Schemas
abs.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
abs.SettingsConfig
account_urlRepresents your storage account in Azure. Typically of the format https://{account}.blob.core.windows.net.
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
compressionThe compression method to be applied to the data before storing in Azure
containerA container organizes a set of blobs, similar to a directory in a file system.
The format config to use
partition_formatDirectory structure used to partition stored objects. Options: simple date (e.g., '2024/01/01'), hive compliant (e.g., 'year=2024/month=01/day=01'), and flat hive compliant (e.g., 'dt=2024-01-01').
prefixAn optional prefix for Azure object keys to organize data within the container
add_id.ArgumentsConfig
keyThe key to add to the record with id value
typeThe type of the identifier
alerts.AlertMeta
categoryconfigdescriptiongranularityhouseinternalmanaged_bynametiertype_idarize_audit_logs.SecretsConfig
APIKey for GreyNoise Community API
arize_audit_logs.SettingsConfig
backfill_start_timeDate to start fetching data from.
interval_secondsTime interval in seconds between consecutive GraphQL API calls
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source
authenticationtypes.AuthenticationMethod
confirmedcreated_atcredential_backed_upcredential_device_typeemailidkey_idlink_idnamephone_numberpublic_keytypeuser_agentauthenticationtypes.TokenResponse
access_tokenemailexpires_inid_tokenrefresh_tokentoken_typeaws_s3.SettingsConfig
bucketName of the S3 bucket.
compressionCompression format of the S3 objects.
formatFile format of the S3 objects.
partition_formatPartition format of your S3 bucket. Options: hive compliant ('year=2024/month=01/day=01'), flat hive compliant ('dt=2024-01-01'), or simple date ('2024/01/01').
schemaOrdered list of column names for headerless delimited files (e.g. PSV). Applies to the "delimited" format only; the "csv" and "wsv" formats always read column names from the first row and ignore this field.
backfill_start_timeDate to start fetching data from. If not specified, no past objects are fetched and ingestion starts from now. All syncs thereafter are incremental.
Optional S3 key filter. nil pointer = no filtering.
prefixPrefix of the S3 object keys to read.
record_locationLocation of the record in the JSON object. This can be ignored if the record is not in JSON format. Leave empty if you want the entire record.
regionAWS Region of your bucket.
role_arnRole ARN to assume when reading from S3.
aws_sqs_s3_cloudtrail.ChunkingMode
ChunkingMode for the Records array. Empty → by_size.
aws_sqs_s3_cloudtrail.SettingsConfig
queue_urlregionchunking_modeChunkingMode for the Records array. Empty → by_size.
exclude_digest_filesExcludeDigestFiles skips keys containing "/CloudTrail-Digest/" (hash signatures, not events).
role_arnuse_fipsuses_snswith_metadataaws_sqs_s3_guardduty.SettingsConfig
queue_urlregionrole_arnuse_fipsuses_snswith_metadataawssqsoutput.QueueType
The type of SQS queue to use. Can be either "standard" or "fifo".
awssqsoutput.SettingsConfig
message_group_idThe message group ID for FIFO queues. This is required for FIFO queues.
queue_typeThe type of SQS queue to use. Can be either "standard" or "fifo".
queue_urlThe URL of the SQS queue to poll for messages.
regionThe AWS region where the SQS queue is located.
role_arnThe ARN of the IAM role to assume for accessing the SQS queue.
awssqss3.SettingsConfig
compressionCompression of S3 objects. oneof must mirror compression_handlers.ListCompressions(); TestCompressionFormatTagDrift guards drift.
formatFormat of S3 objects. oneof must mirror format_handlers.ListFormats(); TestCompressionFormatTagDrift guards drift. csv is omitted because format_handlers' package init wipes its Formats map after per-file inits register, so ListFormats() doesn't include csv today.
queue_urlregionOptional S3 key filter. nil pointer = no filtering.
record_locationRecord location within each parsed object. JSON only; empty = whole record.
role_arnuse_fipsuses_snswith_metadataaxiom.SettingsConfig
datasetName of the Axiom dataset in which data will be written
azure_activity_logs.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
azure_activity_logs.SettingsConfig
correlation_idThe correlation ID of the log
Optional outbound request rate limit. Falls back to the Wiz default when unset.
resource_group_nameThe name of the resource group
resource_providerThe provider of the resource
resource_uriThe URI of the resource
subscription_idThe subscription ID of the Azure subscription
tenant_idThe tenant ID of the Azure AD application
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
azure_blob_storage.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
azure_blob_storage.SettingsConfig
account_urlRepresents your storage account in Azure. Typically of the format https://{account}.blob.core.windows.net.
backfill_start_timeStarting timestamp for initial data sync. Only processes blobs with a last modified time after this timestamp on the initial sync. If not specified, all available data from the specified prefix will be processed. Incremental syncs automatically continue from the last processed timestamp, scanning from the previous day's partition forward to catch late-arriving data. Files updated in partitions older than the current state's previous prefix will not be detected.
compressionThe compression format of objects in the Azure container
containerA container organizes a set of blobs, similar to a directory in a file system.
formatFile format of the Blob storage objects in Azure.
partition_formatPartition format of your Azure container. Options: hive compliant ('year=2024/month=01/day=01'), flat hive compliant ('dt=2024-01-01'), simple date ('2024/01/01'), or custom (specify your own template in PartitionFormatTemplate).
partition_format_templateOnly used when PartitionFormat is "custom": the template describing your bucket's partition path, e.g. 'y={yyyy}/m={mm}/d={dd}'.
prefixAn optional prefix for Azure object keys to organize data within the container
record_locationLocation of the record in the object. Applies only for JSON objects. Leave empty for the entire record.
azure_event_hubs.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
azure_event_hubs.SettingsConfig
consumer_groupThe consumer group name for reading events (default: $Default)
event_hub_nameThe name of the specific Event Hub to consume from
event_hub_namespaceThe fully qualified namespace URL (e.g., your-namespace.servicebus.windows.net)
lookback_durationThe duration to look back for events in minutes (default: 60 minutes)
record_locationLocation of the record in the JSON object. Leave empty if you want the entire record.
subscription_idThe Azure subscription ID containing your Event Hubs namespace
tenant_idThe Azure Entra ID tenant (directory) ID
azure_vnet_flow_logs.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
azure_vnet_flow_logs.SettingsConfig
regionThe Azure region where the virtual network is located
resource_group_nameThe name of the resource group containing the virtual network
storage_account_urlThe Azure storage account URL where flow logs are stored
subscription_idThe Azure subscription ID where the virtual network and storage account are located
tenant_idThe Azure Entra ID tenant (directory) ID.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
virtual_network_nameThe name of the virtual network for which flow logs are being collected
backblaze.SettingsConfig
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
bucketThe name of the B2 bucket where data will be stored
compressionThe compression method to be applied to the data before storing in B2
The format config to use
partition_formatDirectory structure used to partition stored objects. Options: simple date (e.g., '2024/01/01'), hive compliant (e.g., 'year=2024/month=01/day=01'), and flat hive compliant (e.g., 'dt=2024-01-01').
