: {} /assets/{assetId}/activities/rpc/export/csv/{exportId}: {} /assets/{assetId}/activities/rpc/filters: {} /assets/{assetId}/activities/rpc/filters/interface-candidates: {} /assets/{assetId}/activities/rpc/filters/op-candidates: {} /assets/{assetId}/activities/rpc/filters/user-filters: {} /assets/{assetId}/activities/rpc/filters/user-filters/{filterId}: {} /assets/{assetId}/analysis/identity: {} /assets/{assetId}/analysis/identity/export: {} /assets/{assetId}/analysis/identity/export/csv/{exportId}: {} /assets/{assetId}/analysis/network: {} /assets/{assetId}/analysis/network/activity-map: {} /assets/{assetId}/analysis/network/export: {} /assets/{assetId}/analysis/network/export/csv/{exportId}: {} /assets/{assetId}/ancestors: {} /assets/{assetId}/ancestors/candidates: {} /assets/{assetId}/audit: {} /assets/{assetId}/audit/export: {} /assets/{assetId}/audit/export/csv/{exportId}: {} /assets/{assetId}/audit/filters: {} /assets/{assetId}/cluster-info: {} /assets/{assetId}/health-state: {} /assets/{assetId}/identity-actions/protect: {} /assets/{assetId}/identity-actions/protect/validate: {} /assets/{assetId}/identity-actions/queue: {} /assets/{assetId}/identity-actions/unprotect: {} /assets/{assetId}/identity-actions/unprotect/validate: {} /assets/{assetId}/labels/add: {} /assets/{assetId}/labels/key-candidates: {} /assets/{assetId}/labels/remove: {} /assets/{assetId}/labels/value-candidates: {} /assets/{assetId}/listening-ports: {} /assets/{assetId}/managers: {} /assets/{assetId}/managers/{groupOrUserId}: {} /assets/{assetId}/managers/candidates: {} /assets/{assetId}/mirror-candidates: {} /assets/{assetId}/protection/external-access-policies: {} /assets/{assetId}/protection/external-access-policies/{policyId}: {} /assets/{assetId}/protection/external-access-policies/dst-asset-candidates: {} /assets/{assetId}/protection/external-access-policies/filters: {} /assets/{assetId}/protection/external-access-policies/filters/dst-asset-candidates: {} /assets/{assetId}/protection/external-access-policies/filters/src-users-candidates: {} /assets/{assetId}/protection/external-access-policies/src-users-candidates: {} /assets/{assetId}/protection/external-access-policies/statistics: {} /assets/{assetId}/protection/identity-rules: {} /assets/{assetId}/protection/identity-rules/{ruleId}: {} /assets/{assetId}/protection/identity-rules/asset-candidates: {} /assets/{assetId}/protection/identity-rules/excluded-asset-candidates: {} /assets/{assetId}/protection/identity-rules/export: {} /assets/{assetId}/protection/identity-rules/export/csv/{exportId}: {} /assets/{assetId}/protection/identity-rules/filters: {} /assets/{assetId}/protection/identity-rules/filters/asset-candidates: {} /assets/{assetId}/protection/identity-rules/filters/user-candidates: {} /assets/{assetId}/protection/identity-rules/filters/user-filters: {} /assets/{assetId}/protection/identity-rules/filters/user-filters/{filterId}: {} /assets/{assetId}/protection/identity-rules/user-candidates: {} /assets/{assetId}/protection/identity/reactive-policies: {} /assets/{assetId}/protection/identity/reactive-policies/{reactivePolicyId}: {} /assets/{assetId}/protection/identity/reactive-policies/dst-asset-candidates: {} /assets/{assetId}/protection/identity/reactive-policies/excluded-src-asset-candidates: {} /assets/{assetId}/protection/identity/reactive-policies/export: {} /assets/{assetId}/protection/identity/reactive-policies/export/csv/{exportId}: {} /assets/{assetId}/protection/identity/reactive-policies/filters: {} /assets/{assetId}/protection/identity/reactive-policies/filters/dst-asset-candidates: {} /assets/{assetId}/protection/identity/reactive-policies/filters/src-asset-candidates: {} /assets/{assetId}/protection/identity/reactive-policies/filters/src-users-candidates: {} /assets/{assetId}/protection/identity/reactive-policies/filters/user-filters: {} /assets/{assetId}/protection/identity/reactive-policies/filters/user-filters/{filterId}: {} /assets/{assetId}/protection/identity/reactive-policies/mfa-methods: {} /assets/{assetId}/protection/identity/reactive-policies/src-asset-candidates: {} /assets/{assetId}/protection/identity/reactive-policies/src-users-candidates: {} /assets/{assetId}/protection/reactive-policies/inbound: {} /assets/{assetId}/protection/reactive-policies/inbound/{reactivePolicyId}: {} /assets/{assetId}/protection/reactive-policies/inbound/dst-candidates: {} /assets/{assetId}/protection/reactive-policies/inbound/excluded-src-candidates: {} /assets/{assetId}/protection/reactive-policies/inbound/filters: {} /assets/{assetId}/protection/reactive-policies/inbound/filters/dst-candidates: {} /assets/{assetId}/protection/reactive-policies/inbound/filters/src-candidates: {} /assets/{assetId}/protection/reactive-policies/inbound/filters/src-users-candidates: {} /assets/{assetId}/protection/reactive-policies/inbound/filters/user-filters: {} /assets/{assetId}/protection/reactive-policies/inbound/filters/user-filters/{filterId}: {} /assets/{assetId}/protection/reactive-policies/inbound/mfa-methods: {} /assets/{assetId}/protection/reactive-policies/inbound/simulate: {} /assets/{assetId}/protection/reactive-policies/inbound/simulate/dst-candidates: {} /assets/{assetId}/protection/reactive-policies/inbound/simulate/resolve: {} /assets/{assetId}/protection/reactive-policies/inbound/simulate/src-candidates: {} /assets/{assetId}/protection/reactive-policies/inbound/simulate/src-users-candidates: {} /assets/{assetId}/protection/reactive-policies/inbound/src-candidates: {} /assets/{assetId}/protection/reactive-policies/inbound/src-users-candidates: {} /assets/{assetId}/protection/reactive-policies/outbound: {} /assets/{assetId}/protection/reactive-policies/outbound/{reactivePolicyId}: {} /assets/{assetId}/protection/reactive-policies/outbound/dst-candidates: {} /assets/{assetId}/protection/reactive-policies/outbound/excluded-src-candidates: {} /assets/{assetId}/protection/reactive-policies/outbound/filters: {} /assets/{assetId}/protection/reactive-policies/outbound/filters/dst-candidates: {} /assets/{assetId}/protection/reactive-policies/outbound/filters/src-candidates: {} /assets/{assetId}/protection/reactive-policies/outbound/filters/src-users-candidates: {} /assets/{assetId}/protection/reactive-policies/outbound/filters/user-filters: {} /assets/{assetId}/protection/reactive-policies/outbound/filters/user-filters/{filterId}: {} /assets/{assetId}/protection/reactive-policies/outbound/mfa-methods: {} /assets/{assetId}/protection/reactive-policies/outbound/simulate: {} /assets/{assetId}/protection/reactive-policies/outbound/simulate/dst-candidates: {} /assets/{assetId}/protection/reactive-policies/outbound/simulate/resolve: {} /assets/{assetId}/protection/reactive-policies/outbound/simulate/src-candidates: {} /assets/{assetId}/protection/reactive-policies/outbound/simulate/src-users-candidates: {} /assets/{assetId}/protection/reactive-policies/outbound/src-candidates: {} /assets/{assetId}/protection/reactive-policies/outbound/src-users-candidates: {} /assets/{assetId}/protection/rpc-rules: {} /assets/{assetId}/protection/rpc-rules/{ruleId}: {} /assets/{assetId}/protection/rpc-rules/excluded-local-candidates: {} /assets/{assetId}/protection/rpc-rules/export: {} /assets/{assetId}/protection/rpc-rules/export/csv/{exportId}: {} /assets/{assetId}/protection/rpc-rules/filters: {} /assets/{assetId}/protection/rpc-rules/filters/local-candidates: {} /assets/{assetId}/protection/rpc-rules/filters/remote-candidates: {} /assets/{assetId}/protection/rpc-rules/filters/user-candidates: {} /assets/{assetId}/protection/rpc-rules/filters/user-filters: {} /assets/{assetId}/protection/rpc-rules/filters/user-filters/{filterId}: {} /assets/{assetId}/protection/rpc-rules/local-candidates: {} /assets/{assetId}/protection/rpc-rules/remote-candidates: {} /assets/{assetId}/protection/rpc-rules/user-candidates: {} /assets/{assetId}/protection/rules/distribution/{ruleId}: {} /assets/{assetId}/protection/rules/history/{ruleId}: {} /assets/{assetId}/protection/rules/inbound: {} /assets/{assetId}/protection/rules/inbound/{ruleId}: {} /assets/{assetId}/protection/rules/inbound/excluded-local-candidates: {} /assets/{assetId}/protection/rules/inbound/export: {} /assets/{assetId}/protection/rules/inbound/export/csv/{exportId}: {} /assets/{assetId}/protection/rules/inbound/filters: {} /assets/{assetId}/protection/rules/inbound/filters/local-candidates: {} /assets/{assetId}/protection/rules/inbound/filters/remote-candidates: {} /assets/{assetId}/protection/rules/inbound/filters/user-filters: {} /assets/{assetId}/protection/rules/inbound/filters/user-filters/{filterId}: {} /assets/{assetId}/protection/rules/inbound/local-candidates: {} /assets/{assetId}/protection/rules/inbound/remote-candidates: {} /assets/{assetId}/protection/rules/inbound/review/approve-with-changes/{ruleId}: {} /assets/{assetId}/protection/rules/inbound/review/approve/{ruleId}: {} /assets/{assetId}/protection/rules/inbound/review/approve-delete/{ruleId}: {} /assets/{assetId}/protection/rules/inbound/review/reject/{ruleId}: {} /assets/{assetId}/protection/rules/inbound/review/reject-delete/{ruleId}: {} /assets/{assetId}/protection/rules/outbound: {} /assets/{assetId}/protection/rules/outbound/{ruleId}: {} /assets/{assetId}/protection/rules/outbound/excluded-local-candidates: {} /assets/{assetId}/protection/rules/outbound/export: {} /assets/{assetId}/protection/rules/outbound/export/csv/{exportId}: {} /assets/{assetId}/protection/rules/outbound/filters: {} /assets/{assetId}/protection/rules/outbound/filters/excluded-local-candidates: {} /assets/{assetId}/protection/rules/outbound/filters/local-candidates: {} /assets/{assetId}/protection/rules/outbound/filters/remote-candidates: {} /assets/{assetId}/protection/rules/outbound/filters/user-candidates: {} /assets/{assetId}/protection/rules/outbound/filters/user-filters: {} /assets/{assetId}/protection/rules/outbound/filters/user-filters/{filterId}: {} /assets/{assetId}/protection/rules/outbound/local-candidates: {} /assets/{assetId}/protection/rules/outbound/remote-candidates: {} /assets/{assetId}/protection/rules/outbound/review/approve-with-changes/{ruleId}: {} /assets/{assetId}/protection/rules/outbound/review/approve/{ruleId}: {} /assets/{assetId}/protection/rules/outbound/review/approve-delete/{ruleId}: {} /assets/{assetId}/protection/rules/outbound/review/reject/{ruleId}: {} /assets/{assetId}/protection/rules/outbound/review/reject-delete/{ruleId}: {} /assets/{assetId}/protection/rules/outbound/user-candidates: {} /assets/{assetId}/protection/switch-rules/inbound: {} /assets/{assetId}/protection/switch-rules/inbound/{ruleId}: {} /assets/{assetId}/protection/switch-rules/inbound/excluded-local-candidates: {} /assets/{assetId}/protection/switch-rules/inbound/export: {} /assets/{assetId}/protection/switch-rules/inbound/export/csv/{exportId}: {} /assets/{assetId}/protection/switch-rules/inbound/filters: {} /assets/{assetId}/protection/switch-rules/inbound/filters/local-candidates: {} /assets/{assetId}/protection/switch-rules/inbound/filters/remote-candidates: {} /assets/{assetId}/protection/switch-rules/inbound/filters/user-filters: {} /assets/{assetId}/protection/switch-rules/inbound/filters/user-filters/{filterId}: {} /assets/{assetId}/protection/switch-rules/inbound/local-candidates: {} /assets/{assetId}/protection/switch-rules/inbound/remote-candidates: {} /assets/{assetId}/protection/switch-rules/inbound/user-candidates: {} /assets/{assetId}/protection/switch-rules/outbound: {} /assets/{assetId}/protection/switch-rules/outbound/{ruleId}: {} /assets/{assetId}/protection/switch-rules/outbound/excluded-local-candidates: {} /assets/{assetId}/protection/switch-rules/outbound/export: {} /assets/{assetId}/protection/switch-rules/outbound/export/csv/{exportId}: {} /assets/{assetId}/protection/switch-rules/outbound/filters: {} /assets/{assetId}/protection/switch-rules/outbound/filters/local-candidates: {} /assets/{assetId}/protection/switch-rules/outbound/filters/remote-candidates: {} /assets/{assetId}/protection/switch-rules/outbound/filters/user-filters: {} /assets/{assetId}/protection/switch-rules/outbound/filters/user-filters/{filterId}: {} /assets/{assetId}/protection/switch-rules/outbound/local-candidates: {} /assets/{assetId}/protection/switch-rules/outbound/remote-candidates: {} /assets/{assetId}/rpc-actions/monitor: {} /assets/{assetId}/rpc-actions/protect: {} /assets/{assetId}/rpc-actions/queue: {} /assets/{assetId}/rpc-actions/unmonitor: {} /assets/{assetId}/rpc-actions/unprotect: {} /assets/{assetId}/tags: {} /assets/actions/activate: {} /assets/actions/activate-break-glass: {} /assets/actions/deactivate-break-glass: {} /assets/actions/deployments-cluster: {} /assets/actions/inactivate: {} /assets/actions/mirror: {} /assets/actions/os-type: {} /assets/actions/outbound-restriction: {} /assets/actions/preferred-deployment: {} /assets/actions/protect: {} /assets/actions/protect/validate: {} /assets/actions/quarantine: {} /assets/actions/queue: {} /assets/actions/unprotect: {} /assets/actions/unprotect/validate: {} /assets/actions: {} /assets/export: {} /assets/export/csv/{exportId}: {} /assets/exposure-meter-statistics: {} /assets/filters: {} /assets/filters/user-filters: {} /assets/filters/user-filters/{filterId}: {} /assets/firewalls: {} /assets/firewalls/{firewallId}: {} /assets/firewalls/filters: {} /assets/identity-actions/protect: {} /assets/identity-actions/protect/validate: {} /assets/identity-actions/queue: {} /assets/identity-actions/unprotect: {} /assets/identity-actions/unprotect/validate: {} /assets/identity/protected: {} /assets/identity/protected/export: {} /assets/identity/protected/export/csv/{exportId}: {} /assets/identity/protected/filters: {} /assets/identity/protected/filters/user-filters: {} /assets/identity/protected/filters/user-filters/{filterId}: {} /assets/identity/queued: {} /assets/identity/queued/export: {} /assets/identity/queued/export/csv/{exportId}: {} /assets/identity/queued/filters: {} /assets/identity/queued/filters/user-filters: {} /assets/identity/queued/filters/user-filters/{filterId}: {} /assets/inactive: {} /assets/inactive/export: {} /assets/inactive/export/csv/{exportId}: {} /assets/inactive/filters: {} /assets/inactive/filters/user-filters: {} /assets/inactive/filters/user-filters/{filterId}: {} /assets/linux: {} /assets/linux/scripts/add-user: {} /assets/linux/scripts/add-user-available: {} /assets/monitored: {} /assets/monitored/export: {} /assets/monitored/export/csv/{exportId}: {} /assets/monitored/filters: {} /assets/monitored/filters/user-filters: {} /assets/monitored/filters/user-filters/{filterId}: {} /assets/ot: {} /assets/ot/{assetId}: {} /assets/ot/{assetId}/actions/inactivate: {} /assets/ot/{assetId}/actions/protect: {} /assets/ot/{assetId}/actions/queue: {} /assets/ot/{assetId}/actions/unprotect: {} /assets/ot/{assetId}/actions/unprotect/validate: {} /assets/ot/{assetId}/activities/logon: {} /assets/ot/{assetId}/activities/logon/distinctField/{fieldName}: {} /assets/ot/{assetId}/activities/logon/export: {} /assets/ot/{assetId}/activities/logon/export/csv/{exportId}: {} /assets/ot/{assetId}/activities/logon/filters: {} /assets/ot/{assetId}/activities/logon/filters/user-filters: {} /assets/ot/{assetId}/activities/logon/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/activities/network: {} /assets/ot/{assetId}/activities/network/distinctField/{fieldName}: {} /assets/ot/{assetId}/activities/network/export: {} /assets/ot/{assetId}/activities/network/export/csv/{exportId}: {} /assets/ot/{assetId}/activities/network/filters: {} /assets/ot/{assetId}/activities/network/filters/user-filters: {} /assets/ot/{assetId}/activities/network/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/activities/rpc: {} /assets/ot/{assetId}/activities/rpc/export: {} /assets/ot/{assetId}/activities/rpc/export/csv/{exportId}: {} /assets/ot/{assetId}/activities/rpc/filters: {} /assets/ot/{assetId}/activities/rpc/filters/interface-candidates: {} /assets/ot/{assetId}/activities/rpc/filters/op-candidates: {} /assets/ot/{assetId}/activities/rpc/filters/user-filters: {} /assets/ot/{assetId}/activities/rpc/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/analysis/identity: {} /assets/ot/{assetId}/analysis/identity/export: {} /assets/ot/{assetId}/analysis/identity/export/csv/{exportId}: {} /assets/ot/{assetId}/analysis/network: {} /assets/ot/{assetId}/analysis/network/activity-map: {} /assets/ot/{assetId}/analysis/network/export: {} /assets/ot/{assetId}/analysis/network/export/csv/{exportId}: {} /assets/ot/{assetId}/ancestors: {} /assets/ot/{assetId}/ancestors/candidates: {} /assets/ot/{assetId}/audit: {} /assets/ot/{assetId}/audit/export: {} /assets/ot/{assetId}/audit/export/csv/{exportId}: {} /assets/ot/{assetId}/audit/filters: {} /assets/ot/{assetId}/labels/add: {} /assets/ot/{assetId}/labels/key-candidates: {} /assets/ot/{assetId}/labels/remove: {} /assets/ot/{assetId}/labels/value-candidates: {} /assets/ot/{assetId}/managers: {} /assets/ot/{assetId}/managers/{groupOrUserId}: {} /assets/ot/{assetId}/managers/candidates: {} /assets/ot/{assetId}/mirror-candidates: {} /assets/ot/{assetId}/protection/identity-rules: {} /assets/ot/{assetId}/protection/identity-rules/{ruleId}: {} /assets/ot/{assetId}/protection/identity-rules/asset-candidates: {} /assets/ot/{assetId}/protection/identity-rules/excluded-asset-candidates: {} /assets/ot/{assetId}/protection/identity-rules/export: {} /assets/ot/{assetId}/protection/identity-rules/export/csv/{exportId}: {} /assets/ot/{assetId}/protection/identity-rules/filters: {} /assets/ot/{assetId}/protection/identity-rules/filters/asset-candidates: {} /assets/ot/{assetId}/protection/identity-rules/filters/user-candidates: {} /assets/ot/{assetId}/protection/identity-rules/filters/user-filters: {} /assets/ot/{assetId}/protection/identity-rules/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/protection/identity-rules/user-candidates: {} /assets/ot/{assetId}/protection/identity/reactive-policies: {} /assets/ot/{assetId}/protection/identity/reactive-policies/{reactivePolicyId}: {} /assets/ot/{assetId}/protection/identity/reactive-policies/dst-asset-candidates: {} /assets/ot/{assetId}/protection/identity/reactive-policies/excluded-src-asset-candidates: {} /assets/ot/{assetId}/protection/identity/reactive-policies/export: {} /assets/ot/{assetId}/protection/identity/reactive-policies/export/csv/{exportId}: {} /assets/ot/{assetId}/protection/identity/reactive-policies/filters: {} /assets/ot/{assetId}/protection/identity/reactive-policies/filters/dst-asset-candidates: {} /assets/ot/{assetId}/protection/identity/reactive-policies/filters/src-asset-candidates: {} /assets/ot/{assetId}/protection/identity/reactive-policies/filters/src-users-candidates: {} /assets/ot/{assetId}/protection/identity/reactive-policies/filters/user-filters: {} /assets/ot/{assetId}/protection/identity/reactive-policies/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/protection/identity/reactive-policies/mfa-methods: {} /assets/ot/{assetId}/protection/identity/reactive-policies/src-asset-candidates: {} /assets/ot/{assetId}/protection/identity/reactive-policies/src-users-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/inbound: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/{reactivePolicyId}: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/dst-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/excluded-src-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/filters: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/filters/dst-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/filters/src-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/filters/src-users-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/filters/user-filters: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/simulate: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/simulate/dst-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/simulate/resolve: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/simulate/src-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/simulate/src-users-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/mfa-methods: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/src-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/inbound/src-users-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/outbound: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/{reactivePolicyId}: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/dst-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/excluded-src-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/filters: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/filters/dst-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/filters/src-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/filters/src-users-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/filters/user-filters: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/mfa-methods: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/simulate: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/simulate/dst-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/simulate/resolve: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/simulate/src-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/simulate/src-users-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/src-candidates: {} /assets/ot/{assetId}/protection/reactive-policies/outbound/src-users-candidates: {} /assets/ot/{assetId}/protection/rpc-rules: {} /assets/ot/{assetId}/protection/rpc-rules/{ruleId}: {} /assets/ot/{assetId}/protection/rpc-rules/excluded-local-candidates: {} /assets/ot/{assetId}/protection/rpc-rules/export: {} /assets/ot/{assetId}/protection/rpc-rules/export/csv/{exportId}: {} /assets/ot/{assetId}/protection/rpc-rules/filters: {} /assets/ot/{assetId}/protection/rpc-rules/filters/local-candidates: {} /assets/ot/{assetId}/protection/rpc-rules/filters/remote-candidates: {} /assets/ot/{assetId}/protection/rpc-rules/filters/user-candidates: {} /assets/ot/{assetId}/protection/rpc-rules/filters/user-filters: {} /assets/ot/{assetId}/protection/rpc-rules/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/protection/rpc-rules/local-candidates: {} /assets/ot/{assetId}/protection/rpc-rules/remote-candidates: {} /assets/ot/{assetId}/protection/rpc-rules/user-candidates: {} /assets/ot/{assetId}/protection/rules/distribution/{ruleId}: {} /assets/ot/{assetId}/protection/rules/history/{ruleId}: {} /assets/ot/{assetId}/protection/rules/inbound: {} /assets/ot/{assetId}/protection/rules/inbound/{ruleId}: {} /assets/ot/{assetId}/protection/rules/inbound/excluded-local-candidates: {} /assets/ot/{assetId}/protection/rules/inbound/export: {} /assets/ot/{assetId}/protection/rules/inbound/export/csv/{exportId}: {} /assets/ot/{assetId}/protection/rules/inbound/filters: {} /assets/ot/{assetId}/protection/rules/inbound/filters/local-candidates: {} /assets/ot/{assetId}/protection/rules/inbound/filters/remote-candidates: {} /assets/ot/{assetId}/protection/rules/inbound/filters/user-filters: {} /assets/ot/{assetId}/protection/rules/inbound/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/protection/rules/inbound/local-candidates: {} /assets/ot/{assetId}/protection/rules/inbound/remote-candidates: {} /assets/ot/{assetId}/protection/rules/inbound/review/approve-with-changes/{ruleId}: {} /assets/ot/{assetId}/protection/rules/inbound/review/approve/{ruleId}: {} /assets/ot/{assetId}/protection/rules/inbound/review/approve-delete/{ruleId}: {} /assets/ot/{assetId}/protection/rules/inbound/review/reject/{ruleId}: {} /assets/ot/{assetId}/protection/rules/inbound/review/reject-delete/{ruleId}: {} /assets/ot/{assetId}/protection/rules/outbound: {} /assets/ot/{assetId}/protection/rules/outbound/{ruleId}: {} /assets/ot/{assetId}/protection/rules/outbound/excluded-local-candidates: {} /assets/ot/{assetId}/protection/rules/outbound/export: {} /assets/ot/{assetId}/protection/rules/outbound/export/csv/{exportId}: {} /assets/ot/{assetId}/protection/rules/outbound/filters: {} /assets/ot/{assetId}/protection/rules/outbound/filters/excluded-local-candidates: {} /assets/ot/{assetId}/protection/rules/outbound/filters/local-candidates: {} /assets/ot/{assetId}/protection/rules/outbound/filters/remote-candidates: {} /assets/ot/{assetId}/protection/rules/outbound/filters/user-candidates: {} /assets/ot/{assetId}/protection/rules/outbound/filters/user-filters: {} /assets/ot/{assetId}/protection/rules/outbound/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/protection/rules/outbound/local-candidates: {} /assets/ot/{assetId}/protection/rules/outbound/remote-candidates: {} /assets/ot/{assetId}/protection/rules/outbound/user-candidates: {} /assets/ot/{assetId}/protection/rules/outbound/review/approve-with-changes/{ruleId}: {} /assets/ot/{assetId}/protection/rules/outbound/review/approve/{ruleId}: {} /assets/ot/{assetId}/protection/rules/outbound/review/approve-delete/{ruleId}: {} /assets/ot/{assetId}/protection/rules/outbound/review/reject/{ruleId}: {} /assets/ot/{assetId}/protection/rules/outbound/review/reject-delete/{ruleId}: {} /assets/ot/{assetId}/protection/switch-rules/inbound: {} /assets/ot/{assetId}/protection/switch-rules/inbound/{ruleId}: {} /assets/ot/{assetId}/protection/switch-rules/inbound/excluded-local-candidates: {} /assets/ot/{assetId}/protection/switch-rules/inbound/export: {} /assets/ot/{assetId}/protection/switch-rules/inbound/export/csv/{exportId}: {} /assets/ot/{assetId}/protection/switch-rules/inbound/filters: {} /assets/ot/{assetId}/protection/switch-rules/inbound/filters/local-candidates: {} /assets/ot/{assetId}/protection/switch-rules/inbound/filters/remote-candidates: {} /assets/ot/{assetId}/protection/switch-rules/inbound/filters/user-filters: {} /assets/ot/{assetId}/protection/switch-rules/inbound/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/protection/switch-rules/inbound/local-candidates: {} /assets/ot/{assetId}/protection/switch-rules/inbound/remote-candidates: {} /assets/ot/{assetId}/protection/switch-rules/inbound/user-candidates: {} /assets/ot/{assetId}/protection/switch-rules/outbound: {} /assets/ot/{assetId}/protection/switch-rules/outbound/{ruleId}: {} /assets/ot/{assetId}/protection/switch-rules/outbound/excluded-local-candidates: {} /assets/ot/{assetId}/protection/switch-rules/outbound/export: {} /assets/ot/{assetId}/protection/switch-rules/outbound/export/csv/{exportId}: {} /assets/ot/{assetId}/protection/switch-rules/outbound/filters: {} /assets/ot/{assetId}/protection/switch-rules/outbound/filters/local-candidates: {} /assets/ot/{assetId}/protection/switch-rules/outbound/filters/remote-candidates: {} /assets/ot/{assetId}/protection/switch-rules/outbound/filters/user-filters: {} /assets/ot/{assetId}/protection/switch-rules/outbound/filters/user-filters/{filterId}: {} /assets/ot/{assetId}/protection/switch-rules/outbound/local-candidates: {} /assets/ot/{assetId}/protection/switch-rules/outbound/remote-candidates: {} /assets/ot/{assetId}/revive: {} /assets/ot/{assetId}/tags: {} /assets/ot/actions/activate: {} /assets/ot/actions/inactivate: {} /assets/ot/actions/protect: {} /assets/ot/actions/queue: {} /assets/ot/actions/unprotect: {} /assets/ot/actions/unprotect/validate: {} /assets/ot/export: {} /assets/ot/export/csv/{exportId}: {} /assets/ot/filters: {} /assets/ot/filters/user-filters: {} /assets/ot/filters/user-filters/{filterId}: {} /assets/preferred-deployment: {} /assets/protected: {} /assets/protected/export: {} /assets/protected/export/csv/{exportId}: {} /assets/protected/filters: {} /assets/protected/filters/user-filters: {} /assets/protected/filters/user-filters/{filterId}: {} /assets/protected/searchId: {} /assets/queued: {} /assets/queued/export: {} /assets/queued/export/csv/{exportId}: {} /assets/queued/filters: {} /assets/queued/filters/user-filters: {} /assets/queued/filters/user-filters/{filterId}: {} /assets/rpc-actions/monitor: {} /assets/rpc-actions/protect: {} /assets/rpc-actions/queue: {} /assets/rpc-actions/unmonitor: {} /assets/rpc-actions/unprotect: {} /assets/rpc/monitored: {} /assets/rpc/monitored/export: {} /assets/rpc/monitored/export/csv/{exportId}: {} /assets/rpc/monitored/filters: {} /assets/rpc/monitored/filters/user-filters: {} /assets/rpc/monitored/filters/user-filters/{filterId}: {} /assets/rpc/protected: {} /assets/rpc/protected/export: {} /assets/rpc/protected/export/csv/{exportId}: {} /assets/rpc/protected/filters: {} /assets/rpc/protected/filters/user-filters: {} /assets/rpc/protected/filters/user-filters/{filterId}: {} /assets/rpc/queued: {} /assets/rpc/queued/export: {} /assets/rpc/queued/export/csv/{exportId}: {} /assets/rpc/queued/filters: {} /assets/rpc/queued/filters/user-filters: {} /assets/rpc/queued/filters/user-filters/{filterId}: {} /assets/scripts/fix-wmi: {} /assets/scripts/test-udp-net-connection/powershell: {} /assets/scripts/test-udp-net-connection/python: {} /assets/searchId: get: operationId: Assets_Search summary: Search Asset by FQDN description: Returns an assetId. parameters: - $ref: '#/components/parameters/fqdnParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/assetIdSearch' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Assets x-speakeasy-entity-operation: AssetId#get /assets/segmentation-statistics: {} /assets/states/statistics: {} /assets/statistics: {} /assets/switches: {} /assets/switches/{switchId}: {} /assets/switches/{switchId}/switch-vlans: {} /assets/switches/{switchId}/actions/break-glass/monitoring: {} /assets/switches/{switchId}/actions/break-glass/network: {} /assets/switches/{switchId}/activities/network: {} /assets/switches/{switchId}/activities/network/distinctField/{fieldName}: {} /assets/switches/{switchId}/activities/network/export: {} /assets/switches/{switchId}/activities/network/export/csv/{exportId}: {} /assets/switches/{switchId}/activities/network/filters: {} /assets/switches/{switchId}/activities/network/filters/user-filters: {} /assets/switches/{switchId}/activities/network/filters/user-filters/{filterId}: {} /assets/switches/{switchId}/audit: {} /assets/switches/{switchId}/audit/export: {} /assets/switches/{switchId}/audit/export/csv/{exportId}: {} /assets/switches/{switchId}/audit/filters: {} /assets/switches/{switchId}/switch-interfaces: {} /assets/switches/{switchId}/switch-interfaces/monitor: {} /assets/switches/{switchId}/ot: {} /assets/switches/{switchId}/ot/export: {} /assets/switches/{switchId}/ot/export/csv/{exportId}: {} /assets/switches/{switchId}/ot/filters: {} /assets/switches/{switchId}/ot/filters/user-filters: {} /assets/switches/{switchId}/ot/filters/user-filters/{filterId}: {} /assets/switches/{switchId}/protection/rules/history/{ruleId}: {} /assets/switches/{switchId}/protection/rules/distribution/{ruleId}: {} /assets/switches/{switchId}/switch-rules/inbound: {} /assets/switches/{switchId}/switch-rules/inbound/{ruleId}: {} /assets/switches/{switchId}/switch-rules/inbound/excluded-local-candidates: {} /assets/switches/{switchId}/switch-rules/inbound/export: {} /assets/switches/{switchId}/switch-rules/inbound/export/csv/{exportId}: {} /assets/switches/{switchId}/switch-rules/inbound/filters: {} /assets/switches/{switchId}/switch-rules/inbound/filters/local-candidates: {} /assets/switches/{switchId}/switch-rules/inbound/filters/remote-candidates: {} /assets/switches/{switchId}/switch-rules/inbound/filters/user-filters: {} /assets/switches/{switchId}/switch-rules/inbound/filters/user-filters/{filterId}: {} /assets/switches/{switchId}/switch-rules/inbound/local-candidates: {} /assets/switches/{switchId}/switch-rules/inbound/remote-candidates: {} /assets/switches/{switchId}/switch-rules/inbound/user-candidates: {} /assets/switches/{switchId}/switch-rules/outbound: {} /assets/switches/{switchId}/switch-rules/outbound/{ruleId}: {} /assets/switches/{switchId}/switch-rules/outbound/excluded-local-candidates: {} /assets/switches/{switchId}/switch-rules/outbound/export: {} /assets/switches/{switchId}/switch-rules/outbound/export/csv/{exportId}: {} /assets/switches/{switchId}/switch-rules/outbound/filters: {} /assets/switches/{switchId}/switch-rules/outbound/filters/local-candidates: {} /assets/switches/{switchId}/switch-rules/outbound/filters/remote-candidates: {} /assets/switches/{switchId}/switch-rules/outbound/filters/user-filters: {} /assets/switches/{switchId}/switch-rules/outbound/filters/user-filters/{filterId}: {} /assets/switches/{switchId}/switch-rules/outbound/local-candidates: {} /assets/switches/{switchId}/switch-rules/outbound/remote-candidates: {} /assets/switches/actions/break-glass/monitoring: {} /assets/switches/actions/break-glass/network: {} /assets/switches/{switchId}/binding-direction: {} /audit: {} /audit/export: {} /audit/export/csv/{exportId}: {} /audit/filters: {} /auth/challenge: {} /auth/login: {} /auth/logout: {} /cloud/azure/{tenantId}/subscriptions: {} /cloud/azure/subscriptions/filters: {} /cloud/azure/subscriptions/{subscriptionId}: {} /cloud/azure/subscriptions: {} /cloud/azure/{tenantId}/resource-groups: {} /cloud/azure/resource-groups/filters: {} /cloud/azure/resource-groups/{resourceGroupId}: {} /cloud/azure/{tenantId}/resources: {} /cloud/azure/resources/filters: {} /download/cloud-connector/installer: {} /download/connect/client: {} /download/connect/server: {} /download/segment/server: {} /download/segment-connector/installer: {} /entities/encode-ip: {} /entities/encode-ip-range: {} /entities/encode-subnet: {} /environments/move-cluster: {} /environments/cluster: {} /environments/cluster/{deploymentsClusterId}: {} /environments/deployments: {} /environments/deployments/access-token: {} /environments/freeze-period: {} /environments/freeze-period/{freezePeriodId}: {} /environments/learning-config: {} /environments/licenses/{licenseType}: {} /environments/licenses/{licenseType}/export: {} /environments/licenses/{licenseType}/export/csv/{exportId}: {} /environments/licenses/{licenseType}/in-use: {} /environments/system-health: {} /groups: {} /groups/{groupType}: {} /groups/{groupType}/export: {} /groups/{groupType}/export/csv/{exportId}: {} /groups/{groupType}/externalId/{externalId}: {} /groups/{groupType}/filters: {} /groups/{groupType}/{groupId}: {} /groups/{groupType}/{groupId}/access-simulation/expand-record: {} /groups/{groupType}/{groupId}/access-simulation/export: {} /groups/{groupType}/{groupId}/access-simulation/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/access-simulation/generate: {} /groups/{groupType}/{groupId}/access-simulation/report: {} /groups/{groupType}/{groupId}/access-simulation/state: {} /groups/{groupType}/{groupId}/activities/logon: {} /groups/{groupType}/{groupId}/activities/logon/distinctField/{fieldName}: {} /groups/{groupType}/{groupId}/activities/logon/export: {} /groups/{groupType}/{groupId}/activities/logon/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/activities/logon/filters: {} /groups/{groupType}/{groupId}/activities/logon/filters/user-filters: {} /groups/{groupType}/{groupId}/activities/logon/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/activities/network: {} /groups/{groupType}/{groupId}/activities/network/distinctField/{fieldName}: {} /groups/{groupType}/{groupId}/activities/network/export: {} /groups/{groupType}/{groupId}/activities/network/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/activities/network/filters: {} /groups/{groupType}/{groupId}/activities/network/filters/user-filters: {} /groups/{groupType}/{groupId}/activities/network/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/activities/rpc: {} /groups/{groupType}/{groupId}/activities/rpc/export: {} /groups/{groupType}/{groupId}/activities/rpc/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/activities/rpc/filters: {} /groups/{groupType}/{groupId}/activities/rpc/filters/interface-candidates: {} /groups/{groupType}/{groupId}/activities/rpc/filters/op-candidates: {} /groups/{groupType}/{groupId}/activities/rpc/filters/user-filters: {} /groups/{groupType}/{groupId}/activities/rpc/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/analysis/network: {} /groups/{groupType}/{groupId}/analysis/network/export: {} /groups/{groupType}/{groupId}/analysis/network/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/ancestors: {} /groups/{groupType}/{groupId}/ancestors/candidates: {} /groups/{groupType}/{groupId}/audit: {} /groups/{groupType}/{groupId}/audit/export: {} /groups/{groupType}/{groupId}/audit/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/audit/filters: {} /groups/{groupType}/{groupId}/managed-assets: {} /groups/{groupType}/{groupId}/managed-assets/{groupOrAssetId}: {} /groups/{groupType}/{groupId}/managed-assets/candidates: {} /groups/{groupType}/{groupId}/managers: {} /groups/{groupType}/{groupId}/managers/{groupOrUserId}: {} /groups/{groupType}/{groupId}/managers/candidates: {} /groups/{groupType}/{groupId}/protection/external-access-policies: {} /groups/{groupType}/{groupId}/protection/external-access-policies/{policyId}: {} /groups/{groupType}/{groupId}/protection/external-access-policies/dst-asset-candidates: {} /groups/{groupType}/{groupId}/protection/external-access-policies/filters: {} /groups/{groupType}/{groupId}/protection/external-access-policies/filters/dst-asset-candidates: {} /groups/{groupType}/{groupId}/protection/external-access-policies/filters/src-users-candidates: {} /groups/{groupType}/{groupId}/protection/external-access-policies/src-users-candidates: {} /groups/{groupType}/{groupId}/protection/external-access-policies/statistics: {} /groups/{groupType}/{groupId}/protection/identity-rules: {} /groups/{groupType}/{groupId}/protection/identity-rules/{ruleId}: {} /groups/{groupType}/{groupId}/protection/identity-rules/asset-candidates: {} /groups/{groupType}/{groupId}/protection/identity-rules/excluded-asset-candidates: {} /groups/{groupType}/{groupId}/protection/identity-rules/export: {} /groups/{groupType}/{groupId}/protection/identity-rules/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/protection/identity-rules/filters: {} /groups/{groupType}/{groupId}/protection/identity-rules/filters/asset-candidates: {} /groups/{groupType}/{groupId}/protection/identity-rules/filters/user-candidates: {} /groups/{groupType}/{groupId}/protection/identity-rules/filters/user-filters: {} /groups/{groupType}/{groupId}/protection/identity-rules/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/protection/identity-rules/user-candidates: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/{reactivePolicyId}: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/dst-asset-candidates: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/excluded-src-asset-candidates: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/export: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/filters: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/filters/dst-asset-candidates: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/filters/src-asset-candidates: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/filters/src-users-candidates: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/filters/user-filters: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/mfa-methods: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/src-asset-candidates: {} /groups/{groupType}/{groupId}/protection/identity/reactive-policies/src-users-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/{reactivePolicyId}: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/dst-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/excluded-src-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/filters: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/filters/dst-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/filters/src-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/filters/src-users-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/filters/user-filters: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/mfa-methods: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/simulate: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/simulate/dst-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/simulate/resolve: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/simulate/src-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/simulate/src-users-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/src-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/inbound/src-users-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/{reactivePolicyId}: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/dst-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/excluded-src-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/filters: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/filters/dst-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/filters/src-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/filters/src-users-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/filters/user-filters: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/simulate: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/simulate/dst-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/simulate/resolve: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/simulate/src-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/simulate/src-users-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/mfa-methods: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/src-candidates: {} /groups/{groupType}/{groupId}/protection/reactive-policies/outbound/src-users-candidates: {} /groups/{groupType}/{groupId}/protection/rpc-rules: {} /groups/{groupType}/{groupId}/protection/rpc-rules/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rpc-rules/excluded-local-candidates: {} /groups/{groupType}/{groupId}/protection/rpc-rules/export: {} /groups/{groupType}/{groupId}/protection/rpc-rules/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/protection/rpc-rules/filters: {} /groups/{groupType}/{groupId}/protection/rpc-rules/filters/local-candidates: {} /groups/{groupType}/{groupId}/protection/rpc-rules/filters/remote-candidates: {} /groups/{groupType}/{groupId}/protection/rpc-rules/filters/user-candidates: {} /groups/{groupType}/{groupId}/protection/rpc-rules/filters/user-filters: {} /groups/{groupType}/{groupId}/protection/rpc-rules/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/protection/rpc-rules/local-candidates: {} /groups/{groupType}/{groupId}/protection/rpc-rules/remote-candidates: {} /groups/{groupType}/{groupId}/protection/rpc-rules/user-candidates: {} /groups/{groupType}/{groupId}/protection/rules/distribution/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/history/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/inbound: {} /groups/{groupType}/{groupId}/protection/rules/inbound/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/inbound/excluded-local-candidates: {} /groups/{groupType}/{groupId}/protection/rules/inbound/export: {} /groups/{groupType}/{groupId}/protection/rules/inbound/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/protection/rules/inbound/filters: {} /groups/{groupType}/{groupId}/protection/rules/inbound/filters/remote-candidates: {} /groups/{groupType}/{groupId}/protection/rules/inbound/filters/local-candidates: {} /groups/{groupType}/{groupId}/protection/rules/inbound/filters/user-filters: {} /groups/{groupType}/{groupId}/protection/rules/inbound/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/protection/rules/inbound/local-candidates: {} /groups/{groupType}/{groupId}/protection/rules/inbound/remote-candidates: {} /groups/{groupType}/{groupId}/protection/rules/inbound/review/approve-with-changes/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/inbound/review/approve/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/inbound/review/approve-delete/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/inbound/review/reject/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/inbound/review/reject-delete/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/outbound: {} /groups/{groupType}/{groupId}/protection/rules/outbound/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/outbound/excluded-local-candidates: {} /groups/{groupType}/{groupId}/protection/rules/outbound/export: {} /groups/{groupType}/{groupId}/protection/rules/outbound/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/protection/rules/outbound/filters: {} /groups/{groupType}/{groupId}/protection/rules/outbound/filters/excluded-local-candidates: {} /groups/{groupType}/{groupId}/protection/rules/outbound/filters/local-candidates: {} /groups/{groupType}/{groupId}/protection/rules/outbound/filters/remote-candidates: {} /groups/{groupType}/{groupId}/protection/rules/outbound/filters/user-candidates: {} /groups/{groupType}/{groupId}/protection/rules/outbound/filters/user-filters: {} /groups/{groupType}/{groupId}/protection/rules/outbound/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/protection/rules/outbound/local-candidates: {} /groups/{groupType}/{groupId}/protection/rules/outbound/remote-candidates: {} /groups/{groupType}/{groupId}/protection/rules/outbound/review/approve-with-changes/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/outbound/review/approve/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/outbound/review/approve-delete/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/outbound/review/reject/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/outbound/review/reject-delete/{ruleId}: {} /groups/{groupType}/{groupId}/protection/rules/outbound/user-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/{ruleId}: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/excluded-local-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/export: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/filters: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/filters/local-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/filters/remote-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/filters/user-filters: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/local-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/remote-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/inbound/user-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/{ruleId}: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/excluded-local-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/export: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/filters: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/filters/local-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/filters/remote-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/filters/user-filters: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/filters/user-filters/{filterId}: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/local-candidates: {} /groups/{groupType}/{groupId}/protection/switch-rules/outbound/remote-candidates: {} /groups/{groupType}/{groupId}/successors: {} /groups/{groupType}/{groupId}/successors/export: {} /groups/{groupType}/{groupId}/successors/export/csv/{exportId}: {} /groups/{groupType}/{groupId}/successors/filters: {} /groups/custom: post: operationId: CustomGroups_Create summary: Create Custom Group description: Returns an empty object. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/customGroupBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/customGroupResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '409': $ref: '#/components/responses/409' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Groups Custom x-speakeasy-entity-operation: CustomGroup#create /groups/custom/{groupId}: get: operationId: CustomGroups_Get summary: Get a custom group description: Returns the properties of an custom group. parameters: - $ref: '#/components/parameters/groupIdParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/customGroupResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Groups Custom x-speakeasy-entity-operation: CustomGroup#get put: operationId: CustomGroups_Update summary: Update Custom Group description: Returns an empty object. parameters: - $ref: '#/components/parameters/groupIdParameter' requestBody: description: Custom Group properties required: true content: application/json: schema: $ref: '#/components/schemas/customGroupBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/customGroupResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Groups Custom x-speakeasy-entity-operation: CustomGroup#update delete: operationId: CustomGroups_Delete summary: Delete Custom Group description: Returns an empty object. parameters: - $ref: '#/components/parameters/groupIdParameter' responses: '200': description: OK '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Groups Custom x-speakeasy-entity-operation: CustomGroup#delete /groups/custom/member-candidates: {} /groups/custom/{groupId}/members: get: operationId: CustomGroupMembers_List summary: List Custom Group members description: Returns a list of all members parameters: - $ref: '#/components/parameters/groupIdParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/groupMembersList' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Groups Custom x-speakeasy-entity-operation: CustomGroupMembers#get put: operationId: CustomGroupsMembers_Add summary: Add Custom Group members description: Returns an empty object. parameters: - $ref: '#/components/parameters/groupIdParameter' requestBody: description: Custom Group Members properties required: true content: application/json: schema: $ref: '#/components/schemas/customGroupMembersBody' responses: '200': $ref: '#/components/responses/200_empty' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Groups Custom x-speakeasy-entity-operation: - CustomGroupMembers#create - CustomGroupMembers#update delete: operationId: CustomGroupsMembers_Delete summary: Delete Custom Group members description: Returns an empty object. parameters: - $ref: '#/components/parameters/groupIdParameter' requestBody: description: Custom Group Members properties required: true content: application/json: schema: $ref: '#/components/schemas/customGroupMembersBody' responses: '200': description: OK '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Groups Custom x-speakeasy-entity-operation: CustomGroupMembers#delete /groups/statistics: {} /groups/tag/{groupId}/members: {} /groups/tag/member-candidates: {} /identity/ispm/posture-violations: {} /identity/ispm/posture-violations/filters: {} /identity/ispm/posture-violations/users-violation/filters: {} /identity/ispm/posture-violations/users-violation/filters/user-candidates: {} /identity/ispm/posture-violations/{postureCheckType}/users-violation: {} /identity/ispm/posture-violations/{postureCheckType}/users-violation/export: {} /identity/ispm/posture-violations/{postureCheckType}/users-violation/export/csv/{exportId}: {} /identity/ispm/posture-violations/{postureCheckType}/users-violation/status: {} /k8s/clusters: {} /k8s/clusters/{k8sClusterId}: {} /k8s/clusters/{k8sClusterId}/activities/network: {} /k8s/clusters/{k8sClusterId}/activities/network/distinctField/{fieldName}: {} /k8s/clusters/{k8sClusterId}/activities/network/export: {} /k8s/clusters/{k8sClusterId}/activities/network/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/activities/network/filters: {} /k8s/clusters/{k8sClusterId}/activities/network/filters/user-filters: {} /k8s/clusters/{k8sClusterId}/activities/network/filters/user-filters/{filterId}: {} /k8s/clusters/{k8sClusterId}/applications: {} /k8s/clusters/{k8sClusterId}/applications/export: {} /k8s/clusters/{k8sClusterId}/applications/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/applications/filters: {} /k8s/clusters/{k8sClusterId}/applications/{applicationName}: {} /k8s/clusters/{k8sClusterId}/applications/{applicationName}/namespaces: {} /k8s/clusters/{k8sClusterId}/applications/{applicationName}/namespaces/filters: {} /k8s/clusters/{k8sClusterId}/applications/{applicationName}/workloads: {} /k8s/clusters/{k8sClusterId}/applications/{applicationName}/workloads/filters: {} /k8s/clusters/{k8sClusterId}/audit: {} /k8s/clusters/{k8sClusterId}/audit/export: {} /k8s/clusters/{k8sClusterId}/audit/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/audit/filters: {} /k8s/clusters/{k8sClusterId}/command: {} /k8s/clusters/{k8sClusterId}/egress-ips: {} /k8s/clusters/{k8sClusterId}/egress-ips/filters: {} /k8s/clusters/{k8sClusterId}/labels: {} /k8s/clusters/{k8sClusterId}/labels/export: {} /k8s/clusters/{k8sClusterId}/labels/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/labels/filters: {} /k8s/clusters/{k8sClusterId}/labels/{label}: {} /k8s/clusters/{k8sClusterId}/labels/{label}/namespaces: {} /k8s/clusters/{k8sClusterId}/labels/{label}/namespaces/export: {} /k8s/clusters/{k8sClusterId}/labels/{label}/namespaces/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/labels/{label}/namespaces/filters: {} /k8s/clusters/{k8sClusterId}/labels/{label}/rules/inbound: {} /k8s/clusters/{k8sClusterId}/labels/{label}/rules/inbound/export: {} /k8s/clusters/{k8sClusterId}/labels/{label}/rules/inbound/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/labels/{label}/rules/inbound/filters: {} /k8s/clusters/{k8sClusterId}/labels/{label}/rules/outbound: {} /k8s/clusters/{k8sClusterId}/labels/{label}/rules/outbound/export: {} /k8s/clusters/{k8sClusterId}/labels/{label}/rules/outbound/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/labels/{label}/rules/outbound/filters: {} /k8s/clusters/{k8sClusterId}/labels/{label}/workloads: {} /k8s/clusters/{k8sClusterId}/labels/{label}/workloads/export: {} /k8s/clusters/{k8sClusterId}/labels/{label}/workloads/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/labels/{label}/workloads/filters: {} /k8s/clusters/{k8sClusterId}/namespaces: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/activities/network: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/activities/network/distinctField/{fieldName}: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/activities/network/export: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/activities/network/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/activities/network/filters: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/activities/network/filters/user-filters: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/activities/network/filters/user-filters/{filterId}: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/analysis/network: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/analysis/network/activity-map: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/analysis/network/export: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/analysis/network/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/applications: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/applications/export: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/applications/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/applications/filters: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/labels: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/labels/export: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/labels/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/labels/filters: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/network-policies/inbound: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/network-policies/inbound/filters: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/network-policies/outbound: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/network-policies/outbound/filters: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/rules/inbound: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/rules/inbound/export: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/rules/inbound/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/rules/inbound/filters: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/rules/outbound: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/rules/outbound/export: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/rules/outbound/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/rules/outbound/filters: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/workloads: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/workloads/export: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/workloads/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/namespaces/{k8sNamespaceId}/workloads/filters: {} /k8s/clusters/{k8sClusterId}/namespaces/export: {} /k8s/clusters/{k8sClusterId}/namespaces/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/network-policies/inbound: {} /k8s/clusters/{k8sClusterId}/network-policies/inbound/filters: {} /k8s/clusters/{k8sClusterId}/network-policies/outbound: {} /k8s/clusters/{k8sClusterId}/network-policies/outbound/filters: {} /k8s/clusters/{k8sClusterId}/namespaces/filters: {} /k8s/clusters/{k8sClusterId}/nodes: {} /k8s/clusters/{k8sClusterId}/nodes/filters: {} /k8s/clusters/{k8sClusterId}/rules/inbound: {} /k8s/clusters/{k8sClusterId}/rules/inbound/export: {} /k8s/clusters/{k8sClusterId}/rules/inbound/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/rules/inbound/filters: {} /k8s/clusters/{k8sClusterId}/rules/outbound: {} /k8s/clusters/{k8sClusterId}/rules/outbound/export: {} /k8s/clusters/{k8sClusterId}/rules/outbound/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/rules/outbound/filters: {} /k8s/clusters/{k8sClusterId}/workloads: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/activities/network: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/activities/network/distinctField/{fieldName}: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/activities/network/export: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/activities/network/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/activities/network/filters: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/activities/network/filters/user-filters: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/activities/network/filters/user-filters/{filterId}: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/analysis/network: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/analysis/network/activity-map: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/analysis/network/export: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/analysis/network/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/applications: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/applications/export: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/applications/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/applications/filters: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/labels: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/labels/export: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/labels/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/workloads/{k8sWorkloadId}/labels/filters: {} /k8s/clusters/{k8sClusterId}/workloads/export: {} /k8s/clusters/{k8sClusterId}/workloads/export/csv/{exportId}: {} /k8s/clusters/{k8sClusterId}/workloads/filters: {} /k8s/clusters/filters: {} /k8s/namespaces: {} /k8s/namespaces/{k8sNamespaceId}: {} /k8s/namespaces/{k8sNamespaceId}/activities/network: {} /k8s/namespaces/{k8sNamespaceId}/activities/network/distinctField/{fieldName}: {} /k8s/namespaces/{k8sNamespaceId}/activities/network/export: {} /k8s/namespaces/{k8sNamespaceId}/activities/network/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/activities/network/filters: {} /k8s/namespaces/{k8sNamespaceId}/activities/network/filters/user-filters: {} /k8s/namespaces/{k8sNamespaceId}/activities/network/filters/user-filters/{filterId}: {} /k8s/namespaces/{k8sNamespaceId}/analysis/network: {} /k8s/namespaces/{k8sNamespaceId}/analysis/network/activity-map: {} /k8s/namespaces/{k8sNamespaceId}/analysis/network/export: {} /k8s/namespaces/{k8sNamespaceId}/analysis/network/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/applications: {} /k8s/namespaces/{k8sNamespaceId}/applications/export: {} /k8s/namespaces/{k8sNamespaceId}/applications/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/applications/filters: {} /k8s/namespaces/{k8sNamespaceId}/labels: {} /k8s/namespaces/{k8sNamespaceId}/labels/export: {} /k8s/namespaces/{k8sNamespaceId}/labels/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/labels/filters: {} /k8s/namespaces/{k8sNamespaceId}/network-policies/inbound: {} /k8s/namespaces/{k8sNamespaceId}/network-policies/inbound/filters: {} /k8s/namespaces/{k8sNamespaceId}/network-policies/outbound: {} /k8s/namespaces/{k8sNamespaceId}/network-policies/outbound/filters: {} /k8s/namespaces/{k8sNamespaceId}/rules/inbound: {} /k8s/namespaces/{k8sNamespaceId}/rules/inbound/export: {} /k8s/namespaces/{k8sNamespaceId}/rules/inbound/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/rules/inbound/filters: {} /k8s/namespaces/{k8sNamespaceId}/rules/outbound: {} /k8s/namespaces/{k8sNamespaceId}/rules/outbound/export: {} /k8s/namespaces/{k8sNamespaceId}/rules/outbound/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/rules/outbound/filters: {} /k8s/namespaces/{k8sNamespaceId}/workloads: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/activities/network: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/activities/network/distinctField/{fieldName}: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/activities/network/export: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/activities/network/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/activities/network/filters: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/activities/network/filters/user-filters: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/activities/network/filters/user-filters/{filterId}: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/analysis/network: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/analysis/network/activity-map: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/analysis/network/export: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/analysis/network/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/applications: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/applications/export: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/applications/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/applications/filters: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/labels: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/labels/export: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/labels/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/workloads/{k8sWorkloadId}/labels/filters: {} /k8s/namespaces/{k8sNamespaceId}/workloads/export: {} /k8s/namespaces/{k8sNamespaceId}/workloads/export/csv/{exportId}: {} /k8s/namespaces/{k8sNamespaceId}/workloads/filters: {} /k8s/namespaces/export: {} /k8s/namespaces/export/csv/{exportId}: {} /k8s/namespaces/filters: {} /k8s/nodes: {} /k8s/nodes/filters: {} /k8s/workloads: {} /k8s/workloads/{k8sWorkloadId}: {} /k8s/workloads/{k8sWorkloadId}/activities/network: {} /k8s/workloads/{k8sWorkloadId}/activities/network/distinctField/{fieldName}: {} /k8s/workloads/{k8sWorkloadId}/activities/network/export: {} /k8s/workloads/{k8sWorkloadId}/activities/network/export/csv/{exportId}: {} /k8s/workloads/{k8sWorkloadId}/activities/network/filters: {} /k8s/workloads/{k8sWorkloadId}/activities/network/filters/user-filters: {} /k8s/workloads/{k8sWorkloadId}/activities/network/filters/user-filters/{filterId}: {} /k8s/workloads/{k8sWorkloadId}/analysis/network: {} /k8s/workloads/{k8sWorkloadId}/analysis/network/activity-map: {} /k8s/workloads/{k8sWorkloadId}/analysis/network/export: {} /k8s/workloads/{k8sWorkloadId}/analysis/network/export/csv/{exportId}: {} /k8s/workloads/{k8sWorkloadId}/applications: {} /k8s/workloads/{k8sWorkloadId}/applications/export: {} /k8s/workloads/{k8sWorkloadId}/applications/export/csv/{exportId}: {} /k8s/workloads/{k8sWorkloadId}/applications/filters: {} /k8s/workloads/{k8sWorkloadId}/labels: {} /k8s/workloads/{k8sWorkloadId}/labels/export: {} /k8s/workloads/{k8sWorkloadId}/labels/export/csv/{exportId}: {} /k8s/workloads/{k8sWorkloadId}/labels/filters: {} /k8s/workloads/export: {} /k8s/workloads/export/csv/{exportId}: {} /k8s/workloads/filters: {} /labels: {} /labels/filters: {} /maintenance-window-external: {} /profile: {} /profile/environments: {} /protection-policies/identity: {} /protection-policies/identity/{protectionPolicyId}: {} /protection-policies/identity/group-candidates: {} /protection-policies/identity/overriding-candidates: {} /protection-policies/identity/overriding/members: {} /protection-policies/learning-config: {} /protection-policies/network: {} /protection-policies/network/{protectionPolicyId}: {} /protection-policies/network/group-candidates: {} /protection-policies/network/overriding-candidates: {} /protection-policies/network/overriding/members: {} /protection/{assetId}/simulate-access: {} /protection/ae-exclusions/inbound: post: operationId: AEExclusionsInbound_Create summary: Create AE Exclusion Inbound description: Returns the properties of the created AE Exclusion. requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/aeExclusionRuleBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/aeExclusionRuleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '409': $ref: '#/components/responses/409' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - AE Exclusions x-speakeasy-entity-operation: AEExclusionInbound#create /protection/ae-exclusions/inbound/{ruleId}: get: operationId: AEExclusionsInbound_Get summary: Get AE Exclusion description: Returns the properties of the update AE exclusion. parameters: - $ref: '#/components/parameters/ruleIdParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/aeExclusionRuleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - AE Exclusions x-speakeasy-entity-operation: AEExclusionInbound#get delete: operationId: AEExclusionsInbound_Delete summary: Delete Automation Engine Inbound exclusions description: Returns an empty object. parameters: - $ref: '#/components/parameters/ruleIdParameter' responses: '200': description: OK '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - AE Exclusions x-speakeasy-entity-operation: AEExclusionInbound#delete put: operationId: AEExclusionsInbound_Update summary: Update AE Exclusion description: Returns the properties of the update AE exclusion. parameters: - $ref: '#/components/parameters/ruleIdParameter' requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/aeExclusionRuleBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/aeExclusionRuleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - AE Exclusions x-speakeasy-entity-operation: AEExclusionInbound#update /protection/ae-exclusions/inbound/export: {} /protection/ae-exclusions/inbound/export/csv/{exportId}: {} /protection/ae-exclusions/inbound/filters: {} /protection/ae-exclusions/inbound/filters/local-candidates: {} /protection/ae-exclusions/inbound/filters/remote-candidates: {} /protection/ae-exclusions/inbound/filters/user-filters: {} /protection/ae-exclusions/inbound/filters/user-filters/{filterId}: {} /protection/ae-exclusions/inbound/local-candidates: {} /protection/ae-exclusions/inbound/remote-candidates: {} /protection/ae-exclusions/outbound: post: operationId: AEExclusionsOutbound_Create summary: Create AE Exclusion Outbound description: Returns the properties of the created AE Exclusion. requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/aeExclusionRuleBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/aeExclusionRuleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '409': $ref: '#/components/responses/409' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - AE Exclusions x-speakeasy-entity-operation: AEExclusionOutbound#create /protection/ae-exclusions/outbound/{ruleId}: get: operationId: AEExclusionsOutbound_Get summary: Get AE Exclusion description: Returns the properties of the update AE exclusion. parameters: - $ref: '#/components/parameters/ruleIdParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/aeExclusionRuleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - AE Exclusions x-speakeasy-entity-operation: AEExclusionOutbound#get delete: operationId: AEExclusionsOutbound_Delete summary: Delete Automation Engine Outbound exclusions description: Returns an empty object. parameters: - $ref: '#/components/parameters/ruleIdParameter' responses: '200': description: OK '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - AE Exclusions x-speakeasy-entity-operation: AEExclusionOutbound#delete put: operationId: AEExclusionsOutbound_Update summary: Update AE Exclusion description: Returns the properties of the update AE exclusion. parameters: - $ref: '#/components/parameters/ruleIdParameter' requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/aeExclusionRuleBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/aeExclusionRuleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - AE Exclusions x-speakeasy-entity-operation: AEExclusionOutbound#update /protection/ae-exclusions/outbound/export: {} /protection/ae-exclusions/outbound/export/csv/{exportId}: {} /protection/ae-exclusions/outbound/filters: {} /protection/ae-exclusions/outbound/filters/local-candidates: {} /protection/ae-exclusions/outbound/filters/remote-candidates: {} /protection/ae-exclusions/outbound/filters/user-filters: {} /protection/ae-exclusions/outbound/filters/user-filters/{filterId}: {} /protection/ae-exclusions/outbound/local-candidates: {} /protection/ae-exclusions/outbound/remote-candidates: {} /protection/ae-exclusions/outbound/user-candidates: {} /protection/internal-access/policies: post: operationId: InternalAccessPolicy_Create summary: Create an internal access policy description: Returns a the internal access policy requestBody: content: application/json: schema: $ref: '#/components/schemas/internalAccessPolicyBody' required: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/internalAccessPolicyItem' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Internal Access Policy x-speakeasy-entity-operation: InternalAccessPolicy#create /protection/internal-access/policies/{policyId}: get: operationId: InternalAccessPolicy_Get summary: Get an Internal Access policy description: Returns an internal access policy. parameters: - $ref: '#/components/parameters/internalAccessPolicyIdParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/internalAccessPolicyItem' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Internal Access Policy x-speakeasy-entity-operation: InternalAccessPolicy#get put: operationId: InternalAccessPolicy_Update summary: Update an Internal Access policy description: Returns an internal access policy. parameters: - $ref: '#/components/parameters/internalAccessPolicyIdParameter' requestBody: content: application/json: schema: $ref: '#/components/schemas/internalAccessPolicyBody' required: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/internalAccessPolicyItem' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Internal Access Policy x-speakeasy-entity-operation: InternalAccessPolicy#update delete: operationId: InternalAccessPolicy_Delete summary: Delete an Internal Access policy description: Returns an empty object. parameters: - $ref: '#/components/parameters/internalAccessPolicyIdParameter' responses: '200': description: OK '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Internal Access Policy x-speakeasy-entity-operation: InternalAccessPolicy#delete /protection/internal-access/policies/dst-asset-candidates: {} /protection/internal-access/policies/filters: {} /protection/internal-access/policies/filters/dst-asset-candidates: {} /protection/internal-access/policies/filters/src-users-candidates: {} /protection/internal-access/policies/src-users-candidates: {} /protection/external-access-policies: {} /protection/external-access-policies/{policyId}: {} /protection/external-access-policies/dst-asset-candidates: {} /protection/external-access-policies/filters: {} /protection/external-access-policies/filters/dst-asset-candidates: {} /protection/external-access-policies/filters/src-users-candidates: {} /protection/external-access-policies/src-users-candidates: {} /protection/external-access-policies/statistics: {} /protection/identity-rules: {} /protection/identity-rules/{ruleId}: {} /protection/identity-rules/asset-candidates: {} /protection/identity-rules/excluded-asset-candidates: {} /protection/identity-rules/export: {} /protection/identity-rules/export/csv/{exportId}: {} /protection/identity-rules/filters: {} /protection/identity-rules/filters/asset-candidates: {} /protection/identity-rules/filters/user-candidates: {} /protection/identity-rules/filters/user-filters: {} /protection/identity-rules/filters/user-filters/{filterId}: {} /protection/identity-rules/user-candidates: {} /protection/identity/reactive-policies: {} /protection/identity/reactive-policies/{reactivePolicyId}: {} /protection/identity/reactive-policies/dst-asset-candidates: {} /protection/identity/reactive-policies/excluded-src-asset-candidates: {} /protection/identity/reactive-policies/export: {} /protection/identity/reactive-policies/export/csv/{exportId}: {} /protection/identity/reactive-policies/filters: {} /protection/identity/reactive-policies/filters/dst-asset-candidates: {} /protection/identity/reactive-policies/filters/src-asset-candidates: {} /protection/identity/reactive-policies/filters/src-users-candidates: {} /protection/identity/reactive-policies/filters/user-filters: {} /protection/identity/reactive-policies/filters/user-filters/{filterId}: {} /protection/identity/reactive-policies/mfa-methods: {} /protection/identity/reactive-policies/src-asset-candidates: {} /protection/identity/reactive-policies/src-users-candidates: {} /protection/switch-rules/inbound: {} /protection/switch-rules/inbound/{ruleId}: {} /protection/switch-rules/inbound/excluded-local-candidates: {} /protection/switch-rules/inbound/export: {} /protection/switch-rules/inbound/export/csv/{exportId}: {} /protection/switch-rules/inbound/filters: {} /protection/switch-rules/inbound/filters/local-candidates: {} /protection/switch-rules/inbound/filters/remote-candidates: {} /protection/switch-rules/inbound/filters/user-filters: {} /protection/switch-rules/inbound/filters/user-filters/{filterId}: {} /protection/switch-rules/inbound/local-candidates: {} /protection/switch-rules/inbound/remote-candidates: {} /protection/switch-rules/inbound/user-candidates: {} /protection/switch-rules/outbound: {} /protection/switch-rules/outbound/{ruleId}: {} /protection/switch-rules/outbound/excluded-local-candidates: {} /protection/switch-rules/outbound/export: {} /protection/switch-rules/outbound/export/csv/{exportId}: {} /protection/switch-rules/outbound/filters: {} /protection/switch-rules/outbound/filters/local-candidates: {} /protection/switch-rules/outbound/filters/remote-candidates: {} /protection/switch-rules/outbound/filters/user-filters: {} /protection/switch-rules/outbound/filters/user-filters/{filterId}: {} /protection/switch-rules/outbound/local-candidates: {} /protection/switch-rules/outbound/remote-candidates: {} /protection/reactive-policies/distribution: {} /protection/reactive-policies/inbound: post: operationId: MFAInboundPolicies_Create summary: Add Inbound MFA Policy description: Returns the properties of the inbound MFA policy after creation. requestBody: description: MFA properties required: true content: application/json: schema: $ref: '#/components/schemas/reactivePolicyInboundBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/reactivePolicyItem' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - MFA Inbound x-speakeasy-entity-operation: InboundMFAPolicy#create /protection/reactive-policies/inbound/{reactivePolicyId}: get: operationId: MFAInboundPolicies_Get summary: Get Inbound MFA Policy description: Returns a inbound MFA policy object. parameters: - $ref: '#/components/parameters/reactivePolicyIdParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/reactivePolicyResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - MFA Inbound x-speakeasy-entity-operation: InboundMFAPolicy#get put: operationId: MFAInboundPolicies_Update summary: Update Inbound MFA Policy description: Returns the properties of the inbound MFA policy after updating. parameters: - $ref: '#/components/parameters/reactivePolicyIdParameter' requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/reactivePolicyInboundBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/reactivePolicyItem' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - MFA Inbound x-speakeasy-entity-operation: InboundMFAPolicy#update delete: operationId: MFAInboundPolicies_Delete summary: Remove Inbound MFA Policy description: Returns an empty object. parameters: - $ref: '#/components/parameters/reactivePolicyIdParameter' responses: '200': description: OK '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - MFA Inbound x-speakeasy-entity-operation: InboundMFAPolicy#delete /protection/reactive-policies/inbound/dst-candidates: {} /protection/reactive-policies/inbound/excluded-src-candidates: {} /protection/reactive-policies/inbound/filters: {} /protection/reactive-policies/inbound/filters/dst-candidates: {} /protection/reactive-policies/inbound/filters/src-candidates: {} /protection/reactive-policies/inbound/filters/src-users-candidates: {} /protection/reactive-policies/inbound/filters/user-filters: {} /protection/reactive-policies/inbound/filters/user-filters/{filterId}: {} /protection/reactive-policies/inbound/mfa-methods: {} /protection/reactive-policies/inbound/simulate: {} /protection/reactive-policies/inbound/simulate/dst-candidates: {} /protection/reactive-policies/inbound/simulate/resolve: {} /protection/reactive-policies/inbound/simulate/src-candidates: {} /protection/reactive-policies/inbound/simulate/src-users-candidates: {} /protection/reactive-policies/inbound/src-candidates: {} /protection/reactive-policies/inbound/src-users-candidates: {} /protection/reactive-policies/outbound: post: operationId: MFAOutboundPolicies_Create summary: Add Outbound MFA Policy description: Returns a the properties of outbound MFA policy created. requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/reactivePolicyOutboundBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/reactivePolicyItem' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - MFA Outbound x-speakeasy-entity-operation: OutboundMFAPolicy#create /protection/reactive-policies/outbound/{reactivePolicyId}: get: operationId: MFAOutboundPolicies_Get summary: Get Outbound MFA Policy description: Returns the properties of an outbound MFA policy. parameters: - $ref: '#/components/parameters/reactivePolicyIdParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/reactivePolicyResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - MFA