Google Chronicle Legacy API
Google Chronicle Legacy API provides programmatic access to Google's security analytics platform for enhanced threat detection and response.
Google Chronicle Legacy API is a powerful platform for advanced threat intelligence and incident management. This connector enables seamless integration with Swimlane Turbine, allowing users to automate the management of cases, detections, and alerts within Google Chronicle. By leveraging this integration, Swimlane Turbine end-users can enhance their security operations with streamlined workflows, real-time threat detection, and efficient incident response, all without the need for extensive coding.
Limitations
None to Date
Supported Versions
This connector supports the latest version of Google Chronicle Legacy API.
Configuration
Prerequisites
Before you can use the Google Chronicle Legacy API connector for Turbine, you'll need access to the Google Chronicle API. This requires the following:
- OAuth2.0 authentication for Google Chronicle Legacy API using the following parameters:
- Service Account Info: JSON key file for service account authentication.
- URL: Endpoint URL for accessing Google Chronicle services.
- Scopes: Permissions required for accessing specific resources in Google Chronicle.
Authentication Methods
OAuth 2.0 Client Credentials Authentication:
To effectively utilize the Google Chronicle Legacy API connector within Swimlane Turbine, ensure you have the following prerequisites:
- OAuth2.0 authentication for Google Chronicle Legacy API with these parameters:
- Service Account Info: A JSON file containing your service account credentials.
- URL: The endpoint URL for the Google Chronicle Legacy API.
GCP Project Creation:
- Log in to GCP Console here: https://console.cloud.google.com/
- Navigate to this link to create a new project: https://console.cloud.google.com/projectcreate
- Name your project and click Create. We recommend specific and recognizable project names.
- Navigate to your projects, and select your new project.
- Enable the Google Chronicle API:
- Go to the API & Services Dashboard in the Cloud Console.
- Click on the "Enable APIs and Services" button.
Asset Configuration:
Configuring a Service Account:
Google Chronicle Legacy API connector requires a Google service account to authenticate.
- Select the appropriate project.
- Click + CREATE NEW SERVICE ACCOUNT.
- Assign a name for the service account and add a description, click CREATE AND CONTINUE
- Click the Select a Role dropdown and type βOwnerβ in the filter. Choose Owner , Chronicle API Admin and click Continue.
- For the menu specifying Grant users access to this service account (optional) you may select Users or Skip and click Done. This is not required for the connector.
- Click on the newly created service account email.
- Navigate to the KEYS menu.
- Click ADD KEY, select CREATE NEW KEY, select JSON format, and click CREATE. Make sure you download the .json file presented.
- Json needs to be passed in the asset input Service Account Info as a Base64 encoded string. This file will be needed when configuring the asset in Swimlane.
Setting API Scopes:
After creating a service account, the necessary API scopes required to be authorized must be set.
- From https://admin.google.com, navigate to Security > API Controls and then click Manage Domain Wide Delegation at the bottom of the window.
- Click Add new
- In the Client ID field, enter the Unique ID from the service account Details menu
- Enter the following CSV value into the OAuth Scopes (comma-delimited) input: https://www.googleapis.com/auth/chronicle-backstory
- Click Authorize
Capabilities
This Google Chronicle Legacy API Connector provides the following capabilities:
- Add Tag for Case
- Get Case
- Legacy Create or Update Case
- Legacy Get Detection
- Legacy Search Curated Detections
- Legacy Search Detections
- Legacy Search Rule Detection Events
- Legacy Update Alert
- List Cases
- List Rules
- Merge Cases
- Patch Case
Add Tag for Case
- Adds a specified tag to a case in Google Chronicle Legacy API using the case name and tag provided Click Here.
Get Case
- Retrieves a specific case from Google Chronicle Legacy API, providing detailed information about the incident Click Here.
Legacy Create or Update Case
- Create or update cases in Google Chronicle Legacy API using specified instance and caseResource details Click Here.
Legacy Get Detection
- Retrieve a specific detection from Google Chronicle Legacy API using ruleId and detectionId as parameters Click Here.
Legacy Search Curated Detections
- Search for detections associated with a Curated Rule in Google Chronicle using the legacy endpoint. Requires 'instance' path parameter and 'ruleId' Click Here.
Legacy Search Detections
- Search for detections associated with a specific rule version in Google Chronicle using the legacy API endpoint. Requires 'instance' path parameter and 'ruleId' Click Here.
Legacy Search Rule Detection Events
- List events linked to a specific Detection from a Rules Engine rule in Google Chronicle Legacy API, requiring 'instance' and 'ruleId' Click Here.