prefixAn optional prefix for B2 object keys to organize data within the bucket
regionThe B2 region/endpoint (e.g., us-west-001)
backblaze_b2.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
backblaze_b2.SettingsConfig
backfill_start_timeDate to start fetching data from
bucketName of the B2 bucket
compressionCompression format of the B2 objects
formatFile format of the B2 objects
partition_formatPartition format of your B2 bucket. Options: hive compliant ('year=2024/month=01/day=01'), flat hive compliant ('dt=2024-01-01'), or simple date ('2024/01/01').
prefixPrefix of the B2 object keys to read
record_locationLocation of the record in the object. Applies only for JSON objects. Leave empty for the entire record.
regionB2 Region of your bucket (e.g., us-west-001, us-west-002, eu-central-003)
batch_config.BatchConfig
batch_data_sizebatch_record_countpublish_ratebigquery.SettingsConfig
datasetThe name of the BigQuery dataset where the table resides
project_idThe Google Cloud Project ID where the BigQuery instance is located
tableThe name of the table where the data will be written
bigquery_input.SettingsConfig
datasetThe BigQuery dataset ID containing the table
projectThe GCP project ID containing the BigQuery dataset
queryOptional custom query to use instead of table (must include timestamp_column)
tableThe BigQuery table ID to query data from
timestamp_columnThe column containing timestamp values used for incremental loading
blastradius.BlastRadius
blocking_countnot tied to a specific instance
instance_countorganization_countwarning_countblastradius.Finding
bad_valuecodefieldmessageseverityblastradius.InstanceImpact
node_idorganization_idorganization_namepipeline_idpipeline_namebrinqa_audit_logs.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
brinqa_audit_logs.SettingsConfig
backfill_start_timeDate to start fetching data from. If not specified, a full sync is fetched on the first sync. All syncs thereafter will be incremental.
hostnameThe Brinqa environment hostname (e.g., "ssb.brinqa.net")
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
buildkite_graphql_input.SettingsConfig
enable_paginationEnable pagination support
graphql_queryThe GraphQL query to execute against the endpoint to fetch data
has_next_page_pathJSONPath location to check if there are more pages
interval_secondsTime interval in seconds between consecutive GraphQL API calls
pagination_cursor_pathJSONPath location for pagination cursor/token
record_locationJSONPath location of the records array in the GraphQL response
GraphQL query variables to pass with each request
cato_networks_events.SettingsConfig
account_idID of account for which the events need to be fetched
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
cisa_user.SettingsConfig
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
cloud_configuration_findings.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
cloud_configuration_findings.SettingsConfig
endpoint_urlEndpoint URL for the Wiz API. Ex: 'https://api.wiz.io/v1/cloud-configuration-findings'.
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
resultResult types for Wiz. Ex: 'PASSED', 'FAILED', 'ERROR', 'NOT ASSESSED'.
severitySeverity types for Wiz. Ex: 'CRITICAL', 'HIGH', 'MEDIUM', 'LOW', 'NONE'.
statusStatus types for Wiz. Ex: 'OPEN', 'RESOLVED', 'REJECTED'.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
cloud_logs.SettingsConfig
enable_proto_payload_parsingEnables automatic parsing of embedded protocol buffer payloads within the input.
filterThe filter to apply to the logs.
resource_namesThe resources to query logs from.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
cloud_resource_inventory.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
cloud_resource_inventory.SettingsConfig
endpoint_urlEndpoint URL for the Wiz API. Ex: 'https://api.wiz.io/v1/cloud-resource-inventory'.
entityTypeEntity types for Wiz.
backfill_start_timeDate to start fetching data from. If not specified, A Wiz report is generated on the first sync. All syncs thereafter will be of incremental data.
cloudPlatformCloud Platform types for Wiz. Ex: 'AWS', 'AZURE', 'GCP'.
full_snapshotFullSnapshot indicates whether to fetch a full snapshot of the cloud resource inventory.
intervalDefines how frequently (in hours) the system polls the Wiz API to retrieve updated data. Only applicable when full_snapshot is enabled. The interval timer begins after each sync operation completes.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
cloudflare_ddos_attack_analytics.SecretsConfig
APIKey for GreyNoise Community API
cloudflare_ddos_attack_analytics.SettingsConfig
account_idCloudflare Account ID
backfill_start_timeThe date to start fetching data from (RFC3339 format). If not specified, fetches all available data within API retention limits.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
cloudflare_firewall_events.SecretsConfig
APIKey for GreyNoise Community API
cloudflare_firewall_events.SettingsConfig
include_bot_fieldsInclude Bot Management fields (requires Enterprise plan with Bot Management add-on)
lookback_durationInitial lookback duration for first sync (e.g., "24h", "168h"). Respects API retention limits.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
zone_idCloudflare Zone ID
cloudflare_http_requests.SecretsConfig
APIKey for GreyNoise Community API
cloudflare_http_requests.SettingsConfig
fieldsFields to include in the query. Leave empty to use default curated list. Only fields available to your account will be included (validated against API). Maximum 50 fields due to API constraints.
lookback_durationInitial lookback duration for first sync (e.g., "24h", "168h"). Respects API retention limits.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
zone_idCloudflare Zone ID
cloudflare_url_scanner.SecretsConfig
APIKey for GreyNoise Community API
cloudflare_url_scanner.SettingsConfig
account_idCloudflare Account ID
backfill_start_timeDate to start fetching data from (RFC3339 format). Note: Historical data availability depends on your Cloudflare plan (Free: last 50 scans, Self Serve: 30 days, Enterprise: 12 months, Cloudforce One: unlimited)
filter_my_scansFilter to only show scans created by the current API token
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source
cloudflare_zero_trust_access_requests.SecretsConfig
APIKey for GreyNoise Community API
cloudflare_zero_trust_access_requests.SettingsConfig
account_idCloudflare Account ID
backfill_start_timeDate to start fetching data from (RFC3339 format)
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source
cloudtrail.SettingsConfig
backfill_start_timeDate to start fetching data from. If not specified, a full sync of data upto now would be performed on the first sync. All syncs thereafter will be incremental.
bucketThe name of the S3 bucket
prefixPrefix of the S3 object keys to read.
regionThe region of the S3 bucket
role_arnThe ARN of the role to assume to access the bucket
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
clumio_audit_logs.SettingsConfig
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
regionThe region associated with your Clumio account
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
clumio_consolidated_alerts.SettingsConfig
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
parent_entity_idThe system-generated ID of the parent entity that is associated with the primary entity affected by the alert.
parent_entity_typeThe system-generated name of the parent entity that is associated with the primary entity affected by the alert.
regionThe region associated with your Clumio account
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
common.AuthConfig
typecommon.GitHubAppVariant
client_idinstallation_idAPIKey for GreyNoise Community API
common.PersonalAccessTokenVariant
APIKey for GreyNoise Community API
community_edition.SecretsConfig
APIKey for GreyNoise Community API
community_edition.SettingsConfig
destination_pathDestinationPath is the path where the GreyNoise data will be stored
error_on_rate_limitErrorOnRateLimit determines if rate limiting should cause an error (true) or return custom response (false)
ip_address_pathIPAddressPath is the path to a field containing an IP address to look up
no_match_responseNoMatchResponse is the value to add when no match is found
omit_metadatarate_limit_responseRateLimitResponse is the value to add when rate limited
community_transforms_internal.TransformConfig
authorcontributorsdescriptioninputsnametagscommunity_transforms_internal.TransformMetadata
authorcontributorscreated_atdescriptioninputslast_modifiednamepathtagscommunity_transforms_internal.TransformsIndex
last_updatedschema_hashHash of the schema structure
connectormeta.ResourceMetadata
categorydescriptionhousein_betanametiertype_idconvert_cef.ArgumentsConfig
Custom CEF-key -> output-column map; entries override the preset.
continuation_markerCollector continuation marker, e.g. "#LF#" or "#012"; "" disables continuation handling.
continuation_mode"spill" (default), "keep", or "newline".
dialect"cef" (spec-faithful, default) or "legacy_kv" (bug-compat with jq CEF parsers).
empty_to_nullWrite empty-string values as null. Default false.