Outbound x-speakeasy-entity-operation: OutboundMFAPolicy#get put: operationId: MFAOutboundPolicies_Update summary: Update Outbound MFA Policy description: Returns the updated properties of an outbound MFA policy. parameters: - $ref: '#/components/parameters/reactivePolicyIdParameter' requestBody: description: Reactive Policy properties required: true content: application/json: schema: $ref: '#/components/schemas/reactivePolicyOutboundBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/reactivePolicyItem' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - MFA Outbound x-speakeasy-entity-operation: OutboundMFAPolicy#update delete: operationId: MFAOutboundPolicies_Delete summary: Remove Outbound MFA Policy description: Returns an empty object. parameters: - $ref: '#/components/parameters/reactivePolicyIdParameter' responses: '200': description: OK '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - MFA Outbound x-speakeasy-entity-operation: OutboundMFAPolicy#delete /protection/reactive-policies/outbound/dst-candidates: {} /protection/reactive-policies/outbound/excluded-src-candidates: {} /protection/reactive-policies/outbound/filters: {} /protection/reactive-policies/outbound/filters/dst-candidates: {} /protection/reactive-policies/outbound/filters/src-candidates: {} /protection/reactive-policies/outbound/filters/src-users-candidates: {} /protection/reactive-policies/outbound/filters/user-filters: {} /protection/reactive-policies/outbound/filters/user-filters/{filterId}: {} /protection/reactive-policies/outbound/mfa-methods: {} /protection/reactive-policies/outbound/simulate: {} /protection/reactive-policies/outbound/simulate/dst-candidates: {} /protection/reactive-policies/outbound/simulate/resolve: {} /protection/reactive-policies/outbound/simulate/src-candidates: {} /protection/reactive-policies/outbound/simulate/src-users-candidates: {} /protection/reactive-policies/outbound/src-candidates: {} /protection/reactive-policies/outbound/src-users-candidates: {} /protection/reactive-policies/statistics: {} /protection/rpc-rules: post: operationId: RPCRules_Create summary: Create RPC Rule description: Returns the properties of the create RPC rule. requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/rpcRuleBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/rpcRuleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '409': $ref: '#/components/responses/409' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules RPC x-speakeasy-entity-operation: RPCRule#create /protection/rpc-rules/{ruleId}: get: operationId: RPCRule_Get summary: Get RPC Rule description: Returns the properties of an RPC rule. parameters: - $ref: '#/components/parameters/ruleIdParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/rpcRuleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules RPC x-speakeasy-entity-operation: RPCRule#get put: operationId: RPCRule_Update summary: Update RPC Rule description: Returns the properties of the update RPC rule. parameters: - $ref: '#/components/parameters/ruleIdParameter' requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/rpcRuleBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/rpcRuleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules RPC x-speakeasy-entity-operation: RPCRule#update delete: operationId: RPCRule_Delete summary: Remove RPC Rule description: Returns an empty object. parameters: - $ref: '#/components/parameters/ruleIdParameter' responses: '200': description: OK '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules RPC x-speakeasy-entity-operation: RPCRule#delete /protection/rpc-rules/excluded-local-candidates: {} /protection/rpc-rules/export: {} /protection/rpc-rules/export/csv/{exportId}: {} /protection/rpc-rules/filters: {} /protection/rpc-rules/filters/local-candidates: {} /protection/rpc-rules/filters/remote-candidates: {} /protection/rpc-rules/filters/user-candidates: {} /protection/rpc-rules/filters/user-filters: {} /protection/rpc-rules/filters/user-filters/{filterId}: {} /protection/rpc-rules/local-candidates: {} /protection/rpc-rules/remote-candidates: {} /protection/rpc-rules/user-candidates: {} /protection/rules/distribution/{ruleId}: {} /protection/rules/history/{ruleId}: {} /protection/rules/inbound: post: operationId: InboundRules_Create summary: Create Inbound Rule description: Returns the properties of the created Inbound rule. requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/ruleBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ruleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '409': $ref: '#/components/responses/409' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules Inbound x-speakeasy-entity-operation: InboundRule#create /protection/rules/inbound/{ruleId}: get: operationId: InboundRule_Get summary: Get Inbound Rule description: Returns the properties of an Inbound rule. parameters: - $ref: '#/components/parameters/ruleIdParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ruleItem' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules Inbound x-speakeasy-entity-operation: InboundRule#get put: operationId: InboundRule_Update summary: Update Inbound Rule description: Returns the properties of the update Inbound rule. parameters: - $ref: '#/components/parameters/ruleIdParameter' requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/ruleBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ruleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules Inbound x-speakeasy-entity-operation: InboundRule#update delete: operationId: InboundRule_Delete summary: Remove Inbound Rule description: Returns an empty object. parameters: - $ref: '#/components/parameters/ruleIdParameter' responses: '200': description: OK '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules Inbound x-speakeasy-entity-operation: InboundRule#delete /protection/rules/inbound/excluded-local-candidates: {} /protection/rules/inbound/export: {} /protection/rules/inbound/export/csv/{exportId}: {} /protection/rules/inbound/filters: {} /protection/rules/inbound/filters/local-candidates: {} /protection/rules/inbound/filters/remote-candidates: {} /protection/rules/inbound/filters/user-filters: {} /protection/rules/inbound/filters/user-filters/{filterId}: {} /protection/rules/inbound/local-candidates: {} /protection/rules/inbound/remote-candidates: {} /protection/rules/inbound/review/approve-with-changes/{ruleId}: {} /protection/rules/inbound/review/approve/{ruleId}: {} /protection/rules/inbound/review/approve-delete/{ruleId}: {} /protection/rules/inbound/review/reject/{ruleId}: {} /protection/rules/inbound/review/reject-delete/{ruleId}: {} /protection/rules/outbound: post: operationId: OutboundRules_Create summary: Create Outbound Rule description: Returns the properties of the created Outbound rule. requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/ruleBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ruleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '409': $ref: '#/components/responses/409' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules Outbound x-speakeasy-entity-operation: OutboundRule#create /protection/rules/outbound/{ruleId}: get: operationId: OutboundRule_Get summary: Get Outbound Rule description: Returns the properties of an Outbound rule. parameters: - $ref: '#/components/parameters/ruleIdParameter' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ruleItem' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules Outbound x-speakeasy-entity-operation: OutboundRule#get put: operationId: OutboundRule_Update summary: Update Outbound Rule description: Returns the properties of the updated Outbound rules. parameters: - $ref: '#/components/parameters/ruleIdParameter' requestBody: description: Rule properties required: true content: application/json: schema: $ref: '#/components/schemas/ruleBody' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ruleResponse' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules Outbound x-speakeasy-entity-operation: OutboundRule#update delete: operationId: OutboundRule_Delete summary: Remove Outbound Rule description: Returns an empty object. parameters: - $ref: '#/components/parameters/ruleIdParameter' responses: '200': description: OK '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '500': $ref: '#/components/responses/500' security: - api_key: [] tags: - Rules Outbound x-speakeasy-entity-operation: OutboundRule#delete /protection/rules/outbound/excluded-local-candidates: {} /protection/rules/outbound/export: {} /protection/rules/outbound/export/csv/{exportId}: {} /protection/rules/outbound/filters: {} /protection/rules/outbound/filters/excluded-local-candidates: {} /protection/rules/outbound/filters/local-candidates: {} /protection/rules/outbound/filters/remote-candidates: {} /protection/rules/outbound/filters/user-candidates: {} /protection/rules/outbound/filters/user-filters: {} /protection/rules/outbound/filters/user-filters/{filterId}: {} /protection/rules/outbound/local-candidates: {} /protection/rules/outbound/remote-candidates: {} /protection/rules/outbound/user-candidates: {} /protection/rules/outbound/review/approve-with-changes/{ruleId}: {} /protection/rules/outbound/review/approve/{ruleId}: {} /protection/rules/outbound/review/approve-delete/{ruleId}: {} /protection/rules/outbound/review/reject/{ruleId}: {} /protection/rules/outbound/review/reject-delete/{ruleId}: {} /protection/rules/statistics: {} /connect/sessions: {} /connect/sessions/{sessionId}/revoke: {} /connect/sessions/filters: {} /settings/vault/cyberark: {} /settings/version-maintenance-window/modify/{product}: {} /settings/version-maintenance-window/{product}: {} /settings/version-maintenance-window/start-manual/{product}: {} /settings/version-maintenance-window/stop-manual/{product}: {} /settings/version-maintenance-window/manual/{product}: {} /settings/version/desired-version/{product}/{platform}: {} /settings/pilot-group/{product}/{osType}: {} /settings/pilot-group/{product}/{osType}/candidates: {} /settings/pilot-group/{product}/active-rollout/{osType}: {} /settings/pilot-group/{product}/rollout/{osType}/extend: {} /settings/pilot-group/{product}/rollout/{osType}/complete: {} /settings/access-tokens: {} /settings/access-tokens/{clientId}: {} /settings/ai/rule-review: {} /settings/ai/rule-review/cleanup: {} /settings/anti-tampering: {} /settings/applications-label: {} /settings/asset-management/active-directory: {} /settings/asset-management/active-directory/{forestId}: {} /settings/asset-management/active-directory/{forestId}/{domainId}/linux-config: {} /settings/asset-management/active-directory/{forestId}/{domainId}/ou-configs: {} /settings/asset-management/active-directory/{forestId}/groups/linux: {} /settings/asset-management/active-directory/{forestId}/groups/windows: {} /settings/asset-management/active-directory/{forestId}/secondary: {} /settings/asset-management/active-directory/{forestId}/secondary/{domainId}: {} /settings/asset-management/active-directory/candidates/windows-monitored: {} /settings/asset-management/active-directory/candidates/linux-monitored: {} /settings/asset-management/active-directory/candidates/ou: {} /settings/asset-management/active-directory/candidates/protected: {} /settings/asset-management/active-directory/rediscover: {} /settings/asset-management/active-directory/sync-info: {} /settings/asset-management/ansible: {} /settings/asset-management/hypervisors: {} /settings/asset-management/hypervisors/{hypervisorId}: {} /settings/asset-management/linux/rediscover: {} /settings/asset-management/linux/setup: {} /settings/asset-management/linux/user: {} /settings/asset-managers: {} /settings/auth/session-ttl: {} /settings/auth/allowed-ips: {} /settings/azure-ad/credentials: {} /settings/azure-ad/resync: {} /settings/cloud-deployments/azure: {} /settings/cloud-deployments/azure/{tenantId}: {} /settings/cloud-deployments/azure/{tenantId}/sync: {} /settings/claroty: {} /settings/claroty/credentials: {} /settings/claroty/resync: {} /settings/break-glass: {} /settings/break-glass/mfa: {} /settings/break-glass/switches: {} /settings/cloud-connector/access-tokens: {} /settings/cloud-connector/access-tokens/{clientId}: {} /settings/cloud-connector/freeze-period: {} /settings/cloud-connector/freeze-period/{freezePeriodId}: {} /settings/connect/client/auto-update: {} /settings/connect/client/freeze-period: {} /settings/connect/client/freeze-period/{freezePeriodId}: {} /settings/connect/regions: {} /settings/connect/regions/{regionId}: {} /settings/connect/regions/{regionId}/failover-candidates: {} /settings/connect/servers: {} /settings/connect/servers/{connectServerId}: {} /settings/connect/servers/access-token: {} /settings/connect/servers/filters: {} /settings/connect/servers/freeze-period: {} /settings/connect/servers/freeze-period/{freezePeriodId}: {} /connect/policies: {} /connect/policies/{userAccessConfigId}: {} /connect/policies/assets-candidates: {} /connect/policies/destinations-candidates: {} /connect/policies/excluded-assets-candidates: {} /connect/policies/excluded-users-candidates: {} /connect/policies/regions-candidates: {} /connect/policies/users-candidates: {} /connect/posture/checks: {} /connect/posture: {} /connect/posture/{profileId}: {} /settings/data-collection/activities: {} /settings/ai/day-two: {} /settings/posture-checks: {} /settings/posture-checks/excluded-users: {} /settings/posture-checks/excluded-users/user-candidates: {} /settings/domain/subdomains: {} /settings/entities-config: {} /settings/events-receiver/configuration: {} /settings/events-receiver/configuration/exporter-ip: {} /settings/events-receiver/configuration/sync-status: {} /settings/events-receiver/configuration/{receiverType}: {} /settings/events-receiver/configuration/export/{receiverType}/data-structure/{siemEventType}: {} /settings/ext-auth: {} /settings/ext-auth/{pushIdentityProviderId}: {} /settings/external-vpn: {} /settings/firewall: {} /settings/firewall/ignored-gpo-rules: {} /settings/firewall/windowsFirewallProfiles: {} /settings/firewall/windowsIgnoredRules: {} /settings/firewall/mode: {} /settings/firewall/mode/{assetId}: {} /settings/identity/logoff: {} /settings/identity-providers/default-application: {} /settings/identity-providers/saml: {} /settings/identity-providers/saml/{identityProviderId}: {} /settings/inbound/privileged-ports: {} /assets/ip-aliases: {} /assets/ip-aliases/{ipAliasId}: {} /assets/ip-aliases/filters: {} /settings/jamf/credentials: {} /settings/learning-config: {} /settings/learning-with-blocks/rules/inbound: {} /settings/maintenance-window: {} /settings/maintenance-window/{maintenanceWindowId}: {} /settings/notification: {} /settings/occasional-mfa: {} /settings/occasional-mfa/{entityId}: {} /settings/occasional-mfa/candidates: {} /settings/portal/users: {} /settings/portal/users/{customUserId}: {} /settings/portal/users/invite: {} /settings/portal/users/{customUserId}/reinvite: {} /settings/reactive-policy: {} /settings/reactive-policy/auth: {} /settings/roles: {} /settings/roles/{roleEntityId}: {} /settings/roles/candidates: {} /settings/segment-connector/access-tokens: {} /settings/segment-connector/access-tokens/{clientId}: {} /settings/cmdb/access-tokens: {} /settings/cmdb/access-tokens/{clientId}: {} /settings/subscriptions/licenses/{licenseType}: {} /settings/subscriptions/licenses/export: {} /settings/subscriptions/licenses/{licenseType}/in-use: {} /settings/licenses/export/csv/{exportId}: {} /settings/system/internal-subnets: {} /settings/system/internal-subnets/client-subnets: {} /settings/system/restricted/clients/trusted-external: {} /settings/system/restricted/clients: {} /settings/system/restricted/clients/untrusted-external: {} /settings/system/restricted/servers/trusted-external: {} /settings/system/restricted/servers: {} /settings/system/restricted/servers/untrusted-external: {} /settings/system/trusted-external: {} /settings/segment-connector/update-recovery-config: {} /settings/webhooks: {} /settings/webhooks/sender-ip: {} /settings/webhooks/test: {} /settings/webhooks/{webhookId}: {} /settings/webhooks/{webhookId}/test: {} /settings/webhooks/{webhookId}/triggers: {} /users: {} /users/{userId}: {} /users/{userId}/actions/protect: {} /users/{userId}/actions/quarantine: {} /users/{userId}/actions/queue: {} /users/{userId}/actions/unprotect: {} /users/{userId}/activities/logon: {} /users/{userId}/activities/logon/distinctField/{fieldName}: {} /users/{userId}/activities/logon/export: {} /users/{userId}/activities/logon/export/csv/{exportId}: {} /users/{userId}/activities/logon/filters: {} /users/{userId}/activities/logon/filters/user-filters: {} /users/{userId}/activities/logon/filters/user-filters/{filterId}: {} /users/{userId}/activities/network: {} /users/{userId}/activities/network/distinctField/{fieldName}: {} /users/{userId}/activities/network/export: {} /users/{userId}/activities/network/export/csv/{exportId}: {} /users/{userId}/activities/network/filters: {} /users/{userId}/activities/network/filters/user-filters: {} /users/{userId}/activities/network/filters/user-filters/{filterId}: {} /users/{userId}/analysis/identity: {} /users/{userId}/analysis/identity/export: {} /users/{userId}/analysis/identity/export/csv/{exportId}: {} /users/{userId}/analysis/network: {} /users/{userId}/analysis/network/export: {} /users/{userId}/analysis/network/export/csv/{exportId}: {} /users/{userId}/ancestors: {} /users/{userId}/ancestors/candidates: {} /users/{userId}/audit: {} /users/{userId}/audit/export: {} /users/{userId}/audit/filters: {} /users/{userId}/audit/export/csv/{exportId}: {} /users/{userId}/managed-assets: {} /users/{userId}/managed-assets/{groupOrAssetId}: {} /users/{userId}/managed-assets/candidates: {} /users/{userId}/protection/external-access-policies: {} /users/{userId}/protection/external-access-policies/{policyId}: {} /users/{userId}/protection/external-access-policies/dst-asset-candidates: {} /users/{userId}/protection/external-access-policies/filters: {} /users/{userId}/protection/external-access-policies/filters/dst-asset-candidates: {} /users/{userId}/protection/external-access-policies/filters/src-users-candidates: {} /users/{userId}/protection/external-access-policies/src-users-candidates: {} /users/{userId}/protection/external-access-policies/statistics: {} /users/{userId}/protection/identity-rules: {} /users/{userId}/protection/identity-rules/{ruleId}: {} /users/{userId}/protection/identity-rules/asset-candidates: {} /users/{userId}/protection/identity-rules/excluded-asset-candidates: {} /users/{userId}/protection/identity-rules/export: {} /users/{userId}/protection/identity-rules/export/csv/{exportId}: {} /users/{userId}/protection/identity-rules/filters: {} /users/{userId}/protection/identity-rules/filters/asset-candidates: {} /users/{userId}/protection/identity-rules/filters/user-candidates: {} /users/{userId}/protection/identity-rules/filters/user-filters: {} /users/{userId}/protection/identity-rules/filters/user-filters/{filterId}: {} /users/{userId}/protection/identity-rules/user-candidates: {} /users/{userId}/protection/identity/reactive-policies: {} /users/{userId}/protection/identity/reactive-policies/{reactivePolicyId}: {} /users/{userId}/protection/identity/reactive-policies/dst-asset-candidates: {} /users/{userId}/protection/identity/reactive-policies/excluded-src-asset-candidates: {} /users/{userId}/protection/identity/reactive-policies/export: {} /users/{userId}/protection/identity/reactive-policies/export/csv/{exportId}: {} /users/{userId}/protection/identity/reactive-policies/filters: {} /users/{userId}/protection/identity/reactive-policies/filters/dst-asset-candidates: {} /users/{userId}/protection/identity/reactive-policies/filters/src-asset-candidates: {} /users/{userId}/protection/identity/reactive-policies/filters/src-users-candidates: {} /users/{userId}/protection/identity/reactive-policies/filters/user-filters: {} /users/{userId}/protection/identity/reactive-policies/filters/user-filters/{filterId}: {} /users/{userId}/protection/identity/reactive-policies/mfa-methods: {} /users/{userId}/protection/identity/reactive-policies/src-asset-candidates: {} /users/{userId}/protection/identity/reactive-policies/src-users-candidates: {} /users/{userId}/protection/reactive-policies/inbound: {} /users/{userId}/protection/reactive-policies/inbound/{reactivePolicyId}: {} /users/{userId}/protection/reactive-policies/inbound/dst-candidates: {} /users/{userId}/protection/reactive-policies/inbound/excluded-src-candidates: {} /users/{userId}/protection/reactive-policies/inbound/filters: {} /users/{userId}/protection/reactive-policies/inbound/filters/dst-candidates: {} /users/{userId}/protection/reactive-policies/inbound/filters/src-candidates: {} /users/{userId}/protection/reactive-policies/inbound/filters/src-users-candidates: {} /users/{userId}/protection/reactive-policies/inbound/filters/user-filters: {} /users/{userId}/protection/reactive-policies/inbound/filters/user-filters/{filterId}: {} /users/{userId}/protection/reactive-policies/inbound/mfa-methods: {} /users/{userId}/protection/reactive-policies/inbound/simulate: {} /users/{userId}/protection/reactive-policies/inbound/simulate/dst-candidates: {} /users/{userId}/protection/reactive-policies/inbound/simulate/resolve: {} /users/{userId}/protection/reactive-policies/inbound/simulate/src-candidates: {} /users/{userId}/protection/reactive-policies/inbound/simulate/src-users-candidates: {} /users/{userId}/protection/reactive-policies/inbound/src-candidates: {} /users/{userId}/protection/reactive-policies/inbound/src-users-candidates: {} /users/{userId}/protection/reactive-policies/outbound: {} /users/{userId}/protection/reactive-policies/outbound/{reactivePolicyId}: {} /users/{userId}/protection/reactive-policies/outbound/dst-candidates: {} /users/{userId}/protection/reactive-policies/outbound/excluded-src-candidates: {} /users/{userId}/protection/reactive-policies/outbound/filters: {} /users/{userId}/protection/reactive-policies/outbound/filters/dst-candidates: {} /users/{userId}/protection/reactive-policies/outbound/filters/src-candidates: {} /users/{userId}/protection/reactive-policies/outbound/filters/src-users-candidates: {} /users/{userId}/protection/reactive-policies/outbound/filters/user-filters: {} /users/{userId}/protection/reactive-policies/outbound/filters/user-filters/{filterId}: {} /users/{userId}/protection/reactive-policies/outbound/mfa-methods: {} /users/{userId}/protection/reactive-policies/outbound/simulate: {} /users/{userId}/protection/reactive-policies/outbound/simulate/dst-candidates: {} /users/{userId}/protection/reactive-policies/outbound/simulate/resolve: {} /users/{userId}/protection/reactive-policies/outbound/simulate/src-candidates: {} /users/{userId}/protection/reactive-policies/outbound/simulate/src-users-candidates: {} /users/{userId}/protection/reactive-policies/outbound/src-candidates: {} /users/{userId}/protection/reactive-policies/outbound/src-users-candidates: {} /users/{userId}/protection/rules/distribution/{ruleId}: {} /users/{userId}/protection/rules/history/{ruleId}: {} /users/{userId}/protection/rules/outbound: {} /users/{userId}/protection/rules/outbound/{ruleId}: {} /users/{userId}/protection/rules/outbound/excluded-local-candidates: {} /users/{userId}/protection/rules/outbound/export: {} /users/{userId}/protection/rules/outbound/export/csv/{exportId}: {} /users/{userId}/protection/rules/outbound/filters: {} /users/{userId}/protection/rules/outbound/filters/excluded-local-candidates: {} /users/{userId}/protection/rules/outbound/filters/local-candidates: {} /users/{userId}/protection/rules/outbound/filters/remote-candidates: {} /users/{userId}/protection/rules/outbound/filters/user-candidates: {} /users/{userId}/protection/rules/outbound/filters/user-filters: {} /users/{userId}/protection/rules/outbound/filters/user-filters/{filterId}: {} /users/{userId}/protection/rules/outbound/local-candidates: {} /users/{userId}/protection/rules/outbound/remote-candidates: {} /users/{userId}/protection/rules/outbound/review/approve-with-changes/{ruleId}: {} /users/{userId}/protection/rules/outbound/review/approve/{ruleId}: {} /users/{userId}/protection/rules/outbound/review/approve-delete/{ruleId}: {} /users/{userId}/protection/rules/outbound/review/reject/{ruleId}: {} /users/{userId}/protection/rules/outbound/review/reject-delete/{ruleId}: {} /users/{userId}/protection/rules/outbound/user-candidates: {} /users/{userId}/type: {} /users/export: {} /users/actions/inactivate: {} /users/actions/activate: {} /users/{userId}/actions/activate: {} /users/{userId}/actions/inactivate: {} /users/actions/quarantine: {} /users/export/csv/{exportId}: {} /users/filters: {} /users/inactive: {} /users/inactive/export: {} /users/inactive/export/csv/{exportId}: {} /users/inactive/filters: {} /users/privileged: {} /users/privileged/export: {} /users/privileged/export/csv/{exportId}: {} /users/privileged/filters: {} /users/queued: {} /users/queued/export: {} /users/queued/export/csv/{exportId}: {} /users/queued/filters: {} /users/searchIdByPrincipalName: {} /users/searchIdBySid: {} /users/segmented: {} /users/segmented/export: {} /users/segmented/export/csv/{exportId}: {} /users/segmented/filters: {} /users/service-account: {} /users/service-account/export: {} /users/service-account/export/csv/{exportId}: {} /users/service-account/filters: {} /users/protect: {} /users/queue: {} /users/unprotect: {} /users/set-users-type: {} /users/statistics: {} components: parameters: activityTypeParameter: name: activityType in: path description: the activity type required: true schema: type: string enum: - network addAncestorsParameter: name: _add_ancestors in: query description: show rules where the asset is part of a group schema: type: boolean default: true addBuiltinsParameter: name: _add_builtins in: query description: show global rules schema: type: boolean default: false analysisDirectionParameter: name: direction in: query description: 'direction for the query, incoming or outgoing' required: true schema: type: string example: incoming assetIdParameter: name: assetId in: path description: assetId to filter on required: true schema: type: string pattern: '^a:[ault]:[a-zA-Z0-9]{8}$' example: 'a:a:8ErCHXe8' clientIdParameter: name: clientId in: path description: clientId to filter on required: true schema: type: string connectionStateParameter: name: connection_state in: query description: connection state for the query schema: type: integer example: 1 connectClientDownloadParameter: name: platform in: query description: connect client platform required: true schema: type: integer enum: - 1 - 2 - 3 connectRegionIdParameter: name: regionId in: path description: connect region id required: true schema: type: string example: 'r:a:q0tqD2rf' connectServerIdParameter: name: connectServerId in: path description: connect server id required: true schema: type: string example: 'y:a:jUDZuhXU' postureProfileIdParameter: name: profileId in: path description: posture profile id required: true schema: type: string format: uuid example: ab803afb-83bd-4bfe-9e0e-a5db212d134b cursorParameter: name: _cursor in: query description: cursor position to start at schema: type: integer format: int64 pattern: '^\d{13}$' example: 1647305854366 customUserIdParameter: name: customUserId in: path description: id of the customer user required: true schema: type: string format: uuid example: ab803afb-83bd-4bfe-9e0e-a5db211d134b freezePeriodIdPathParameter: name: freezePeriodId in: path description: id of freeze period required: true schema: type: string format: uuid platformParameter: name: platform in: path description: platform required: true schema: type: string enum: - WIN_X64 - WIN_X86 - LINUX_X64 - LINUX_X86 - MAC_X64 - MAC_ARM64 productPathParam: name: product in: path required: true description: Product type for which to modify or fetch the version maintenance window schema: type: string enum: - segment-server - connect-server pilotGroupProductPathParam: name: product in: path required: true description: Product type for pilot group schema: type: string enum: - cloud-connector pilotGroupOsTypePathParam: name: osType in: path required: true description: OS type for pilot group schema: $ref: '#/components/schemas/osType' directionParameter: name: direction in: query description: 'direction for the query, 1=Inbound, 2=Outbound, 3=Both' required: true schema: type: integer example: 1 directlyRetrievedFromAssetParameter: name: directly_retrieved_from_asset in: query description: Only get activities retrieved from the asset required: true schema: type: boolean example: true domainParameter: name: domain in: query description: The domain to filter on required: true schema: type: string example: child.zeronetworks.com domainIdParameter: name: domainId in: path description: The fqdn of the domain required: true schema: type: string example: child.zeronetworks.com dstAssetId: name: dstAssetId in: query description: Id of dest asset required: true schema: type: string dstProcess: name: dstProcess in: query description: Dest process schema: type: string enrichRemoteIPsParameter: name: _enrich_remote_ips in: query description: enrich remote IPs schema: type: boolean default: true entityCursorParameter: name: _cursor in: query description: Used to page through results schema: type: string entityIdParameter: name: entityId in: path description: The id of the user or group required: true schema: type: string entityIdQueryParameter: name: _entityId in: query description: entityId to filter on schema: type: string entityParams: name: entityParams in: query required: false schema: type: string description: 'JSON string URI encoded object {id: string, direction: AssetDirection}' exportIdParameter: name: exportId in: path description: exportId to download required: true schema: type: string externalAccessPolicyIdParameter: name: policyId in: path description: id of the external acess policy required: true schema: type: string example: 'p:e:8199d54b' externalIdParameter: name: externalId in: path description: The external id of the group required: true schema: type: string eventTypeParameter: name: eventType in: query description: '0-Success, 2-Failure' required: true schema: type: integer enum: - 1 - 2 fieldNameParameter: name: fieldName in: path description: The field name to filter on required: true schema: type: string enum: - authenticationPackageName - connectionStatus - dstAsset - dstPort - dstProcess - dstProcessPath - dstSwitch - dstSwitchInterface - dstUser - dstWfpFilter - failureReason - impersonationLevel - lmPackageName - logonProvider - logonStatus - logonType - logonTypeAndStatus - process - srcAsset - srcProcess - srcProcessPath - srcSwitch - srcSwitchInterface - srcUser - srcWfpFilter - subjectUsername - subjectUsernameSID - targetAccountRisks - targetUsername - targetUsernameSID - targetUserProtectionState - targetUserType filterIdParameter: name: filterId in: path description: The saved filter id required: true schema: type: string example: 'e:f:VGL7nXce' filtersParameter: name: _filters in: query description: JSON string URI encoded set of filters schema: type: string forestIdParameter: name: forestId in: path description: The forest id required: true schema: type: string example: 'f:a:8199d54b' forestIdQueryParameter: name: _forestId in: query description: The forest id required: true schema: type: string example: 'f:a:8199d54b' fqdnParameter: name: fqdn in: query description: fully qualified domain name schema: type: string example: server.domain.local fromParameter: name: from in: query description: startTime in epoch(ms) schema: type: integer format: int64 pattern: '^\d{13}$' example: 1647308838000 groupIdParameter: name: groupId in: path description: groupId to filter on required: true schema: type: string pattern: '^g:[acsot]:[a-zA-Z0-9]{8}$' example: 'g:t:01445453' x-speakeasy-name-override: id groupIdQueryParameter: name: _groupId in: query description: groupId to filter on schema: type: string pattern: '^g:[acs]:[a-zA-Z0-9]{8}$' groupOrAssetIdParameter: name: groupOrAssetId description: group or asset id to filter on in: path required: true schema: type: string pattern: '^[ag]:[acdjlngt]:[a-zA-Z0-9]{8}$' groupOrUserIdParameter: name: groupOrUserId description: group or user id to filter on in: path required: true schema: type: string pattern: '^[gu]:[ac]:[a-zA-Z0-9]{8}$' groupTypeParameter: name: groupType in: path description: group type to filter on required: true schema: type: string pattern: ^ad$|^custom$|^ot$|^snow$|^system$|^tag$|^inactive$ identityProviderIdParameter: name: identityProviderId in: path description: Identity provider Id required: true schema: type: string enum: - azure - custom - cyberark - duo - ping-identity - okta includeNestedMembersQueryParameter: name: includeNestedMembers in: query description: include nested members in the result required: true schema: type: boolean ipAliasIdParameter: name: ipAliasId in: path description: IP Alias ID required: true schema: type: string example: e:i:9xuR9t8M ipParameter: name: ip in: query description: IP address required: true schema: type: string pattern: '[0-9]{1,3}[.][0-9]{1,3}[.][0-9]{1,3}[.][0-9]{1,3}' ipRangeParameter: name: ipRange in: query description: IP Address Range required: true schema: type: string example: 1.1.1.1-1.1.1.2 pattern: '[0-9]{1,3}[.][0-9]{1,3}[.][0-9]{1,3}[.][0-9]{1,3}-[0-9]{1,3}[.][0-9]{1,3}[.][0-9]{1,3}[.][0-9]{1,3}' ipSubnetParameter: name: subnet in: query description: IP Subnet required: true schema: type: string example: 192.168.1.0/24 pattern: '[0-9]{1,3}[.][0-9]{1,3}[.][0-9]{1,3}[.][0-9]{1,3}/[0-9]{1,3}' internalAccessPolicyIdParameter: name: policyId in: path description: id of the external acess policy required: true schema: type: string example: 'p:e:8199d54b' x-speakeasy-name-override: id deploymentsClusterIdParameter: name: deploymentsClusterId in: path required: true schema: type: string pattern: '^C:d:' isSrcAssetUnmonitoredParameter: name: isSrcAssetUnmonitored in: query description: filter for unmonitored sources required: false schema: type: boolean limitParameter: name: _limit in: query description: Limit the return results required: true schema: type: integer default: 30 maximum: 400 minimum: 1 maintenanceWindowIdParameter: name: maintenanceWindowId in: path required: true description: id of the maintence window schema: type: string pattern: '^[e]:[m]:[a-zA-Z0-9]{8}$' postureCheckTypeParameter: name: postureCheckType in: path description: posture check type required: true schema: type: string enum: - PASSWORD_NOT_NEEDED - USE_DES_KEY_ONLY - DONT_REQUIRE_PREAUTH - PASSWORD_NEVER_EXPIRE - UNCONSTRAINED_DELEGATION_ENABLED - DEFAULT_ADMIN_ACCOUNT_ENABLED offsetParameter: name: _offset required: false in: query description: Used to page through results schema: type: integer default: 0 maximum: 1000000000 minimum: 0 protectionPolicyIdParameter: name: protectionPolicyId in: path description: The id of the onboarding policy required: true schema: type: string format: uuid optionalOffsetParameter: name: _offset in: query description: Used to page through results required: false schema: type: integer maximum: 1000000000 minimum: 0 optionalOrderParameter: name: order in: query description: What order to sort the results required: false schema: type: string enum: - asc - desc optionalOrderColumnParameter: name: 'orderColumns[]' in: query description: what column to order on required: false schema: type: array items: type: string example: [name] orderParameter: name: order in: query description: What order to sort the results schema: type: string default: desc enum: - asc - desc orderColumnParameter: name: 'orderColumns[]' in: query description: what column to order on schema: type: array items: type: string default: [name] example: [name] otRuleIdParameter: name: ruleId in: path description: The id of the rule required: true schema: type: string example: 'r:s:f52f491fd5b8' port: name: port in: query description: port required: true schema: type: integer principalNameParameter: name: principalName in: query required: true description: sid to query for schema: type: string processes: name: 'processes[]' in: query description: process schema: type: string example: 'c:\windows\system32\lsass.exe' k8sApplicationNameParameter: name: applicationName in: path description: application name to filter on required: true schema: type: string k8sClusterIdParameter: name: k8sClusterId in: path description: cluserId to filter on required: true schema: type: string k8sLabelParameter: name: label in: path required: true description: id of the K8s namespace schema: type: string k8sNamespaceIdParameter: name: k8sNamespaceId in: path required: true description: id of the K8s namespace schema: type: string k8sWorkloadIdParameter: name: k8sWorkloadId in: path required: true description: id of the K8s workload schema: type: string licenseTypeParameter: name: licenseType in: path description: The license type required: true schema: type: string enum: - identity - network - rpc - connect - externalAccess protocolType: name: protocolType in: query description: protocol type required: true schema: type: integer pushIdentityProviderIdParameter: name: pushIdentityProviderId in: path description: Push Identity provider Id required: true schema: type: string enum: - duo - microsoftAuthenticator - okta reactivePolicyIdParameter: name: reactivePolicyId in: path description: The id of the MFA policy required: true schema: type: string format: uuid x-speakeasy-name-override: id receiverTypeParameter: name: receiverType in: path description: receiver type required: true schema: type: string enum: - elastic - splunk - microsoft-sentinel - google-secops roleEntityIdParameter: name: roleEntityId in: path description: The id of the user or group required: true schema: type: string ruleDirectionParameter: name: ruleDirection in: query description: 'direction of the rule (1-Inbound, 2-Outbound)' required: true schema: type: integer enum: - 1 - 2 ruleIdParameter: name: ruleId in: path description: The id of the rule required: true schema: type: string format: uuid example: d37077dc-0660-454d-81a0-f52f491fd5b8 x-speakeasy-name-override: id ruleTypeParameter: name: ruleType in: query description: rule type to filter on required: true schema: type: integer description: '1 - Inbound Allow, 2 - Inbound Block, 3 - Outbound Allow, 4 - Outbound Block' searchParameter: name: _search in: query description: Test to search for schema: type: string segmentConnectorDownloadParameter: name: platform in: query description: segment connector platform required: true schema: type: string enum: - MAC_ARM64 - MAC_X64 - LEGACY_WIN_X64 - LINUX_X64 - LINUX_X86 - WIN_X64 - WIN_X86 sessionIdParameter: name: sessionId in: path description: The id of the session required: true schema: type: string pattern: '^s:a:[a-zA-Z0-9]{8}$' showInactiveParameter: name: showInactive in: query description: show inactive assets schema: type: boolean default: false showOnlyIpSecConfiguredAssets: name: showOnlyIpSecConfiguredAssets in: query description: show only ipsec configured assets schema: type: boolean default: false showPodlessWorkloadsParameter: name: showPodlessWorkloads in: query description: show podless workloads schema: type: boolean default: false sidParameter: name: sid in: query required: true description: sid to query for schema: type: string siemEventTypeParameter: name: siemEventType in: path required: true description: siem event type for the query schema: type: string enum: - identityActivity - networkActivity - rpcActivity - audit simulationParams: name: simulationParams in: query required: false schema: type: string description: 'JSON string URI encoded object {"srcAssetId":"a:a:blah","srcUserId":"b:blah","srcProcess":"","dstAssetId":"a:a:blah","dstProcess":"","protocolType":6,"port":"3389"}' sortParameter: name: sort in: query description: sort for the query schema: type: string example: occurred_desc srcAssetId: name: srcAssetId in: query description: Src asset id required: true schema: type: string srcProcess: name: srcProcess in: query description: Src process schema: type: string srcUserId: name: srcUserId in: query description: Id of src user required: true schema: type: string switchIdParameter: name: switchId in: path description: switch to delete schema: type: string required: true firewallIdParameter: name: firewallId in: path description: firewall id schema: type: string required: true timeFrameParameter: name: timeFrame in: query description: timeframe parameter Max = -1 One Month = 1 Three Monthes = 3 Six Monthes = 6 One Year = 12 schema: type: integer format: int32 enum: - -1 - 1 - 3 - 6 - 12 required: true toParameter: name: to in: query description: endTime in epoch(ms) schema: type: integer format: int64 pattern: '^\d{13}$' example: 1647305854366 trafficTypeParameter: name: traffic_type in: query description: '1-Internal, 2-External or 3-Both' required: true schema: type: integer updateIdParameter: name: updateId in: query description: version required: true schema: type: integer userAccessConfigParameter: name: userAccessConfigId in: path description: userAccessConfigId to filter on required: true schema: type: string pattern: '^v:[a-zA-Z0-9]{8}$' userIdParameter: name: userId in: path description: userId to filter on required: true schema: type: string pattern: '^u:[a]:[a-zA-Z0-9]{8}$' example: 'u:a:w27loY5p' webhookIdParameter: name: webhookId in: path description: webhookId to filter on required: true schema: type: string pattern: '^e:w:[a-zA-Z0-9]{8}$' example: 'e:w:1ZdDPsky' widgetIdParameter: name: widgetId in: path description: The id of the widget required: true schema: type: string format: guid withCountParameter: name: with_count in: query description: return count of objects schema: type: boolean default: false responses: '204': description: No Content '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/error' '403': description: Forbidden content: application/json: schema: $ref: '#/components/schemas/error' '404': description: Not Found content: application/json: schema: $ref: '#/components/schemas/error' '409': description: Already exists content: application/json: schema: $ref: '#/components/schemas/error' '500': description: Server Error content: application/json: schema: $ref: '#/components/schemas/error' 200_empty: description: OK content: application/json: schema: $ref: '#/components/schemas/emptyResponse' schemas: accessInfo: type: object properties: hasAccess: type: boolean ruleFilters: type: array items: $ref: '#/components/schemas/ruleFilter' accessToken: description: Access Token type: object properties: clientId: type: string accessType: $ref: '#/components/schemas/accessTypeEnum' name: type: string expiry: type: string issuedAt: type: string createdAt: type: string token: type: string x-examples: example-1: clientId: 'm:195d7d50e8c0c2864c985e72de1a2fdef7dfdc6e' accessType: 2 name: example expiry: '2024-06-27T08:38:17.000Z' issuedAt: '2022-06-27T08:38:17.000Z' createdAt: '2022-06-27T08:21:21.000Z' token: eyJhbGciOiJSUzI1NiIsIna5cCI6IkpXVCJ9.eyJzdWIiOiJtOjY5NWQ3ZDUwZThjMGMyODY0Yzk4NWU3MmRlMWEyZmRlZjdkZmRjNmUiLCJuYW1lIjoiYXNkIiwiZWlkIjoiMTc2MjRhNTctNzI5ZS00ODA1LTk3MDMtNjc5NDdkM2RiMDFlIiwic2NvcGUiOjUsImVfbmFtZSI6ImxhYjgiLCJ2IjoxLCJpYXQiOjE2NTYzMTkwOTcsImV4cCI6MTcxOTQ3NzQ5NywiYXVkIjoicG9ydGFsLWxhYjguemVyb25ldHdvcmtzLmNvbSIsImlzcyI6Inplcm9uZXR3b3Jrcy5jb20vYXBpL3YxL2FjY2Vzcy10b2tlbiJ9.S0P3tyeU7BOPd0P27GKyFeWidoFSKEMiKhHbRLikyy4_34FafcpykiLO1vKBH6iB0utnEO4BwohlWeRWCi6LWkm5R2GxSLVo9GEuuTLPfqUkMzwpMpUkc-MniERH508z7LsxKrPA9VGCmMDKUh87PasooHfWaPgYtWTygV_uAtu1ppIde4V86WsqEmvbZt2gNGBLxwLgIgUgGuOExHu5MOM9fttiNKtuceJxP-RXFAFluXlfJwmjeY-WWHTU6AdvhB0HeJKAA7Pb8A60OkYxQsLxZKLS0K9WKFekYflh-nZBOQRfU3aUygmRyxtknvE0yZ7aK290y2Vb-lnqtl3k5Q accessTokenInfo: type: object properties: clientId: type: string readOnly: true name: type: string expiry: type: string issuedAt: type: string readOnly: true createdAt: type: string readOnly: true accessType: $ref: '#/components/schemas/accessTypeEnum' title: '' x-examples: example-1: clientId: 'm:81a8735b5fed82c9c497163477c98fd835b58f83' accessType: 3 name: access token - cloud connector provisioning expiry: '2022-07-26T15:49:49.000Z' issuedAt: '2022-06-26T15:49:49.000Z' createdAt: '2022-06-26T12:12:56.000Z' example-2: clientId: string accessType: 1 name: string expiry: string issuedAt: string createdAt: string accessTypeEnum: description: '1=Full Access, 2=Read Only, 3=Cloud Connector Provisioning' type: integer enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 title: accessTypeEnum productType: description: '1=Cloud-Connector, 2=Segment-Connector, 3=Segment-Server, 4=Connect-Client, 5=Connect-Server' type: integer enum: - 1 - 2 - 3 - 4 - 5 title: productType freezePeriodState: description: '1=Created, 2=Started, 3=About to end, 4=Ended' type: integer enum: - 1 - 2 - 3 - 4 title: freezePeriodState actionType: description: | * '1' - Allow * '2' - Block type: integer format: int32 enum: - 1 - 2 activitiesAnalysisWidget: type: object properties: createdAt: $ref: '#/components/schemas/epochMillis' createdById: type: string creator: $ref: '#/components/schemas/idNamePair' description: type: string distinctOnField: type: string filters: type: array items: type: object properties: id: type: string includeValues: type: array items: type: string excludeValues: type: array items: type: string id: type: string format: guid name: type: string type: type: string enum: - CUSTOM - SYSTEM updatedAt: $ref: '#/components/schemas/epochMillis' updatedById: type: string resolvedFilters: $ref: '#/components/schemas/resolvedFilterMap' resolvedFilter: type: object properties: excludeValues: type: array items: $ref: '#/components/schemas/idNamePair' id: type: string enum: - authenticationPackageName - connectionStatus - dstAsset - dstPort - dstProcess - dstProcessPath - dstSwitch - dstSwitchInterface - dstUser - dstWfpFilter - failureReason - impersonationLevel - lmPackageName - logonProvider - logonStatus - logonType - logonTypeAndStatus - process - srcAsset - srcProcess - srcProcessPath - srcSwitch - srcSwitchInterface - srcUser - srcWfpFilter - subjectUsername - subjectUsernameSID - targetAccountRisks - targetUsername - targetUsernameSID - targetUserProtectionState - targetUserType includeValues: type: array items: $ref: '#/components/schemas/idNamePair' name: type: string resolvedFilterMap: type: object additionalProperties: $ref: '#/components/schemas/resolvedFilter' activitiesAnalysisWidgetBody: type: object properties: name: type: string description: type: string distinctOnField: type: string enum: - authenticationPackageName - connectionStatus - dstAsset - dstPort - dstProcess - dstProcessPath - dstSwitch - dstSwitchInterface - dstUser - dstWfpFilter - failureReason - impersonationLevel - lmPackageName - logonProvider - logonStatus - logonType - logonTypeAndStatus - process - srcAsset - srcProcess - srcProcessPath - srcSwitch - srcSwitchInterface - srcUser - srcWfpFilter - subjectUsername - subjectUsernameSID - targetAccountRisks - targetUsername - targetUsernameSID - targetUserProtectionState - targetUserType filters: type: array items: type: object properties: excludeValues: type: array items: type: string id: type: string includeValues: type: array items: type: string required: - description - distinctOnField - filters - name activitiesAnalysisWidgetList: type: object properties: items: type: array items: $ref: '#/components/schemas/activitiesAnalysisWidget' activitiesDistictValue: type: object properties: count: type: integer id: type: string name: type: string asset: $ref: '#/components/schemas/assetBasicInfo' logonTypeAndStatus: type: object properties: logonType: type: integer eventType: type: integer port: type: object properties: port: type: integer protocol: type: integer wfpFilter: type: object properties: layer: type: string name: type: string sublayer: type: string activitiesDistictValuesList: type: object properties: items: type: object properties: aggregations: type: array items: $ref: '#/components/schemas/activitiesDistictValue' activitiesList: type: object properties: items: type: array items: $ref: '#/components/schemas/activity' scrollCursor: type: string activity: type: object properties: conflictingInboundRuleMatches: type: array items: $ref: '#/components/schemas/ruleMatch' conflictingOutboundRuleMatches: type: array items: $ref: '#/components/schemas/ruleMatch' dst: type: object properties: assetId: type: string assetSrc: $ref: '#/components/schemas/source' assetType: $ref: '#/components/schemas/assetType' eventRecordId: type: integer fqdn: type: string ip: type: string ipThreatScore: type: integer networkProtectionState: $ref: '#/components/schemas/protectionState' port: type: integer processId: type: string processName: type: string processPath: type: string user: $ref: '#/components/schemas/userConnectionEnrichment' userId: type: string userName: type: string inboundRuleMatches: type: array items: $ref: '#/components/schemas/ruleMatch' outboundRuleMatches: type: array items: $ref: '#/components/schemas/ruleMatch' protocol: $ref: '#/components/schemas/protocol' reason: type: integer format: int32 description: | * '1' - Requested, * '2' - RequestedDstProtected, * '3' - RequestedSrcAllowWithRule, * '4' - RequestedSrcAllowWithRuleDstProtected, * '5' - Established, * '6' - EstablishedBothWithAllowRules, * '7' - EstablishedDstAllowWithRule, * '8' - EstablishedDstAllowWithImplicitIcmpRule, * '9' - EstablishedBothAllowWithImplicitIcmpRule, * '10' - EstablishedSrcAllowWithRule, * '11' - BlockedSrc, * '12' - BlockedSrcProtected, * '13' - BlockedSrcProtectedDstOtAsset, * '14' - BlockedSrcWithRule, * '15' - Blocked, * '16' - BlockedDstProtected, * '17' - BlockedDstWithRule, * '18' - BlockedAllowSrcBlockDstWithRule, * '19' - BlockedAllowSrcBlockDstProtected, * '20' - BlockedSrcThirdParty, * '21' - BlockedThirdParty, * '22' - BlockedAllowSrcBlockDstThirdParty, * '23' - BlockedAllowSrcThirdPartyBlockDstWithRule, * '24' - BlockedAllowSrcThirdPartyBlockDstProtected, * '25' - BlockedAllowSrcThirdPartyBlockDst, * '26' - EstablishedDstThirdParty, * '27' - EstablishedSrcThirdPartyDstWithRule, * '28' - EstablishedSrcThirdPartyDstWithImplicitIcmpRule, * '29' - EstablishedSrcThirdParty, * '30' - BlockedAllowSrcThirdPartyBlockDstNoMfa, * '31' - BlockedAllowSrcThirdPartyBlockDstPromptMfa, * '32' - BlockedAllowSrcBlockDstzNoMfa, * '33' - BlockedAllowSrcBlockDstPromptMfa, * '34' - BlockedDstUnmonitoredNoMfa, * '35' - BlockedDstMonitoredNoMfa, * '36' - BlockedDstPromptMfa, * '37' - BlockedSrcNoMfa, * '38' - BlockedSrcPromptMfa, enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 - 31 - 32 - 33 - 34 - 35 - 36 - 37 - 38 src: type: object properties: assetId: type: string assetProtectionState: $ref: '#/components/schemas/protectionState' assetSrc: $ref: '#/components/schemas/source' assetType: $ref: '#/components/schemas/assetType' eventRecordId: type: integer fqdn: type: string ip: type: string ipThreatScore: type: integer networkProtectionState: $ref: '#/components/schemas/protectionState' port: type: integer processId: type: string processName: type: string processPath: type: string user: $ref: '#/components/schemas/userConnectionEnrichment' userId: type: string userName: type: string state: description: | * '1' - Blocked * '2' - Requested * '3' - Established * '4' - Blocked At Source * '5' - Blocked By Third Party * '6' - Blocked At Source By Third Party type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 - 6 timestamp: $ref: '#/components/schemas/epochMillis' trafficType: $ref: '#/components/schemas/trafficType' adDomain: type: object properties: id: type: string name: type: string adDomainsList: type: object properties: items: type: array items: $ref: '#/components/schemas/adDomain' aeExclusion: allOf: - $ref: '#/components/schemas/rule' - type: object properties: deletedAt: $ref: '#/components/schemas/epochMillis' deletedBy: $ref: '#/components/schemas/idNamePair' x-speakeasy-entity: - AEExclusionInbound - AEExclusionOutbound aeExclusionList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/aeExclusion' aeExclusionRuleResponse: type: object properties: item: $ref: '#/components/schemas/aeExclusion' aeExclusionRuleBody: type: object properties: action: $ref: '#/components/schemas/actionType' description: type: string excludedLocalIdsList: type: array items: type: string ipSecOpt: $ref: '#/components/schemas/ipSecOpt' localEntityId: type: string localProcessesList: type: array items: type: string portsList: $ref: '#/components/schemas/portsList' remoteEntityIdsList: type: array items: type: string state: $ref: '#/components/schemas/ruleState' srcUsersList: $ref: '#/components/schemas/srcUsersList' required: - localEntityId - localProcessesList - portsList - remoteEntityIdsList x-speakeasy-entity: - AEExclusionInbound - AEExclusionOutbound asset: allOf: - $ref: '#/components/schemas/assetBasicInfo' - type: object properties: assetStatus: $ref: '#/components/schemas/assetStatus' assignedDeploymentId: type: string assignedDeployment: $ref: '#/components/schemas/idNamePair' cloudConnectorVersion: type: string deploymentaClusterId: type: string deploymentsClusterSource: $ref: '#/components/schemas/deploymentsClusterSource' deploymentsCluster: $ref: '#/components/schemas/idNamePair' enforcementMethod: $ref: '#/components/schemas/enforcementMethod' environmentGroup: $ref: '#/components/schemas/idNamePair' externalDeviceId: type: string fqdn: type: string example: laptoppc.domain.local hasDns: type: boolean healthState: $ref: '#/components/schemas/healthState' identityProtectAt: $ref: '#/components/schemas/epochMillis' identityProtectedAt: $ref: '#/components/schemas/epochMillis' inactiveReason: $ref: '#/components/schemas/inactiveReason' inactiveSince: $ref: '#/components/schemas/epochMillis' ipV4Addresses: type: array items: type: string example: 1.1.1.1 ipV6Addresses: type: array items: type: string ipSpace: type: integer isIpSecConfigured: type: boolean lastLogon: $ref: '#/components/schemas/epochMillis' manufacturer: type: string operatingSystem: type: string example: Windows 10 Pro osType: $ref: '#/components/schemas/osType' outboundRestriction: $ref: '#/components/schemas/outboundRestrictionMode' passwordUpdateTime: $ref: '#/components/schemas/epochMillis' preferredDeploymentId: type: string preferredDeployment: $ref: '#/components/schemas/idNamePair' principalName: type: string protectAt: $ref: '#/components/schemas/epochMillis' protectedAt: $ref: '#/components/schemas/epochMillis' purdueLevel: $ref: '#/components/schemas/purdueLevel' rpcMonitored: type: boolean rpcProtectAt: $ref: '#/components/schemas/epochMillis' rpcProtectedAt: $ref: '#/components/schemas/epochMillis' source: $ref: '#/components/schemas/source' state: $ref: '#/components/schemas/state' switchLocationOverridden: type: boolean assetActivateBody: type: object properties: comment: type: string assetIdentityAnalysis: type: object properties: items: type: object properties: authenticationPackage: type: array items: $ref: '#/components/schemas/identityAnalysis' counts: type: object properties: authenticationPackage: type: integer targetUsername: type: integer logonType: type: integer srcAsset: type: integer srcAsset: type: array items: $ref: '#/components/schemas/identityAnalysis' logonType: type: array items: $ref: '#/components/schemas/identityAnalysis' targetUsername: type: array items: $ref: '#/components/schemas/identityAnalysis' assetBasicInfo: allOf: - $ref: '#/components/schemas/idNamePair' - type: object properties: assetStatus: $ref: '#/components/schemas/assetStatus' assetType: $ref: '#/components/schemas/assetType' breakGlassActivated: type: boolean domain: type: string id: type: string identityProtectionState: $ref: '#/components/schemas/protectionState' isQuarantined: type: boolean name: type: string otLocattion: $ref: '#/components/schemas/otLocation' protectionState: $ref: '#/components/schemas/protectionState' rpcProtectionState: $ref: '#/components/schemas/protectionState' assetBasicInfoList: type: object properties: items: type: array items: $ref: '#/components/schemas/assetBasicInfo' assetCandidate: type: object properties: assetType: type: integer breakGlassActivated: type: boolean domain: type: string id: type: string identityProtectionState: $ref: '#/components/schemas/identityProtectionState' name: type: string protectionState: $ref: '#/components/schemas/protectionState' rpcProtectionState: $ref: '#/components/schemas/rpcProtectionState' assetIdSearch: type: object properties: assetId: type: string x-speakeasy-entity: AssetId assetList: type: object properties: items: type: array items: $ref: '#/components/schemas/asset' count: type: integer assetManager: type: object properties: manager: type: object anyOf: - $ref: '#/components/schemas/user' - $ref: '#/components/schemas/group' managerId: type: string permission: type: integer format: int32 relation: type: integer format: int32 assetManagersBody: type: object required: - managerIds - permission properties: managerIds: description: managers id type: array items: type: string pattern: '^[ug]:[ac]:[a-zA-Z0-9]{8}$' example: - 'g:c:ab124as2' - 'u:a:ab124as2' permission: description: '2 - Viewer, 3 - Manager' type: integer enum: - 2 - 3 assetManagersList: type: object properties: items: type: array items: $ref: '#/components/schemas/assetManager' assetManagersUpdateBody: type: object required: - managerId - permission properties: managerId: type: string pattern: '^[ug]:[a-z]:[a-zA-Z0-9]{8}$' example: 'g:c:ab124as2' permission: description: '2 - Viewer, 3 - Manager' type: integer enum: - 2 - 3 assetNetworkAnalysis: type: object properties: items: type: object properties: byLocalAsset: type: array items: $ref: '#/components/schemas/networkAnalysis' byPort: type: array items: $ref: '#/components/schemas/networkAnalysis' byRemoteAsset: type: array items: $ref: '#/components/schemas/networkAnalysis' bySrcProcess: type: array items: $ref: '#/components/schemas/networkAnalysis' byUser: type: array items: $ref: '#/components/schemas/networkAnalysis' counts: type: object properties: byLocalAsset: type: integer byPort: type: integer byRemoteAsset: type: integer bySrcProcess: type: integer byUser: type: integer assetOt: type: object properties: assetStatus: $ref: '#/components/schemas/assetStatus' assetType: $ref: '#/components/schemas/assetType' domain: type: string example: domain.local fqdn: type: string example: laptoppc.domain.local healthState: $ref: '#/components/schemas/healthState' id: type: string example: 'a:a:6d020055' ipV4Addresses: type: array items: type: string example: 1.1.1.1 ipV6Addresses: type: array items: type: string name: type: string example: router principalName: type: string operatingSystem: type: string protectionState: $ref: '#/components/schemas/protectionState' source: $ref: '#/components/schemas/source' state: $ref: '#/components/schemas/state' assetOtList: type: object properties: items: type: array items: $ref: '#/components/schemas/assetOt' count: type: integer nextOffset: type: integer assetOtResponse: type: object properties: entity: $ref: '#/components/schemas/assetOt' assetResponse: type: object properties: entity: $ref: '#/components/schemas/asset' assetsActivateBody: type: object required: - items properties: comment: type: string items: type: array items: type: string assetsBreakGlassBody: type: object required: - items properties: items: type: array items: type: string assetsIdentityQueueBody: type: object properties: items: type: array items: type: string queueDays: description: number of days type: integer enum: - 14 - 30 - 60 - 90 required: - items - queueDays assetsMirrorBody: type: object properties: originalAssetId: type: string targetAssetId: type: string required: - originalAssetId - targetAssetId assetsOrGroupsList: type: object properties: items: type: array items: anyOf: - $ref: '#/components/schemas/assetBasicInfo' - $ref: '#/components/schemas/groupBasicInfo' - $ref: '#/components/schemas/idNamePair' scrollCursor: type: string assetsPreferredSegmentServer: type: object properties: preferredDeployment: type: string assetsPreferredSegmentServerSetBody: type: object properties: assetIds: type: array items: type: string preferredDeploymentId: type: string description: If not provided sets the asset back to no preferred segment server required: - assetIds assetsPreferredSegmentServerBody: type: object properties: assetId: type: string required: - assetId assetsProtectBody: type: object properties: items: type: array items: type: string required: - items assetsQueueBody: type: object properties: items: type: array items: type: string queueDays: description: number of days type: integer enum: - 14 - 30 - 60 - 90 required: - items - queueDays assetsRpcBody: type: object properties: items: type: array items: type: string required: - items assetsRPCQueueBody: type: object properties: items: type: array items: type: string queueDays: description: number of days type: integer enum: - 14 - 30 - 60 - 90 required: - items - queueDays assetsSegmentationStatistic: type: object properties: date: $ref: '#/components/schemas/epochMillis' monitorAssets: type: integer segmentedAssets: type: integer segmentedOutOfMonitor: type: number assetsSegmentationStatistics: type: object properties: items: type: array items: $ref: '#/components/schemas/assetsSegmentationStatistic' assetsStatesStatistics: type: object properties: assetsStatesStatistics: type: object properties: connectedAssetsCount: type: integer x-examples: example-1: assetsStatesStatistics: connectedAssetsCount: 13 assetsStatistics: type: object properties: item: type: object properties: totalCount: type: integer deletedCount: type: integer protectedCount: type: integer queuedCount: type: integer monitoredCount: type: integer protectedDueToProtectionPolicyCount: type: integer queuedDueToProtectionPolicyCount: type: integer forcedUnprotectedCount: type: integer removingProtectionCount: type: integer forceRemovingProtectionCount: type: integer addingProtectionCount: type: integer forceAddingProtectionCount: type: integer notProtectedLink: type: array items: $ref: '#/components/schemas/requestedFilter' x-examples: example-1: item: totalCount: 82 deletedCount: 2 protectedCount: 31 queuedCount: 2 monitoredCount: 37 protectedDueToProtectionPolicyCount: 0 queuedDueToProtectionPolicyCount: 0 forcedUnprotectedCount: 0 removingProtectionCount: 1 forceRemovingProtectionCount: 0 addingProtectionCount: 3 forceAddingProtectionCount: 6 notProtectedLink: - id: protectionStatus includeValues: - '1' - '6' - id: status excludeValues: - '3' assetStatus: description: | Possible asset status: * '1' - Not monitored * '2' - Segment server * '4' - Can't be monitored (unsupported OS) * '5' - Can't be monitored (unmonitorable) * '6' - Can't be monitored (unmonitorable) * '7' - Cloud connector * '8' - Not monitored (ansible unreachable) * '9' - Not monitored (cloud connector uninstalled) * '10' - Not monitored (cloud connector required) * '12' - Can't be monitored (inactive entity) * '13' - Stalked Externally * '14' - Lightweight Agent type: integer enum: - 1 - 2 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 12 - 13 - 14 enforcementMethod: description: | Possible values: * '1' - Linux IP Tables * '2' - Linux NF Tables * '3' - Windows Firewall * '4' - Windows WFP type: integer enum: - 0 - 1 - 2 - 3 - 4 assetSummary: type: object properties: count: type: integer id: type: string name: type: string assetsUnprotectBody: type: object properties: items: type: array items: type: string required: - items assetType: description: | Possible asset status: * '0' - Unknown * '1' - Client * '2' - Server * '3' - Virtual cluster * '4' - IP camera * '5' - Smart TV * '6' - Factory controller * '7' - Medical device * '8' - Printer * '9' - Scanner * '10' - Smart card reader * '11' - Router * '12' - Hypervisor * '13' - PLC * '14' - HMI * '15' - Switch * '16' - Terminal station * '17' - RTU * '18' - Wireless access point * '19' - Historian * '20' - Game console * '21' - Fire alarm * '22' - UPS * '23' - Storage appliance * '24' - Virtualization appliance * '25' - Firewall appliance * '26' - Security scanner * '27' - Security controller * '28 ' - Door lock * '29' - Biometric entry system * '30' - HVAC * '31' - Room scheduler * '32' - Load Balancer Appliance * '33' - WAN Concentrator * '34' - IPAM Appliance * '35' - TEMPERATURE SENSOR GATEWAY * '36' - POWER METER * '37' - CONVEYOR SYSTEM * '38' - BUILDING AUTOMATION DEVICE * '39' - VISION CONTROLLER * '40' - MANUFACTURING EXECUTION SYSTEM * '41' - BACNET BROADCAST MANAGEMENT DEVICE BBMD * '42' - BACNET ROUTER AND BBMD * '43' - CLOCK * '44' - RFID * '45' - SCALE * '46' - MOBILE PRINTER * '47' - IED * '48' - CNC MILL * '49' - ROOM MONITOR * '50' - SMART SPEAKER * '51' - VENDING MACHINE * '52' - AUTONOMOUS VEHICLE * '53' - FLEET MANAGEMENT SYSTEM * '54' - BACNET ROUTER * '55' - MOTOR CONTROLLER * '56' - OT GATEWAY * '57' - CONTROLLER * '58' - BUILDING MANAGEMENT SYSTEM * '59' - VOIP PHONE * '60' - VISION SENSOR * '61' - REMOTE IO * '62' - VOIP SERVER * '63' - FLOW METER * '64' - BUILDING AUTOMATION CONTROLLER * '65' - SECURITY CAMERA * '66' - DIGITAL SIGN * '67' - REMOTE ACCESS GATEWAY * '68' - TEMPERATURE SENSOR * '69' - RTLS * '70' - SERIAL TO ETHERNET * '71' - INTERCOM * '72' - ENGINEERING STATION * '73' - DATA LOGGER GATEWAY * '74' - ROBOT * '75' - TABLET * '76' - SCADA SERVER * '77' - INDUSTRIAL PRINTER * '78' - VISION CAMERA * '79' - TIME CLOCK * '80' - VIDEO CONFERENCE * '81' - ELECTRICAL DRIVE * '82' - ACCESS CONTROL * '83' - PRINTER 3D * '84' - ACCESS CONTROL GATEWAY * '85' - ATM * '86' - AUDIO DECODER * '87' - AV SYSTEM * '88' - BACNET ROUTER BBMD * '89' - BADGE READER * '90' - BARCODE SCANNER * '91' - BUILDING AUTOMATION CONTROLLER GATEWAY * '92' - BUILDING MANAGEMENT SENSOR * '93' - BUILDING MANAGEMENT SENSOR GATEWAY * '94' - BUILDING MANAGEMENT SYSTEM GATEWAY * '95' - CAR * '96' - CIRCUIT MONITOR * '97' - CLINICAL MOBILE DEVICE * '98' - CLINICAL MOBILE DEVICE GATEWAY * '99' - CLOCK GATEWAY * '100' - CNC SYSTEM * '101' - CONFERENCE ROOM * '102' - DATA LOGGER * '103' - DIGITAL SIGN WORKSTATION * '104' - DISK PUBLISHER * '105' - DISPATCHER * '106' - EMBEDDED PC * '107' - ENCODER * '108' - EV CHARGING * '109' - FITNESS DEVICE * '110' - GENERIC MOBILE DEVICE * '111' - GPS NAVIGATOR * '112' - INDUSTRIAL BARCODE SCANNER * '113' - INDUSTRIAL METAL DETECTOR * '114' - INDUSTRIAL NETWORK EQUIPMENT * '115' - INDUSTRIAL THIN CLIENT * '116' - INDUSTRIAL THIN CLIENT GATEWAY * '117' - INDUSTRIAL WIRELESS * '118' - INDUSTRIAL WORKSTATION * '119' - INSPECTION SYSTEM * '120' - INTERACTIVE VOICE RESPONSE * '121' - INTERCOM GATEWAY * '122' - IOT CONTROLLER * '123' - LOCK BOX * '124' - MACHINERY HEALTH ANALYZER * '125' - MAILING SYSTEM * '126' - MEDIA GATEWAY * '127' - MEDIA PLAYER * '128' - MEDIA STREAMER * '129' - MICROSCOPE * '130' - MOBILE COMPUTER * '131' - MOTOR STARTER * '132' - MUSICAL INSTRUMENT * '133' - OPC SERVER * '134' - ORDER FULFILLMENT SYSTEM * '135' - OT DEVICE * '136' - OT SERVER * '137' - PA SYSTEM * '138' - PAYMENT KIOSK * '139' - PHYSICAL SECURITY PLATFORM * '140' - POINT OF SALE * '141' - POINT OF SALE GATEWAY * '142' - POWER DISTRIBUTION UNIT * '143' - POWER DISTRIBUTION UNIT GATEWAY * '144' - POWER SUPPLY * '145' - PRINT SERVER * '146' - PROJECTOR * '147' - RADIO * '148' - RADIO REPEATER * '149' - RECORDING SERVER * '150' - REPORTING SERVER * '151' - ROOM AUTOMATION STATION * '152' - ROOM DISPLAY * '153' - RTLS GATEWAY * '154' - SAFETY SYSTEM * '155' - SCADA CLIENT * '156' - SCREEN SHARE * '157' - SECURITY XRAY SCANNER * '158' - SENSOR * '159' - SERIAL TO ETHERNET GATEWAY * '160' - SERVICE TROLLEY * '161' - SMART BOARD * '162' - SMART HOME * '163' - SMART LIGHT * '164' - SMART LIGHT GATEWAY * '165' - SMART LOCK CONTROLLER * '166' - SMARTPHONE * '167' - SMARTWATCH * '168' - SOLAR ENERGY * '169' - TIME CLOCK GATEWAY * '170' - VIDEO CONFERENCE GATEWAY * '171' - VIDEO DECODER * '172' - VIDEO ENCODER * '173' - VIDEO SURVEILLANCE DEVICE * '174' - VOIP ADAPTER * '175' - VOIP PHONE GATEWAY * '176' - WATER SYSTEM * '177' - WIRELESS PHONE * '178' - WIRELESS PHONE GATEWAY * '1001' - OTHER OT type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 29 - 30 - 31 - 32 - 33 - 34 - 35 - 36 - 37 - 38 - 39 - 40 - 41 - 42 - 43 - 44 - 45 - 46 - 47 - 48 - 49 - 50 - 51 - 52 - 53 - 54 - 55 - 56 - 57 - 58 - 59 - 60 - 61 - 62 - 63 - 64 - 65 - 66 - 67 - 68 - 69 - 70 - 71 - 72 - 73 - 74 - 75 - 76 - 77 - 78 - 79 - 80 - 81 - 82 - 83 - 84 - 85 - 86 - 87 - 88 - 89 - 90 - 91 - 92 - 93 - 94 - 95 - 96 - 97 - 98 - 99 - 100 - 101 - 102 - 103 - 104 - 105 - 106 - 107 - 108 - 109 - 110 - 111 - 112 - 113 - 114 - 115 - 116 - 117 - 118 - 119 - 120 - 121 - 122 - 123 - 124 - 125 - 126 - 127 - 128 - 129 - 130 - 131 - 132 - 133 - 134 - 135 - 136 - 137 - 138 - 139 - 140 - 141 - 142 - 143 - 144 - 145 - 146 - 147 - 148 - 149 - 150 - 151 - 152 - 153 - 154 - 155 - 156 - 157 - 158 - 159 - 160 - 161 - 162 - 163 - 164 - 165 - 166 - 167 - 168 - 169 - 170 - 171 - 172 - 173 - 174 - 175 - 176 - 177 - 178 - 1001 audienceType: description: | dictionary: * '0' PORTAL_AUDIENCE * '1' SSP_AUDIENCE * '2' RP_AUDIENCE type: integer enum: - 0 - 1 - 2 audit: type: object properties: auditType: $ref: '#/components/schemas/auditType' destinationEntitiesList: type: array items: $ref: '#/components/schemas/idNamePair' details: type: string enforcementSource: $ref: '#/components/schemas/enforcementSource' isoTimestamp: type: string parentObjectId: type: string performedBy: $ref: '#/components/schemas/idNamePair' reportedObjectId: type: string timestamp: $ref: '#/components/schemas/epochMillis' userRole: $ref: '#/components/schemas/userRole' auditList: type: object properties: items: type: array items: $ref: '#/components/schemas/audit' scrollCursor: type: string auditType: description: | * 1 - Asset is being segmented (network) * 2 - Asset segmented (network) * 3 - Asset failed segmenting * 4 - Asset is being unsegmented (network) * 5 - Asset unsegmented (network) * 6 - Asset failed unsegmenting * 7 - Asset added to learning (network) * 8 - Asset removed from learning (network) * 9 - Inbound allow rule created * 10 - Inbound allow rule deleted * 11 - Inbound allow rule expired * 12 - Inbound allow rule edited * 17 - Inbound MFA policy created * 18 - Inbound MFA policy deleted * 19 - Inbound MFA policy edited * 20 - Inbound JIT rule created * 21 - Inbound JIT rule deleted * 22 - Inbound JIT rule expired * 23 - Inbound JIT rule revived * 24 - Inbound JIT rule edited * 25 - API Token created * 26 - API Token deleted * 27 - API Token regenerated * 28 - Asset segmentation date postponed (network) * 29 - Outbound block rule created * 30 - Outbound block rule deleted * 31 - Outbound block rule expired * 32 - Outbound block rule edited * 33 - Inbound block rule created * 34 - Inbound block rule deleted * 35 - Inbound block rule expired * 36 - Inbound block rule edited * 39 - Asset unsegmented (network) (overriding policy) * 40 - Asset is being unsegmented (network) (overriding policy) * 41 - Asset removed from learning (network) (overriding policy) * 42 - Asset is being segmented (network) (policy) * 43 - Asset segmented (network) (policy) * 44 - Asset added to learning (network) (policy) * 45 - Network onboarding policy created * 46 - Network onboarding policy deleted * 47 - Network onboarding policy edited * 48 - Inbound JIT access rejected * 49 - Inbound JIT fallback rule created * 50 - Inbound JIT fallback rule deleted * 51 - Inbound JIT fallback rule expired * 53 - Outbound allow rule created * 54 - Outbound allow rule deleted * 55 - Outbound allow rule expired * 56 - Outbound allow rule edited * 58 - Admin portal role changed to admin * 59 - Admin portal role changed to viewer * 60 - Admin portal role revoked * 61 - Outbound JIT rule created * 62 - Outbound JIT rule deleted * 63 - Outbound JIT rule expired * 64 - Outbound MFA policy created * 65 - Outbound MFA policy deleted * 66 - Outbound MFA policy edited * 67 - Outbound JIT access rejected * 68 - Asset learning is done (network) * 69 - Asset learning (policy) is done (network) * 70 - Manual Linux asset created * 71 - Manual OT/IoT asset created * 72 - Asset learning extended (network) * 73 - Admin portal logon * 74 - Asset manager added * 75 - Asset manager removed * 76 - Asset is monitored by Cloud connector * 77 - Asset is no longer monitored by Cloud connector * 78 - Asset is monitored by Segment server * 79 - Asset is back to learning (network) * 80 - Manual OT/IoT asset edited * 81 - Admin portal role changed to operator * 82 - Segment server deployed * 83 - Automation engine inbound allow rule rejected * 84 - Automation engine inbound block rule rejected * 85 - Automation engine outbound allow rule rejected * 86 - Automation engine outbound block rule rejected * 87 - Automation engine inbound allow rule approved * 88 - Automation engine inbound block rule approved * 89 - Automation engine outbound allow rule approved * 90 - Automation engine outbound block rule approved * 91 - Automation engine inbound allow rule approved with changes * 92 - Automation engine inbound block rule approved with changes * 93 - Automation engine outbound allow rule approved with changes * 94 - Automation engine outbound block rule approved with changes * 95 - Region created * 96 - Connect session created * 97 - Connect session expired * 98 - Connect session revoked * 99 - Connect session logout * 100 - Connect policy created * 101 - Connect policy edited * 102 - Connect policy deleted * 103 - Connect server deployed * 104 - Connect asset created * 105 - Asset segmentation blocked (network) * 106 - Region edited * 107 - Connect server edited * 108 - Asset is being segmented (identity) * 109 - Asset segmented (identity) * 110 - Asset is being unsegmented (identity) * 111 - Asset unsegmented (identity) * 112 - Identity rule created * 113 - Identity rule deleted * 114 - Identity rule expired * 115 - Identity rule edited * 116 - User segmented (identity) * 117 - User unsegmented (identity) * 118 - User added to learning (identity) * 119 - User removed from learning (identity) * 120 - Asset added to RPC monitoring * 121 - Asset removed from RPC monitoring * 122 - User classification changed * 123 - Connect session extended * 124 - Asset marked as inactive by entity repository * 125 - Asset marked as active by entity repository * 126 - Asset manually marked as inactive * 127 - Asset manually marked as active * 128 - Break glass activated * 129 - Break glass deactivated * 132 - Break glass activated for asset * 133 - Break glass deactivated for asset * 134 - Asset is being segmented (RPC) * 135 - Asset segmented (RPC) * 136 - Asset is being unsegmented (RPC) * 137 - Asset unsegmented (RPC) * 138 - RPC rule created * 139 - RPC rule deleted * 140 - RPC rule expired * 141 - RPC rule edited * 142 - Asset was revived but still marked as inactive * 143 - User learning is done (identity) * 144 - User is back to learning (identity) * 145 - Asset added to tag * 146 - Asset removed from tag * 147 - Identity MFA policy created * 148 - Identity MFA policy edited * 149 - Identity MFA policy deleted * 150 - Identity JIT rule created * 151 - Identity JIT rule deleted * 152 - Identity JIT rule expired * 153 - Identity JIT rule edited * 154 - Identity JIT access rejected * 155 - Asset type changed * 156 - Asset added to learning (RPC) * 157 - Asset removed from learning (RPC) * 158 - Asset learning extended (RPC) * 159 - Asset segmentation date postponed (RPC) * 160 - Asset learning is done (RPC) * 161 - Asset is back to learning (RPC) * 162 - Asset added to environment * 163 - Asset removed from environment * 164 - Asset environment updated * 165 - Asset added to learning (identity) * 166 - Asset removed from learning (identity) * 167 - Asset learning extended (identity) * 168 - Asset segmentation date postponed (identity) * 169 - Asset learning is done (identity) * 170 - Asset is back to learning (identity) * 171 - Enforcing block rules * 172 - Enforcing block rules due to policy * 173 - Block rules enforced * 174 - Removing block rules * 175 - Group marked as inactive by entity repository * 176 - Group marked as active by entity repository * 177 - Cache MFA config created * 178 - Cache MFA config updated * 179 - Cache MFA config removed * 180 - Identity onboarding policy created * 181 - Identity onboarding policy deleted * 182 - Identity onboarding policy edited * 183 - Asset unsegmented (identity) (overriding policy) * 184 - Asset removed from learning (identity) (overriding policy) * 185 - Asset is being unsegmented (identity) (overriding policy) * 186 - Access portal logon * 187 - Asset OS type changed * 188 - User marked as inactive by entity repository * 189 - User marked as active by entity repository * 190 - Connect server deleted * 191 - Region deleted * 192 - External MFA policy created * 193 - External MFA policy removed * 194 - External MFA policy edited * 195 - Switch added * 196 - Switch edited * 197 - Switch deleted * 198 - OT/IoT is being segmented * 199 - OT/IoT segmented * 200 - OT/IoT is being unsegmented * 201 - OT/IoT unsegmented * 202 - OT/IoT rule added * 203 - OT/IoT rule deleted * 204 - OT/IoT rule edited * 205 - OT/IoT rule expired * 206 - Download portal logon * 207 - External access portal logon * 208 - Maintenance window added * 209 - Maintenance window deleted * 210 - Maintenance window edited * 211 - Maintenance window set as default * 212 - Tag group created * 213 - Custom user created * 214 - Custom user deleted * 215 - User learning extended (identity) * 216 - Asset restricted outbound enabled * 217 - Asset restricted outbound disabled * 218 - Asset restricted outbound changed * 219 - Asset mirrored * 220 - Asset quarantined * 221 - Asset unquarantined * 222 - Custom user invited * 223 - Custom user role changed to admin * 224 - Custom user role changed to viewer * 225 - Custom user role changed to operator * 226 - Custom user re-invited * 227 - Custom user approved invite * 228 - Custom user rejected invite * 229 - Inbound AE exclusion deleted * 230 - Outbound AE exclusion deleted * 231 - Asset manager permission changed * 232 - Added switch interfaces to monitor * 233 - Removed switch interfaces to monitor * 234 - Attempted to exceed network license limit * 235 - Network licenses available * 236 - Attempted to exceed identity license limit * 237 - Identity licenses available * 238 - Attempted to exceed RPC license limit * 239 - RPC licenses available * 240 - Network anti-tampering detected and handled * 241 - Identity anti-tampering detected and handled * 242 - RPC anti-tampering detected and handled * 243 - User manually marked as