Legacy Update Alert
- Updates an existing alert in Google Chronicle using the legacy API endpoint, requiring alertId and feedback Click Here.
List Cases
- Retrieve a list of cases from Google Chronicle Legacy API using the specified parent path parameter Click Here.
List Rules
- Retrieves a list of rules from Google Chronicle Legacy API based on the specified parent path parameter Click Here.
Merge Cases
- Combine multiple cases into a single case in Google Chronicle, specifying the parent case and the IDs of cases to merge Click Here.
Patch Case
- Updates an existing case in Google Chronicle Legacy API using the specified case name Click Here.
Additional Documentation
Configurations
Google Chronicle Legacy API Authentication
OAuth2.0 authentication for Google Chronicle Legacy API.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
b64_service_info | Base64-encoded credentials JSON authentication file contents. | string | Required |
url | Server API Address. | string | Required |
scopes | Scope to be used for authentication. | array | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Add Tag for Case
Add a specified tag to an existing case in Google Chronicle Legacy API using the case name and tag.
Endpoint
- URL: v1alpha/{{name}}:addTag
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.name | string | Required | The resource name of the Case to add Tag for. Format - projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ/cases/ο»Ώ. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
tag | string | Optional | The tag to add to the case. |
Input Example
{"json_body":{"tag":"tag-1234567890"},"path_parameters":{"name":"projects/1234567890/locations/us-central1/instances/1234567890/cases/1234567890"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Get Case
Retrieve detailed information about a specific incident case from Google Chronicle Legacy API using the provided case name.
Endpoint
- URL: v1alpha/{{name}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.expand | string | Optional | Expand field for getting related resources. |
path_parameters.name | string | Required | The resource name of the Case to retrieve. Format - projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ/cases/ο»Ώ. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
Input Example
{"parameters":{"expand":"expand-1"},"path_parameters":{"name":"projects/1234567890/locations/us-central1/instances/1234567890/cases/1234567890"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Legacy Create or Update Case
Create or update cases in Google Chronicle Legacy API using the specified instance and caseResource details.
Endpoint
- URL: v1alpha/{{instance}}/legacy:legacyCreateOrUpdateCase
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.instance | string | Required | The name of the parent resource, which is the SecOps instance this request is sent to. Format - projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
caseResource | object | Optional | The case to be created or updated. |
caseResource.id | string | Optional | The ID of the case. |
caseResource.soarPlatformInfo | object | Optional | Case related info of this same case in customer's SOAR platform. |
caseResource.soarPlatformInfo.caseId | string | Optional | Id of the case in SOAR product. |
caseResource.soarPlatformInfo.responsePlatformType | string | Optional | Type of SOAR product. |
caseResource.displayName | string | Optional | The display name of the case. |
caseResource.stage | string | Optional | The stage of the case. Predefined values include "Triage", "Assessment", "Investigation", "Incident", "Improvement", "Research". And users can define custom string values. |
caseResource.priority | string | Optional | The priority of the case. |
caseResource.status | string | Optional | The status of the case. |
caseResource.alertIds | array | Optional | Alert IDs that are part of this case. |
Input Example
{"json_body":{"caseResource":{"id":"case-1234567890","soarPlatformInfo":{"caseId":"case-1234567890","responsePlatformType":"RESPONSE_PLATFORM_TYPE_UNSPECIFIED"},"displayName":"testing case 1","stage":"STAGE_UNSPECIFIED","priority":"PRIORITY_UNSPECIFIED","status":"STATUS_UNSPECIFIED","alertIds":["alert-1234567890"]}},"path_parameters":{"instance":"projects/1234567890/locations/us-central1/instances/1234567890"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Legacy Get Detection
Retrieve a specific detection from Google Chronicle Legacy API using the provided instance, ruleId, and detectionId.
Endpoint
- URL: v1alpha/{{instance}}/legacy:legacyGetDetection
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.ruleId | string | Required | The specific rule revision to get a detection for. Here are two acceptable formats - ο»Ώ gets a detection for the latest revision of the Rule with rule ID ruleId - ο»Ώ@ο»Ώ gets a detection for the Rule revision with rule ID ruleId and revision ID revisionId. |
parameters.detectionId | string | Required | The detection to get. |
path_parameters.instance | string | Required | The instance to get a detection for. The name of the parent resource, which is the SecOps instance this request is sent to. Format - projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
Input Example
{"parameters":{"ruleId":"1234567890","detectionId":"1234567890"},"path_parameters":{"instance":"projects/1234567890/locations/us-central1/instances/1234567890"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Legacy Search Curated Detections
Retrieve detections linked to a specific Curated Rule in Google Chronicle, utilizing 'instance' and 'ruleId' for targeted results.