Output field -> record path (JSONPath), copied verbatim; missing -> null.
header_fieldsExactly 7 output names for the header slots; default per preset.
iso_date_columnsOutput columns rewritten "YYYY/MM/DD HH:MM:SS" -> "YYYY-MM-DDTHH:MM:SSZ".
keySource key holding the CEF line (JSONPath). Default "message".
numeric_columnsOutput columns coerced to number (invalid -> null); unset = preset default, [] = off.
output_keyTarget key when output_mode is "under_key".
output_mode"replace" (default), "merge", or "under_key".
overflow_fieldUnmapped keys joined into this field; "" emits unmapped keys as individual fields.
overflow_separatorSeparator between overflow entries. Default ";".
preset"" (none), "cef_full_names", or "common_security_log".
resolve_labelsPromote csN/csNLabel-style pairs into fields named by the label. Default false.
strictFail the record on structural problems instead of best-effort parsing. Default false.
strip_quotesRemove one leading+trailing double-quote from values that carry both. Default false.
warnings_keyWrite parse warnings as a string array under this key; "" (default) omits them.
convert_timestamp.ArgumentsConfig
source_formatRequired: Format of source timestamp
source_format_customOptional: Custom Go time layout (only if SourceFormat = "custom")
source_keyRequired: JSONPath to source timestamp field
source_timezoneOptional: Source timezone (default: UTC)
target_formatRequired: Format of source timestamp
target_format_customOptional: Custom target format (only if TargetFormat = "custom")
target_keyOptional: Target field (if empty, overwrites SourceKey)
target_timezoneOptional: Target timezone (default: UTC)
convert_timestamp.TimestampFormat
Required: Format of source timestamp
coralogix.RESTVariant
APIKey for GreyNoise Community API
coralogix.SettingsConfig
application_nameApplicationName is stamped on every record. Coralogix uses this to separate environments/tenants.
regionCoralogix region (e.g. us1, eu2). Determines which regional ingress hostname is used. See https://coralogix.com/docs/integrations/coralogix-endpoints/.
subsystem_nameSubsystemName is stamped on every record. Coralogix uses this to separate components within an application.
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
timestamp_record_locationTimestampRecordLocation is an optional JSONPath ($.event.time) or
gjson path pointing at the timestamp field inside each incoming record.
When unset the connector stamps the current time on every record; when
set the connector reads the field and fails the batch if the value is
not a parseable timestamp.
cortex_xsoar_management_logs.SecretsConfig
APIKey for GreyNoise Community API
cortex_xsoar_management_logs.SettingsConfig
api_key_idAPI Key ID for authentication
domain_nameDomain name of the Cortex XSOAR instance
backfill_start_timeStart time for backfilling data
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
create_key_value_if_key_value.ArgumentsConfig
keyThe key to add to the record
key_to_watchThe key to watch for
valueThe value to add to the record
value_to_watchThe value to watch for
cribl_http.SettingsConfig
ingress_addressYour group's ingress address found in your group information panel. This is the hostname where your Cribl instance is accessible.
pathThe path you've set for your HTTP Source's HTTP Event API. This is the endpoint path where data will be sent. Note: You do not need to append _bulk to this path as monad already does this for you.
portThe port you've set your HTTP Source to listen on. This should be the port number where your Cribl HTTP Source is configured to receive data.
databricks_delta_table.AutoLoaderWriteMode
volumeThe Unity Catalog Volume used for staging JSONL files for Autoloader to ingest.
databricks_delta_table.CopyIntoWriteMode
http_pathThe SQL warehouse HTTP path from connection details (e.g. /sql/1.0/warehouses/abc123). Required for copy_into mode; not needed for autoloader.
table_nameThe target Delta table name. Required for copy_into mode. If the table doesn't exist, Monad will create it.
volumeThe Unity Catalog Volume used for staging JSONL files before COPY INTO.
databricks_delta_table.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
databricks_delta_table.SettingsConfig
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
catalogThe Unity Catalog name
schemaThe target schema within the catalog
server_hostnameThe Databricks workspace hostname (e.g. adb-1234567890.azuredatabricks.net)
The write mode controls how data is loaded.
databricks_delta_table.WriteMode
write_modedatabricks_delta_table.ZeroBusWriteMode
regionThe Databricks workspace region (e.g. us-west-2) used to form the ZeroBus data-plane endpoint.
table_nameThe target Delta table name. The table must already exist with the expected schema.
workspace_idThe numeric Databricks workspace ID used to scope the ZeroBus OAuth token and form the data-plane endpoint.
databricks_lakehouse.AutoLoaderWriteMode
volumeThe Unity Catalog Volume used for staging JSONL files
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
Who manages the Auto Loader ingestion pipeline; omitted means self-managed
databricks_lakehouse.MonadManagedPipeline
intervalHow often the pipeline runs, in minutes; defaults to 60
table_nameThe bronze table the pipeline writes into; defaults to bronze_
databricks_lakehouse.PipelineConfig
modedatabricks_lakehouse.SettingsConfig
catalogThe Unity Catalog name
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
schemaThe target schema within the catalog
server_hostnameThe Databricks workspace hostname (e.g. adb-1234567890.azuredatabricks.net)
The write mode: autoloader stages files for Databricks Autoloader to ingest; zerobus sends data via the ZeroBus streaming protocol
databricks_lakehouse.WriteMode
write_modedatabricks_lakehouse.ZeroBusWriteMode
regiontable_nameworkspace_idControls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
datadog.SettingsConfig
ddsourceThe integration name associated with your log: the technology from which the log originated. When it matches an integration name, Datadog automatically installs the corresponding parsers and facets.
ddtagsTags associated with your logs.
domain_urlThe base domain of the Datadog API (e.g., us5.datadoghq.com). Logs are sent to https://http-intake.logs.<DOMAIN_URL>/api/v2/logs
hostnameThe name of the originating host of the log.
serviceThe name of the application or service generating the log events. It is used to switch from Logs to APM, so make sure you define the same value when you use both products.
datastore.TaggedResource
idkindnametypeconnector sub_type; empty for pipelines
dedup.ArgumentsConfig
fieldsfields to key on, in order; empty = whole record
windowdedup window / key TTL: one of 1m..5m
defender_for_endpoint_alerts.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
defender_for_endpoint_alerts.SettingsConfig
categoryOptional outbound request rate limit. Falls back to the Wiz default when unset.
