Tool: evaluate_rule_coverage_long_running
Evaluates rule coverage for a given set of synthetic UDM events by ingesting them into the customer environment and initiating evaluation.
Input Requirements: - threat_detection_opportunity_events: A list of objects containing threat_detection_opportunity_id and udms_json. - threat_detection_opportunity_id is REQUIRED for each entry. This ID exists in the TDO object returned by the generate_threat_detection_opportunity tool. - exclude_composite_coverage: Optional boolean. Set to true to exclude composite rules from running, which can help reduce coverage evaluation time.
Workflow Integration & Order of Operations: - This tool MUST be called AFTER ALL synthetic logs are generated for ALL TDOs using generate_synthetic_events. Do not call this tool while synthetic log generation is still in progress for other TDOs. - Once all synthetic events are ready, bundle them into threat_detection_opportunity_events and call this tool once to initiate the coverage evaluation.
Instructions for Polling with get_operation: - This tool returns a google.longrunning.Operation object containing an operation name (e.g., projects/.../operations/dea-12345) and done: false. - You MUST use the get_operation tool, passing the returned name as the name parameter, to poll for completion. - Poll get_operation periodically (once a minute) until done is true. - When done is true, the result.response field in the operation will contain an EvaluateRuleCoverageLongRunningResponse object. - EvaluateRuleCoverageLongRunningResponse contains coverage_results: a list of EvaluatedRuleCoverageResult objects (each having matched_rule, feedback_id, and threat_detection_opportunity_id). - Inspect coverage_results to determine which rules matched which TDOs. If coverage_results is empty for a TDO, there is a coverage gap and you should call generate_rules next.
Example Usage: - evaluate_rule_coverage_long_running(project_id='my-project', region='us', customer_id='my-instance', threat_detection_opportunity_events=[{'threat_detection_opportunity_id': 'tdo-123', 'udms_json': ['{"metadata": {"event_timestamp": "2023-10-27T10:00:00Z"}}']}], exclude_composite_coverage=true)
The following sample demonstrate how to use curl to invoke the evaluate_rule_coverage_long_running MCP tool.
| Curl Request |
|---|
curl --location 'https://chronicle.googleapis.com/mcp' \ --header 'content-type: application/json' \ --header 'accept: application/json, text/event-stream' \ --data '{ "method": "tools/call", "params": { "name": "evaluate_rule_coverage_long_running", "arguments": { // provide these details according to the tool's MCP specification } }, "jsonrpc": "2.0", "id": 1 }' |
Input Schema
Request message for EvaluateRuleCoverageLongRunning.
EvaluateRuleCoverageLongRunningRequest
| JSON representation |
|---|
{
"projectId": string,
"customerId": string,
"region": string,
"threatDetectionOpportunityEvents": [
{
object ( |
| Fields | |
|---|---|
projectId |
Required. Google Cloud project ID. |
customerId |
Required. Chronicle customer ID. |
region |
Required. Chronicle region (e.g., "us", "europe"). |
threatDetectionOpportunityEvents[] |
Required. The TDO events to evaluate rule coverage for. |
excludeCompositeCoverage |
Optional. Whether to exclude composite rules from the evaluation. |
ThreatDetectionOpportunityEvents
| JSON representation |
|---|
{ "threatDetectionOpportunityId": string, "udmsJson": [ string ] } |
| Fields | |
|---|---|
threatDetectionOpportunityId |
Required. The id of the associated Threat Detection Opportunity. |
udmsJson[] |
Required. The input JSON UDM to evaluate all managed content rules against. |
Output Schema
This resource represents a long-running operation that is the result of a network API call.
Operation
| JSON representation |
|---|
{ "name": string, "metadata": { "@type": string, field1: ..., ... }, "done": boolean, // Union field |
| Fields | |
|---|---|
name |
The server-assigned name, which is only unique within the same service that originally returns it. If you use the default HTTP mapping, the |
metadata |
Service-specific metadata associated with the operation. It typically contains progress information and common metadata such as create time. Some services might not provide such metadata. Any method that returns a long-running operation should document the metadata type, if any. An object containing fields of an arbitrary type. An additional field |
done |
If the value is |
Union field result. The operation result, which can be either an error or a valid response. If done == false, neither error nor response is set. If done == true, exactly one of error or response can be set. Some services might not provide the result. result can be only one of the following: |
|
error |
The error result of the operation in case of failure or cancellation. |
response |
The normal, successful response of the operation. If the original method returns no data on success, such as An object containing fields of an arbitrary type. An additional field |
Any
| JSON representation |
|---|
{ "typeUrl": string, "value": string } |
| Fields | |
|---|---|
typeUrl |
Identifies the type of the serialized Protobuf message with a URI reference consisting of a prefix ending in a slash and the fully-qualified type name. Example: type.googleapis.com/google.protobuf.StringValue This string must contain at least one The prefix is arbitrary and Protobuf implementations are expected to simply strip off everything up to and including the last All type URL strings must be legal URI references with the additional restriction (for the text format) that the content of the reference must consist only of alphanumeric characters, percent-encoded escapes, and characters in the following set (not including the outer backticks): In the original design of |
value |
Holds a Protobuf serialization of the type described by type_url. A base64-encoded string. |
Status
| JSON representation |
|---|
{ "code": integer, "message": string, "details": [ { "@type": string, field1: ..., ... } ] } |
| Fields | |
|---|---|
code |
The status code, which should be an enum value of |
message |
A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the |
details[] |
A list of messages that carry the error details. There is a common set of message types for APIs to use. An object containing fields of an arbitrary type. An additional field |
Tool Annotations
Destructive Hint: ❌ | Idempotent Hint: ❌ | Read Only Hint: ✅ | Open World Hint: ❌