Endpoint
- URL: v1alpha/{{instance}}/legacy:legacySearchCuratedDetections
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.ruleId | string | Required | The specific Curated Rule ID to list detections for. Detections will be aggregated across all versions of the rule. |
parameters.alertState | string | Optional | Filters which detections are returned by their AlertState. |
parameters.startTime | string | Optional | The time to start search detections from, inclusive. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples - "2014-10-02T15:01:23Z", "2014-10-02T15:01:23.045123456Z" or "2014-10-02T15:01:23+05:30". |
parameters.endTime | string | Optional | The time to end search detections from, exclusive. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples - "2014-10-02T15:01:23Z", "2014-10-02T15:01:23.045123456Z" or "2014-10-02T15:01:23+05:30". |
parameters.listBasis | string | Optional | The basis on which detections are listed. |
parameters.pageSize | number | Optional | The maximum number of detections to return. The service may return fewer than this value. If unspecified, at most 100 detections will be returned. The maximum value is 1000; values above 1000 will be coerced to 1000. |
parameters.pageToken | string | Optional | A page token, received from a previous legacy.legacySearchCuratedDetections call. Provide this to retrieve the subsequent page. When paginating, all other parameters provided to legacy.legacySearchCuratedDetections must match the call that provided the page token. |
parameters.maxRespSizeBytes | number | Optional | The maximum size of response in bytes. If it is set to 0 (or is omitted), the server will not enforce any max response size limit. |
parameters.includeNestedDetections | boolean | Optional | If true, include one level of nested detections in the response. |
path_parameters.instance | string | Required | The name of the parent resource, which is the SecOps instance this request is sent to. Format - projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
Input Example
{"parameters":{"ruleId":"1234567890","alertState":"NOT_ALERTING","startTime":"2014-10-02T15:01:23Z","endTime":"2014-10-02T15:01:23Z","listBasis":"LIST_BASIS_UNSPECIFIED","pageSize":100,"pageToken":"testtoken","maxRespSizeBytes":1024,"includeNestedDetections":true},"path_parameters":{"instance":"projects/1234567890/locations/us-central1/instances/1234567890"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Legacy Search Detections
Search for detections linked to a rule version in Google Chronicle Legacy API using 'instance' and 'ruleId'.
Endpoint
- URL: v1alpha/{{instance}}/legacy:legacySearchDetections
- Method: GET
Input
Argument Name | Type | Required | Description | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
parameters.ruleId | string | Required | The specific rule revision to search detections for. There are four acceptable formats - ο»Ώ retrieves detections for the latest revision of the Rule with rule ID | ruleId | - ο»Ώ@ο»Ώ retrieves detections for the Rule revision with rule ID | ruleId | and revision ID | revisionId | . - ο»Ώ@ο»Ώ retrieves detections for all revisions of the Rule with rule ID | ruleId | . - ο»Ώ retrieves detections for all revisions of all Rules. |
parameters.alertState | string | Optional | Filters which detections are returned by their AlertState. | ||||||||
parameters.startTime | string | Optional | The time to start search detections from, inclusive. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples - "2014-10-02T15:01:23Z", "2014-10-02T15:01:23.045123456Z" or "2014-10-02T15:01:23+05:30". | ||||||||
parameters.endTime | string | Optional | The time to end search detections from, exclusive. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples - "2014-10-02T15:01:23Z", "2014-10-02T15:01:23.045123456Z" or "2014-10-02T15:01:23+05:30". | ||||||||
parameters.listBasis | string | Optional | The basis on which detections are listed. | ||||||||
parameters.pageSize | number | Optional | The maximum number of detections to return. The service may return fewer than this value. If unspecified, at most 100 detections will be returned. The maximum value is 1000; values above 1000 will be coerced to 1000. | ||||||||
parameters.pageToken | string | Optional | A page token, received from a previous legacy.legacySearchDetections call. Provide this to retrieve the subsequent page. When paginating, all other parameters provided to legacy.legacySearchDetections must match the call that provided the page token. | ||||||||
parameters.maxRespSizeBytes | number | Optional | The maximum size of response in bytes. If it is set to 0 (or is omitted), the server will not enforce any max response size limit. | ||||||||
parameters.includeNestedDetections | boolean | Optional | If true, include one level of nested detections in the response. | ||||||||
path_parameters.instance | string | Required | The name of the parent resource, which is the SecOps instance this request is sent to. Format - projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ. | ||||||||
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
Input Example
{"parameters":{"ruleId":"1234567890","alertState":"NOT_ALERTING","startTime":"2014-10-02T15:01:23Z","endTime":"2014-10-02T15:01:23Z","listBasis":"LIST_BASIS_UNSPECIFIED","pageSize":100,"pageToken":"testtoken","maxRespSizeBytes":1024,"includeNestedDetections":true},"path_parameters":{"instance":"projects/1234567890/locations/us-central1/instances/1234567890"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Legacy Search Rule Detection Events
List events linked to a detection rule in Google Chronicle Legacy API using 'instance' and 'ruleId'.
