-
Notifications
You must be signed in to change notification settings - Fork 4
/
Copy pathrule.go
126 lines (116 loc) · 3.94 KB
/
rule.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
package qradar
import (
"context"
"fmt"
"net/http"
)
// RuleService handles methods related to Rule of the QRadar API.
type RuleService service
const ruleAPIPrefix = "api/analytics/rules"
// Rule represents QRadar's Rule.
type Rule struct {
ID *int `json:"id,omitempty"`
Name *string `json:"name,omitempty"`
Type *string `json:"type,omitempty"`
Enabled *bool `json:"enabled,omitempty"`
Owner *string `json:"owner,omitempty"`
Origin *string `json:"origin,omitempty"`
BaseCapacity *int `json:"base_capacity,omitempty"`
BaseHostID *int `json:"base_host_id,omitempty"`
AverageCapacity *int `json:"average_capacity,omitempty"`
CapacityTimestamp *int `json:"capacity_timestamp,omitempty"`
Identifier *string `json:"identifier,omitempty"`
LinkedRuleIdentifier *string `json:"linked_rule_identifier,omitempty"`
CreationDate *int `json:"creation_date,omitempty"`
ModificationDate *int `json:"modification_date,omitempty"`
}
// Get returns Rules of the current QRadar installation.
func (c *RuleService) Get(ctx context.Context, fields, filter string, from, to int) ([]Rule, error) {
req, err := c.client.requestHelp(http.MethodGet, ruleAPIPrefix, fields, filter, from, to, nil, nil)
if err != nil {
return nil, err
}
var result []Rule
_, err = c.client.Do(ctx, req, &result)
if err != nil {
return nil, err
}
return result, nil
}
// GetByID returns Rule of the current QRadar installation by ID.
func (c *RuleService) GetByID(ctx context.Context, fields string, id int) (*Rule, error) {
req, err := c.client.requestHelp(http.MethodGet, ruleAPIPrefix, fields, "", 0, 0, &id, nil)
if err != nil {
return nil, err
}
var result Rule
_, err = c.client.Do(ctx, req, &result)
if err != nil {
return nil, err
}
return &result, nil
}
// UpdateByID updates the rule owner or toggle the rule enabled/disabled by ID.
func (c *RuleService) UpdateByID(ctx context.Context, fields string, id int, data interface{}) (*Rule, error) {
req, err := c.client.requestHelp(http.MethodPost, ruleAPIPrefix, fields, "", 0, 0, &id, data)
if err != nil {
return nil, err
}
var result Rule
_, err = c.client.Do(ctx, req, &result)
if err != nil {
return nil, err
}
return &result, nil
}
// DeleteByID creates A Delete Task in QRadar installation in order to safely delete Rule by ID.
func (c *RuleService) DeleteByID(ctx context.Context, fields string, id int) (*DeleteTask, error) {
req, err := c.client.requestHelp(http.MethodDelete, ruleAPIPrefix, fields, "", 0, 0, &id, nil)
if err != nil {
return nil, err
}
var result DeleteTask
_, err = c.client.Do(ctx, req, &result)
if err != nil {
return nil, err
}
return &result, nil
}
// GetByName returns Rule of the current QRadar installation by Name.
func (c *RuleService) GetByName(ctx context.Context, fields string, name string) (*Rule, error) {
req, err := c.client.requestHelp(http.MethodGet, ruleAPIPrefix, fields, fmt.Sprintf("name=\"%s\"", name), 0, 0, nil, nil)
if err != nil {
return nil, err
}
var result []Rule
_, err = c.client.Do(ctx, req, &result)
if err != nil {
return nil, err
}
if len(result) == 0 {
return nil, nil
}
if len(result) > 1 {
return nil, fmt.Errorf("found more rules than expected - %d", len(result))
}
return &result[0], nil
}
// GetByUUID returns Rule of the current QRadar installation by UUID.
func (c *RuleService) GetByUUID(ctx context.Context, fields string, uuid string) (*Rule, error) {
req, err := c.client.requestHelp(http.MethodGet, ruleAPIPrefix, fields, fmt.Sprintf("identifier=\"%s\"", uuid), 0, 0, nil, nil)
if err != nil {
return nil, err
}
var result []Rule
_, err = c.client.Do(ctx, req, &result)
if err != nil {
return nil, err
}
if len(result) == 0 {
return nil, nil
}
if len(result) > 1 {
return nil, fmt.Errorf("found more rules than expected - %d", len(result))
}
return &result[0], nil
}