severitytenant_iduse_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
drop_key_where_value_eq.ArgumentsConfig
keyThe key to drop from the record
valueThe value to drop to check for equality with the record's value
drop_record_where_value_eq.ArgumentsConfig
keyThe key which values should be checked
valueThe value to compare with the record's value
duplicate_key_value_to_key.ArgumentsConfig
keyThe key to duplicate from the record
new_keyThe new key to duplicate the value to
elasticsearch.SecretVariant
APIKey for GreyNoise Community API
elasticsearch.SettingsConfig
indexThe name of the Elasticsearch index to write data to. If the index doesn't exist, it will be created automatically. Supports date templating, e.g. "index-test-{yyyy}-{mm}-{dd}". Tokens are resolved against the current UTC time at write time. Supported tokens: {yyyy}, {yy}, {mm}, {dd}, {hh}, {mi}, {ss}. Must not be a data stream, or a name that matches a data stream index template such as "logs--".
usernameUsername for authenticating with the Elasticsearch cluster.
auth_typeDEPRECATED: use AuthConfig & ConnectionConfig instead
cloud_idconnection_typeinsecure_skip_verifyIf set to true, it skips verification of the server's TLS certificate. This is insecure and should only be used for testing purposes.
urlencrypt.ArgumentsConfig
Encryption algorithm configuration
keyKey whose value will be encrypted
endor_labs_audit_logs.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
endor_labs_audit_logs.SettingsConfig
namespaceYour Endor Labs organization namespace (e.g., "your-org")
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
enrichment.ConnectorMeta
configconnector_categorydescriptionhousein_betainternalnamerelease_datetiertype_identra_id.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
entra_id.SettingsConfig
categoryThe Category of logs to query
tenant_idThe tenant ID of the Azure AD application
workspace_idThe workspace ID of the Log Analytics workspace
backfill_start_timeThe date to start fetching data from on first sync
ingestion_delayThe ingestion delay in seconds for the data source
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
event.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
event.SettingsConfig
app_nameThe application name the connector uses to connect to the CrowdStrike data stream. It's important that this name is unique to avoid conflicts with other applications connecting to the same stream. You're advised to use a unique identifier for this application. For example, if you have 2 stream input connections they should not both share the same name.
cloudYour cloud type for CrowdStrike. Ex: 'autodiscover', 'us-1', 'us-2', 'eu-1', 'us-gov-1'.
member_cidIn environments where an entity (like an MSSP) manages security for multiple clients, each client is typically assigned a unique CID. This identifier allows the managing entity to access and operate within the specific customer's environment. This is crucial for scenarios where operational isolation between different clients' data and configurations is necessary.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
flatten.ArgumentsConfig
delimiterThe delimiter to use when flattening for example flattening an array of assets: _ would result in assets_0, assets_1
keyThe key to flatten
flattenall.ArgumentsConfig
delimiterThe delimiter to use when flattening for example flattening an array of assets: _ would result in assets_0, assets_1
formatter.FormatConfig
FormatConfiguration for formatting data in Apache Parquet format
full_scans.SecretsConfig
APIKey for GreyNoise Community API
full_scans.SettingsConfig
org_slugCron expression for scheduling the input
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
repoA repository slug to filter full-scans by.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
geolocus.SettingsConfig
destination_pathDestinationPath is the path where Geolocus results will be added to each record
ip_address_pathIPAddressPath is the path to a field containing an IP address to look up
no_match_responseNoMatchResponse is the value to add when no match is found
omit_metadatagithub_actions_workflow_logs_webhook.ScopeConfig
typegithub_actions_workflow_logs_webhook.SettingsConfig
APIKey for GreyNoise Community API
AuthConfig downloads logs; needs actions:read on the scoped repos.
github_com_monad-inc_core_pkg_types_models.Pagination
limitoffsettotalgke_audit_logs.SecretsConfig
APIKey for GreyNoise Community API
gke_audit_logs.SettingsConfig
cluster_nameThe name of the GKE cluster.
locationThe GCP location (region or zone) where the GKE cluster runs, e.g. us-central1.
project_idThe GCP project ID that contains the GKE cluster.
google_cloud_storage.SettingsConfig
bucket_nameThe name of the Google Cloud Storage bucket to use
compressionCompression format of the Google Cloud Storage objects.
formatThe format of the files in the bucket, e.g., "json", "csv", etc.
partition_formatPartition format of your bucket. Options: hive compliant ('year=2024/month=01/day=01'), flat hive compliant ('dt=2024-01-01'), or simple date ('2024/01/01').
project_idThe Google Cloud project ID to use
backfill_start_timeDate to start fetching data from. If not specified, no past objects are fetched and ingestion starts from now.
cronOptional cron schedule to control polling cadence. Blank keeps the default continuous polling.
prefixThe prefix to use when reading from the bucket. This is used to filter objects in the bucket.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
record_locationLocation of the record in the object. Applies only for JSON objects. Leave empty for the entire record.
google_cloud_storage_output.SettingsConfig
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
bucketThe name of the bucket where data will be stored
compressionThe compression method to be applied to the data before storing
The format config to use
partition_formatDirectory structure used to partition stored objects. Options: simple date (e.g., '2024/01/01'), hive compliant (e.g., 'year=2024/month=01/day=01'), and flat hive compliant (e.g., 'dt=2024-01-01').
prefixAn optional prefix for object keys to organize data within the bucket
google_secops.SettingsConfig
collection_time_pathAPIKey for GreyNoise Community API
instance_idlog_entry_time_pathlog_typeproject_idregionControls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
compressendpointenvironment_namespaceforwardergoogle_workspace.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
google_workspace.SettingsConfig
auth_typeAuthentication type (service_account or oauth)
backfill_start_timeDate to start fetching data from. If not specified, a full sync of data from google workspace is fetched on the first sync. All syncs thereafter will be incremental.
emailEmail address to use for authenticating with Google Cloud (required for service_account auth).
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
hash.ArgumentsConfig
algorithmHash algorithm
fieldsFields to hash, in order; empty hashes the whole record
keyKey to store the resulting hash in
http.PayloadStructure
Determines how the payload is structured. 'single' sends each record as a separate request, 'array' sends multiple records as an array, 'wrapped' sends multiple records within a wrapper object.
http.SettingsConfig
endpointThe full URL of the HTTP endpoint to send data to. Must include the scheme (http or https).
Non secret headers
max_batch_data_sizeThe maximum size in KB for a single batch of data to be sent in one request. This does not effect the single payload structure.
max_batch_record_countThe maximum number of records to include in a single batch. For single payload structure, this is automatically set to 1. For other payload structures, this determines the maximum number of records sent in a single request.
methodThe HTTP method to use for requests (GET, POST, PUT, PATCH, or DELETE).
payload_structureDetermines how the payload is structured. 'single' sends each record as a separate request, 'array' sends multiple records as an array, 'wrapped' sends multiple records within a wrapper object.
rate_limitMaximum number of requests per second to send to the endpoint.
tls_skip_verifySkip TLS verification.
wrapper_keyThe key to use for wrapping the payload when PayloadStructure is set to 'wrapped'.
hydrolix.AuthConfig
typehydrolix.PasswordAuth
APIKey for GreyNoise Community API
usernameHydrolix user account username.
hydrolix.ServiceAccountAuth
APIKey for GreyNoise Community API
hydrolix.SettingsConfig
Authentication method. Either a static service-account bearer token or a username/password pair exchanged at Init time for a 24h access token.
hostThe hostname of the Hydrolix cluster (no scheme). Example: mycluster.hydrolix.live.
tableThe fully-qualified target table in the form project.table. Sent as
the X-Hdx-Table header on /ingest/event.