Endpoint
- URL: v1alpha/{{instance}}/legacy:legacySearchRuleDetectionEvents
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.ruleId | string | Required | The rule ID that generated the detection. |
parameters.versionTimestamp | string | Optional | The version timestamp of the rule that generated the detection. If omitted, the latest version of the rule will be used. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples - "2014-10-02T15:01:23Z", "2014-10-02T15:01:23.045123456Z" or "2014-10-02T15:01:23+05:30". |
parameters.detectionId | string | Optional | The ID of the detection. |
parameters.maxEvents | number | Optional | Max events returned over all event variables. The default and limit is 100k events over all event variables. The events of this detection are sorted by event timestamp, truncated to maxEvents events, and grouped by event variable in the response. |
path_parameters.instance | string | Required | Chronicle instance this request is sent to. Format - projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
Input Example
{"parameters":{"ruleId":"1234567890","versionTimestamp":"2014-10-02T15:01:23Z","detectionId":"1234567890","maxEvents":10000},"path_parameters":{"instance":"projects/1234567890/locations/us-central1/instances/1234567890"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Legacy Update Alert
Update an existing alert in Google Chronicle Legacy API using the provided alertId and feedback. Requires instance as a path parameter.
Endpoint
- URL: v1alpha/{{instance}}/legacy:legacyUpdateAlert
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.instance | string | Required | Chronicle instance this request is sent to. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
alertId | string | Optional | The unique identifier for the alert to be updated. |
feedback | object | Optional | Parameter for Legacy Update Alert |
feedback.verdict | string | Optional | A verdict on whether the finding reflects a security inc. |
feedback.reputation | string | Optional | A categorization of the finding as useful or not useful. |
feedback.confidenceScore | number | Optional | Confidence score (0-100) of the finding. |
feedback.riskScore | number | Optional | Risk score (0-100) of the finding. |
feedback.disregarded | boolean | Optional | Analyst disregard (or un-disregard) the event. |
feedback.severity | number | Optional | Severity score (1-100) of the finding. |
feedback.comment | string | Optional | Analyst comment. |
feedback.status | string | Optional | The status of the alert. |
feedback.priority | string | Optional | The priority of the alert. |
feedback.rootCause | string | Optional | The root cause of the alert. |
feedback.reason | string | Optional | The reason for the alert. |
feedback.severityDisplay | string | Optional | Severity display name for UI and filtering. |
feedback.triageAgentInvestigationId | string | Optional | Output only. Investigation Id of the latest investigation performed by the Triage Agent on the alert. The Triage Agent is designed to autonomously investigate alerts and determine whether an alert needs to be escalated to a human while providing transparency about the actions it took as part of its investigation. |
feedback.userType | string | Optional | Output only. Type of user that submitted or updated the feedback. This field is used to distinguish between the feedback submitted by a human analyst and an AI agent. By default, the user is assumed to be a human analyst. |
caseName | string | Optional | The case name that the alert is associated with. |
responsePlatformInfo | object | Optional | The response platform info of the alert. |
responsePlatformInfo.alertId | string | Optional | Id of the alert in SOAR product. |
responsePlatformInfo.responsePlatformType | string | Optional | Type of SOAR product. |
Input Example
{"json_body":{"alertId":"alert 1","feedback":{"verdict":"MALICIOUS","reputation":"HIGH","confidenceScore":85,"riskScore":70,"disregarded":false,"severity":4,"comment":"Suspicious activity detected.","status":"OPEN","priority":"HIGH","rootCause":"Phishing email","reason":"SUSPICIOUS_BEHAVIOR","severityDisplay":"Critical","triageAgentInvestigationId":"invest-67890","userType":"EMPLOYEE"},"caseName":"case name 1","responsePlatformInfo":{"alertId":"alert 1","responsePlatformType":"RESPONSE_PLATFORM_TYPE_UNSPECIFIED"}},"path_parameters":{"instance":"testing 1"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
List Cases
Retrieve a list of cases from Google Chronicle Legacy API using the specified 'parent' path parameter.