inactive * 244 - User manually marked as active * 245 - User was revived but still marked as inactive * 246 - Asset segmentation blocked (identity) * 247 - Asset segmentation blocked (rpc) * 248 - Outbound AE exclusion created * 249 - Inbound AE exclusion created * 250 - Outbound AE exclusion edited * 251 - Inbound AE exclusion edited * 252 - Cluster added * 253 - Cluster edited * 254 - Cluster deleted * 255 - User marked as disabled by entity repository * 256 - User marked as enabled by entity repository * 257 - User marked as disabled by entity repository (previously inactive) * 258 - User marked as inactive by entity repository (previously disabled) * 259 - User manually marked as inactive (previously disabled) * 260 - Attempted to exceed connect license limit * 261 - Connect licenses available * 287 - type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 - 31 - 32 - 33 - 34 - 35 - 36 - 39 - 40 - 41 - 42 - 43 - 44 - 45 - 46 - 47 - 48 - 49 - 50 - 51 - 53 - 54 - 55 - 56 - 58 - 59 - 60 - 61 - 62 - 63 - 64 - 65 - 66 - 67 - 68 - 69 - 70 - 71 - 72 - 73 - 74 - 75 - 76 - 77 - 78 - 79 - 80 - 81 - 82 - 83 - 84 - 85 - 86 - 87 - 88 - 89 - 90 - 91 - 92 - 93 - 94 - 95 - 96 - 97 - 98 - 99 - 100 - 101 - 102 - 103 - 104 - 105 - 106 - 107 - 108 - 109 - 110 - 111 - 112 - 113 - 114 - 115 - 116 - 117 - 118 - 119 - 120 - 121 - 122 - 123 - 124 - 125 - 126 - 127 - 128 - 129 - 130 - 131 - 132 - 133 - 134 - 135 - 136 - 137 - 138 - 139 - 140 - 141 - 142 - 143 - 144 - 145 - 146 - 147 - 148 - 149 - 150 - 151 - 152 - 153 - 154 - 155 - 156 - 157 - 158 - 159 - 160 - 161 - 162 - 163 - 164 - 165 - 166 - 167 - 168 - 169 - 170 - 171 - 172 - 173 - 174 - 175 - 176 - 177 - 178 - 179 - 180 - 181 - 182 - 183 - 184 - 185 - 186 - 187 - 188 - 189 - 190 - 191 - 192 - 193 - 194 - 195 - 196 - 197 - 198 - 199 - 200 - 201 - 202 - 203 - 204 - 205 - 206 - 207 - 208 - 209 - 210 - 211 - 212 - 213 - 214 - 215 - 216 - 217 - 218 - 219 - 220 - 221 - 222 - 223 - 224 - 225 - 226 - 227 - 228 - 229 - 230 - 231 - 232 - 233 - 234 - 235 - 236 - 237 - 238 - 239 - 240 - 241 - 242 - 243 - 244 - 245 - 246 - 247 - 248 - 249 - 250 - 251 - 252 - 253 - 254 - 255 - 256 - 257 - 258 - 259 - 260 - 261 authenticationPackageSummary: type: object properties: count: type: integer name: type: string azureTenantCredentialsBody: type: object required: - tenantId - tenantName - clientId - clientSecret - autoSyncNewSubscriptions - managementScope properties: tenantId: type: string description: Azure Tenant ID tenantName: type: string description: Azure Tenant Name clientId: type: string description: Azure Client ID clientSecret: type: string description: Azure Client Secret autoSyncNewSubscriptions: type: boolean description: Auto sync new subscriptions managementScope: type: string enum: [ALL_RESOURCES, ALL_RESOURCES_EXCLUDE_VMS] description: Management scope for Azure resources azureTenantInfo: type: object properties: tenantId: type: string description: Azure Tenant ID tenantName: type: string description: Azure Tenant Name clientId: type: string description: Azure Client ID syncStatus: $ref: '#/components/schemas/azureTenantSyncStatus' autoSyncNewSubscriptions: type: boolean description: Auto sync new subscriptions managementScope: type: string enum: [ALL_RESOURCES, ALL_RESOURCES_EXCLUDE_VMS] description: Management scope for Azure resources azureTenantSyncStatus: type: object properties: lastSyncedAt: type: integer description: Last synced timestamp errorType: type: integer description: Error type if sync failed lastErrorTime: type: integer description: Last error timestamp azureSubscriptionInfo: type: object properties: id: type: string format: uuid description: Subscription ID name: type: string description: Subscription name tenantId: type: string format: uuid description: Azure Tenant ID managementGroupId: type: string description: Management Group ID managementGroupName: type: string description: Management Group Name shouldSync: type: boolean description: Whether subscription should be synced azureSubscriptionsList: type: object properties: items: type: array items: $ref: '#/components/schemas/azureSubscriptionInfo' count: type: integer description: Total count of items azureSubscriptionResponse: type: object properties: subscriptionInfo: $ref: '#/components/schemas/azureSubscriptionInfo' azureSubscriptionsSyncConfigBody: type: object required: - subscriptionIds - shouldSync properties: subscriptionIds: type: array items: type: string format: uuid description: List of subscription IDs to update shouldSync: type: boolean description: Whether subscriptions should be synced azureResourceGroupInfo: type: object properties: id: type: string format: uuid description: Resource Group ID name: type: string description: Resource Group name subscriptionId: type: string format: uuid description: Parent Subscription ID subscriptionName: type: string description: Parent Subscription name managementGroupId: type: string description: Management Group ID managementGroupName: type: string description: Management Group Name shouldSynced: type: boolean description: Whether resource group is synced azureResourceGroupsList: type: object properties: items: type: array items: $ref: '#/components/schemas/azureResourceGroupInfo' count: type: integer description: Total count of items azureResourceGroupResponse: type: object properties: resourcesGroup: $ref: '#/components/schemas/azureResourceGroupInfo' byAsset: type: object properties: aggregation: type: object properties: count: type: integer id: type: string name: type: string assets: type: array items: $ref: '#/components/schemas/assetSummary' connectionState: $ref: '#/components/schemas/connectionState' lastTimeSeen: type: string occurred: type: integer ports: type: array items: $ref: '#/components/schemas/portSummary' srcProcesses: type: array items: $ref: '#/components/schemas/processSummary' users: type: array items: $ref: '#/components/schemas/userSummary' byPort: type: object properties: aggregation: type: object properties: count: type: integer port: type: object properties: protocol: $ref: '#/components/schemas/protocol' port: type: integer dstAssets: type: array items: $ref: '#/components/schemas/assetSummary' connectionState: $ref: '#/components/schemas/connectionState' lastTimeSeen: type: string occurred: type: integer ports: type: array items: $ref: '#/components/schemas/portSummary' srcAssets: type: array items: $ref: '#/components/schemas/assetSummary' srcProcesses: type: array items: $ref: '#/components/schemas/processSummary' byProcess: type: object properties: occurred: type: integer lastTimeSeen: type: string aggregation: type: object properties: count: type: integer name: type: string assets: type: array items: $ref: '#/components/schemas/assetSummary' ports: type: array items: $ref: '#/components/schemas/portSummary' users: type: array items: $ref: '#/components/schemas/userSummary' processes: type: array items: $ref: '#/components/schemas/processSummary' connectionState: $ref: '#/components/schemas/connectionState' byUser: type: object properties: aggregation: type: object properties: count: type: integer id: type: string name: type: string assets: type: array items: $ref: '#/components/schemas/assetSummary' connectionState: $ref: '#/components/schemas/connectionState' lastTimeSeen: type: string occurred: type: integer ports: type: array items: $ref: '#/components/schemas/portSummary' srcProcesses: type: array items: $ref: '#/components/schemas/processSummary' users: type: array items: $ref: '#/components/schemas/userSummary' candidatesList: type: object properties: items: type: array items: anyOf: - $ref: '#/components/schemas/assetCandidate' - $ref: '#/components/schemas/groupCandidate' - $ref: '#/components/schemas/userCandidate' scrollCursor: type: string challengeBody: type: object properties: email: type: string sendSkip: type: boolean challengeResponse: type: object properties: authenticatedVia: type: string isPhoneChallengeSupported: type: boolean clusterInfo: type: object properties: clusterInfo: type: object properties: clusterName: type: string clusterMembersList: type: array items: type: string connectionState: type: integer description: | dictionary: * '1' Blocked * '2' Requested * '3' Established * '4' Blocked at source * '5' All enum: - 1 - 2 - 3 - 4 - 5 connectionStatesCounts: type: object properties: established: type: integer blocked: type: integer requested: type: integer connectivityStateAfterReboot: type: integer enum: - 1 - 2 - 3 - 4 description: | dictionary: * '1' Previous connectivity state * '2' Connected (Always-on) * '3' Disconnected * '4' Signed out connectRegion: type: object properties: connectServers: type: array items: $ref: '#/components/schemas/idNamePair' createdBy: type: string createdAt: $ref: '#/components/schemas/epochMillis' dnsServersIpAddressList: type: array items: type: string id: type: string ipAddress: type: string format: ipv4 name: type: string updatedBy: type: string updatedAt: $ref: '#/components/schemas/epochMillis' connectRegionBody: type: object properties: name: type: string ipAddress: type: string format: ipv4 dnsServersIpAddressList: type: array items: type: string format: ipv4 dnsSuffixesList: type: array items: type: string required: - name - ipAddress - dnsServersIpAddressList connectRegionsList: type: object properties: items: type: array items: $ref: '#/components/schemas/connectRegion' postureProfile: type: object properties: id: type: string name: type: string description: type: string action: type: string enum: - BLOCK - ALERT_ONLY description: 'Posture action' checkIntervalSeconds: type: integer windowsChecks: $ref: '#/components/schemas/windowsPostureChecks' macChecks: $ref: '#/components/schemas/macPostureChecks' roleIds: type: array items: $ref: '#/components/schemas/idNamePair' createdBy: $ref: '#/components/schemas/idNamePair' createdAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' updatedAt: $ref: '#/components/schemas/epochMillis' postureProfileBody: type: object properties: name: type: string description: type: string action: type: string enum: - BLOCK - ALERT_ONLY description: 'Posture action' checkIntervalSeconds: type: integer windowsChecks: $ref: '#/components/schemas/windowsPostureChecks' macChecks: $ref: '#/components/schemas/macPostureChecks' required: - name - action - checkIntervalSeconds postureProfilesList: type: object properties: items: type: array items: $ref: '#/components/schemas/postureProfile' count: type: integer postureCheckDefinitionsList: type: object properties: checks: type: array items: $ref: '#/components/schemas/postureCheckDefinition' postureCheckDefinition: type: object properties: id: type: string name: type: string singleValueOnly: type: boolean maxItems: type: integer windows: type: array items: $ref: '#/components/schemas/postureCheckFieldDefinition' mac: type: array items: $ref: '#/components/schemas/postureCheckFieldDefinition' postureCheckFieldDefinition: type: object properties: id: type: string name: type: string inputType: type: string enum: - boolean - text - dropdown required: type: boolean placeholder: type: string listLogic: type: string options: type: array items: $ref: '#/components/schemas/postureCheckDropdownOption' postureCheckDropdownOption: type: object properties: label: type: string value: type: string children: type: array items: $ref: '#/components/schemas/postureCheckDropdownOption' windowsPostureChecks: type: object properties: antivirus: type: object properties: isEnabled: type: boolean certificateExistsList: type: array items: type: object properties: subjectNameList: type: array items: type: string diskEncrypted: type: object properties: isEncrypted: type: boolean fileExistsList: type: array items: type: object properties: filePathList: type: array items: type: string processRunningList: type: array items: type: object properties: processPathList: type: array items: type: string osVersionBuild: type: object properties: osVersionsList: type: array items: type: object required: - osName - version - allowNewer properties: osName: type: string description: Windows OS marketing name enum: - Windows 10 - Windows 11 version: type: string patch: type: integer allowNewer: type: boolean domainJoinedList: type: array items: type: object properties: domainList: type: array items: type: string registryKeyValueDataExistsList: type: array items: type: object properties: entriesList: type: array items: type: object required: - keyPath properties: keyPath: type: string valueName: type: string dataList: type: array items: type: string macPostureChecks: type: object properties: antivirus: type: object properties: isEnabled: type: boolean certificateExistsList: type: array items: type: object properties: subjectNameList: type: array items: type: string diskEncrypted: type: object properties: isEncrypted: type: boolean fileExistsList: type: array items: type: object properties: filePathList: type: array items: type: string processRunningList: type: array items: type: object properties: processPathList: type: array items: type: string osVersionBuild: type: object properties: osVersionsList: type: array items: type: object required: - osName - version - allowNewer properties: osName: type: string description: macOS marketing name enum: - Tahoe - Sequoia - Sonoma - Ventura - Monterey - Big Sur - Catalina - Mojave - High Sierra - Sierra version: type: string allowNewer: type: boolean domainJoinedList: type: array items: type: object properties: domainList: type: array items: type: string connectServer: type: object properties: assemblyVersion: type: string clientsDnsServerIPs: type: array items: type: string connectionState: type: integer externalIPAddress: type: string format: ipv4 fqdn: type: string id: type: string installedAt: $ref: '#/components/schemas/epochMillis' internalIPAddress: type: string format: ipv4 name: type: string port: type: integer region: $ref: '#/components/schemas/idNamePair' subnet: $ref: '#/components/schemas/idNamePair' connectServerBody: type: object properties: publicPort: type: string required: - publicPort connectServersList: type: object properties: items: type: array items: $ref: '#/components/schemas/connectServer' connectUserAccessConfig: type: object properties: allowedAssetIds: type: array items: $ref: '#/components/schemas/idNamePair' allowedAssetSources: type: array items: $ref: '#/components/schemas/idNamePair' allowedDestinations: type: array items: type: object properties: guid: type: string id: type: string name: type: string domain: type: string hasProtectionPolicy: type: boolean allowedRegions: type: array items: $ref: '#/components/schemas/idNamePair' allowedUserIds: type: array items: $ref: '#/components/schemas/userSimple' connectivityStateAfterReboot: type: integer createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/userSimple' description: type: string excludedAssetIds: type: array items: $ref: '#/components/schemas/idNamePair' excludedUserIds: type: array items: $ref: '#/components/schemas/userSimple' forceSsoAuthentication: type: boolean id: type: string name: type: string sessionTtlHours: type: integer updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/userSimple' connectUserAccessConfigBody: type: object required: - allowedRegions - connectivityStateAfterReboot - dstEntityIdsList - forceSsoAuthentication - loginAuthorizedEntities - name - sessionTtlHours properties: allowedRegions: type: array items: type: string connectivityStateAfterReboot: $ref: '#/components/schemas/connectivityStateAfterReboot' description: type: string dstEntityIdsList: type: array items: type: string loginAuthorizedEntities: type: object required: - allowedAssetIdsList - allowedAssetsSourcesList - allowedUsersIdsList properties: allowedAssetIdsList: type: array items: type: string allowedAssetsSourcesList: type: array items: type: string allowedUsersIdsList: type: array items: type: string excludedAssetIdsList: type: array items: type: string excludedUserIdsList: type: array items: type: string forceSsoAuthentication: type: boolean name: type: string sessionTtlHours: type: integer connectUserAccessConfigList: type: object properties: items: type: array items: $ref: '#/components/schemas/connectUserAccessConfig' createdBy: type: object properties: createdBy: $ref: '#/components/schemas/idNamePair' email: type: string enforcementSource: $ref: '#/components/schemas/enforcementSource' userRole: $ref: '#/components/schemas/userRole' createOtAssetResponse: type: object properties: assetId: type: string customGroup: type: object properties: createdAt: $ref: '#/components/schemas/epochMillis' description: type: string directMembersCount: type: integer domain: type: string guid: type: string format: uuid hasProtectionPolicy: type: boolean id: type: string name: type: string principalName: type: string role: type: integer sid: type: string updatedAt: $ref: '#/components/schemas/epochMillis' addedAt: $ref: '#/components/schemas/epochMillis' addedBy: type: object properties: id: type: string name: type: string example: User Name x-speakeasy-entity: CustomGroup customGroupBody: type: object required: - name properties: name: type: string description: type: string membersId: description: members id type: array items: type: string pattern: '^g:[c]:[a-zA-Z0-9]{8}$' example: - 'g:c:ab124as2' conditions: $ref: '#/components/schemas/groupConditions' minProperties: 1 example: osNamePatterns: - "Windows.*" assetTypes: - 1 - 2 x-speakeasy-entity: CustomGroup customGroupMembersBody: type: object properties: membersId: description: members id type: array items: type: string pattern: '^g:[c]:[a-zA-Z0-9]{8}$' example: - 'g:c:ab124as2' required: - membersId x-speakeasy-entity: CustomGroupMembers customGroupResponse: type: object properties: entity: $ref: '#/components/schemas/customGroup' customUser: type: object properties: activeEnvironmentId: type: string format: uuid activeSince: type: string email: type: string fullName: type: string id: type: string format: uuid invitedAt: type: string invitedBy: type: string inviteExpiry: type: string inviter: $ref: '#/components/schemas/userSimple' jobTitle: type: string phone: type: string portalUserType: type: string role: $ref: '#/components/schemas/userRole' status: type: string customUsersList: type: object properties: items: type: array items: $ref: '#/components/schemas/customUser' deployment: type: object properties: assemblyVersion: type: string assetId: type: string clusterId: type: string defaultGateway: type: string environmentId: type: string externalIpAddress: type: string id: type: string internalIpAddress: type: string isPreferred: type: boolean name: type: string numOfAssets: type: integer state: type: integer status: type: integer subnetMask: type: string deploymentsClusterSource: description: | * '1' - System * '2' - User * '3' - Domain * '4' - Subnet * '5' - None * '6' - N/A type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 - 6 deploymentsList: type: object properties: items: type: array items: $ref: '#/components/schemas/deployment' deploymentsClusters: type: object properties: id: type: string name: type: string isDefault: type: boolean strategy: type: integer assignedDeployments: type: array items: $ref: '#/components/schemas/deployment' preferredDeployment: $ref: '#/components/schemas/idNamePair' numOfAssets: type: integer deploymentsClustersList: type: object properties: items: type: array items: $ref: '#/components/schemas/deploymentsClusters' distribution: type: object properties: timestamp: $ref: '#/components/schemas/epochMillis' activitiesCount: type: integer downloadUrl: type: object properties: url: type: string emptyResponse: type: object moveCluster: type: object properties: deploymentId: type: string deploymentsClusterId: type: string createCluster: type: object properties: clusterName: type: string strategy: type: integer editCluster: type: object properties: clusterName: type: string preferredDeploymentId: type: string strategy: type: integer encodedEntity: type: object properties: id: type: string enforcementSource: description: | * '1' - ReactivePolicy * '2' - Automated * '3' - AccessPortal * '4' - AdminPortal * '5' - AI * '6' - API * '7' - Setup * '8' - Connect * '9' - System * '10' - DownloadPortal * '11' - ExternalAccessPortal * '12' - DayTwo type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 entityInactiveReason: description: | * '1' - Repository Duplicated * '2' - Manual * '3' - None * '4' - Repository Disabled * '5' - Repository Inactive * '6' - Repository Deleted type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 - 6 entitiesList: type: object properties: items: type: array items: $ref: '#/components/schemas/entity' count: type: integer nextCursor: type: string nextOffset: type: integer entity: type: object anyOf: - $ref: '#/components/schemas/asset' - $ref: '#/components/schemas/user' - $ref: '#/components/schemas/group' envConfig: type: object properties: licenses: type: object properties: connect: $ref: '#/components/schemas/envConfigLicense' identity: $ref: '#/components/schemas/envConfigLicense' network: $ref: '#/components/schemas/envConfigLicense' rpc: $ref: '#/components/schemas/envConfigLicense' periodicallyCheckDeployments: type: boolean example: true envConfigLicense: type: object properties: activitiesRetentionDays: type: integer clientsLimit: type: integer endTime: $ref: '#/components/schemas/epochMillis' licenseMode: type: integer enum: - 1 - 2 - 3 - 4 - 5 limit: type: integer otsLimit: type: integer serversLimit: type: integer startTime: $ref: '#/components/schemas/epochMillis' epochMillis: description: Epoch Millis type: integer format: int64 title: epochMillis error: type: object properties: error: type: string message: type: string exportBody: type: object properties: from: type: integer to: type: integer _search: type: string _filters: type: string localDateTimeFormat: type: string default: en-US switchInterfaceBody: type: object properties: interfaces: type: array items: type: string shouldMonitor: type: boolean required: - interfaces - shouldMonitor exportBodyActivities: type: object properties: from: type: integer to: type: integer _search: type: string _filters: type: string localDateTimeFormat: type: string default: en-US required: - localDateTimeFormat - _filters - _search exportBodyAnalysis: type: object properties: from: type: integer to: type: integer _filters: type: string default: '{"groupBy":"byPort","direction":"incoming","connection":3}' localDateTimeFormat: type: string default: en-US required: - localDateTimeFormat - _filters - from exportBodyAssets: type: object properties: _filters: type: string default: '{"groupBy":"byPort","direction":"incoming","connection":3}' localDateTimeFormat: type: string default: en-US required: - localDateTimeFormat - _filters exportBodyRules: type: object properties: addAncestors: type: boolean default: true addBuiltins: type: boolean default: false assetDirection: $ref: '#/components/schemas/ruleDirection' _filters: type: string localDateTimeFormat: type: string default: en-US required: - addAncestors - addBuiltins - localDateTimeFormat - _filters exportId: type: object properties: exportId: type: string exposureMeterStatistics: type: object properties: items: type: array $ref: '#/components/schemas/exposureMeterStatisticsItem' exposureMeterStatisticsItem: type: object properties: date: $ref: '#/components/schemas/epochMillis' monitoredAssets: $ref: '#/components/schemas/exposureMeterStatisticsItemCounts' segmentedAssets: $ref: '#/components/schemas/exposureMeterStatisticsItemCounts' segmentationCoverage: $ref: '#/components/schemas/exposureMeterStatisticsItemCounts' lateralMovementRisk: $ref: '#/components/schemas/exposureMeterStatisticsItemCounts' exposureMeterStatisticsItemCounts: type: object properties: total: type: integer clients: type: integer servers: type: integer externalAccessPolicy: type: object properties: changeTicket: type: string createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/createdBy' description: type: string dstAssetId: type: string dstAssetInfo: $ref: '#/components/schemas/asset' dstPortsList: $ref: '#/components/schemas/portsList' dstProcessNamesList: type: array items: type: string id: type: string name: type: string ruleDuration: $ref: '#/components/schemas/ruleDuration' srcUserInfos: type: array items: $ref: '#/components/schemas/idNamePair' srcUserIdsList: type: array items: type: string state: $ref: '#/components/schemas/ruleState' updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' url: type: string externalAccessPolicyBody: type: object properties: changeTicket: type: string description: type: string dstAssetId: type: string dstPortsList: $ref: '#/components/schemas/portsList' dstProcessNamesList: type: array items: type: string name: type: string ruleDuration: $ref: '#/components/schemas/ruleDuration' srcUserIdsList: type: array items: type: string state: $ref: '#/components/schemas/ruleState' url: type: string required: - dstAssetId - dstPortsList - dstProcessNamesList - name - ruleDuration - srcUserIdsList externalAccessPolicyItem: type: object properties: item: $ref: '#/components/schemas/externalAccessPolicy' externalAccessPolicyList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/externalAccessPolicy' externalAccessPolicyStatistics: type: object properties: policiesStatistics: type: object properties: totalCount: type: integer externalIpsList: description: Collection of Internet IPs that are trusted type: array items: type: string example: 192.168.0.0 filter: type: object properties: aliases: type: array items: type: string allowedCharactersRegex: type: string apiCall: type: object properties: apiPath: type: string searchParamName: type: string disableExcludeSupport: type: boolean displayFormatter: type: integer enableBulkSelection: type: boolean id: type: string isSingleValue: type: boolean name: type: string placeholder: type: string type: type: integer selections: type: array items: $ref: '#/components/schemas/idNamePair' filtersList: type: object properties: defaultSelectedFilterId: type: string filters: type: array items: $ref: '#/components/schemas/filter' hasActiveFiltersChanged: type: boolean resolvedFilters: type: object userFilter: type: object properties: resolvedFilters: type: object group: type: object properties: id: type: string name: type: string domain: type: string guid: type: string format: uuid hasNetworkProtectionPolicy: type: boolean hasIdentityProtectionPolicy: type: boolean sid: type: string addedAt: $ref: '#/components/schemas/epochMillis' addedBy: $ref: '#/components/schemas/idNamePair' createdAt: $ref: '#/components/schemas/epochMillis' conditions: $ref: '#/components/schemas/groupConditions' description: type: string directMembersCount: type: integer externalId: type: string principalName: type: string role: $ref: '#/components/schemas/userRole' source: $ref: '#/components/schemas/source' type: type: string updatedAt: $ref: '#/components/schemas/epochMillis' groupBasicInfo: type: object properties: id: type: string name: type: string domain: type: string guid: type: string format: uuid hasNetworkProtectionPolicy: type: boolean hasIdentityProtectionPolicy: type: boolean sid: type: string groupAnalysis: type: object properties: items: type: object properties: byLocalAsset: type: array items: $ref: '#/components/schemas/byAsset' byPort: type: array items: $ref: '#/components/schemas/byPort' byRemoteAsset: type: array items: $ref: '#/components/schemas/byAsset' bySrcProcess: type: array items: $ref: '#/components/schemas/byProcess' byUser: type: array items: $ref: '#/components/schemas/byUser' counts: type: object properties: byLocalAsset: type: integer byPort: type: integer byRemoteAsset: type: integer bySrcProcess: type: integer byUser: type: integer groupCandidate: type: object properties: domain: type: string guid: type: string hasIdentityProtectionPolicy: type: boolean hasNetworkProtectionPolicy: type: boolean id: type: string name: type: string sid: type: string groupCandidatesList: type: object properties: items: type: array items: $ref: '#/components/schemas/groupCandidate' scrollCursor: type: string groupConditions: type: object properties: domains: type: array items: type: string namePatterns: type: array items: type: string osNamePatterns: type: array items: type: string osTypes: type: array items: $ref: '#/components/schemas/osType' assetTypes: type: array items: $ref: '#/components/schemas/assetType' ipBuiltins: type: array items: type: string groupIdOrAssetId: type: string pattern: '^[ag]:[acdjlngt]:[a-zA-Z0-9]{8}$' groupIdOrUserId: type: string pattern: '^[gu]:[ac]:[a-zA-Z0-9]{8}$' groupResponse: type: object properties: entity: $ref: '#/components/schemas/group' groupItem: type: object properties: items: $ref: '#/components/schemas/group' groupMembersList: type: object properties: membersId: type: array items: type: string x-speakeasy-entity: CustomGroupMembers groupSimulateSegmentationEntity: type: object properties: count: type: integer id: type: string name: type: string groupSimulateSegmentationItem: type: object properties: coveredEntities: type: array items: $ref: '#/components/schemas/groupSimulateSegmentationEntity' lastTimeSeen: $ref: '#/components/schemas/iso8601DateTimeUTC' localProcessesList: type: array items: type: string memberAssets: type: array items: $ref: '#/components/schemas/idNamePair' occurred: type: integer port: type: integer protocolType: $ref: '#/components/schemas/protocol' uncoveredEntities: type: array items: $ref: '#/components/schemas/groupSimulateSegmentationEntity' groupSimulateSegmentationReport: type: object properties: from: type: string items: type: array items: $ref: '#/components/schemas/groupSimulateSegmentationItem' ruleStates: type: array items: $ref: '#/components/schemas/ruleState' to: type: string trafficType: $ref: '#/components/schemas/trafficType' groupSimulateSegmentationReportBody: type: object properties: from: $ref: '#/components/schemas/epochMillis' ruleStates: type: array items: $ref: '#/components/schemas/ruleState' to: $ref: '#/components/schemas/epochMillis' trafficType: $ref: '#/components/schemas/trafficType' groupSimulateSegmentationReportRecord: type: array items: $ref: '#/components/schemas/groupSimulateSegmentationItem' groupSimulateSegmentationState: type: object properties: generationState: type: string hasReport: type: boolean groupsList: type: object properties: items: type: array items: $ref: '#/components/schemas/group' count: type: integer groupsOrUsersList: type: object properties: items: type: array items: anyOf: - $ref: '#/components/schemas/groupBasicInfo' - $ref: '#/components/schemas/idNamePair' - $ref: '#/components/schemas/userBasicInfo' cursor: type: string groupsStatistics: type: object properties: groupStatistics: type: object properties: adGroupsCount: type: integer customGroupsCount: type: integer protectionPoliciesCount: type: integer x-examples: example-1: groupStatistics: adGroupsCount: 106 customGroupsCount: 1 protectionPoliciesCount: 2 settingsFreezePeriod: type: object properties: createdById: type: string format: uuid description: type: string endTime: $ref: '#/components/schemas/epochMillis' freezeWindowId: type: string format: uuid freezeState: $ref: '#/components/schemas/freezePeriodState' startTime: $ref: '#/components/schemas/epochMillis' updatedById: type: string format: uuid settingsFreezePeriodBody: type: object properties: startTime: $ref: '#/components/schemas/epochMillis' endTime: $ref: '#/components/schemas/epochMillis' description: type: string required: - startTime - endTime settingsFreezePeriodList: type: object properties: items: type: array items: $ref: '#/components/schemas/settingsFreezePeriod' settingsFreezePeriodResponse: type: object properties: freezeWindowId: type: string format: uuid healthIssue: type: object properties: issueCode: description: | * '0' - Unspecified * '1' - Unknown * '2' - Access Denied * '3' - IO Device Issue * '4' - DotNet 3.5 * '5' - WMI Corrupted * '6' - URL Filtering * '7' - Out of Space * '8' - Unsupported HMAC * '9' - Unsupported Encryption * '10' - Setup Script Failed * '11' - Slow MFA * '12' - Unexpted GPO Rules * '13' - Zero Networks GPO Rule Mismatch * '14' - Audit Mismatch * '15' - Asset ID Mismatch * '16' - Unsupported HTTP Version * '17' - Registry Marked for Deletion * '18' - Unable to add to automation group * '19' - Incorrect Username or Password * '20' - RPC Open Source Installed * '21' - Timeout during initialization * '22' - Data collection timeout * '23' - Not in Sudoers * '24' - Invalid SSH Key * '25' - Events Unavailable * '26' - SSH Password Incorrect * '27' - SSH Password Expired * '28' - Segmneted Users not found * '29' - Unsupported Python Versions * '30' - Cound not query segmented users * '31' - Switch unreachable * '32' - Switch communication issue * '33' - Interface protection resource exceeded * '34' - Unsupported Package Manager * '35' - Firewall disabled by GPO * '36' - Linux firewall logs oversized * '1000' - First blocker issue code * '1001' - Cluster node ipv6 disabled * '1002' - Local rules merge disallowed type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 - 31 - 32 - 33 - 34 - 35 - 36 - 1000 - 1001 - 1002 details: type: string healthStateObject: type: object properties: healthState: $ref: '#/components/schemas/healthState' healthState: type: object properties: healthStatus: description: | * '0' - Unspecified * '1' - Healthy * '2' - Error * '3' - Warning * '4' - N/A * '5' - Retrying * '6' - Blocker type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 healthIssuesList: type: array items: $ref: '#/components/schemas/healthIssue' historyRule: type: object properties: id: type: string portsList: $ref: '#/components/schemas/portsList' expiresAt: $ref: '#/components/schemas/epochMillis' createdAt: $ref: '#/components/schemas/epochMillis' description: type: string remoteEntityInfos: type: array items: $ref: '#/components/schemas/idNamePair' localEntityInfo: $ref: '#/components/schemas/idNamePair' localProcessesList: type: array items: type: string servicesList: type: array items: type: string createdBy: type: object properties: createdBy: $ref: '#/components/schemas/idNamePair' enforcementSource: $ref: '#/components/schemas/enforcementSource' identityAnalysis: type: object properties: aggregation: type: object properties: count: type: integer name: type: string authenticationPackages: type: array items: $ref: '#/components/schemas/authenticationPackageSummary' dstAssets: type: array items: $ref: '#/components/schemas/assetSummary' eventType: type: integer lastTimeSeen: type: string logonTypes: type: array items: $ref: '#/components/schemas/logonTypeSummary' occurred: type: integer srcAssets: type: array items: $ref: '#/components/schemas/assetSummary' identityPostureViolation: type: object properties: affectedIdentitiesCount: type: integer category: description: | * '1' - Authentication * '2' - Operational * '3' - Privilege * '4' - Life Cycle type: integer enum: - 1 - 2 - 3 - 4 description: type: string id: type: string format: uuid ignoredAffectedIdentitiesCount: type: integer mitreTactics: type: array items: type: string mitreTechniques: type: array items: type: string postureCheckType: $ref: "#/components/schemas/identityPostureCheckType" remediation: type: string severity: description: | * '1' - CRITICAL * '2' - HIGH * '3' - MEDIUM * '4' - LOW type: integer enum: - 1 - 2 - 3 - 4 totalCheckedUsers: type: integer identityPostureViolationsList: type: object properties: items: type: array items: $ref: '#/components/schemas/identityPostureViolation' count: type: integer identityPostureCheckType: description: | * '1' - Password Not Needed * '2' - Use DES key only * '3' - Dont Require PreAuth * '4' - Password Never Expire * '5' - Unconstrained Delegation Enabled * '6' - Default Admin Account Enabled type: integer enum: - 1 - 2 - 3 - 4 - 5 - 6 identityProtectionState: description: | Possible asset status: * '0' - Unspecified * '1' - Unsegmented * '2' - Unspecified * '3' - Segmented * '4' - Unsegmented * '5' - In learning * '6' - Forced Unprotected * '7' - Forced Removing Protection * '8' - Protected Due To Policy * '9' - Applying Protection Due To Policy * '10' - In learning Due To Policy * '11' - Learning Done * '12' - In learning Due To Policy Done type: integer enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 identityReactivePolicy: type: object properties: createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/createdBy' changeTicket: type: string description: type: string dstAssetId: type: string dstEntityInfo: $ref: '#/components/schemas/idNamePair' excludedDstAssetIdsList: type: array items: type: string excludedSrcAssetIdsList: type: array items: type: string excludedSrcAssetInfos: type: array items: $ref: '#/components/schemas/asset' extraIdentityProtectionCategoryList: type: array items: $ref: '#/components/schemas/identityProtectionCategory' fallbackToSingleLoggedOnUser: type: boolean id: type: string example: 00000000-0000-0000-0000-000000000000 identityProtectionCategoryList: type: array items: $ref: '#/components/schemas/identityProtectionCategory' name: type: string mfaMethodsList: type: array items: $ref: '#/components/schemas/mfaMethods' overrideBuiltins: type: boolean restrictLoginToOriginatingUser: type: boolean ruleDuration: $ref: '#/components/schemas/ruleDuration' srcAssetIdsList: type: array items: type: string srcAssetInfos: type: array items: $ref: '#/components/schemas/idNamePair' srcUserIdsList: type: array items: type: string srcUserInfos: type: array items: $ref: '#/components/schemas/idNamePair' state: $ref: '#/components/schemas/reactivePolicyState' updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' useDefaultIdp: type: boolean useOccasionalMfa: type: boolean identityReactivePolicyBody: type: object properties: changeTicket: type: string description: type: string dstAssetId: type: string excludedDstAssetIdsList: type: array items: type: string excludedSrcAssetIdsList: type: array items: type: string extraIdentityProtectionCategoryList: type: array items: $ref: '#/components/schemas/identityProtectionCategory' fallbackToSingleLoggedOnUser: type: boolean identityProtectionCategoryList: type: array items: $ref: '#/components/schemas/identityProtectionCategory' name: type: string mfaMethodsList: type: array items: $ref: '#/components/schemas/mfaMethods' overrideBuiltins: type: boolean restrictLoginToOriginatingUser: type: boolean ruleDuration: $ref: '#/components/schemas/ruleDuration' srcAssetIdsList: type: array items: type: string srcUserIdsList: type: array items: type: string state: $ref: '#/components/schemas/reactivePolicyState' useDefaultIdp: type: boolean useOccasionalMfa: type: boolean required: - dstAssetId - fallbackToSingleLoggedOnUser - identityProtectionCategoryList - mfaMethodsList - overrideBuiltins - ruleDuration - srcAssetIdsList - srcUserIdsList - state identityReactivePolicyItem: type: object properties: item: $ref: '#/components/schemas/identityReactivePolicy' identityReactivePolicyList: type: object properties: items: type: array items: $ref: '#/components/schemas/identityReactivePolicy' count: type: integer identityReactivePolicyResponse: type: object properties: items: $ref: '#/components/schemas/identityReactivePolicy' identityRule: type: object properties: action: $ref: '#/components/schemas/ruleAction' assetId: type: string changeTicket: type: string createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/createdBy' description: type: string excludedAssetIdsList: type: array items: type: string excludedAssetInfos: type: array items: $ref: '#/components/schemas/idNamePair' expiresAt: $ref: '#/components/schemas/epochMillis' id: type: string identityProtectionCategoryList: type: array items: $ref: '#/components/schemas/identityProtectionCategory' parentId: type: string parentType: type: integer format: int32 ruleclass: $ref: '#/components/schemas/ruleClass' state: type: integer format: int32 updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' userIdsList: type: array items: type: string userInfos: type: array items: $ref: '#/components/schemas/idNamePair' identityRuleBody: type: object required: - action - assetId - identityProtectionCategoryList - state - userIdsList properties: action: $ref: '#/components/schemas/ruleAction' assetId: type: string changeTicket: type: string description: type: string excludedAssetIdsList: type: array items: type: string expiresAt: type: integer format: int64 identityProtectionCategoryList: type: array items: $ref: '#/components/schemas/identityProtectionCategory' name: type: string state: $ref: '#/components/schemas/ruleState' userIdsList: type: array items: type: string identityRuleItem: type: object properties: item: $ref: '#/components/schemas/identityRule' identityRulesList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/identityRule' idNamePair: type: object properties: id: description: EntityId type: string name: description: Entity Name type: string idNamePairList: type: object properties: items: type: array items: $ref: '#/components/schemas/idNamePair' inactiveAssetsConfig: type: object required: - lastActiveDurationInMonths properties: lastActiveDurationInMonths: type: integer format: int32 enum: - 0 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 - 31 - 32 - 33 - 34 - 35 - 36 inactiveAssetsConfigBody: type: object properties: lastActiveDurationInMonths: type: integer format: int32 enum: - 0 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 - 31 - 32 - 33 - 34 - 35 - 36 inactiveReason: description: | * '1' - Duplicated in asset repository * '2' - Manually set as inactive * '3' - None * '4' - Disabled in asset repository * '5' - Inactive in asset repository * '6' - Deleted in asset repository type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 - 6 interfaceUuidsList: type: array items: type: string format: uuid or string description: "one of the following: \n* \"rpcAnyInterface\" for any interface \n* List of interface uuids for explicit interfaces\n" internalAccessPolicy: type: object properties: changeTicket: type: string createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/createdBy' description: type: string dstAssetId: type: string dstAssetInfo: $ref: '#/components/schemas/asset' dstPortsList: $ref: '#/components/schemas/portsList' dstProcessNamesList: type: array items: type: string id: type: string name: type: string ruleDuration: $ref: '#/components/schemas/ruleDuration' srcUserInfos: type: array items: $ref: '#/components/schemas/idNamePair' srcUserIdsList: type: array items: type: string state: $ref: '#/components/schemas/ruleState' updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' x-speakeasy-entity: InternalAccessPolicy internalAccessPolicyBody: type: object properties: changeTicket: type: string description: type: string dstAssetId: type: string dstPortsList: $ref: '#/components/schemas/portsList' dstProcessNamesList: type: array items: type: string name: type: string ruleDuration: $ref: '#/components/schemas/ruleDuration' srcUserIdsList: type: array items: type: string state: $ref: '#/components/schemas/ruleState' required: - dstAssetId - dstPortsList - dstProcessNamesList - name - ruleDuration - srcUserIdsList x-speakeasy-entity: InternalAccessPolicy internalAccessPolicyItem: type: object properties: item: $ref: '#/components/schemas/internalAccessPolicy' internalAccessPolicyList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/internalAccessPolicy' ipSecOpt: description: | * For allow rule only. * '1' - Off * '2' - Null encapsulation connections * '3' - Authenticated and integrity-protected connections * '4' - Encrypted connections and dynamically negotiate encryption (inbound rule only) * '5' - Encrypted connections type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 ipSubnet: type: string example: 192.168.1.0/24 pattern: '[0-9]{1,3}[.][0-9]{1,3}[.][0-9]{1,3}[.][0-9]{1,3}/[0-9]{1,3}' iso8601DateTimeUTC: description: ISO 8601 Date Time in UTC type: string example: 'YYYY-HH-DDTHH:MM:SSSZ' k8s: type: object properties: agentExternalIp: type: string agentVersion: type: string clusterType: type: integer cniType: type: integer cniVersion: type: string connectedSince: $ref: '#/components/schemas/epochMillis' connectionState: type: integer createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/idNamePair' generation: type: integer format: int64 id: type: string k8sClusterVersion: type: string k8sUid: type: string format: uuid lastConnected: $ref: '#/components/schemas/epochMillis' lastDisconnected: $ref: '#/components/schemas/epochMillis' name: type: string updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' k8sApplication: type: object properties: cluster: $ref: '#/components/schemas/idNamePair' name: type: string namespaces: type: array items: $ref: '#/components/schemas/idNamePair' workloads: type: array items: $ref: '#/components/schemas/idNamePair' k8sApplicationEntity: type: object properties: entity: $ref: '#/components/schemas/k8sApplication' k8sApplicationsList: type: object properties: items: type: array items: $ref: '#/components/schemas/k8sApplication' count: type: integer k8sBody: type: object properties: name: type: string required: - name k8sCommands: type: object properties: dockerLoginCommand: type: string installationCommand: type: string loginCommand: type: string pullActivityCollectorImageCommand: type: string pullHelmChartCommand: type: string pullImageCommand: type: string uninstallationCommand: type: string k8sEgressIp: type: object properties: affectedEntities: type: array items: $ref: '#/components/schemas/k8sEntityInfo' clusterId: type: string id: type: string ips: type: array items: type: string k8sUid: type: string name: type: string rawSelector: type: string k8sEgressIpList: type: object properties: items: type: array items: $ref: '#/components/schemas/k8sEgressIp' count: type: integer k8sEntity: type: object properties: entity: $ref: '#/components/schemas/k8s' k8sEntityInfo: type: object properties: application: type: string hostNamespace: $ref: '#/components/schemas/idNamePair' type: type: integer k8sEntityType: description: "* 0 - Other\n* 1 - Cluster\n* 2 - Namespace\n* 3 - Node\n* 4 - Pod\n* 5 - Deployment\n* 6 - Daemonset\n* 7 - Statefulset\n* 8 - Job\n* 9 - Service\n* 10 - Network Policy\n* 11 - Ingress\n* 12 - Gateway\n* 13 - HTTP Route\n* 14 - gRPC Route\n* 15 - Replica Set\n* 16 - Replication Controller \n" type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 k8sItem: type: object properties: item: $ref: '#/components/schemas/k8s' k8sLabel: type: object properties: cluster: $ref: '#/components/schemas/idNamePair' key: type: string namespaces: type: array items: $ref: '#/components/schemas/idNamePair' nodes: type: array items: $ref: '#/components/schemas/idNamePair' value: type: string workloads: type: array items: $ref: '#/components/schemas/idNamePair' k8sLabelEntity: type: object properties: entity: $ref: '#/components/schemas/k8sLabel' k8sLabelsList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/k8sLabel' k8sList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/k8s' k8sNamespace: type: object properties: applicationsList: type: array items: $ref: '#/components/schemas/idNamePair' cluster: $ref: '#/components/schemas/idNamePair' id: type: string k8sUid: type: string format: uuid labelsList: type: array items: $ref: '#/components/schemas/idNamePair' name: type: string workloadsList: type: array items: $ref: '#/components/schemas/idNamePair' k8sNamespaceEntity: type: object properties: entity: $ref: '#/components/schemas/k8sNamespace' k8sNamespacesList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/k8sNamespace' k8sNetworkPolicy: type: object properties: clusterId: type: string egressRules: type: string id: type: string ingressRules: type: string isEgressPolicy: type: boolean isIngressPolicy: type: boolean k8sUid: type: string format: uuid name: type: string namespace: $ref: '#/components/schemas/idNamePair' selectorString: type: string k8sNetworkAnalysis: type: object properties: items: type: object properties: byPort: type: array items: $ref: '#/components/schemas/networkAnalysis' byRemoteAsset: type: array items: $ref: '#/components/schemas/networkAnalysis' counts: type: object properties: byPort: type: integer byRemoteAsset: type: integer k8sNetworkPolicyList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/k8sNetworkPolicy' k8sNode: type: object properties: id: type: string k8sUid: type: string format: uuid labelsList: type: array items: $ref: '#/components/schemas/idNamePair' name: type: string k8sNodesList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/k8sNode' k8sRule: type: object properties: action: $ref: "#/components/schemas/ruleAction" clusterId: type: string direction: $ref: "#/components/schemas/k8sRuleDirection" environmentId: type: string excludedCidrsList: type: array items: type: string localEntity: $ref: '#/components/schemas/k8sTranslatedEntity' localSelectors: type: string namespace: $ref: '#/components/schemas/idNamePair' networkPolicyName: type: string networkPolicyUid: type: string portsList: $ref: '#/components/schemas/portsList' remoteEntities: type: array items: $ref: '#/components/schemas/k8sTranslatedEntity' remoteSelectors: type: string k8sRuleDirection: description: | * '1' - Ingress * '2' - Egress enum: - 1 - 2 format: int32 type: integer k8sRulesList: type: object properties: items: type: array items: $ref: '#/components/schemas/k8sRule' scrollCursor: type: string k8sTranslatedEntity: type: object properties: hostNamespace: $ref: '#/components/schemas/idNamePair' application: type: string labelsMap: type: array items: $ref: '#/components/schemas/keyValuePair' subnet: type: string type: $ref: '#/components/schemas/k8sTranslatedEntityType' k8sTranslatedEntityType: description: | * 1 - Unsupported * 2 - Namespace * 3 - App * 4 - Label * 5 - App in Namespace * 6 - Label in Namespace * 7 - Namespace with constraints * 8 - Labels * 9 - Subnet * 10 - Any type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 k8sWorkload: type: object properties: annotationsList: type: array items: $ref: '#/components/schemas/idNamePair' applicationsList: type: array items: $ref: '#/components/schemas/idNamePair' cluster: $ref: '#/components/schemas/idNamePair' id: type: string k8sUid: type: string format: uuid labelsList: items: type: array items: $ref: '#/components/schemas/keyValuePair' name: type: string namespace: $ref: '#/components/schemas/idNamePair' podsCount: type: integer type: $ref: '#/components/schemas/k8sEntityType' k8sWorkloadEntity: type: object properties: entity: $ref: '#/components/schemas/k8sWorkload' k8sWorkloadsList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/k8sWorkload' labelsKeyCandidatesList: type: object properties: items: type: array items: $ref: '#/components/schemas/idNamePair' labelsValueCandidatesList: type: object properties: items: type: array items: $ref: '#/components/schemas/idNamePair' keyValuePair: type: object properties: key: type: string value: type: string label: type: object properties: entityCount: type: integer key: type: string source: type: integer value: type: string labelsBody: type: object properties: lables: type: array $ref: '#/components/schemas/keyValuePair' removeLabelsBody: type: object properties: lables: type: array $ref: '#/components/schemas/keyValuePair' source: type: integer description: 'Label source to remove (1 = Manual). Defaults to Manual if omitted.' labelsList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/label' labelsResponse: type: object properties: affectedEntities: type: integer licensedUserInfo: type: object properties: email: type: string expiresAt: $ref: '#/components/schemas/epochMillis' id: type: string lastConnected: $ref: '#/components/schemas/epochMillis' name: type: string licensesConfig: type: object properties: licenseState: type: object properties: configInfo: type: object properties: activitiesRetentionDays: type: integer enableActivitySync: type: boolean clientsLimit: type: integer endTime: $ref: '#/components/schemas/epochMillis' k8sLicenseMode: description: '1-On, 2-Off, 3-Trial, 4-Trial_NoLimits, 5-On_WithLimits' type: integer enum: - 1 - 2 - 3 - 4 - 5 licenseMode: description: '1-On, 2-Off, 3-Trial, 4-Trial_NoLimits, 5-On_WithLimits' type: integer enum: - 1 - 2 - 3 - 4 - 5 limit: type: integer nodesLimit: type: integer otsLimit: type: integer serversLimit: type: integer selfTrialAvailable: type: boolean startTime: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' updatedAt: $ref: '#/components/schemas/epochMillis' inUse: type: integer counts: type: object properties: nodesCount: type: integer totalClientUsed: type: integer totalOtsUsed: type: integer totalServerUsed: type: integer licenseConfigBody: type: object properties: licenseConfig: type: object properties: activitiesRetentionDays: type: integer clientsLimit: type: integer endTime: $ref: '#/components/schemas/epochMillis' licenseMode: type: integer otsLimit: type: integer selfTrialAvailable: type: boolean default: false serversLimit: type: integer startTime: $ref: '#/components/schemas/epochMillis' licensesInUse: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/licensedUserInfo' linuxBody: type: object properties: displayName: type: string example: linuxserver fqdn: type: string example: linuxserver.domain.local required: - displayName - fqdn linuxResponse: type: object properties: items: type: array items: type: string linuxScriptAvailable: type: object properties: userScriptAvailable: type: boolean listeningAddress: type: object properties: ipAddress: type: string tcpPorts: type: string udpPorts: type: string listeningPort: type: object properties: processName: type: string processId: type: integer username: type: string listeningAddressList: type: array items: $ref: '#/components/schemas/listeningAddress' listeningPortsList: type: object properties: items: type: array items: $ref: '#/components/schemas/listeningPort' loginBody: type: object properties: email: type: string otp: type: string loginResponse: type: object properties: user: $ref: '#/components/schemas/user' token: type: string logonActivitiesList: type: object properties: items: type: array items: $ref: '#/components/schemas/logonActivity' scrollCursor: type: string logonActivity: type: object properties: authenticationPackageName: type: string dst: type: object properties: assetId: type: string assetSrc: type: integer assetType: $ref: '#/components/schemas/assetType' fqdn: type: string identityProtectionState: type: integer networkProtectionState: type: integer src: type: object nullable: true properties: assetId: type: string assetProtectionState: type: integer assetSrc: type: integer assetType: $ref: '#/components/schemas/assetType' fqdn: type: string identityProtectionState: type: integer ip: type: string networkProtectionState: type: integer port: type: integer eventType: type: integer impersonationLevel: type: integer logonProvider: type: string logonType: type: integer processId: type: string processName: type: string recordId: type: integer format: int64 subjectUser: $ref: '#/components/schemas/userConnectionEnrichment' targetUser: $ref: '#/components/schemas/userConnectionEnrichment' timestamp: $ref: '#/components/schemas/epochMillis' logonTypeSummary: type: object properties: count: type: integer logonType: type: integer maintenanceWindow: type: object properties: createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/idNamePair' id: type: string isDefault: type: boolean name: type: string startTime: type: integer description: '0-24 in UTC. 1 would be 01:00-02:00UTC' enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' weekday: type: integer description: 'Sunday is 1, Saturday is 7' enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 maintenanceWindowBody: type: object properties: isDefault: type: boolean name: type: string startTime: type: integer description: '0-24 in UTC. 1 would be 01:00-02:00UTC' enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 weekday: type: integer description: 'Sunday is 1, Saturday is 7' enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 required: - isDefault - name - startTime - weekday maintenanceWindowItem: type: object properties: item: $ref: '#/components/schemas/maintenanceWindow' maintenanceWindowItems: type: object properties: items: $ref: '#/components/schemas/maintenanceWindow' maintenanceWindowList: type: object properties: items: type: array items: $ref: '#/components/schemas/maintenanceWindow' osType: description: | Possible osType: * '1' - Unmanagable * '2' - Windows * '3' - Linux * '4' - Mac type: integer format: int32 enum: - 1 - 2 - 3 - 4 managedAsset: type: object properties: entity: type: object anyOf: - $ref: '#/components/schemas/asset' - $ref: '#/components/schemas/group' entityId: type: string permission: type: integer format: int32 relation: type: integer format: int32 managedAssetsBody: type: object properties: entityIds: description: managed asset ids type: array items: type: string pattern: '^[ag]:[acdjlngt]:[a-zA-Z0-9]{8}$' example: - 'g:c:ab124as2' - 'a:a:ab124as2' permission: type: integer format: int32 managedAssetsUpdateBody: type: object properties: managedEntityId: description: managed asset id type: string pattern: '^[ag]:[a-z]:[a-zA-Z0-9]{8}$' example: 'g:c:ab124as2' permission: type: integer format: int32 required: - managedEntityId - permission managedAssetsList: type: object properties: items: type: array items: $ref: '#/components/schemas/managedAsset' manager: type: object properties: manager: type: object anyOf: - $ref: '#/components/schemas/groupBasicInfo' - $ref: '#/components/schemas/userBasicInfo' managerId: type: string permission: type: integer format: int32 relation: type: integer format: int32 managersList: type: object properties: items: type: array items: $ref: '#/components/schemas/manager' mfaMethods: description: | * '1' - SMS * '2' - Email * '3' - Duo * '4' - Browser * '5' - No MFA * '6' - MicrosoftAuthenticator * '7' - Okta type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 networkActivityMap: type: object properties: incoming: $ref: '#/components/schemas/networkActivityMapAnalysisResult' outgoing: $ref: '#/components/schemas/networkActivityMapAnalysisResult' privilegedPorts: type: object properties: tcpPorts: type: string udpPorts: type: string networkActivityMapAnalysisResult: type: object properties: byRemoteAsset: type: object properties: clients: type: array items: $ref: '#/components/schemas/networkAssetAnalysisRecord' clusters: type: array items: $ref: '#/components/schemas/networkAssetAnalysisRecord' externalIps: type: array items: $ref: '#/components/schemas/networkAssetAnalysisRecord' internalIps: type: array items: $ref: '#/components/schemas/networkAssetAnalysisRecord' ot: type: array items: $ref: '#/components/schemas/networkAssetAnalysisRecord' servers: type: array items: $ref: '#/components/schemas/networkAssetAnalysisRecord' swtiches: type: array items: $ref: '#/components/schemas/networkAssetAnalysisRecord' networkAssetAnalysisRecord: type: object properties: aggregation: $ref: '#/components/schemas/networkAnalysisRecordData' connectionState: $ref: '#/components/schemas/connectionState' dstAssets: type: array items: $ref: '#/components/schemas/networkAnalysisRecordData' lastTimeSeen: type: string format: date-time occurred: type: integer ports: type: array items: $ref: '#/components/schemas/networkAnalysisRecordData' srcAssets: type: array items: $ref: '#/components/schemas/networkAnalysisRecordData' srcProcesses: type: array items: $ref: '#/components/schemas/networkAnalysisRecordData' users: type: array items: $ref: '#/components/schemas/networkAnalysisRecordData' networkAnalysisRecordData: type: object properties: connectionStatesCounts: $ref: '#/components/schemas/connectionStatesCounts' count: type: integer id: type: string name: type: string port: $ref: '#/components/schemas/protocolAndPortAndProcess' protectionType: type: integer networkAnalysis: type: object properties: aggregation: type: object properties: count: type: integer id: type: string name: type: string connectionState: $ref: '#/components/schemas/connectionState' dstAssets: type: array items: $ref: '#/components/schemas/assetSummary' lastTimeSeen: type: string occurred: type: integer ports: type: array items: $ref: '#/components/schemas/portSummary' srcAssets: type: array items: $ref: '#/components/schemas/assetSummary' srcProcesses: type: array items: $ref: '#/components/schemas/processSummary' nextBatch: type: object properties: networkIt: type: integer format: int64 identityAssets: type: integer format: int64 rpc: type: integer format: int64 nonOtAssetType: description: | Possible asset status: * '1' - Client * '2' - Server type: integer format: int32 enum: - 1 - 2 orderedReactivePolicies: type: array items: $ref: '#/components/schemas/reactivePolicy' otAssetBody: type: object properties: ipv4: type: string format: ipv4 type: type: number enum: - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 displayName: type: string fqdn: type: string switchId: type: string interfaceName: type: string required: - ipv4 - type - displayName - fqdn title: otAssetBody x-examples: example-1: value: ipv4: 192.168.0.1 type: 4 displayName: string otAssetEditBody: type: object properties: type: type: number enum: - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 displayName: type: string description: Display name of the asset example: Smart Bell fqdn: type: string description: Fully Qualified Domain Name example: rafa.com switchId: type: string interfaceName: type: string ipv4: type: string description: IPv4 address of the asset format: ipv4 example: 10.0.1.49 required: - type - displayName - fqdn - ipv4 title: otAssetEditBody otLocation: type: object properties: interfaceName: type: string name: type: string switchId: type: string outboundRestrictionMode: description: | * '1' - No restrictions * '2' - Internal Restricted * '3' - External Restricted * '4' - Internal and External Restricted * '5' - No applicable type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 overridingProtectionPolicyBody: type: object properties: memberIds: type: array items: type: string portsList: type: array items: type: object properties: ports: type: string protocolType: $ref: '#/components/schemas/protocol' portSummary: type: object properties: count: type: integer port: type: object properties: protocol: $ref: '#/components/schemas/protocol' port: type: integer privateIpv4NetworksList: description: Collection of IPv4 subnets that are internal type: array items: type: string example: 192.168.0.0/24 privateIpv6NetworksList: description: Collection of IPv6 subnets that are internal type: array items: type: string example: 'fd12:3456:789a:1::/64' PrivilegedPorts: type: string x-example: '1,3,4,5-8' processSummary: type: object properties: count: type: integer name: type: string profileResponse: type: object properties: envConfig: $ref: '#/components/schemas/envConfig' features: type: array items: type: string portalEnvUrl: type: string user: $ref: '#/components/schemas/profileUser' profileUser: type: object properties: activeEnvironmentId: type: string example: 17624a57-729e-4805-9703-67947d3bd888 activeEnvironmentName: type: string example: office-windows distributor: type: string email: type: string example: team@zeronetworks.com fullName: type: string example: Zero Networks id: type: string example: 1f352ed0-86f1-454f-90a5-592c197c8000 isExperimental: type: boolean example: true jobTitle: type: string role: $ref: '#/components/schemas/role' partnerName: type: string phone: type: string example: '+14242997613' platformType: type: integer example: 5 portalUserType: type: integer tenantId: type: string format: uuid type: $ref: '#/components/schemas/audienceType' protectionPoliciesList: type: object properties: items: type: array items: $ref: '#/components/schemas/protectionPolicy' protectionPolicy: type: object properties: createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/createdBy' description: type: string enabled: type: boolean enforceBlocks: type: boolean existingMembersLearningDays: type: integer enum: - -1 - 0 - 14 - 30 - 60 - 90 groupId: type: string groupInfo: type: object properties: domain: type: string guid: type: string hasIdentityProtectionPolicy: type: boolean hasNetworkProtectionPolicy: type: boolean id: type: string name: type: string id: type: string initialProtectAt: $ref: '#/components/schemas/epochMillis' newMembersLearningDays: type: integer enum: - -1 - 0 - 14 - 30 - 60 - 90 policyType: type: integer updatedAt: $ref: '#/components/schemas/epochMillis' protectionPolicyBody: type: object properties: description: type: string enabled: type: boolean enforceBlocks: type: boolean existingMembersLearningDays: type: integer default: 30 enum: - -1 - 0 - 14 - 30 - 60 - 90 groupId: type: string maintenanceWindowId: type: string newMembersLearningDays: type: integer default: 30 enum: - -1 - 0 - 14 - 30 - 60 - 90 required: - groupId - existingMembersLearningDays - newMembersLearningDays protectionPolicyResponse: type: object properties: items: $ref: '#/components/schemas/protectionPolicy' protectionPolicyUpdateBody: type: object properties: description: type: string enabled: type: boolean enforceBlocks: type: boolean default: false existingMembersLearningDays: type: integer default: 30 enum: - -1 - 0 - 14 - 30 - 60 - 90 id: type: string newMembersLearningDays: type: integer default: 30 enum: - -1 - 0 - 14 - 30 - 60 - 90 required: - existingMembersLearningDays - newMembersLearningDays - enforceBlocks protectionState: description: | * '0' - Unspecified * '1' - Unsegmented * '2' - Unsegmenting * '3' - Segmented * '4' - Segmenting * '5' - Learning until * '6' - forced_unprotected * '7' - Unsegmenting' - Due to Policy * '8' - Segmented' - Due to Policy * '9' - Segmenting- Due to Policy * '10' - Learning until' - Due to Policy * '11' - Learning done * '12' - Learning done- Due to Policy * '13' - APPLYING_QUEUE_WITH_BLOCKS * '14' - APPLYING_QUEUE_WITH_BLOCKS_DUE_TO_POLICY * '15' - QUEUED_WITH_BLOCKS * '16' - QUEUED_WITH_BLOCKS_DUE_TO_POLICY * '17' - QUEUED_WITH_BLOCKS_DONE * '18' - QUEUED_WITH_BLOCKS_DUE_TO_POLICY_DONE type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 protocol: description: | * '0' - HOPOPT * '1' - ICMP * '2' - IGMP * '3' - GGP * '4' - IPv4 * '5' - ST * '6' - TCP * '7' - CBT * '8' - EGP * '9' - IGP * '10' - BBN-RCC-MON * '11' - NVP-II * '12' - PUP * '13' - ARGUS * '14' - EMCON * '15' - XNET * '16' - CHAOS * '17' - UDP * '18' - MUX * '19' - DCN-MEAS * '20' - HMP * '21' - PRM * '22' - XNS-IDP * '23' - TRUNK-1 * '24' - TRUNK-2 * '25' - LEAF-1 * '26' - LEAF-2 * '27' - RDP * '28' - IRTP * '29' - ISO-TP4 * '30' - NETBLT * '31' - MFE-NSP * '32' - MERIT-INP * '33' - DCCP * '34' - 3PC * '35' - IDPR * '36' - XTP * '37' - DDP * '38' - IDPR-CMTP * '39' - TP++ * '40' - IL * '41' - Embedded * '42' - SDRP * '43' - IPv6RoutingHeader * '44' - IPv6FragmentHeader * '45' - IDRP * '46' - RSVP * '47' - GRE * '48' - DSR * '49' - BNA * '50' - ESP * '51' - AH * '52' - I-NLSP * '53' - SwIPe * '54' - NARP * '55' - MOBILE * '56' - TLSP * '57' - SKIP * '58' - ICMPv6 * '59' - IPv6NonExtHeader * '60' - IPv6DestinationOptions * '61' - Host-interanl * '62' - CFTP * '63' - local-network * '64' - SAT-EXPAK * '65' - KRYPTOLAN * '66' - RVD * '67' - IPPC * '68' - distributed-file-system * '69' - SAT-MON * '70' - VISA * '71' - IPCU * '72' - CPNX * '73' - CPHB * '74' - WSN * '75' - PVP * '76' - BR-SAT-MON * '77' - ND * '78' - WB-MON * '79' - WB-EXPAK * '80' - ISO-IP * '81' - VMTP * '82' - SECURE-VMTP * '83' - VINES * '84' - IPTM * '85' - NSFNET-IGP * '86' - DGP * '87' - TCF * '88' - EIGRP * '89' - OSPF * '90' - Sprite-RPC * '91' - LARP * '92' - MTP * '93' - AX.25 * '94' - OS * '95' - MICP * '96' - SCC-SP * '97' - ETHERIP * '98' - ENCAP * '99' - private-encryption * '100' - GMTP * '101' - IFMP * '102' - PNNI * '103' - PIM * '104' - ARIS * '105' - SCPS * '106' - QNX * '107' - A/N * '108' - IPComp * '109' - SNP * '110' - Compaq-Peer * '111' - IPX-in-IP * '112' - VRRP * '113' - PGM * '114' - 0-hop * '115' - L2TP * '116' - DDX * '117' - IATP * '118' - STP * '119' - SRP * '120' - UTI * '121' - SMP * '122' - SM * '123' - PTP * '124' - IS-IS-over-IPv4 * '125' - FIRE * '126' - CRTP * '127' - CRUDP * '128' - SSCOPMCE * '129' - IPLT * '130' - SPS * '131' - PIPE * '132' - SCTP * '133' - FC * '134' - RSVP-E2E-IGNORE * '135' - Mobility-Header * '136' - UDPLite * '137' - MPLS-in-IP * '138' - manet * '139' - HIP * '140' - Shim6 * '141' - WESP * '142' - ROHC * '143' - Ethernet * '144' - 144 (custom) * '145' - 145 (custom) * '146' - 146 (custom) * '147' - 147 (custom) * '148' - 148 (custom) * '149' - 149 (custom) * '150' - 150 (custom) * '151' - 151 (custom) * '152' - 152 (custom) * '153' - 153 (custom) * '154' - 154 (custom) * '155' - 155 (custom) * '156' - 156 (custom) * '157' - 157 (custom) * '158' - 158 (custom) * '159' - 159 (custom) * '160' - 160 (custom) * '161' - 161 (custom) * '162' - 162 (custom) * '163' - 163 (custom) * '164' - 164 (custom) * '165' - 165 (custom) * '166' - 166 (custom) * '167' - 167 (custom) * '168' - 168 (custom) * '169' - 169 (custom) * '170' - 170 (custom) * '171' - 171 (custom) * '172' - 172 (custom) * '173' - 173 (custom) * '174' - 174 (custom) * '175' - 175 (custom) * '176' - 176 (custom) * '177' - 177 (custom) * '178' - 178 (custom) * '179' - 179 (custom) * '180' - 180 (custom) * '181' - 181 (custom) * '182' - 182 (custom) * '183' - 183 (custom) * '184' - 184 (custom) * '185' - 185 (custom) * '186' - 186 (custom) * '187' - 187 (custom) * '188' - 188 (custom) * '189' - 189 (custom) * '190' - 190 (custom) * '191' - 191 (custom) * '192' - 192 (custom) * '193' - 193 (custom) * '194' - 194 (custom) * '195' - 195 (custom) * '196' - 196 (custom) * '197' - 197 (custom) * '198' - 198 (custom) * '199' - 199 (custom) * '200' - 200 (custom) * '201' - 201 (custom) * '202' - 202 (custom) * '203' - 203 (custom) * '204' - 204 (custom) * '205' - 205 (custom) * '206' - 206 (custom) * '207' - 207 (custom) * '208' - 208 (custom) * '209' - 209 (custom) * '210' - 210 (custom) * '211' - 211 (custom) * '212' - 212 (custom) * '213' - 213 (custom) * '214' - 214 (custom) * '215' - 215 (custom) * '216' - 216 (custom) * '217' - 217 (custom) * '218' - 218 (custom) * '219' - 219 (custom) * '220' - 220 (custom) * '221' - 221 (custom) * '222' - 222 (custom) * '223' - 223 (custom) * '224' - 224 (custom) * '225' - 225 (custom) * '226' - 226 (custom) * '227' - 227 (custom) * '228' - 228 (custom) * '229' - 229 (custom) * '230' - 230 (custom) * '231' - 231 (custom) * '232' - 232 (custom) * '233' - 233 (custom) * '234' - 234 (custom) * '235' - 235 (custom) * '236' - 236 (custom) * '237' - 237 (custom) * '238' - 238 (custom) * '239' - 239 (custom) * '240' - 240 (custom) * '241' - 241 (custom) * '242' - 242 (custom) * '243' - 243 (custom) * '244' - 244 (custom) * '245' - 245 (custom) * '246' - 246 (custom) * '247' - 247 (custom) * '248' - 248 (custom) * '249' - 249 (custom) * '250' - 250 (custom) * '251' - 251 (custom) * '252' - 252 (custom) * '253' - 253 (custom) * '254' - 254 (custom) * '255' - Raw * '256' - Any type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 - 31 - 32 - 33 - 34 - 35 - 36 - 37 - 38 - 39 - 40 - 41 - 42 - 43 - 44 - 45 - 46 - 47 - 48 - 49 - 50 - 51 - 52 - 53 - 54 - 55 - 56 - 57 - 58 - 59 - 60 - 61 - 62 - 63 - 64 - 65 - 66 - 67 - 68 - 69 - 70 - 71 - 72 - 73 - 74 - 75 - 76 - 77 - 78 - 79 - 80 - 81 - 82 - 83 - 84 - 85 - 86 - 87 - 88 - 89 - 90 - 91 - 92 - 93 - 94 - 95 - 96 - 97 - 98 - 99 - 100 - 101 - 102 - 103 - 104 - 105 - 106 - 107 - 108 - 109 - 110 - 111 - 112 - 113 - 114 - 115 - 116 - 117 - 118 - 119 - 120 - 121 - 122 - 123 - 124 - 125 - 126 - 127 - 128 - 129 - 130 - 131 - 132 - 133 - 134 - 135 - 136 - 137 - 138 - 139 - 140 - 141 - 142 - 143 - 144 - 145 - 146 - 147 - 148 - 149 - 150 - 151 - 152 - 153 - 154 - 155 - 156 - 157 - 158 - 159 - 160 - 161 - 162 - 163 - 164 - 165 - 166 - 167 - 168 - 169 - 170 - 171 - 172 - 173 - 174 - 175 - 176 - 177 - 178 - 179 - 180 - 181 - 182 - 183 - 184 - 185 - 186 - 187 - 188 - 189 - 190 - 191 - 192 - 193 - 194 - 195 - 196 - 197 - 198 - 199 - 200 - 201 - 202 - 203 - 204 - 205 - 206 - 207 - 208 - 209 - 210 - 211 - 212 - 213 - 214 - 215 - 216 - 217 - 218 - 219 - 220 - 221 - 222 - 223 - 224 - 225 - 226 - 227 - 228 - 229 - 230 - 231 - 232 - 233 - 234 - 235 - 236 - 237 - 238 - 239 - 240 - 241 - 242 - 243 - 244 - 245 - 246 - 247 - 248 - 249 - 250 - 251 - 252 - 253 - 254 - 255 - 256 protocolTypeMFA: description: '6=TCP, 17=UDP' type: integer format: int32 enum: - 6 - 17 protocolAndPortAndProcess: type: object properties: protocol: $ref: '#/components/schemas/protocol' port: type: integer process: type: string purdueLevel: description: | Purdue Level: * '0' - Unspecified * '1' - Level 0 * '2' - Level 1 * '3' - Level 2 * '4' - Level 3 * '5' - Level 4 type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 queueAssetBody: type: object properties: queueDays: description: number of days type: integer enum: - 14 - 30 - 60 - 90 required: - queueDays queueAssetExtendBody: type: object properties: extendByDays: description: number of days type: integer enum: - 14 - 30 - 60 - 90 relearnReason: type: string required: - extendByDays queueAssetIdentityBody: type: object properties: queueDays: description: number of days type: integer enum: - 14 - 30 - 60 - 90 required: - queueDays queueAssetIdentityExtendBody: type: object properties: extendByDays: description: number of days type: integer enum: - 14 - 30 - 60 - 90 relearnReason: type: string required: - extendByDays queueExtendBody: type: object properties: items: type: array items: type: string extendByDays: description: number of days type: integer enum: - 14 - 30 - 60 - 90 relearnReason: type: string required: - items - extendByDays queueExtendIdentityBody: type: object properties: items: type: array items: type: string extendByDays: description: number of days type: integer enum: - 14 - 30 - 60 - 90 relearnReason: type: string required: - items - extendByDays queueExtendRPCBody: type: object properties: items: type: array items: type: string extendByDays: description: number of days type: integer enum: - 14 - 30 - 60 - 90 relearnReason: type: string required: - items - extendByDays reactivePoliciesStatistics: type: object properties: reactivePoliciesStatistics: type: object properties: totalCount: type: integer reactivePolicy: type: object properties: additionalPortsList: $ref: '#/components/schemas/portsList' changeTicket: type: string context: $ref: '#/components/schemas/reactivePolicyContext' createdAt: $ref: '#/components/schemas/epochMillis' createdBy: type: string createdByName: type: string example: User Name dstEntityInfo: $ref: '#/components/schemas/asset' description: type: string dstPort: type: string example: '3389' dstProcessNames: type: array items: type: string example: 'c:\test.exe' enforcementSource: $ref: '#/components/schemas/enforcementSource' excludedSrcEntityInfos: type: array items: $ref: '#/components/schemas/idNamePair' excludedSrcProcesses: type: array items: type: string fallbackToLoggedOnUser: type: boolean id: type: string format: uuid example: 00000000-0000-0000-0000-000000000000 identityProtectionCategoryList: type: array items: $ref: '#/components/schemas/identityProtectionCategory' name: type: string mfaMethods: type: array items: $ref: '#/components/schemas/mfaMethods' overrideBuiltins: type: boolean protocolType: $ref: '#/components/schemas/protocolTypeMFA' restrictToOriginatedUser: type: boolean restrictLoginToOriginatingUser: type: boolean ruleDuration: $ref: '#/components/schemas/ruleDuration' srcEntityInfos: type: array items: $ref: '#/components/schemas/asset' srcProcessNames: type: array items: type: string example: system srcUserInfos: type: array items: $ref: '#/components/schemas/idNamePair' state: $ref: '#/components/schemas/reactivePolicyState' updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: type: string updatedByName: type: string example: User Name useDefaultIdp: type: boolean useOccasionalMfa: type: boolean x-speakeasy-entity: - InboundMFAPolicy - OutboundMFAPolicy reactivePolicyContext: description: | * '0' - Unspecified * '1' - Unmonitored Policies * '2' - Default MFA Policies * '3' - Senstive Tools and Processes type: integer format: int32 enum: - 0 - 1 - 2 - 3 reactivePolicyDistribution: type: object properties: mfaDistribution: type: array items: type: object properties: timestamp: $ref: '#/components/schemas/epochMillis' approved: type: integer rejected: type: integer x-examples: example-1: mfaDistribution: - timestamp: 1654905600000 approved: 0 rejected: 0 - timestamp: 1654992000000 approved: 5 rejected: 0 - timestamp: 1655078400000 approved: 7 rejected: 0 - timestamp: 1655164800000 approved: 13 rejected: 0 - timestamp: 1655251200000 approved: 7 rejected: 0 - timestamp: 1655337600000 approved: 2 rejected: 0 - timestamp: 1655424000000 approved: 6 rejected: 0 - timestamp: 1655510400000 approved: 0 rejected: 0 - timestamp: 1655596800000 approved: 1 rejected: 0 - timestamp: 1655683200000 approved: 7 rejected: 0 - timestamp: 1655769600000 approved: 3 rejected: 0 - timestamp: 1655856000000 approved: 7 rejected: 0 - timestamp: 1655942400000 approved: 4 rejected: 0 - timestamp: 1656028800000 approved: 4 rejected: 0 - timestamp: 1656115200000 approved: 0 rejected: 0 - timestamp: 1656201600000 approved: 2 rejected: 0 - timestamp: 1656288000000 approved: 4 rejected: 0 - timestamp: 1656374400000 approved: 8 rejected: 0 - timestamp: 1656460800000 approved: 7 rejected: 0 - timestamp: 1656547200000 approved: 9 rejected: 0 - timestamp: 1656633600000 approved: 3 rejected: 0 - timestamp: 1656720000000 approved: 0 rejected: 0 - timestamp: 1656806400000 approved: 4 rejected: 1 - timestamp: 1656892800000 approved: 2 rejected: 0 - timestamp: 1656979200000 approved: 3 rejected: 0 - timestamp: 1657065600000 approved: 16 rejected: 2 - timestamp: 1657152000000 approved: 17 rejected: 0 - timestamp: 1657238400000 approved: 13 rejected: 0 - timestamp: 1657324800000 approved: 0 rejected: 0 - timestamp: 1657411200000 approved: 3 rejected: 0 - timestamp: 1657497600000 approved: 4 rejected: 0 reactivePolicyInboundBody: type: object properties: additionalPortsList: $ref: '#/components/schemas/portsList' changeTicket: type: string description: type: string dstEntityInfo: type: object properties: id: type: string required: - id dstPort: type: string dstProcessNames: type: array items: type: string excludedSrcEntityInfos: type: array items: required: - id type: object properties: id: type: string excludedSrcProcesses: type: array items: type: string fallbackToLoggedOnUser: type: boolean identityProtectionCategoryList: type: array items: $ref: '#/components/schemas/identityProtectionCategory' name: type: string mfaMethods: type: array items: $ref: '#/components/schemas/mfaMethods' overrideBuiltins: type: boolean protocolType: type: integer restrictLoginToOriginatingUser: type: boolean ruleDuration: $ref: '#/components/schemas/ruleDuration' srcEntityInfos: type: array items: required: - id type: object properties: id: type: string srcProcessNames: type: array items: type: string srcUserInfos: type: array items: required: - id type: object properties: id: type: string state: $ref: '#/components/schemas/reactivePolicyState' useDefaultIdp: type: boolean useOccasionalMfa: type: boolean required: - dstEntityInfo - dstPort - dstProcessNames - fallbackToLoggedOnUser - mfaMethods - overrideBuiltins - protocolType - ruleDuration - srcEntityInfos - srcProcessNames - srcUserInfos - state - additionalPortsList x-speakeasy-entity: InboundMFAPolicy reactivePolicyItem: type: object properties: item: $ref: '#/components/schemas/reactivePolicy' reactivePolicyList: type: object properties: items: type: array items: $ref: '#/components/schemas/reactivePolicy' reactivePolicyMethods: type: object properties: items: type: array items: type: integer reactivePolicyOutboundBody: type: object properties: additionalPortsList: $ref: '#/components/schemas/portsList' changeTicket: type: string description: type: string dstEntityInfo: type: object properties: id: type: string required: - id dstPort: type: string dstProcessNames: type: array items: type: string excludedSrcEntityInfos: type: array items: required: - id type: object properties: id: type: string excludedSrcProcesses: type: array items: type: string fallbackToLoggedOnUser: type: boolean name: type: string mfaMethods: type: array items: $ref: '#/components/schemas/mfaMethods' overrideBuiltins: type: boolean protocolType: type: integer restrictToOriginatedUser: type: boolean restrictLoginToOriginatingUser: type: boolean ruleDuration: $ref: '#/components/schemas/ruleDuration' srcEntityInfos: type: array items: required: - id type: object properties: id: type: string srcProcessNames: type: array items: type: string srcUserInfos: type: array items: required: - id type: object properties: id: type: string state: $ref: '#/components/schemas/reactivePolicyState' useDefaultIdp: type: boolean useOccasionalMfa: type: boolean required: - dstEntityInfo - dstPort - fallbackToLoggedOnUser - mfaMethods - overrideBuiltins - protocolType - ruleDuration - srcEntityInfos - srcProcessNames - srcUserInfos - state - additionalPortsList x-speakeasy-entity: OutboundMFAPolicy reactivePolicyResponse: type: object properties: items: $ref: '#/components/schemas/reactivePolicy' reactivePolicyState: description: | * '1' - Enabled * '2' - Disabled type: integer format: int32 enum: - 1 - 2 requestedFilter: type: object properties: id: type: string excludeValues: type: array items: type: string includeValues: type: array items: type: string required: - id title: requestedFilter role: description: | dictionary: * '0' ROLE_UNSPECIFIED * '1' ROLE_ADMIN * '2' ROLE_VIEWER * '3' ROLE_REGULAR * '4' ROLE_MACHINE_FULL_ACCESS * '5' ROLE_MACHINE_READ_ONLY * '6' ROLE_SELF_SERVICE * '7' ROLE_CLOUD_CONNECTOR_PROVISIONING * '8' ROLE_JAMF_ASSET * '9' ROLE_ASSET_MANAGER type: integer enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 roleBody: type: object properties: role: description: '1 - Viewer, 2 - Admin' type: integer roleCandidatesList: type: object properties: items: type: array items: anyOf: - $ref: '#/components/schemas/group' - $ref: '#/components/schemas/user' scrollCursor: type: string rolesList: type: object properties: items: type: array items: anyOf: - $ref: '#/components/schemas/group' - $ref: '#/components/schemas/user' scrollCursor: type: string rpcActivitiesList: type: object properties: items: type: array items: $ref: '#/components/schemas/rpcActivity' scrollCursor: type: string rpcActivity: type: object properties: timestamp: $ref: '#/components/schemas/epochMillis' trafficType: type: integer protocolType: type: integer user: $ref: '#/components/schemas/userConnectionEnrichment' userName: type: string interfaceUuid: type: string opNumber: type: integer status: type: integer srcAsset: type: object properties: assetId: type: string assetSrc: type: integer assetProtectionState: type: integer assetType: $ref: '#/components/schemas/assetType' fqdn: type: string ip: type: string srcPort: type: integer dstAsset: type: object properties: assetId: type: string assetSrc: type: integer assetProtectionState: type: integer assetType: $ref: '#/components/schemas/assetType' fqdn: type: string ip: type: string dstEndpoint: type: object properties: port: type: integer dstEventRecordId: type: integer format: int64 dstProcessId: type: integer dstProcessNames: type: string dstProcessPath: type: string rpcFilter: type: object properties: id: type: string name: type: string placeholder: type: string disableExcludeSupport: type: boolean enableBulkSelection: type: boolean allowedCharactersRegex: type: string selections: type: array items: type: object properties: id: type: string name: type: string rpcFiltersList: type: object properties: items: type: array items: $ref: '#/components/schemas/rpcFilter' rpcProtectionState: description: | * '0' - Unspecified * '1' - Unsegmented * '2' - Unsegmenting * '3' - Segmented * '4' - Segmenting * '5' - Learning until * '6' - forced_unprotected * '7' - Unsegmenting' - Due to Policy * '8' - Segmented' - Due to Policy * '9' - Segmenting- Due to Policy * '10' - Learning until' - Due to Policy * '11' - Learning done * '12' - Learning done- Due to Policy * '13' - APPLYING_QUEUE_WITH_BLOCKS * '14' - APPLYING_QUEUE_WITH_BLOCKS_DUE_TO_POLICY * '15' - QUEUED_WITH_BLOCKS * '16' - QUEUED_WITH_BLOCKS_DUE_TO_POLICY * '17' - QUEUED_WITH_BLOCKS_DONE * '18' - QUEUED_WITH_BLOCKS_DUE_TO_POLICY_DONE type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 rpcProtocolsList: type: array items: type: integer description: | * NULL - Any * '1' - Rules RPC over SMB * '2' - Rules RPC over TCP rpcRule: type: object properties: action: $ref: '#/components/schemas/ruleAction' changeTicket: type: string createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/createdBy' description: type: string excludedAssetIdsList: type: array items: type: string excludedAssetInfos: type: array items: $ref: '#/components/schemas/idNamePair' expiresAt: $ref: '#/components/schemas/epochMillis' id: type: string interfaceUuidsList: $ref: '#/components/schemas/interfaceUuidsList' localAssetId: type: string localAssetInfo: $ref: '#/components/schemas/idNamePair' name: type: string opNumbersList: type: array items: type: integer parentId: type: string parentType: type: integer format: int32 protocolsList: $ref: '#/components/schemas/rpcProtocolsList' remoteAssetIdsList: type: array items: type: string remoteAssetInfos: type: array items: $ref: '#/components/schemas/idNamePair' ruleClass: $ref: '#/components/schemas/ruleClass' state: $ref: '#/components/schemas/ruleState' updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' userIdsList: type: array items: type: string userInfos: type: array items: $ref: '#/components/schemas/idNamePair' x-speakeasy-entity: RPCRule rpcRuleBody: type: object properties: action: $ref: '#/components/schemas/ruleAction' changeTicket: type: string description: type: string excludedAssetIdsList: type: array items: type: string expiresAt: $ref: '#/components/schemas/epochMillis' interfaceUuidsList: $ref: '#/components/schemas/interfaceUuidsList' localAssetId: type: string name: type: string opNumbersList: type: array items: type: integer protocolsList: $ref: '#/components/schemas/rpcProtocolsList' remoteAssetIdsList: type: array items: type: string state: $ref: '#/components/schemas/ruleState' userIdsList: type: array items: type: string required: - action - description - excludedAssetIdsList - interfaceUuidsList - localAssetId - opNumbersList - protocolsList - remoteAssetIdsList - state - userIdsList x-speakeasy-entity: RPCRule rpcRuleResponse: type: object properties: item: $ref: '#/components/schemas/rpcRule' rpcRulesList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/rpcRule' rule: type: object properties: action: $ref: '#/components/schemas/ruleAction' activitiesCount: type: integer format: int32 aeOverridden: type: boolean approvedAt: $ref: '#/components/schemas/epochMillis' approvedBy: $ref: '#/components/schemas/idNamePair' changeTicket: type: string context: $ref: '#/components/schemas/ruleContext' createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/createdBy' deletedAt: $ref: '#/components/schemas/epochMillis' deletedBy: $ref: '#/components/schemas/idNamePair' deleteSuggestionRejected: type: boolean description: type: string direction: $ref: '#/components/schemas/ruleDirection' enforcementSource: $ref: '#/components/schemas/enforcementSource' excludedEntityInfos: type: array items: $ref: '#/components/schemas/idNamePair' excludedEntitySuccessor: $ref: '#/components/schemas/idNamePair' excludedLocalIdsList: type: array items: type: string expiresAt: $ref: '#/components/schemas/epochMillis' id: type: string format: uuid ipSecOpt: $ref: '#/components/schemas/ipSecOpt' isRejectOnLinux: type: boolean localEntityId: type: string localEntityInfos: type: array items: anyOf: - $ref: '#/components/schemas/asset' - $ref: '#/components/schemas/idNamePair' localEntitySuccessor: $ref: '#/components/schemas/idNamePair' localProcessesList: type: array items: type: string multipleLocalEntityIdsList: type: array items: type: string name: type: string parentId: type: string parentSwitchRuleId: type: string parentSwitchRuleType: type: integer format: int32 parentType: type: integer format: int32 portsList: $ref: '#/components/schemas/portsList' remoteEntityIdsList: type: array items: type: string remoteEntityInfos: type: array items: anyOf: - $ref: '#/components/schemas/asset' - $ref: '#/components/schemas/idNamePair' remoteEntitySuccessor: $ref: '#/components/schemas/idNamePair' reviewMode: $ref: '#/components/schemas/ruleReviewMode' ruleClass: $ref: '#/components/schemas/ruleClass' ruleReview: $ref: '#/components/schemas/ruleReviewReason' servicesList: type: array items: type: string skipAudit: type: boolean srcUsersInfos: type: array items: $ref: '#/components/schemas/idNamePair' srcUsersList: $ref: '#/components/schemas/srcUsersList' state: $ref: '#/components/schemas/ruleState' suggestionReason: type: string suggestionType: $ref: "#/components/schemas/ruleSuggestionType" updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' x-speakeasy-entity: - InboundRule - OutboundRule example: id: 6a4a42aa-c207-4860-8b32-a8e186f8af80 localEntityId: g:t:01085899 action: 1 createdBy: createdBy: id: u:a:2IzNIRlf name: nicholas userRole: 1 enforcementSource: 4 description: DCs direction: 1 parentId: '' parentType: 0 portsList: - ports: 53,88,135,389,445,464,636,3268-3269,49152-65535 protocolType: 6 - ports: '53,67,88,123,138,389,464' protocolType: 17 remoteEntityIdsList: - b:110001 state: 1 createdAt: 1661349648315 updatedAt: 1684409059065 localProcessesList: - "*" servicesList: [] excludedLocalIdsList: [] updatedBy: id: '' name: '' approvedBy: id: '' name: '' ruleClass: 3 ipSecOpt: 1 srcUsersList: [] multipleLocalEntityIdsList: [] parentSwitchRuleId: '' parentSwitchRuleType: 0 name: '' changeTicket: '' context: 0 aeOverridden: false localEntityInfos: - id: g:t:01085899 name: Domain controllers domain: tag hasNetworkProtectionPolicy: false hasIdentityProtectionPolicy: false guid: 978f7753-650a-4ef1-aeeb-d2ceee64855b sid: '' remoteEntityInfos: - id: b:110001 name: Any asset excludedEntityInfos: [] activitiesCount: 498871 srcUserInfos: [] ruleAction: description: | * 1 - Allow * 2 - Block * 3 - Force Block type: integer format: int32 enum: - 1 - 2 - 3 ruleBody: type: object properties: action: $ref: '#/components/schemas/ruleAction' reviewMode: $ref: '#/components/schemas/ruleReviewMode' changeTicket: type: string description: type: string excludedLocalIdsList: type: array items: type: string expiresAt: $ref: '#/components/schemas/epochMillis' x-speakeasy-param-optional: true ipSecOpt: $ref: '#/components/schemas/ipSecOpt' name: type: string localEntityId: type: string localProcessesList: type: array items: type: string servicesList: type: array items: type: string portsList: $ref: '#/components/schemas/portsList' remoteEntityIdsList: type: array items: type: string srcUsersList: $ref: '#/components/schemas/srcUsersList' state: $ref: '#/components/schemas/ruleState' context: type: integer format: int32 required: - action - localEntityId - localProcessesList - portsList - remoteEntityIdsList - state x-speakeasy-entity: - InboundRule - OutboundRule example: remoteEntityIdsList: - g:s:14085899 localEntityId: a:a:rHXNGBbN excludedLocalIdsList: [] portsList: - ports: '67' protocolType: 6 ipSecOpt: 1 description: '' state: 1 action: 1 localProcessesList: - "*" servicesList: [] srcUsersList: [] name: '' changeTicket: '' ruleClass: description: | * '1' - Trivial * '2' - Permissive * '3' - Privileged * '4' - Critical * '5' - System * '6' - Preventative * '8' - Dangerous type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 - 6 - 8 ruleContext: description: | - '0' - Unspecified - '1' - Block - '2' - App Ring - '3' - Global RPC - '4' - Populare App - '5' - MS Cluster - '6' - Tag - '7' - Scanner - '8' - Popular Destination - '9' - Popular Source - '10' - MFA with Rule - '11' - Inter Server - '12' - AE Group - '13' - Block High Risk IPs - '14' - Unmonitored Source - '15' - Popular Client - '16' - Externally Facing Popular Destination - '17' - External IP Source - '18' - DC Tag - '19' - MDI Tag - '20' - DHCP Tag - '21' - DHCP Failover Tag - '22' - SCCM Tag - '23' - DNS Tag - '24' - Web Server Tag - '25' - Exchange Tag - '26' - Exchange Internal Tag - '27' - DFSR Tag - '28' - FTP Tag - '29' - ADFS Tag - '30' - WSUS Tag - '31' - PDQ Incoming - '32' - PDQ Outgoing - '33' - Citrix ICA - '34' - Citrix Broker Incoming - '35' - Citrix Broker Outgoing - '36' - WDS Tag - '37' - MS CA Tag - '38' - Direct Access Tag - '39' - KMS Tag - '40' - Security Scanners - '41' - Backup Tag - '42' - Databases Tag - '43' - Port Scanners - '44' - MS Cluster to external assets type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 - 31 - 32 - 33 - 34 - 35 - 36 - 37 - 38 - 39 - 40 - 41 - 42 - 43 - 44 ruleDirection: description: | * '1' - Inbound * '2' - Outbound * '3' - Both type: integer format: int32 enum: - 1 - 2 - 3 ruleDistribution: type: object properties: items: type: array items: $ref: '#/components/schemas/distribution' ruleDuration: description: | * '1' - Hour * '2' - Day * '3' - Week * '4' - Month * '5' - Never * '6' - 4 hours * '7' - 12 hours * '8' - 8 hours type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 ruleFilter: type: object properties: id: type: string includeValues: type: array items: type: string ruleItem: type: object properties: item: $ref: '#/components/schemas/rule' ruleMatch: type: object properties: ruleId: description: Id of the Rule type: string format: uuid example: b4565b6b-d20f-407d-9075-e354da6ffc64 updateId: type: number ruleResponse: type: object properties: item: $ref: '#/components/schemas/rule' ruleReviewApproveWithChanges: description: Mandatory object for rule review approve_with_changes / reject. type: object properties: review: $ref: '#/components/schemas/ruleReviewReason' ruleInfo: $ref: '#/components/schemas/ruleReviewBody' required: - review - ruleInfo x-examples: example-1: review: reason: 4 ruleInfo: action: 1 description: string direction: 1 excludedLocalIdsList: - string expiresAt: 0 localEntityId: string localProcessesList: - string portsList: - ports: string - protocolType: 0 remoteEntityIdsList: - string state: 1 updatedAt: 0 updatedBy: id: string name: string ruleReviewBody: type: object properties: action: $ref: '#/components/schemas/ruleAction' description: type: string direction: $ref: '#/components/schemas/ruleDirection' excludedLocalIdsList: type: array items: type: string expiresAt: $ref: '#/components/schemas/epochMillis' ipSecOpt: $ref: '#/components/schemas/ipSecOpt' localEntityId: type: string localProcessesList: type: array items: type: string servicesList: type: array items: type: string portsList: $ref: '#/components/schemas/portsList' remoteEntityIdsList: type: array items: type: string srcUsersList: $ref: '#/components/schemas/srcUsersList' state: description: '1=Enabled, 2=Disabled' type: integer enum: - 1 - 2 required: - action - direction - expiresAt - localEntityId - localProcessesList - portsList - remoteEntityIdsList - state ruleReviewMode: description: | * 1 - Apply Immediately * 2 - Review * 3 - Conditional Review enum: - 1 - 2 - 3 format: int32 type: integer ruleReviewReason: description: |- Mandatory object for rule review approve_with_changes / reject. reason: { HUMAN_TRAFFIC_COVERED_BY_MFA = 1, TIGHTEN_RULE_SCOPE = 2, MISSING_PORT_OR_PROCESS = 3, AFFECTED_ENTITIES_CONTAINED_IN_AN_EXISTING_GROUP = 4, REDUNDANT_RULE = 5, TRAFFIC_SHOULD_BE_BLOCKED = 6, OTHER = 7 } type: object properties: reason: type: integer details: description: 'Optional if reason != OTHER(7), mandatory if reason == OTHER(7)' type: string required: - reason x-examples: example-1: review: reason: 7 details: 'reason == 7 means OTHER, so details field is mandatory' example-2: review: reason: 2 rulesList: type: object properties: items: type: array items: $ref: '#/components/schemas/rule' count: type: integer ruleState: description: | * '1' - Enabled * '2' - Disabled * '3' - Deleted By User * '4' - Pending Review * '5' - Pending Review Auto * '6' - Rejected by User * '7' - Excluded by User type: integer format: int32 enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 ruleStatistics: type: object properties: aiStatistics: $ref: '#/components/schemas/ruleStatisticsType' mfaStatistics: $ref: '#/components/schemas/ruleStatisticsType' sspStatistics: $ref: '#/components/schemas/ruleStatisticsType' portalStatistics: $ref: '#/components/schemas/ruleStatisticsType' ruleStatisticsObject: type: object properties: enabledCount: type: integer disabledCount: type: integer pendingReviewCount: type: integer ruleStatisticsType: type: object properties: inboundAllow: $ref: '#/components/schemas/ruleStatisticsObject' inboundBlock: $ref: '#/components/schemas/ruleStatisticsObject' outboundAllow: $ref: '#/components/schemas/ruleStatisticsObject' outboundBlock: $ref: '#/components/schemas/ruleStatisticsObject' ruleSuggestionType: description: | * '0' - Unspecified * '1' - Create * '2' - Delete type: integer format: int32 enum: - 0 - 1 - 2 savedFilter: type: object properties: excludeValues: type: array items: type: string id: type: string includeValues: type: array items: type: string required: - id savedFilterBody: type: object properties: description: type: string filters: type: array items: $ref: '#/components/schemas/savedFilter' name: type: string permission: $ref: '#/components/schemas/savedFilterPermission' required: - description - filters - name - permission savedFilterId: type: object properties: userFilterId: type: string savedFilterPermission: type: string description: | * 'private' - only the creator can see the filter * 'public' - all users can see the filter savedFilterObject: type: object properties: createdAt: $ref: '#/components/schemas/iso8601DateTimeUTC' createdById: type: string description: type: string filters: type: array items: $ref: '#/components/schemas/savedFilter' id: type: string name: type: string permission: $ref: '#/components/schemas/savedFilterPermission' updatedAt: $ref: '#/components/schemas/iso8601DateTimeUTC' savedFiltersList: type: object properties: private: type: array items: $ref: '#/components/schemas/savedFilterObject' public: type: array items: $ref: '#/components/schemas/savedFilterObject' savedFilterUpdateBody: type: object properties: description: type: string filters: type: array items: $ref: '#/components/schemas/savedFilter' name: type: string required: - description - filters - name searchAssetsResponse: type: object properties: items: type: array items: $ref: '#/components/schemas/asset' count: type: integer nextCursor: type: string nextOffset: type: integer searchGroupsResponse: type: object properties: items: type: array items: $ref: '#/components/schemas/group' count: type: integer nextCursor: type: string nextOffset: type: integer searchUsersResponse: type: object properties: items: type: array items: $ref: '#/components/schemas/user' count: type: integer nextCursor: type: string nextOffset: type: integer session: type: object properties: asset: $ref: '#/components/schemas/asset' clientPrivateIp: type: string format: ipv4 clientVersion: type: string connectedSince: $ref: '#/components/schemas/epochMillis' connectionState: type: integer currentPublicIp: type: string format: ipv4 id: type: string createdAt: $ref: '#/components/schemas/epochMillis' lastLogon: $ref: '#/components/schemas/epochMillis' roleId: type: string server: $ref: '#/components/schemas/idNamePair' user: $ref: '#/components/schemas/idNamePair' connectivityStateAfterReboot: $ref: '#/components/schemas/connectivityStateAfterReboot' expiresAt: $ref: '#/components/schemas/epochMillis' sessionsList: type: object properties: items: type: array items: $ref: '#/components/schemas/session' setAssetType: type: object properties: type: $ref: '#/components/schemas/nonOtAssetType' required: - type setOSType: type: object properties: assetIds: type: array items: type: string osType: $ref: '#/components/schemas/osType' required: - assetIds - osType setOutboundRestriction: type: object properties: assetIds: type: array items: type: string maxItems: 100 outboundRestriction: type: integer description: | * 1 - NO_RESTRICTION * 2 - RESTRICTED_INTERNAL * 3 - RESTRICTED_EXTERNAL * 4 - RESTRICTED_INTERNAL_EXTERNAL enum: - 1 - 2 - 3 - 4 required: - assetIds - outboundRestriction settingsActivities: type: object properties: config: type: object properties: shouldFilterExternalTraffic: description: Disable/Enable external traffic collection type: boolean settingsActivitiesBody: type: object properties: shouldFilterExternalTraffic: description: Disable/Enable external traffic collection type: boolean required: - shouldFilterExternalTraffic settingsAdForest: type: object properties: activeDirectoryInfo: $ref: '#/components/schemas/settingsAdInfo' allowNtlmFallback: type: boolean automationGroups: $ref: '#/components/schemas/settingsProtectionAutomationResponse' forestId: type: string linuxAutomationGroups: $ref: '#/components/schemas/settingsLinuxAutomationResponse' secondaryDomains: type: array items: $ref: '#/components/schemas/settingsAdSecondaryBody' usePrimaryLinuxUserForAllDomains: type: boolean usePrimaryUserForAllDomains: type: boolean settingsAdInfo: type: object properties: allowInstallLinuxPackages: type: boolean domainControllerFqdn: description: Domain Controller from AD Domain type: string example: dc.zeronetworks.com domainName: description: FQDN of the AD domain type: string example: zeronetworks.com useLdaps: description: Use LDAP or LDAPs type: boolean userFqdn: description: Service Account for Zero Networks type: string example: znremotemanagement settingsAdInfoBody: type: object properties: primaryDomainConfig: type: object properties: assetsClusterId: type: string deploymentsClusterID: type: string domainControllerFqdn: description: Domain Controller from AD Domain type: string example: dc.zeronetworks.com domainName: description: FQDN of the AD domain type: string example: zeronetworks.com password: type: string description: password for the service account syncingClusterId: type: string useLdaps: description: Use LDAP or LDAPs type: boolean userFqdn: description: Service Account for Zero Networks type: string example: znremotemanagement required: - domainControllerFqdn - domainName - password - syncingClusterId - useLdaps - userFqdn usePrimaryUserForAllDomains: type: boolean allowNtlmFallback: type: boolean required: - primaryDomainConfig - usePrimaryUserForAllDomains - allowNtlmFallback settingsAdInfoResponse: type: object properties: forests: type: array items: $ref: '#/components/schemas/settingsAdForest' settingsAdLinuxAutomationGroupsBody: type: object properties: monitoredGroupId: type: string required: - monitoredGroupId settingsAdLinuxBody: type: object properties: adLinuxConfig: type: object properties: allowInstallPackages: type: boolean password: type: string privateKey: type: string username: type: string required: - allowInstallPackages - password - privateKey - username useForAllDomains: type: boolean required: - adLinuxConfig settingsAdSecondaryBody: type: object properties: secondaryDomainConfig: type: object properties: domainControllerFqdn: type: string example: dc.child.zeronetworks.com domainName: type: string example: child.zeronetworks.com required: - secondaryDomainConfig getOuConfigs: type: object properties: ouInfo: type: object properties: ouConfigs: type: array items: type: object properties: ouName: type: string userFqdn: type: string password: type: string required: - ouName - userFqdn required: - ouConfigs required: - ouInfo ouConfig: type: object properties: ouName: type: string userFqdn: type: string password: type: string required: - ouName - userFqdn - password createOuConfigs: type: object properties: ouConfigs: type: array items: $ref: '#/components/schemas/ouConfig' required: - ouConfigs editOuConfigs: type: object properties: ouConfigs: type: array items: $ref: '#/components/schemas/ouConfig' required: - ouConfigs deleteOuConfigs: type: object properties: ouNames: type: array items: type: string required: - ouNames settingsAdSyncInfoResponse: type: object additionalProperties: $ref: '#/components/schemas/settingsAdSyncInfoResponseForestItem' settingsAdSyncInfoResponseDcItem: type: object properties: dcFqdn: type: string lastUpdateTime: $ref: '#/components/schemas/epochMillis' lastUsn: type: integer format: int32 settingsAdSyncInfoResponseDomainItem: type: object properties: dcToSyncInfo: type: object properties: errorType: type: integer serverType: type: integer lastErrorMsg: type: string additionalProperties: $ref: '#/components/schemas/settingsAdSyncInfoResponseDcItem' settingsAdSyncInfoResponseForestItem: type: object properties: domainToSyncInfo: type: object additionalProperties: $ref: '#/components/schemas/settingsAdSyncInfoResponseDomainItem' settingsAdWindowsAutomationGroupsBody: type: object properties: monitoredGroupId: type: string protectedGroupId: type: string settingsAiRuleReview: type: object properties: ruleClassesList: type: array items: type: integer postponeProtection: type: boolean x-examples: example-1: ruleClassesList: - 1 - 6 settingsAiRuleReviewCleanup: type: object properties: unusedRulesCleanupState: type: string settingsAiRuleReviewCleanupBody: type: object properties: unusedRulesCleanupState: type: string description: "Possible values: 'OFF', 'ON_'REVIEW" required: - unusedRulesCleanupState settingsCyberarkConfig: type: object properties: address: type: string cyberArkLogonType: type: integer secretsType: type: integer userName: type: string vaultType: type: integer settingsCyberarkConfigBody: type: object properties: address: type: string cyberArkLogonType: type: integer description: | * 1 - CyberArk * 2 - LDAP * 3 - Radius * 4 - Windows enum: - 1 - 2 - 3 - 4 password: type: string secretsType: type: integer description: | * 1 - Plain * 2 - RDP File enum: - 1 - 2 userName: type: string vaultType: type: integer description: | * 1 - CyberArk enum: - 1 required: - address - cyberArkLogonType - password - secretsType - userName - vaultType settingsCyberarkConfigTest: type: object properties: errMsg: type: string success: type: boolean settingsAnsible: type: object properties: clientId: description: OAuth Client Id type: string credentialsName: description: Name of the creds used to instruct Ansible to connect to linux machines type: string disableCertificateValidation: description: Control certificate validation type: boolean url: description: URL of the Ansible server type: string username: description: username to access Ansible API. type: string settingsAnsibleBody: type: object properties: clientId: description: OAuth Client Id type: string credentialsName: description: Name of the creds used to instruct Ansible to connect to linux machines type: string disableCertificateValidation: description: Control certificate validation type: boolean password: description: password to access Ansible API type: string url: description: URL of the Ansible server type: string username: description: username to access Ansible API. type: string clientSecret: description: OAuth Client Secret type: string required: - clientId - credentialsName - disableCertificateValidation - password - url - username - clientSecret settingsHypervisor: type: object properties: hypervisorId: description: Hypervisor ID type: string type: description: 'Hypervisor type: vcenter' type: string enum: - vcenter name: description: Hypervisor name type: string config: $ref: '#/components/schemas/settingsHypervisorConfig' settingsHypervisorConfig: type: object properties: hostname: description: Hypervisor hostname type: string username: description: Username to access the hypervisor type: string settingsHypervisorConfigWithPassword: type: object properties: hostname: description: Hypervisor hostname type: string username: description: Username to access the hypervisor type: string password: description: Password to access the hypervisor type: string required: - hostname - username - password settingsHypervisorsList: type: object properties: items: type: array items: $ref: '#/components/schemas/settingsHypervisor' settingsHypervisorCreateBody: type: object properties: type: description: 'Hypervisor type: vcenter' type: string enum: - vcenter name: description: Hypervisor name type: string config: $ref: '#/components/schemas/settingsHypervisorConfigWithPassword' required: - type - name - config settingsHypervisorCreateResponse: type: object properties: hypervisorId: description: Created hypervisor ID type: string settingsHypervisorUpdateBody: type: object properties: type: description: 'Hypervisor type: vcenter' type: string enum: - vcenter name: description: Hypervisor name type: string config: $ref: '#/components/schemas/settingsHypervisorConfigWithPassword' required: - type - name - config settingsAntitamper: type: object properties: config: type: object properties: auditCooldownMinutes: type: integer settingsAntitamperBody: type: object properties: auditCooldownMinutes: type: integer required: - auditCooldownMinutes settingsAssetsManagersBody: type: object properties: entityIds: type: array items: $ref: '#/components/schemas/groupIdOrAssetId' managerIds: type: array items: $ref: '#/components/schemas/groupIdOrUserId' sessionTtl: type: object properties: item: type: object properties: portalTokenTtl: description: Portal session token timeout (in minutes) type: integer title: sessionTtl sessionTtlBody: type: object properties: portalTokenTtl: description: Portal session token timeout (in minutes) type: integer title: sessionTtlBody allowedIps: type: object properties: item: type: object properties: allowedIPs: description: Portal allowed ips and subnets type: array items: type: string title: allowedIps allowedIpsBody: type: object properties: allowedIPs: description: Portal allowed ips and subnets type: array items: type: string required: - allowedIPs title: allowedIpsBody settingsAzureAd: type: object properties: clientId: type: string format: uuid clientSecret: type: string tenantId: type: string format: uuid settingsAzureAdBody: type: object properties: clientId: type: string format: uuid clientSecret: type: string tenantId: type: string format: uuid settingsClaroty: type: object properties: apiUrl: type: string errorType: type: integer settingsClarotyBody: type: object properties: apiUrl: type: string token: type: string required: - apiUrl - token settingsBreakGlass: type: object properties: agentConfig: type: object properties: allowInbound: type: boolean allowOutbound: type: boolean allowIdentity: type: boolean allowRpc: type: boolean trustConfig: type: object properties: allowInbound: type: boolean allowOutbound: type: boolean allowIdentity: type: boolean allowRpc: type: boolean settingsBreakGlassBody: type: object properties: agentConfig: type: object properties: allowInbound: type: boolean allowOutbound: type: boolean allowIdentity: type: boolean allowRpc: type: boolean required: - allowInbound - allowOutbound - allowIdentity - allowRpc trustConfig: type: object properties: allowInbound: type: boolean allowOutbound: type: boolean allowIdentity: type: boolean allowRpc: type: boolean required: - allowInbound - allowOutbound - allowIdentity - allowRpc required: - agentConfig - trustConfig settingsBreakGlassMFA: type: object properties: enabled: type: boolean settingsBreakGlassMFABody: type: object properties: isBreakGlassMfaEnabled: type: boolean required: - isBreakGlassMfaEnabled settingsBreakGlassSwitches: type: object properties: allowNetworkTraffic: type: boolean stopMonitoring: type: boolean settingsBreakGlassSwitchesBody: type: object properties: allowNetworkTraffic: type: boolean stopMonitoring: type: boolean required: - allowNetworkTraffic - stopMonitoring settingsClientSubnets: type: object properties: config: type: object properties: privateIpv4NetworksList: $ref: '#/components/schemas/privateIpv4NetworksList' settingsClientSubnetsBody: type: object properties: privateIpv4NetworksList: $ref: '#/components/schemas/privateIpv4NetworksList' required: - privateIpv4NetworksList settingsConnectClientAutoUpdate: type: object properties: clientAutoUpdate: type: boolean settingsConnectClientAutoUpdateBody: type: object properties: clientAutoUpdate: type: boolean required: - clientAutoUpdate settingsCustomerUserBody: type: object properties: permission: type: integer required: - permission settingsCustomerUserInviteBody: type: object properties: email: type: string permission: $ref: '#/components/schemas/userRole' required: - email - permission settingsDay2Automation: type: object properties: state: type: boolean settingsDay2AutomationBody: type: object properties: state: type: boolean required: - state settingsPostureCheckDefinition: type: object properties: type: $ref: '#/components/schemas/identityPostureCheckType' category: type: integer description: | Posture check category: * `1` - AUTHENTICATION * `2` - OPERATIONAL * `3` - PRIVILEGE * `4` - LIFE_CYCLE enum: [1, 2, 3, 4] severity: type: integer description: | Violation severity: * `1` - CRITICAL * `2` - HIGH * `3` - MEDIUM * `4` - LOW enum: [1, 2, 3, 4] enabled: type: boolean mitreTacticsList: type: array items: type: string mitreTechniquesList: type: array items: type: string remediation: type: string description: type: string excludedUserIdsList: type: array items: type: string description: User IDs excluded from this specific posture check type settingsPostureCheckSettingInput: type: object properties: type: $ref: '#/components/schemas/identityPostureCheckType' severity: type: integer description: | Violation severity: * `1` - CRITICAL * `2` - HIGH * `3` - MEDIUM * `4` - LOW enum: [1, 2, 3, 4] enabled: type: boolean excludedUserIdsList: type: array items: type: string description: User IDs to exclude from this specific posture check type required: - type - severity - enabled settingsDomain: type: object properties: ip: type: string url: type: string urlType: type: integer settingsDomains: type: object properties: items: type: array items: $ref: '#/components/schemas/settingsDomain' settingsEventsReceiverConfig: type: object properties: config: type: object properties: auditsEndpoint: type: string identityActivitiesEndpoint: type: string networkActivitiesEndpoint: type: string receiverType: type: integer receiverConfig: oneOf: - $ref: '#/components/schemas/settingsEventsReceiverConfigElastic' - $ref: '#/components/schemas/settingsEventsReceiverConfigMicrosoftSentinel' - $ref: '#/components/schemas/settingsEventsReceiverConfigSplunk' rpcActivitiesEndpoint: type: string settingsEventsReceiverConfigBody: type: object properties: auditsEndpoint: type: string identityActivitiesEndpoint: type: string networkActivitiesEndpoint: type: string receiverConfig: oneOf: - $ref: '#/components/schemas/settingsEventsReceiverConfigElasticBody' - $ref: '#/components/schemas/settingsEventsReceiverConfigMicrosoftSentinelBody' - $ref: '#/components/schemas/settingsEventsReceiverConfigSplunkBody' rpcActivitiesEndpoint: type: string required: - receiverConfig settingsEventsReceiverConfigElastic: type: object properties: url: type: string settingsEventsReceiverConfigElasticBody: type: object properties: url: type: string apiKey: type: string required: - url - apiKey settingsEventsReceiverConfigMicrosoftSentinel: type: object properties: tenantId: type: string clientId: type: string url: type: string settingsEventsReceiverConfigMicrosoftSentinelBody: type: object properties: tenantId: type: string clientId: type: string clientSecret: type: string url: type: string required: - tenantId - clientId - clientSecret - url settingsEventsReceiverConfigSplunk: type: object properties: hecUri: type: string settingsEventsReceiverConfigSplunkBody: type: object properties: hecUri: type: string token: type: string required: - hecUri - token settingsEventsReceiverExportIp: type: object properties: exporterIp: type: string format: ipv4 settingsEventsReceiverSyncStatus: type: object properties: identityActivity: $ref: '#/components/schemas/settingsEventsReceiverSyncState' networkActivity: $ref: '#/components/schemas/settingsEventsReceiverSyncState' rpcActivity: $ref: '#/components/schemas/settingsEventsReceiverSyncState' audit: $ref: '#/components/schemas/settingsEventsReceiverSyncState' settingsEventsReceiverSyncState: type: object properties: errorType: type: integer errorMessage: type: string lastSyncTime: $ref: '#/components/schemas/epochMillis' lastSuccessfulSyncTime: $ref: '#/components/schemas/epochMillis' settingsFirewall: type: object properties: implicitIcmpRuleEnabled: type: boolean settingsFirewallBody: type: object properties: implicitIcmpRuleEnabled: type: boolean required: - implicitIcmpRuleEnabled settingsFirewallIgnoredGPO: type: object properties: inboundList: type: array items: type: string outboundList: type: array items: type: string settingsFirewallIgnoredGPOBody: type: object properties: inboundList: type: array items: type: string outboundList: type: array items: type: string settingsFirewallIgnoredRules: type: object properties: inboundList: type: array items: type: string outboundList: type: array items: type: string settingsFirewallIgnoredRulesBody: type: object properties: inboundList: type: array items: type: string outboundList: type: array items: type: string settingsFirewallProfiles: type: object properties: inboundAllow: type: object properties: domain: type: boolean private: type: boolean public: type: boolean inboundBlock: type: object properties: domain: type: boolean private: type: boolean public: type: boolean outboundBlock: type: object properties: domain: type: boolean private: type: boolean public: type: boolean settingsFirewallProfilesBody: type: object properties: inboundAllow: type: object properties: domain: type: boolean private: type: boolean public: type: boolean required: - domain - private - public inboundBlock: type: object properties: domain: type: boolean private: type: boolean public: type: boolean required: - domain - private - public outboundBlock: type: object properties: domain: type: boolean private: type: boolean public: type: boolean required: - domain - private - public required: - inboundAllow - inboundBlock - outboundBlock settingsFirewallMode: type: object properties: mode: $ref: '#/components/schemas/firewallMode' firewallMode: type: string enum: - windows_defender - wfp settingsIdentityLogoff: type: object properties: enforceLogoffDeniedUsers: type: boolean settingsIdentityLogoffBody: type: object properties: enforceLogoffDeniedUsers: type: boolean required: - enforceLogoffDeniedUsers settingsIdp: type: object properties: certificate: description: Identity Provider certificate type: string createdAt: $ref: '#/components/schemas/iso8601DateTimeUTC' createdBy: type: string format: uuid identityProviderType: type: string enum: - azure - custom - cyberark - duo - okta isDefault: description: Set as the default authentication method type: boolean sloUrl: description: Single Log out url type: string ssoUrl: description: Single sign on url type: string updatedAt: $ref: '#/components/schemas/iso8601DateTimeUTC' updatedBy: type: string format: uuid settingsIdpBody: type: object properties: certificate: description: Identity Provider certificate type: string identityProvider: type: string enum: - azure - custom - cyberark - duo - ping-identity - okta isDefault: description: Set as the default authentication method type: boolean sloUrl: description: Single Log out url type: string ssoUrl: description: Single sign on url type: string required: - certificate - identityProvider - isDefault - sloUrl - ssoUrl settingsIdpDefaultApplication: type: object properties: application: description: '1-Admin Portal, 2-Access Portal' type: integer enum: - 1 - 2 settingsIdpDefaultApplicationBody: type: object properties: application: description: '1-Admin Portal, 2-Access Portal' type: integer enum: - 1 - 2 required: - application settingsIdpList: type: object properties: items: type: array items: $ref: '#/components/schemas/settingsIdp' settingsInternalSubnets: type: object properties: config: type: object properties: privateIpv4NetworksList: $ref: '#/components/schemas/privateIpv4NetworksList' privateIpv6NetworksList: $ref: '#/components/schemas/privateIpv6NetworksList' settingsInternalSubnetsBody: type: object properties: privateIpv4NetworksList: $ref: '#/components/schemas/privateIpv4NetworksList' privateIpv6NetworksList: $ref: '#/components/schemas/privateIpv4NetworksList' required: - privateIpv4NetworksList - privateIpv6NetworksList assetIpAlias: type: object properties: alias: type: string createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/idNamePair' id: type: string ip: type: string updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' assetIpAliasBody: type: object properties: alias: type: string ipAddress: type: string required: - alias - ipAddress assetIpAliasItem: type: object properties: item: $ref: '#/components/schemas/assetIpAlias' assetIpAliasList: type: object properties: items: type: array items: $ref: '#/components/schemas/assetIpAlias' count: type: integer settingsJamfCredentials: type: object properties: host: description: JAMF url type: string password: type: string username: description: JAMF username type: string settingsJamfCredentialsBody: type: object properties: host: description: JAMF url type: string password: description: JAMF Password type: string username: description: JAMF username type: string required: - host - password - username settingsK8sApplicationsLabel: type: object properties: label: type: string settingsK8sApplicationsLabelBody: type: object properties: overrideApplicationLabel: type: string required: - overrideApplicationLabel settingsLearningConfig: type: object properties: allowQueueForever: type: boolean allowQuickLearning: type: boolean enforceBlocksAsDefault: type: boolean settingsLearningConfigBody: type: object required: - allowQueueForever - allowQuickLearning properties: allowQueueForever: type: boolean allowQuickLearning: type: boolean settingsLearnWithBlockInbound: type: object properties: portsList: $ref: '#/components/schemas/portsList' settingsLearnWithBlockInboundBody: $ref: '#/components/schemas/portsList' settingsLinuxAutomationResponse: type: object properties: monitoredGroup: $ref: '#/components/schemas/groupCandidate' settingsLinuxSetup: type: object properties: allowInstallPackages: type: boolean settingsLinuxSetupBody: type: object required: - allowInstallPackages properties: allowInstallPackages: type: boolean settingsLinuxUser: type: object properties: username: description: The linux username for ssh type: string settingsLinuxUserBody: type: object properties: password: description: password for the linux user type: string privateKey: description: private key for the linux user type: string username: description: the linux user name type: string required: - password - privateKey - username settingsMfaAuthentication: type: object properties: isRequiresAuth: description: Authentication Required type: boolean isSsoForceAuth: description: Force sso authentication type: boolean tokenTtl: description: Token time to live in minutes type: integer example: 1440 settingsMfaAuthenticationBody: type: object properties: isRequiresAuth: description: Authentication Required type: boolean isSsoForceAuth: description: Force sso authentication type: boolean tokenTtl: description: Token time to live in minutes type: integer example: 1440 required: - isRequiresAuth - isSsoForceAuth - tokenTtl settingsMfaAuthenticationResponse: type: object properties: item: $ref: '#/components/schemas/settingsMfaAuthentication' settingsMfaCache: type: object properties: assetLimit: type: integer entityId: type: string entityInfo: anyOf: - $ref: '#/components/schemas/user' - $ref: '#/components/schemas/group' ttlMinutes: type: integer settingsMfaCacheBody: type: object properties: assetLimit: type: integer entityId: type: string ttlMinutes: type: integer required: - assetLimit - entityId - ttlMinutes settingsMfaCacheItem: type: object properties: item: type: object properties: assetLimit: type: integer entityId: type: string ttlMinutes: type: integer settingsMfaCacheList: type: object properties: items: type: array items: $ref: '#/components/schemas/settingsMfaCache' count: type: integer settingsMfaDetection: type: object properties: timeoutMinutes: description: access policy cooldown type: integer example: 5 settingsMfaDetectionBody: type: object properties: timeoutMinutes: description: access policy cooldown type: integer example: 5 required: - timeoutMinutes settingsMfaDetectionResponse: type: object properties: item: $ref: '#/components/schemas/settingsMfaDetection' settingsNotification: type: array items: type: object properties: type: type: integer enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 enabled: type: boolean roles: type: array items: type: integer enum: - 1 - 2 - 10 settingsNotificationBody: type: array items: type: object properties: type: type: integer enum: - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 enabled: type: boolean roles: type: array items: type: integer enum: - 1 - 2 - 10 settingsPrivilegedPorts: type: object properties: item: type: object properties: tcpPorts: $ref: '#/components/schemas/PrivilegedPorts' UdpPorts: $ref: '#/components/schemas/PrivilegedPorts' settingsPrivilegedPortsBody: type: object required: - tcpPorts - udpPorts properties: tcpPorts: $ref: '#/components/schemas/PrivilegedPorts' udpPorts: $ref: '#/components/schemas/PrivilegedPorts' settingsProtectionAutomationResponse: type: object properties: monitoredGroup: $ref: '#/components/schemas/groupCandidate' protectedGroup: $ref: '#/components/schemas/groupCandidate' settingsPushNotifications: type: object properties: host: type: string id: type: string identityProvider: type: string silverfortMfaUnpairedAction: type: integer description: | Silverfort unpaired action (1) default behavior (2) allow (3) deny silverfortExtraConfig: type: object properties: unpairedAction: $ref: '#/components/schemas/silverfortMfaUnpairedAction' required: - unpairedAction settingsPushNotificationsBody: type: object properties: host: description: empty for Microsoft Authenticator type: string id: type: string identityProvider: type: string secretKey: type: string extraConfig: $ref: '#/components/schemas/silverfortExtraConfig' required: - identityProvider - secretKey settingsPushNotificationsList: type: object properties: items: type: array items: $ref: '#/components/schemas/settingsPushNotifications' settingsTrustedInternet: type: object properties: ports: $ref: '#/components/schemas/portsList' settingsTrustedInternetAddresses: type: object properties: config: type: object properties: externalIpsList: $ref: '#/components/schemas/externalIpsList' settingsTrustedInternetAddressesBody: type: object properties: externalIpsList: $ref: '#/components/schemas/externalIpsList' required: - externalIpsList settingsInternetAccessBody: type: object properties: trusted: $ref: '#/components/schemas/portsList' untrusted: $ref: '#/components/schemas/portsList' required: - trusted - untrusted settingsUntrustedInternet: type: object properties: ports: $ref: '#/components/schemas/portsList' settingsSegmentConnectorUpdateRecoveryBody: type: object properties: maxUpdateTries: type: integer updateCooldownHours: type: integer updateCooldownMinutes: type: integer required: - maxUpdateTries - updateCooldownHours - updateCooldownMinutes settingsWebhook: type: object properties: authType: type: integer description: type: string isEnabled: type: boolean id: type: string name: type: string syncStatus: type: object properties: errorType: type: integer errorMessage: type: string statusCode: type: integer triggers: type: array items: $ref: '#/components/schemas/settingsWebhookTrigger' url: type: string validateCertificate: type: boolean settingsWebhookBody: type: object properties: authType: type: integer description: type: string isEnabled: type: boolean name: type: string triggers: type: array items: $ref: '#/components/schemas/settingsWebhookTriggersBody' url: type: string validateCertificate: type: boolean required: - authType - isEnabled - name - triggers - url - validateCertificate settingsWebhookItem: type: object properties: webhook: type: object properties: webhookServer: type: object properties: credentials: type: object properties: authType: type: integer description: type: string id: type: string isEnabled: type: boolean name: type: string syncStatus: type: object properties: errorType: type: integer errorMessage: type: string statusCode: type: integer url: type: string validateCertificate: type: boolean triggersList: type: array items: $ref: '#/components/schemas/settingsWebhookTrigger' settingsWebhookTestBody: type: object properties: authType: type: integer description: type: string isEnabled: type: boolean name: type: string url: type: string validateCertificate: type: boolean required: - authType - isEnabled - name - url - validateCertificate settingsWebhookTriggersBody: type: object properties: triggers: type: array items: type: object properties: topic: type: integer eventsConfig: type: object properties: ruleEventsConfigs: type: object properties: resource: type: integer eventList: type: array items: type: integer enforcementSourcesList: type: array items: type: integer required: - resource - eventList - enforcementSourcesList required: - ruleEventsConfigs required: - topic - eventsConfig required: - triggers settingsWebhookTestResponse: type: object properties: connectionState: type: object properties: errorType: type: integer errorMessage: type: string statusCode: type: integer settingsWebhookTrigger: type: object properties: topic: type: integer eventsConfig: type: object properties: ruleEventsConfigs: type: object properties: resource: type: integer eventList: type: array items: type: integer enforcementSourcesList: type: array items: type: integer settingsWebhooksList: type: object properties: webhooks: type: array items: $ref: '#/components/schemas/settingsWebhook' settingsWebhooksSenderIp: type: object properties: senderIp: type: string format: ipv4 settingsZpa: type: object properties: config: type: object properties: isEnabled: type: boolean clientOutboundSubnet: $ref: '#/components/schemas/ipSubnet' gatewayIpsList: type: array items: type: string pattern: '^\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}$' portsToMfaTcp: type: string pattern: '^((\d{1,5}-\d{1,5})|\d{1,5})(,(\d{1,5}-\d{1,5})|,\d{1,5})*$' portsToMfaUdp: type: string pattern: '^((\d{1,5}-\d{1,5})|\d{1,5})(,(\d{1,5}-\d{1,5})|,\d{1,5})*$' settingsZpaBody: type: object required: - isEnabled - clientOutboundSubnet - gatewayIpsList - portsToMfaTcp - portsToMfaUdp properties: isEnabled: type: boolean clientOutboundSubnet: $ref: '#/components/schemas/ipSubnet' gatewayIpsList: type: array items: type: string pattern: '^\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}$' portsToMfaTcp: type: string pattern: '^((\d{1,5}-\d{1,5})|\d{1,5})(,(\d{1,5}-\d{1,5})|,\d{1,5})*$' portsToMfaUdp: type: string pattern: '^((\d{1,5}-\d{1,5})|\d{1,5})(,(\d{1,5}-\d{1,5})|,\d{1,5})*$' setUsersTypeBody: type: object required: - userIds - userType - comment properties: userIds: type: array items: type: string userType: $ref: '#/components/schemas/userType' comment: type: string setUserTypeBody: type: object required: - userType properties: userType: $ref: '#/components/schemas/userType' comment: type: string simulateAccess: type: array items: $ref: '#/components/schemas/simulateAccessRecord' simulateAccessBody: type: object properties: assetId: type: string direction: type: integer records: type: array items: $ref: '#/components/schemas/simulateAccessRecordBody' ruleStates: type: array items: type: integer enum: - 1 - 2 - 4 required: - assetId - direction - records - ruleStates simulateAccessRecord: type: object properties: coveredIdsList: type: string uncoveredIdsList: type: string coveredByMfaIdsList: type: string simulateAccessRecordBody: type: object properties: entitiesIdsList: type: array items: type: string localProcessesList: type: array items: type: string port: type: integer protocolType: type: integer simulationParams: type: object properties: dstAsset: $ref: '#/components/schemas/assetBasicInfo' dstProcess: type: string port: type: string protocolType: type: integer srcAsset: $ref: '#/components/schemas/assetBasicInfo' srcProcess: type: string srcUserId: $ref: '#/components/schemas/idNamePair' simulationResponse: type: object properties: accessInfo: $ref: '#/components/schemas/accessInfo' dstAssetInfo: $ref: '#/components/schemas/asset' orderedReactivePolicies: $ref: '#/components/schemas/orderedReactivePolicies' srcAssetInfo: $ref: '#/components/schemas/asset' source: description: | Possible asset sources: * '0' - Unspecified * '1' - Access portal * '2' - SSP * '3' - Active directory * '4' - Custom * '5' - System * '6' - Ansible * '7' - Manual OT/IoT * '8' - Workgroup * '9' - Azure active directory * '10' - Azure * '11' - AWS * '12' - GCP * '13' - Tag * '14' - Jamf * '15' - Manual Linux * '16' - IBM cloud * '17' - Oracle cloud * '18' - VMware cloud * '19' - Alibaba cloud * '20' - Lumen cloud * '21' - OVH cloud * '22' - Connect * '23' - AI * '24' - SNOW * '25' - Google Workspace * '26' - OU * '27' - Environment * '28' - Conditional * '29' - Claroty OT * '30' - Manual Mac type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 - 15 - 16 - 17 - 18 - 19 - 20 - 21 - 22 - 23 - 24 - 25 - 26 - 27 - 28 - 29 - 30 userCandidate: type: object properties: domain: type: string email: type: string id: type: string name: type: string sid: type: string srcUserCandidatesList: type: object properties: items: type: array items: $ref: '#/components/schemas/userCandidate' scrollCursor: type: string srcUsersList: type: array items: type: object properties: id: type: string sid: type: string state: type: object properties: assetId: type: string identityProtectedAt: $ref: '#/components/schemas/epochMillis' identityProtectionState: $ref: '#/components/schemas/identityProtectionState' isAssetConnected: type: boolean lastConnectedAt: $ref: '#/components/schemas/epochMillis' lastDisconnectedAt: $ref: '#/components/schemas/epochMillis' protectedAt: $ref: '#/components/schemas/epochMillis' protectionState: $ref: '#/components/schemas/protectionState' protectAt: $ref: '#/components/schemas/epochMillis' identityProtectAt: $ref: '#/components/schemas/epochMillis' rpcProtectionState: $ref: '#/components/schemas/protectionState' rpcProtectAt: $ref: '#/components/schemas/epochMillis' rpcProtectedAt: $ref: '#/components/schemas/epochMillis' switch: type: object properties: healthState: $ref: '#/components/schemas/healthState' id: type: string interfacesList: type: array items: type: string ip: type: string monitorInterfaceOnOtAdded: type: boolean monitorOnInterfaceDiscovery: type: boolean name: type: string numOfOts: type: integer type: type: integer username: type: string vlans: $ref: '#/components/schemas/switchVlanList' switchBody: type: object properties: name: type: string ip: type: string monitorInterfaceOnOtAdded: type: boolean monitorOnInterfaceDiscovery: type: boolean type: type: integer default: 1 username: type: string password: type: string required: - name - ip - monitorInterfaceOnOtAdded - monitorOnInterfaceDiscovery - type - username - password switchesMonitoringBreakGlassBody: allOf: - $ref: '#/components/schemas/switchMonitoringBreakGlassBody' - type: object properties: switchIds: type: array items: type: string required: - switchIds switchesNetworkBreakGlassBody: allOf: - $ref: '#/components/schemas/switchNetworkBreakGlassBody' - type: object properties: switchIds: type: array items: type: string required: - switchIds switchId: type: object properties: switchId: type: string switchItem: type: object properties: entity: $ref: '#/components/schemas/switch' permission: description: '2 - Viewer, 3 - Manager' type: integer enum: - 2 - 3 switchInterface: type: object properties: isMonitored: type: boolean name: type: string numOfOts: type: integer switchInterfacesList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/switchInterface' switchVlan: type: object properties: id: type: string name: type: string interfaces: type: array items: type: string switchVlanList: type: object properties: count: type: integer items: $ref: '#/components/schemas/switchVlan' switchList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/switch' switchSetBindingDirectionalBody: type: object properties: bindingDirection: type: string enum: - both - ingress - egress description: | Binding direction options: * 'both' - Both directions active * 'ingress' - Ingress only * 'egress' - Egress only firewall: type: object properties: id: type: string name: type: string type: type: integer description: | Firewall type: * '1' - Palo Alto AIRS tunnelInterfaceIp: type: string firewallBody: type: object properties: name: type: string type: type: integer default: 1 tunnelInterfaceIp: type: string required: - name - type - tunnelInterfaceIp firewallId: type: object properties: firewallId: type: string firewallList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/firewall' switchMonitoringBreakGlassBody: type: object properties: monitoringBreakGlassEnabled: type: boolean required: - monitoringBreakGlassEnabled switchNetworkBreakGlassBody: type: object properties: networkBreakGlassEnabled: type: boolean required: - networkBreakGlassEnabled switchProtocolsList: type: object properties: localPorts: type: string protocolType: $ref: '#/components/schemas/protocol' remotePorts: type: string switchProtocolsListBody: type: array items: type: object properties: localPorts: type: string ports: type: string protocolType: $ref: '#/components/schemas/protocol' remotePorts: type: string switchRule: type: object properties: action: $ref: '#/components/schemas/ruleAction' activitiesCount: type: integer format: int32 changeTicket: type: string createdAt: $ref: '#/components/schemas/epochMillis' createdBy: $ref: '#/components/schemas/createdBy' description: type: string direction: $ref: '#/components/schemas/ruleDirection' excludedAssetInfos: type: array items: $ref: '#/components/schemas/idNamePair' excludedLocalIdsList: type: array items: type: string expiresAt: $ref: '#/components/schemas/epochMillis' id: type: string localEntityId: type: string localEntityInfos: type: array items: anyOf: - $ref: '#/components/schemas/asset' - $ref: '#/components/schemas/idNamePair' localProcessesList: type: array items: type: string mirrorNetworkRuleId: type: string format: uuid mirrorSwitchRuleId: type: string format: uuid multipleLocalEntityIdsList: type: array items: type: string name: type: string policyParentRuleId: type: string policyParentRuleType: type: integer protocolsList: type: array items: $ref: '#/components/schemas/switchProtocolsList' remoteEntitiesIdList: type: array items: type: string remoteEntitiesInfos: type: array items: $ref: '#/components/schemas/idNamePair' shouldBuildMirrorRules: type: boolean servicesList: type: array items: type: string srcUserInfos: type: array items: $ref: '#/components/schemas/idNamePair' srcUsersList: type: array items: $ref: '#/components/schemas/idNamePair' state: $ref: '#/components/schemas/ruleState' switchParentRuleId: type: string switchParentRuleType: type: integer updatedAt: $ref: '#/components/schemas/epochMillis' updatedBy: $ref: '#/components/schemas/idNamePair' switchRuleBody: type: object properties: action: $ref: '#/components/schemas/ruleAction' changeTicket: type: string description: type: string direction: type: integer enum: - 1 - 2 excludedLocalIdsList: type: array items: type: string expiresAt: $ref: '#/components/schemas/epochMillis' localEntityId: type: string localProcessesList: type: array items: type: string protocolsList: $ref: '#/components/schemas/switchProtocolsListBody' remoteEntitiesIdList: type: array items: type: string shouldBuildMirrorRules: type: boolean srcUsersList: $ref: '#/components/schemas/srcUsersList' servicesList: type: array items: type: string state: $ref: '#/components/schemas/ruleState' required: - action - direction - localEntityId - protocolsList - remoteEntitiesIdList - shouldBuildMirrorRules - state switchRuleItem: type: object properties: item: $ref: '#/components/schemas/switchRule' switchRulesList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/switchRule' versionMaintenanceWindowList: type: object required: - items properties: items: type: array items: $ref: '#/components/schemas/versionMaintenanceWindow' versionMaintenanceWindow: type: object required: - weekday - startTime - duration properties: weekday: type: integer description: Day of week (1 = Sunday, 7 = Saturday) minimum: 1 maximum: 7 startTime: type: integer description: Start hour of maintenance window (0–24) minimum: 0 maximum: 24 duration: $ref: '#/components/schemas/duration' description: type: string description: Optional description of the version maintenance window duration: type: object required: - seconds - nanos properties: seconds: type: integer format: int64 description: Duration in seconds minimum: 0 nanos: type: integer description: Nanoseconds part of the duration minimum: 0 maximum: 999999999 tempVersionMaintenanceWindowList: type: object required: - items properties: items: type: array items: $ref: '#/components/schemas/tempVersionMaintenanceWindow' tempVersionMaintenanceWindow: type: object required: - startTime - duration properties: startTime: $ref: '#/components/schemas/epochMillis' duration: $ref: '#/components/schemas/duration' pilotGroupAssetList: type: object properties: items: type: array items: $ref: '#/components/schemas/pilotGroupAsset' count: type: integer pilotGroupAsset: type: object properties: id: type: string name: type: string assetType: type: integer protectionState: type: integer assetStatus: type: integer assetId: type: string version: type: string createdBy: type: object properties: id: type: string email: type: string createdAt: type: object properties: seconds: type: integer nanos: type: integer osType: $ref: '#/components/schemas/osType' pilotGroupModifyBody: type: object required: - assetIds properties: assetIds: type: array minItems: 1 items: type: string pilotRolloutInfo: type: object properties: pilotVersion: type: string baselineVersion: type: string pilotStartTime: $ref: '#/components/schemas/epochMillis' pilotEndTime: $ref: '#/components/schemas/epochMillis' extensionCount: type: integer systemHealthIssue: type: object properties: type: type: string severity: type: string systemHealthList: type: object properties: issues: type: array items: $ref: '#/components/schemas/systemHealthIssue' tagGroupBody: type: object properties: membersId: description: members id type: array items: type: string pattern: '^a:[ault]:[a-zA-Z0-9]{8}$' example: - 'a:a:8ErCHXe8' comment: type: string required: - membersId tags: type: object properties: items: type: array items: $ref: '#/components/schemas/group' trafficType: description: | * '1' - Internal * '2' - External * '3' - Both * '4' - Any type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 pinDeploymentsClusterBody: type: object properties: assetIds: type: array items: type: string deploymentsClusterId: type: string required: - assetIds unpinDeploymentsClusterBody: type: object properties: assetIds: type: array items: type: string required: - assetIds user: allOf: - $ref: '#/components/schemas/userBasicInfo' - type: object properties: addedAt: $ref: '#/components/schemas/epochMillis' addedBy: $ref: '#/components/schemas/epochMillis' classifiedBy: $ref: '#/components/schemas/idNamePair' createdAt: $ref: '#/components/schemas/epochMillis' disabledSince: $ref: '#/components/schemas/epochMillis' distinguishedName: type: string firstName: type: string guid: type: string inactiveReason: $ref: '#/components/schemas/entityInactiveReason' inactiveSince: $ref: '#/components/schemas/epochMillis' isDisabled: type: boolean isQuarantined: type: boolean jobTitle: type: string lastLogon: $ref: '#/components/schemas/epochMillis' lastName: type: string passwordUpdateTime: $ref: '#/components/schemas/epochMillis' phone: type: string principalName: type: string protectAt: $ref: '#/components/schemas/epochMillis' protectedAt: $ref: '#/components/schemas/epochMillis' protectionState: $ref: '#/components/schemas/userProtectionState' role: $ref: '#/components/schemas/userRole' source: $ref: '#/components/schemas/source' status: $ref: '#/components/schemas/userActiveState' userPrincipleName: type: string userActiveState: description: | * '1' - Active * '2' - Deleted * '3' - Disabled type: integer format: int32 enum: - 1 - 2 - 3 userBasicInfo: allOf: - $ref: '#/components/schemas/idNamePair' - type: object properties: domain: type: string email: type: string sid: type: string userType: $ref: '#/components/schemas/userType' userIdentityAnalysis: type: object properties: items: type: object properties: authenticationPackage: type: array items: $ref: '#/components/schemas/identityAnalysis' counts: type: object properties: authenticationPackage: type: integer dstAsset: type: integer logonType: type: integer srcAsset: type: integer dstAsset: type: array items: $ref: '#/components/schemas/identityAnalysis' logonType: type: array items: $ref: '#/components/schemas/identityAnalysis' srcAsset: type: array items: $ref: '#/components/schemas/identityAnalysis' userIdResponse: type: object properties: userId: type: string x-examples: example-1: userId: 'u:a:tOUovcIQ' userNetworkAnalysis: type: object properties: items: type: object properties: counts: type: object properties: byDstAsset: type: integer byPort: type: integer bySrcAsset: type: integer bySrcProcess: type: integer byDstAsset: type: array items: $ref: '#/components/schemas/networkAnalysis' byPort: type: array items: $ref: '#/components/schemas/networkAnalysis' bySrcAsset: type: array items: $ref: '#/components/schemas/networkAnalysis' bySrcProcess: type: array items: $ref: '#/components/schemas/networkAnalysis' userProtectionState: description: | * '1' - Unsegmented * '3' - Segmented * '5' - Learning until * '6' - Learning done type: integer format: int32 enum: - 1 - 3 - 5 - 6 userResponse: type: object properties: entity: $ref: '#/components/schemas/user' userRole: description: "* '0' - Unspecified\n* '1' - Admin\n* '2' - Viewer\n* '3' - Regular\n* '4' - API-FullAccess\n* '5' - API-ReadOnly\n* '6' - SelfService\n* '7' - CloudConnectorProvisioning\n* '8' - JAMF Asset\n* '9' - Asset Manager\n* '10' - Operator\n* '11' - Service Now Token\n* '12' - Segment Server Provisioning\n* '13' - Connect Server Provisioning\n* '14' - Segment Connector Provisioning \n" type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 - 9 - 10 - 11 - 12 - 13 - 14 userSimple: type: object properties: domain: type: string email: type: string id: type: string name: type: string usersProtectBody: type: object properties: userIds: type: array items: type: string required: - userIds usersQueueBody: type: object properties: userIds: type: array items: type: string queueDays: type: integer enum: - 14 - 30 required: - userIds - queueDays userStatistics: type: object properties: userStatistics: type: object properties: totalCount: type: integer adminsCount: type: integer viewersCount: type: integer x-examples: example-1: userStatistics: totalCount: 87 adminsCount: 14 viewersCount: 6 userSummary: type: object properties: count: type: integer id: type: string name: type: string userType: type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 - 6 - 7 usersActivateBody: type: object required: - items properties: comment: type: string items: type: array items: type: string userActivateBody: type: object properties: comment: type: string userConnectionEnrichment: type: object properties: domain: type: string id: type: string logonId: type: string name: type: string protectionState: type: integer format: int32 enum: - 0 - 1 - 3 - 5 - 6 riskTypes: type: array items: type: integer format: int32 enum: - 0 - 1 - 2 sid: type: string status: type: integer format: int32 enum: - 0 - 1 - 2 - 3 userType: $ref: '#/components/schemas/userType' userViolation: type: object properties: userId: type: string userName: type: string userType: $ref: '#/components/schemas/userType' postureCheckType: $ref: "#/components/schemas/identityPostureCheckType" violationState: $ref: '#/components/schemas/userViolationState' lastLogon: $ref: '#/components/schemas/epochMillis' foundTime: $ref: '#/components/schemas/epochMillis' userViolationBody: type: object properties: violationState: $ref: '#/components/schemas/userViolationState' userIds: type: array items: type: string required: - violationState - userIds usersViolationList: type: object properties: count: type: integer items: type: array items: $ref: '#/components/schemas/userViolation' userViolationState: description: | * '1' - FOUND * '2' - IGNORED * '3' - DEFERRED type: integer enum: - 1 - 2 - 3 validateResponse: type: object properties: affectedAssetsCount: type: integer identityProtectionCategory: description: | * '0' - Unspecified * '1' - Locally * '2' - Network * '3' - Batch * '4' - Service * '5' - RDP type: integer format: int32 enum: - 0 - 1 - 2 - 3 - 4 - 5 securitySchemes: api_key: type: apiKey name: Authorization in: header security: - api_key: [] tags: - name: Activities description: API calls related to Activities. - name: AE Exclusions description: API calls related to AE Exclusions. - name: Asset description: API calls related to a specific Asset. - name: Asset actions description: API calls related to a specific Asset actions. - name: Asset activities description: API calls related to a specific Asset activities. - name: Asset analysis description: API calls related to a specific Asset analysis. - name: Asset ancestors description: API calls related to a specific Asset ancestors. - name: Asset audit description: API calls related to a specific Asset audit. - name: Asset identity-actions description: API calls related to a specific Asset identity actions. - name: Asset managers description: API calls related to a specific Asset managers. - name: Asset protection description: API calls related to a specific Asset protection. - name: Asset rpc-actions description: API calls related to a specific Asset rpc actions. - name: Asset OT/IoT description: API calls related to a specific OT/IoT Asset. - name: Asset OT/IoT actions description: API calls related to a Asset OT/IoT actions. - name: Asset OT/IoT activities description: API calls related to a Asset OT/IoT activities. - name: Asset OT/IoT analysis description: API calls related to a Asset OT/IoT analysis. - name: Asset OT/IoT ancestors description: API calls related to a Asset OT/IoT ancestors. - name: Asset OT/IoT audit description: API calls related to a Asset OT/IoT audit. - name: Asset OT/IoT managers description: API calls related to a Asset OT/IoT managers. - name: Asset OT/IoT protection description: API calls related to a Asset OT/IoT protection. - name: Asset OT/IoT tags description: API calls related to a Asset OT/IoT tags. - name: Assets description: API calls related to Assets. - name: Assets OT/IoT description: API calls related to OT/IoT Assets. - name: Assets OT/IoT actions description: API calls related to a Assets OT/IoT actions. - name: Assets Switches description: API calls related to Switches. - name: Assets Firewalls description: API calls related to Firewalls. - name: Audit description: API calls related to Audits. - name: Auth description: API calls related to Authentication. - name: Entity description: API calls related to Entities. - name: Environment description: API calls related to Environment. - name: External Access Policy description: API calls related to a External Access Policy. - name: Group description: API calls related to a specific Group. - name: Groups description: API calls related to Groups. - name: Groups activities description: API calls related to Groups activities. - name: Groups Active Directory description: API calls related to Active Directory Groups. - name: Groups Custom description: API calls related to Custom Groups. - name: Groups protection description: API calls related to Groups Protection. - name: Groups Tag description: API calls related to Tag Groups. - name: K8s description: API calls related to K8s. - name: K8s audit description: API calls related to K8s Audit. - name: K8s namespaces description: API calls related to K8s Namespaces. - name: K8s network policy description: API calls related to K8s Network Policy. - name: K8s nodes description: API calls related to K8s Nodes. - name: K8s workloads description: API calls related to K8s Workloads. - name: MFA description: API calls related to MFA policies. - name: MFA Identity description: API Calls related to MFA Identity settings. - name: MFA Inbound description: API calls related to Inbound MFA policies. - name: MFA Outbound description: API calls related to Outbound MFA policies. - name: Onboarding Policies description: API calls related to Onboarding policies. - name: Profile description: API calls related to profile. - name: Rules description: API calls related to Rules. - name: Rules Identity description: API calls related to Identity Rules. - name: Rules Inbound description: API calls related to Inbound rules. - name: Rules Outbound description: API calls related to Outbound rules. - name: Rules OT/IoT Inbound description: API calls related to OT/IoT Inbound rules. - name: Rules OT/IoT Outbound description: API calls related to OT/IoT Outbound rules. - name: Rules RPC description: API calls related to RPC Rules - name: Sessions description: API calls related to Sessions. - name: Settings description: API calls related to Settings. - name: Settings Access Tokens description: API calls related to Access Tokens settings. - name: Settings Activities description: API calls related to Activities settings. - name: Settings AE description: API calls related to AI settings. - name: Settings AE Learning description: API calls related to AI Learning settings. - name: Settings AE Rules Review description: API calls related to AI Rule Review settings. - name: Settings Antitampering description: API calls related to Antitampering settings. - name: Settings Asset Management description: API calls related to Asset Management settings. - name: Settings Asset Managers description: API calls related to Asset Managers settings. - name: Settings Break Glass description: API calls related to Break Glass settings. - name: Settings Cloud Connector description: API calls related to Cloud Connector settings. - name: Settings Connect description: API calls related to Connect settings. - name: Settings Custom Users description: API calls related to Custom Users settings. - name: Settings Domains description: API calls related to Domains. - name: Settings Firewall description: API calls related to Firewall settings. - name: Settings Identity Providers description: API calls related to Identity Providers settings. - name: Settings Inactive Assets description: API calls related to Inactive Assets settings. - name: Settings Internal Subnets description: API Calls related to Internal Subnets settings. - name: Settings Learning description: API calls related to AI Learning settings. - name: Settings Licenses description: API calls related to Licenses settings. - name: Settings Mail Notifications description: API calls related to Mail Notifications settings. - name: Settings Maintenance Window description: API calls related to Maintenance Window settings. - name: Settings MFA description: API Calls related to MFA settings. - name: Settings MFA Cache description: API Calls related to MFA Cache settings. - name: Settings Portal Security description: API calls related to Portal Security settings. - name: Settings Privileged Ports description: API calls related to Privileged Ports settings. - name: Settings Protection Policies description: API calls related to Protection Automation settings. - name: Settings Push Notifications description: API calls related to Push Notifications settings. - name: Settings Roles description: API calls related to Roles settings. - name: Settings Segment Servers description: API Calls related to Segment Server Settings. - name: Settings Segment Connector description: API calls related to Segment Connector settings. - name: Settings CMDB description: API calls related to CMDB settings. - name: Settings Trusted Internet description: API calls related to Trust Internet Settings - name: Settings ZTNA proxy description: API calls related to ZPA Settings. - name: Switch description: API calls related to switches - name: Switch activities description: API calls related to a specific Switch activities. - name: Switch audit description: API calls related to a specific Switch audit. - name: Switch OT/IoT description: API calls related to switch OT/IoT - name: Switch protection description: API calls related to a specific Switch protection. - name: User description: API calls related to a specific User. - name: Users description: API calls related to Users.