APIKey for GreyNoise Community API
transformOptional transform schema Hydrolix should apply when handling payloads.
Sent as the X-Hdx-Transform header.
ibm_qradar.AuthConfig
typeibm_qradar.BasicAuthVariant
APIKey for GreyNoise Community API
usernameUsername for HTTP Basic authentication.
ibm_qradar.CommunicationConfig
typeibm_qradar.EventFormatConfig
typeibm_qradar.HTTPSMTLSVariant
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
insecure_skip_verifyibm_qradar.HTTPSVariant
APIKey for GreyNoise Community API
insecure_skip_verifyWhether to skip TLS certificate verification (not recommended for production).
ibm_qradar.HeaderAuthVariant
header_nameHeader name to send (e.g. 'Authorization' or 'X-Api-Key').
APIKey for GreyNoise Community API
ibm_qradar.SettingsConfig
hostHostname or IP of the QRadar HTTP Receiver log source. Do not include a scheme or a port here.
portTCP port the HTTP Receiver log source listens on (configured on the QRadar log source).
Optional authentication for the HTTP Receiver. Leave unset for an unauthenticated log source.
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
Transport mode: plain HTTP, HTTPS, or HTTPS with mutual TLS.
How events are framed in the request body. Must match the QRadar log source's Event Parsing Method.
individual_alerts.SettingsConfig
alert_typeFilter by alert type (e.g., policy_violated, tag_conflict)
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
embedEmbed related resources in the data returned (e.g., read-consolidated-alert)
primary_entity_typeFilter by primary entity type (e.g., aws_ebs_volume, vmware_vm)
primary_entity_valueFilter by primary entity value (contains search)
regionThe region associated with your Clumio account
severityFilter by alert severity (error, warning)
statusFilter by alert status (active, cleared)
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
inputs.ConnectorMeta
billing_typecategoryconfigdescriptionhousein_betainternalis_defaultnamerelease_datetiertype_idversionissues.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
issues.SettingsConfig
tenant_data_centerDataCenter represents the tenant's data center location @Description Enter a tenant data center, e.g., "us1", "us2", "us3" @Description Find your tenant data center on the Tenant Info page in Wiz, or request it from your Wiz customer contact
backfill_start_timeDate to start fetching data from. If not specified, A Wiz report is generated on the first sync. All syncs thereafter will be of incremental data.
control_ids@Description Filter Issues created by specific control IDs
has_note@Description Filter Issues with or without a note
has_remediation@Description Filter Issues with or without remediation
has_service_ticket@Description Filter Issues with or without related service ticket
issue_ids@Description Filter only Issues that match these specific IDs
issue_types@Description Filter by Issue type
project_ids@Description Filter Issues associated with specific project IDs
Optional outbound request rate limit. Falls back to the Wiz default when unset.
related_entity_id@Description Filter by related entity ids
resolution_reasons@Description Filter Issues by resolution reason
risk_equals_all@Description Filters Issues by risk type according to Wiz-defined types of risk @Description Use the risk ID and not the risk name @Description All specified risks must be present
risk_equals_any@Description Filters Issues by risk type according to Wiz-defined types of risk @Description Use the risk ID and not the risk name
search_query@Description Free text search on Issue title or object name @Description Returns NULL if no match is found
security_scan@Description Filter by security scan source
severities@Description Filter Issues according to Control severity
stack_layers@Description Filter Issues from specific stack layers
status@Description Filter by Issue handling status @Description Default: OPEN
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
jq.ArgumentsConfig
keyOptional key to store result under
prevent_data_droppingPreventDataDropping errors instead of dropping the record when the query produces no output. Only applies when Key is unset, since storing the result under a key always emits a record.
queryThe raw query string from config
json.JsonFormatter
typekeykafka.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
kafka.SettingsConfig
acksAcknowledgment level (0=none, 1=leader only, all=all replicas)
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
bootstrap_serversComma-separated list of Kafka broker addresses (host:port)
compression_typeCompression codec for messages (none, gzip, snappy, lz4, zstd)
Static headers to add to each Kafka message
message_key_fieldJSON field path to extract as the Kafka message key (uses gjson syntax)
payload_formatHow records map onto Kafka messages: individual (one message per record) or json_array (bundle the whole batch into a single JSON-array message)
retriesNumber of retry attempts for failed writes
sasl_mechanismSASL authentication mechanism (PLAIN, SCRAM-SHA-256, SCRAM-SHA-512)
security_protocolSecurity protocol for broker connections (NONE, SASL_PLAINTEXT, SASL_SSL, SSL)
topicThe Kafka topic to publish messages to
usernameUsername for SASL authentication
kafka.acks
Acknowledgment level (0=none, 1=leader only, all=all replicas)
kafka.compressionType
Compression codec for messages (none, gzip, snappy, lz4, zstd)
kafka.payloadFormat
How records map onto Kafka messages: individual (one message per record) or json_array (bundle the whole batch into a single JSON-array message)
kafka.saslMechanism
SASL authentication mechanism (PLAIN, SCRAM-SHA-256, SCRAM-SHA-512)
kafka.securityProtocol
Security protocol for broker connections (NONE, SASL_PLAINTEXT, SASL_SSL, SSL)
koi_audit_logs.SecretsConfig
APIKey for GreyNoise Community API
koi_audit_logs.SettingsConfig
audit_log_typesFilter audit logs by type(s). Available types: approval_requests, devices, endpoints, extensions, firewall. Leave empty to fetch all types.
backfill_start_timeBackfillStartTime is an optional ISO8601 timestamp to start fetching from. If not set, the input starts from the current time (no historical backfill). Example: "2024-01-01T00:00:00Z"
base_urlBase URL for the Koi API (default: https://api.prod.koi.security)
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
kv_lookup.SettingsConfig
destination_keyDestinationKey is the path where the result will be stored in the record
error_on_missing_keyErrorOnMissingKey If true, throw an error when key is not found in the KV store
join_pathJoinPath is the path to a field whose values will be used as the lookup keys
kv_lookup_output_idKVLookupOutputID is the id of the KV lookup output to join with
no_match_responseNoMatchResponse is the value to add to the record when no match is found
omit_metadatakv_lookup_output.SettingsConfig
key_fieldThe field in the incoming record to use as the key
ttlTime-to-live in seconds for stored key-value pairs, between 5 seconds and 48 hours
value_fieldThe field in the incoming record to use as the value
kvlookup.GetMetadataResponse
byteslast_ingested_timemax_bytesnumber_of_keysttllog_analytics_query.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
log_analytics_query.SettingsConfig
queryThe query to run against the Log Analytics workspace
tenant_idThe tenant ID of the Azure AD application
workspace_idThe workspace ID of the Log Analytics workspace
backfill_start_timeThe date to start fetching data from on first sync
ingestion_delayThe ingestion delay in seconds for the data source
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
looker_audit_logs.SecretsConfig
APIKey for GreyNoise Community API
looker_audit_logs.SettingsConfig
log_categoriesThe audit log categories to ingest.
project_idsThe GCP project IDs hosting Looker Core instances.
mask.ArgumentsConfig
keyKey whose value will be masked
Masking mode. Simple replaces values with a fixed mask. Deterministic produces a stable, correlatable output using HMAC.
mask.ModeConfig
simpletypeType of masking mode. "simple" or "deterministic". Defaults to "simple".
math_multiply_with_value.ArgumentsConfig
keyThe Key value to multiply
new_keyThe key to store the result of the multiplication
valueThe value to multiply with
microsoft_365_generic.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
microsoft_365_generic.SettingsConfig
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
tenant_idThe Azure Entra ID tenant (directory) ID
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
models.APIKey
created_atdescriptionexpiration_timeidjwt_signing_key_idJWTSigningKeyID is the jwt_signing_keys row that signed the key's current token. Re-stamped on rotation. Empty when signed via the legacy HS256 path (no signing-key row), or for keys created before this was recorded.
last_used_atLastUsedAt is when the key, or a token minted from it, last authenticated a request. Recorded at most once a minute, so it can lag real use by that much. Nil when the key has not been used since tracking began.
nameorganization_idrole_idtoken_versionTokenVersion is the current generation of the key. It is embedded in
minted JWTs as the ver claim and bumped on rotation to invalidate
previously-issued tokens without changing the key's id.
updated_atmodels.APIKeyWithToken
created_atdescriptionexpiration_timeidjwt_signing_key_idJWTSigningKeyID is the jwt_signing_keys row that signed the key's current token. Re-stamped on rotation. Empty when signed via the legacy HS256 path (no signing-key row), or for keys created before this was recorded.
last_used_atLastUsedAt is when the key, or a token minted from it, last authenticated a request. Recorded at most once a minute, so it can lag real use by that much. Nil when the key has not been used since tracking began.
nameorganization_idrole_idtokentoken_versionTokenVersion is the current generation of the key. It is embedded in
minted JWTs as the ver claim and bumped on rotation to invalidate
previously-issued tokens without changing the key's id.
updated_atmodels.Alert
created_atincident start (frozen across re-fires)
descriptionfired_atthis emission's fire time; differs per re-fire
idmetadatanameorganization_idrule_idrule_typeseveritymodels.AlertRule
activecreated_atdescriptionidinvert_selectionInvertSelection flips the meaning of PipelineIDs from an include-list to an exclude-list, so the rule monitors every pipeline except those listed. It only applies to pipeline-granularity rule types; billing- and organization-scoped types never consult PipelineIDs.
managed_bynameorganization_idpipeline_idsseveritytypeupdated_atmodels.AlertStatus
clearing_started_atWhen clearing began
resolved_atUnix timestamp when resolved
statemodels.BillingAccount
billing_emailcreated_atcurrent_billing_cycle_endcurrent_billing_cycle_startdeleted_atdescriptionhas_payment_methodidnamenext_product_idproduct_change_afterproduct_idstatussuspend_onupdated_atmodels.BillingAccountRole
billing_account_idcreated_atdescriptionidnamepermissionsupdated_atmodels.BillingProduct
contact_emailcreated_atdescriptionfeaturesidis_defaultnameproduct_typerecurring_cost_centsrecurring_frequencyslugupdated_atusage_unitusage_unit_cost_centsmodels.ComponentReference
idkindbase type (input, output, enrichment)
nametypemodels.ComponentType
base type (input, output, enrichment)
models.ConditionEvaluatable
leaf config
operatorOnly set for logical nodes
type_idOnly set for leaf nodes
models.Connection
created_atdescriptionemail_domainsidnameorganization_idpublic_namesaml_entity_idsaml_metadata_urlSessionSettings controls the session length for logins through this connection. Optional; nil preserves the existing value, non-nil overwrites.
typeupdated_atmodels.ConnectionSessionSettings
session_timeoutmodels.Enrichment
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
typeupdated_atversionmodels.Input
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
typeupdated_atversionmodels.InputConnectorCategory
models.InputRateLimit
rateunitmodels.MCPClientRegistration
client_idclient_namecreated_by_user_idgrant_typeslast_used_atorganization_idredirect_urisrevoked_atsoftware_idsoftware_versiontoken_endpoint_auth_methodupdated_atmodels.NodeComponent
The blocks below are populated only for a node carrying an override delta, so the UI can derive per-field overridden markers client-side without a server-built per-field structure (R-1). A node with no delta leaves them empty, and BaseConfig == Config.
BaseConfig is the component's config before the override delta is applied.
Config is the node's effective config: for a node carrying an override delta it is the base merged with that delta (RFC 0017 §3); otherwise it is the component's base config unchanged.
descriptionidnameOverrides is the node's sparse override delta (secrets as {id} refs only).
ResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
typeversionmodels.Organization
billing_account_idconnection_idcreated_atdescriptionfriendly_nameidnameparent_organization_idupdated_atmodels.OrganizationAuditLog
actionidoccurred_atorganization_idrequest_idmodels.OrganizationAuditLogHistogram
bucket_secondsearliest_occurred_atlatest_occurred_attotalmodels.OrganizationUser
connection_idcreated_atemailidinheritedrole_idrole_namesource_organization_idsource_organization_nameupdated_atusernamemodels.Output
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
typeupdated_atversionmodels.OutputConnectorCategory
models.Permission
created_atdescriptionidnameslugupdated_atmodels.Pipeline
component_tiercreated_atcron_scheduledescriptionenabledidinput_idmanaged_bynameorganization_idtagscustomer tag names
updated_atmodels.PipelineConfigV2
billingAccountIdcomponent_tiercreatedAtcron_scheduledescriptionenabledidis_syntheticmanaged_bynamenext_cron_run_atorganizationIdorganizationNameDeprecated: Never set. Removed along with pkg/datastore/postgres.
routableRoutable is set by the api from the inputs registry when the pipeline's input is a push (HTTP, OTEL, TCP) input, and the pipeline-operator labels the Pipeline from it. omitempty keeps it off customer reads and leaves the ConfigHash unchanged for non-push pipelines.
tagsTags is the pipeline's customer tag names, populated only on customer reads (never on the operator path), so omitempty keeps the ConfigHash unchanged and tag edits don't roll pods.
updatedAtmodels.PipelineEdge
created_atdescriptiondisabledfrom_node_instance_ididnameorganization_idpipeline_idto_node_instance_idupdated_atmodels.PipelineMetrics
end_atmetricnode_idnode_slugorganization_idorganization_namepipeline_idpipeline_nameresolutionstart_atmodels.PipelineNode
component_housecomponent_idcomponent_sub_typecomponent_typebase type (input, output, enrichment)
ConfigOverrides is the node's sparse override delta over its component's base config (RFC 0017 §3). Nil when the node has no override.
created_atenabledidorganization_idpipeline_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
slugmodels.PipelineNodeStatus
avg_bytes_per_record_egressavg_bytes_per_record_ingresscomponent_typecomponent_type_iderrorslast_ingested_timelast_record_processed_timelast_updated_atnode_idnode_slugstatusmodels.PipelineRetentionPolicy
stream_age_limitstream_size_limitmodels.PipelineStatus
average_size_egressedaverage_size_ingestederrorslast_ingested_timelast_updated_atorganization_idorganization_namepipeline_idpipeline_namestatusmodels.ProgressEntry
labelLabel is an optional descriptor that is human-readable and can be displayed in the UI It should mainly be used to contain the field name/path that is used to extract timestamp for a given inputs data
partition_keyPartitionKey is an optional identifier for multi-entity inputs (e.g., "detector-123", "us-east-1") In a case where we store multiple state timestamps for a singular input we would use this field as a differentiator
Ranges represents the time ranges that have been read by an input node. Each range is a tuple of (start, end) timestamps indicating what data has been processed. Multiple ranges allow tracking non-contiguous data reads.
models.ProgressLabel
Label is an optional descriptor that is human-readable and can be displayed in the UI It should mainly be used to contain the field name/path that is used to extract timestamp for a given inputs data
models.Quota
actionbilling_account_idcreated_atcurrent_usagecurrent_usage_updated_atend_atidlimit_amountlimit_typelimit_unitnameorganization_idstart_attimeframeupdated_atmodels.Reference
idnameName is the referenced resource's display name, filled at read time on component responses. Never persisted: writes rebuild references from request state (the name is display sugar and would go stale), and an empty name is omitted from the stored JSON.
organization_idsharedShared reports that the referenced resource is owned by an org other than the component's owner — a directly-shared secret the component pulls in. Same read-time-only contract as Name: computed on responses, never persisted (omitted when false).
models.References
models.ResourceReference
parent_ide.g., pipeline ID if resource is a node
parent_nameHuman-readable name for ParentID
parent_typeFor hierarchical resources
resource_idresource_nameHuman-readable name for ResourceID; omitted when unresolved
resource_type"pipeline", "node", "organization"
models.ResourceShare
created_atWhen the share was created.
idUnique identifier of the share.
owner_organization_idOrganization that owns the shared resource (the parent org).
resource_idIdentifier of the shared secret or component.
resource_typeType of the shared resource: "secret" or "component".
target_organization_idDirect child the resource is shared with.
models.ResourceShareChangeSet
Shares newly created by the request.
Shares revoked (deleted) by the request.
share_with_all_new_childrenThe resource's auto-share policy state after the request.
SkippedInUse holds shares a revoke_all_not_in_use request deliberately left in place because the target org is still using the resource. Empty for every other request shape.
models.ResourceShareTarget
in_useWhether the child is actively using the resource (references a shared secret, or binds a shared component in a pipeline node). Always false when not shared.
nameFriendly name of the child organization.
organization_idThe direct child organization.
sharedWhether the resource is currently shared to this child.
shared_atWhen the share was created; nil when not shared.
models.ResourceShareTargetList
The page of child orgs.
Pagination metadata.
share_with_all_new_childrenWhether the resource's policy auto-shares it with new direct children.
models.ResourceShareWithUsage
created_atWhen the share was created.
idUnique identifier of the share.
in_useWhether the target org is using the shared resource.
owner_organization_idOrganization that owns the shared resource (the parent org).
resource_idIdentifier of the shared secret or component.
resource_typeType of the shared resource: "secret" or "component".
target_organization_idDirect child the resource is shared with.
target_organization_nameFriendly name of the target org.
models.ResourceShareWithUsageList
The shares of a single resource, each with its usage flag.
share_with_all_new_childrenWhether the resource's policy auto-shares it with new direct children.
models.RoleWithPermissions
created_atdescriptionidnameorganization_idprotectedupdated_atmodels.SchemaHistory
created_atedge_idevent_tagsfrom_node_nameidorganization_idpipeline_idpipeline_nameto_node_namemodels.Secret
created_atWhen the secret was created
descriptionThe user set Description of the secret
idThe ID of the secret
nameThe user set Name of the secret
organization_idThe OrganizationID the secret belongs to
ShareDetails is set when the enrichment is involved in org-to-org sharing.
updated_atWhen the secret was updated
valueThe value of the secret. This will never be returned to the client but can be used to set new values when used in a request payload.
models.ShareDetails
owner_organization_idOwnerOrganizationID is the org that owns the resource; set only when SharedWithMe.
owner_organization_nameOwnerOrganizationName is the owner org's friendly name, filled at read time alongside OwnerOrganizationID. Never persisted: friendly names are editable and a stored copy would go stale; omitted when unset.
shared_with_childrenSharedWithChildren is true when the requesting org owns the resource and has shared it out to at least one child org.
shared_with_meSharedWithMe is true when the resource is shared to the requesting org by a parent org.
models.StorageTypeCostEntry
cost_per_gbidoutput_idoutput_namestorage_typemodels.StorageTypeCostSummary
total_org_cost_post_filtertotal_org_cost_pre_filtertotal_org_ingest_bytestotal_org_ingest_gbtotal_org_output_storage_bytestotal_org_output_storage_gbtotal_org_routing_dropped_bytesBytes that reached a routing fan-out and matched none of its edges. They were dropped silently — no output ever saw them — so they are counted in no output's baseline and reported here on their own, where a misrouted pipeline shows up.
total_org_routing_dropped_gbmodels.StorageTypeOutputDetail
cost_idcost_per_gbegress_bytesegress_bytes_gbnum_pipelinespre_filter_bytespre_filter_bytes_gbtotal_cost_post_filtertotal_cost_pre_filtermodels.StorageTypeSummaryResponse
end_atorganization_idorganization_namestart_atmodels.StorageTypeTimeSeriesResponse
end_atmetricorganization_idorganization_nameresolutionstart_atmodels.TimeRange
endEnd is the end of the time range (inclusive)
startStart is the beginning of the time range (inclusive)
models.Transform
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
updated_atversionmodels.TransformsRepositoryTransform
created_atdescriptionidinput_type_idnameupdated_atmodels.UserAuthProvider
connection_idcreated_atidproviderprovider_iduser_idmodels.UserOrganization
billing_account_idcreated_atdescriptionfriendly_nameidinheritednameparent_organization_idsource_organization_idsource_organization_nameupdated_atmodels.UserRoleWithPermissions
inheritedorganization_idrole_idrole_namesource_organization_idmonad_log.SettingsConfig
log_typeuse_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
mutate_type.ArgumentsConfig
keyThe key to mutate the type of
typeThe new type of the key
mutate_value_where_key_eq_and_value_eq.ArgumentsConfig
keyThe key to mutate
valueThe value to check for
value_to_setThe value to set if the key and value match
object_storage.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
object_storage.SettingsConfig
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
bucketThe name of the object storage bucket where data will be stored
compressionThe compression method to be applied to the data before storing
endpointThe endpoint URL for the object storage service (e.g., https://fly.storage.tigris.dev, https://minio.example.com)
The format config to use
partition_formatDirectory structure used to partition stored objects. Options: simple date (e.g., '2024/01/01'), hive compliant (e.g., 'year=2024/month=01/day=01'), and flat hive compliant (e.g., 'dt=2024-01-01').
prefixAn optional prefix for object keys to organize data within the bucket
regionThe region for the object storage service (optional for some providers)
skip_ssl_verificationWhether to skip SSL certificate verification (useful for self-signed certificates or development environments)
use_path_styleWhether to use path-style URLs (bucket.endpoint.com/object vs endpoint.com/bucket/object). Most S3-compatible services require this to be true.
object_storage_input.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
object_storage_input.SettingsConfig
bucketName of the storage bucket
compressionCompression format of the objects
endpointEndpoint URL for the object storage service (e.g., https://minio.example.com, https://s3.amazonaws.com)
formatFile format of the objects
backfill_start_timeDate to start fetching data from. If not specified, no past objects are fetched and ingestion starts from now.