Endpoint
- URL: v1alpha/{{parent}}/cases
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.pageSize | number | Optional | The maximum number of cases to return. The service may return fewer than this value. If unspecified, at most 50 Cases will be returned. The maximum value is 1000; values above 1000 will be coerced to 1000. |
parameters.pageToken | string | Optional | A page token, received from a previous cases.list call. Provide this to retrieve the subsequent page. When paginating, all other parameters provided to cases.list must match the call that provided the page token. |
parameters.filter | string | Optional | A filter to apply to the list of Cases. Supported filter fields - displayName , creatorUserId , creatorUser , lastModifyingUserId , lastModifyingUser , assignee , assignedUser , stage , priority , important , type , environment , case_data_state , score , alertsSla , sla , tags , products , closureDetails , tasks. |
parameters.orderBy | string | Optional | Configures ordering of Cases in the response. If not specified, Cases are returned in descending order of their create time. The default ordering is by create time in descending order. The orderBy string is a comma separated list of fields. Supported sort fields - displayName , creatorUserId , creatorUser , lastModifyingUserId , lastModifyingUser , assignee , assignedUser , stage , priority , important , type , environment , case_data_state , score , alertsSla , sla , tags , products , closureDetails , tasks. |
parameters.expand | string | Optional | Expand the response to include the full case object. Supported values - tasks, tags, products. |
path_parameters.parent | string | Required | The instance to list Cases for. Format - projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ/cases. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
Input Example
{"parameters":{"pageSize":100,"pageToken":"testtoken","filter":"displayName='some_name'","orderBy":"displayName desc, priority","expand":"tags, products"},"path_parameters":{"parent":"projects/1234567890/locations/us-central1/instances/1234567890/cases"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
List Rules
Retrieve a list of detection rules from Google Chronicle Legacy API using the specified 'parent' path parameter.
Endpoint
- URL: v1alpha/{{parent}}/rules
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.pageSize | number | Optional | The maximum number of rules to return. The service may return fewer than this value. If unspecified, at most 100 rules will be returned. The maximum value is 1000; values above 1000 will be coerced to 1000. |
parameters.pageToken | string | Optional | A page token, received from a previous rules.list call. Provide this to retrieve the subsequent page. When paginating, all other parameters provided to rules.list must match the call that provided the page token. |
parameters.view | string | Optional | View indicates the scope of fields to populate for the Rule being returned. If unspecified, defaults to BASIC. |
parameters.filter | string | Optional | Only the following filters are allowed - "referenceLists:ο»Ώ", "dataTables:ο»Ώ", "displayName:ο»Ώ". |
path_parameters.parent | string | Required | The parent, which owns this collection of rules. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
Input Example
{"parameters":{"pageSize":50,"pageToken":"testtoken","view":"RULE_VIEW_UNSPECIFIED","filter":"referenceLists:{reference_list_name}"},"path_parameters":{"parent":"projects/1234567890/locations/us-central1/instances/1234567890"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Merge Cases
Combine multiple cases into one within Google Chronicle using the parent case ID and specific case IDs to merge.
Endpoint
- URL: v1alpha/{{parent}}/cases:merge
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.parent | string | Required | The instance to merge cases on. Format - projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ/cases. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
casesIds | array | Optional | The IDs of the cases to merge. |
caseToMergeWith | number | Optional | The ID of the case to merge with. |
Input Example
{"json_body":{"casesIds":[1234567890,1234567891],"caseToMergeWith":1234567890},"path_parameters":{"parent":"projects/1234567890/locations/us-central1/instances/1234567890/cases"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Patch Case
Update an existing case in Google Chronicle Legacy API using the specified 'case_name'. Requires path parameters and JSON body.
Endpoint
- URL: v1alpha/{{case_name}}
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.updateMask | string | Optional | The list of fields to update. If not included, all fields with default/non-default values will be overwritten. This is a comma-separated list of fully qualified names of fields. |
path_parameters.case_name | string | Required | The unique name(ID) of the Case. Format - projects/ο»Ώ/locations/ο»Ώ/instances/ο»Ώ/cases/ο»Ώ. |
timeout | integer | Optional | Maximum number of seconds to wait for the search to complete before timing out. Default is 600 seconds (10 minutes). |
Input Example
{"parameters":{"updateMask":"user.displayName,photo"},"json_body":{},"path_parameters":{"case_name":"projects/1234567890/locations/us-central1/instances/1234567890/cases/1234567890"}}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
Output Example
{"data":{}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |