Node

A generic node in a graph.

JSON representation
{
  "id": string,
  "displayName": string,

  // The following is a list of mutually exclusive fields. At most one of the
  // fields will be set in a response:
  "individualNode": {
    object (IndividualNode)
  },
  "groupNode": {
    object (GroupNode)
  }
  // End of mutually exclusive fields.
}
Fields
id

string

Required. The unique string id of the node.

displayName

string

Output only. The display name of the node.

Detailed information about a node. A node can be either an individual node or a group node. The following is a list of mutually exclusive fields. At most one of the fields will be set in a response:
individualNode

object (IndividualNode)

A individual node which contains a resource.

groupNode

object (GroupNode)

A group node in a graph which represents a collection of individual nodes.

End of mutually exclusive fields.

IndividualNode

A individual node which contains a resource.

JSON representation
{
  "adjacentIndividualNodesCount": integer,

  // The following is a list of mutually exclusive fields. At most one of the
  // fields will be set in a response:
  "detection": {
    object (Collection)
  },
  "indicatorSummary": {
    object (IndicatorSummary)
  }
  // End of mutually exclusive fields.
}
Fields
adjacentIndividualNodesCount

integer

Output only. The number of individual nodes adjacent to the current node.

Detailed information of the node. The following is a list of mutually exclusive fields. At most one of the fields will be set in a response:
detection

object (Collection)

Output only. Detail about a detection node.

indicatorSummary

object (IndicatorSummary)

Output only. Indicator summary information about an entity node.

End of mutually exclusive fields.

IndicatorSummary

A summary of aliased indicators of an entity.

JSON representation
{
  "entity": string,
  "timeRange": {
    object (Interval)
  },
  "displayIndicator": {
    object (EntityIndicator)
  },
  "aliases": [
    {
      object (IndicatorAliases)
    }
  ],
  "entityRiskScore": integer
}
Fields
entity

string

The resource name of an entity. Format: projects/{project}/locations/{location}/instances/{instance}/entities/{entity}

timeRange

object (Interval)

The time range that the aliases are valid for. This is the same as the Entity interval, and is duplicated here for convenience.

displayIndicator

object (EntityIndicator)

The EntityIndicator used to represent the IndicatorSummary.

aliases[]

object (IndicatorAliases)

A list of IndicatorAliases across different time ranges.

entityRiskScore

integer

The risk score of the entity at the end of the time range.

IndicatorAliases

A list of aliased indicators within a time range.

JSON representation
{
  "timeRange": {
    object (Interval)
  },
  "aliases": [
    {
      object (EntityIndicator)
    }
  ]
}
Fields
timeRange

object (Interval)

The time range of the aliases is valid for.

aliases[]

object (EntityIndicator)

A list of aliased indicators within the time range.

GroupNode

A group node in a graph, which can be a indicator-related detection group or a rule-related detection group.

JSON representation
{
  "groupNodeDetail": {
    object (GroupNodeDetail)
  },
  "individualNodeCount": integer
}
Fields
groupNodeDetail

object (GroupNodeDetail)

Output only. The detail information of a group node.

individualNodeCount

integer

Output only. The individual nodes count in the group.

GroupNodeDetail

Detail information of a group node.

JSON representation
{
  "parentNodeId": string,

  // The following is a list of mutually exclusive fields. At most one of the
  // fields will be set in a response:
  "indicatorRelatedDetectionGroup": {
    object (DetectionGroup)
  },
  "ruleRelatedDetectionGroup": {
    object (DetectionGroup)
  },
  "entityGroupMetadata": {
    object (EntityGroupMetadata)
  }
  // End of mutually exclusive fields.
}
Fields
parentNodeId

string

The source of the parent node of the current group node. The parent node can only be an individual node.

The detailed information about a group node. The following is a list of mutually exclusive fields. At most one of the fields will be set in a response:
entityGroupMetadata

object (EntityGroupMetadata)

An entity group.

End of mutually exclusive fields.

DetectionGroup

A detection group, which contains fields about how the detections got grouped.

JSON representation
{
  "alertState": enum (AlertState),
  "rule": string,
  "ruleDisplayName": string
}
Fields
alertState

enum (AlertState)

Output only. The state of a detection representing if the detection is an alert or not.

rule

string

Optional. The Rule a detection generated from. Format: projects/{project}/locations/{location}/instances/{instance}/rules/{rule}

ruleDisplayName

string

Output only. The rule display name.

AlertState

The alert state of a detection.

Enums
ALERT_STATE_UNSPECIFIED The default/unset value. The API will default to the ALERT_STATE_ALERTING.
ALERT_STATE_NOT_ALERTING A not alerting state.
ALERT_STATE_ALERTING An alerting state.

EntityGroupMetadata

An entity group metadata, which contains fields about how the entities got grouped.

JSON representation
{
  "entityType": enum (EntityType)
}
Fields
entityType

enum (EntityType)

Output only. The type of entities in the group.