partition_formatPartition format of your bucket. Options: hive compliant ('year=2024/month=01/day=01'), flat hive compliant ('dt=2024-01-01'), or simple date ('2024/01/01').
prefixPrefix that leads to the start of the expected partition. For example: "/foobar/year=2024/month=01/day=01/". The prefix is foobar.
record_locationLocation of the record in the object. Applies only for JSON objects. Leave empty for the entire record.
regionOptional region for the object storage service. This is often required for services like AWS S3.
skip_ssl_verificationSkip SSL verification for self-signed certificates
use_path_styleWhether to use path-style URLs (bucket.endpoint.com/object vs endpoint.com/bucket/object). Most S3-compatible services require this to be true.
opensearch.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
opensearch.SettingsConfig
auth_modeThe authentication mode (basic, aws_role)
indexThe name of the OpenSearch index to use.
insecure_skip_verifyWhether to skip TLS certificate verification (not recommended for production).
regionThe AWS Region where the OpenSearch domain is located
role_arnThe AWS IAM Role ARN to assume (used for aws_role auth)
urlThe URL of the OpenSearch instance (must start with https).
usernameThe username for authenticating with OpenSearch (used for basic auth).
operation_logs.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
operation_logs.SettingsConfig
account_idAccount ID for the input
backfill_start_timeDate to start fetching data from. If not specified, data from 6 months ago up till now from zoom is fetched on the first sync. All syncs thereafter will be incremental.
category_typeThe category of logs to pull
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
org_audit_logs.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
org_audit_logs.SettingsConfig
auth_typeAuthentication type to use
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
github_app_installation_idGitHub App Installation ID (required when using GitHub App authentication)
github_client_idGitHub Client ID (alternative to personal access token)
includeEvent types to include. web: Gets all web (non-git) events. git: Gets git events. all: Gets both.
organizationYour GitHub organization name
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
outputs.ConnectorMeta
billing_typecategoryconfigdescriptionhousein_betainternalnamerelease_datetiertype_idversionpagerduty.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
pagerduty.SettingsConfig
AlertsConfig contains configuration options that apply only when EventType is set to 'alert'
default_event_typeEventType determines whether events are sent as 'change' or 'alert' events. We recommend reading the docs for this output before making this choice.
SummaryConfig allows customization of event summary messages displayed in PagerDuty
pagerduty.alertsConfig
classClass defines the class/type of the event based on the input source. Defaults to an empty value.
groupA cluster or grouping of sources. For example, sources "prod-datapipe-02" and "prod-datapipe-03" might both be part of "prod-datapipe". Applicable if event type is set to alerts. Defaults to an empty value.
severityIndicates the severity of the impact to the affected system. Applicable for you if event type is set to alerts. Defaults to 'critical'.
pagerduty.eventType
EventType determines whether events are sent as 'change' or 'alert' events. We recommend reading the docs for this output before making this choice.
pagerduty.summaryConfig
alert_sourcealertSource is the source identifier for alert events. Defaults to 'monad-platform'.
alert_summaryalertSummary is the custom summary message for alert events. Defaults to 'Monad triggered alert event'.
change_sourcechangeSource is the source identifier for change events. Defaults to 'monad-platform'.
change_summarychangeSummary is the custom summary message for change events. Defaults to 'Monad triggered change event'.
palo_alto_data_security_alerts.SecretsConfig
APIKey for GreyNoise Community API
palo_alto_data_security_alerts.SettingsConfig
base_urlURL of the organization
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
parquet.ParquetFormatter
schemaplaid_webhooks.SettingsConfig
client_idClientID is the Plaid API client_id. Required only when verification is enabled.
verify_webhooksVerifyWebhooks toggles Plaid signature verification. Unset defaults to true.
webhook_typesWebhookTypes restricts which webhook_type values are emitted. Empty = keep all.
postgresql.SettingsConfig
column_namesThe column names to write data to, must match the root fields of the data If not provided all root fields will be used
databaseThe database name to connect to
hostThe host of the PostgreSQL database
portThe port of the PostgreSQL database
tableThe table name to write data to
userThe user to connect to the PostgreSQL database
prometheus.SettingsConfig
endpointlabel_fieldstimestamp_fieldtls_skip_verifyvalue_fieldredshift_audit_logs.SettingsConfig
bucketName of the S3 bucket that receives Redshift audit logs.
log_typeWhich Redshift audit log to ingest. Must be one of the supported log types (connectionlog, userlog).
backfill_start_timeDate to start fetching data from. If not specified, a full sync of data up to now is performed on the first sync; subsequent syncs are incremental.
prefixPrefix of the audit log keys, up to (but not including) the date partition — e.g. "AWSLogs/123456789012/redshift/us-east-1". If you configured a custom S3 key prefix for audit logging, include it here.
regionAWS Region of your bucket.
role_arnRole ARN to assume when reading from S3.
rename_key_where_value_eq.ArgumentsConfig
keyThe key to rename
new_keyThe new key to rename to
valueThe value to check for
routes.CreateOrganizationRequest
namebilling_account_iddescriptionfriendly_nameroutes.GetInputResponse
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
typeupdated_atversionroutes.GetOutputResponse
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
typeupdated_atversionroutes.GetTransformResponse
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
updated_atversionroutes.InputWithMetadata
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
typeupdated_atversionroutes.OutputWithMetadata
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
typeupdated_atversionroutes.RetryQueueMessage
created_atdatadata_bytesDataBytes is the payload size in bytes. Omitted is set when the payload was left out for exceeding maxRetryRecordBytes. (meta_only leaves out every payload without setting Omitted — it isn't a size decision.)
eligible_atEligibleAt is a rough estimate of the earliest retry time (see estEligibleAt), not an authoritative floor — it under-estimates output/enrichment nodes.
error_node_idlast_errorlast_seen_atomittedretry_countstream_seqroutesV2.ApplyTransformationResponse
bytes_afterbytes_beforepercentage_changeroutesV2.CreateAPIKeyRequest
expiration_timenamerole_iddescriptionroutesV2.CreateBillingAccountRequest
billing_emailEmail address for billing
nameName of the billing account
descriptionDescription of the billing account
routesV2.CreateBillingAccountRoleRequest
nameName of the role
permissionsPermission slugs for the role
descriptionDescription of the role
routesV2.CreateBillingAccountSubscriptionRequest
product_idProductID is the ID of the product to subscribe to
routesV2.CreateBillingAccountSubscriptionResponse
checkout_urlCheckoutURL is a secure URL to add payment information and subscribe to the product
routesV2.CreateOutputRequest
descriptionnamepromise_idtypeversionroutesV2.CreatePipelineRequest
namedescriptionenablednil => enabled
tagstag names; must exist in the org
routesV2.CreateRoleV2Request
namepermission_idsdescriptionroutesV2.PipelineRequestEdge
from_node_instance_idto_node_instance_iddescriptiondisabledidnameroutesV2.PipelineRequestNode
component_idcomponent_typebase type (input, output, enrichment)
ConfigOverrides is the per-node override delta applied over the component's base config (RFC 0017). The save-time gate merges it and fully validates the effective config. A non-empty delta requires the pipeline_node_config_overrides flag — see nodeOverridesDisallowed — so the column stays nil for every org until the feature is turned on.
enablednil => enabled
idslugroutesV2.PipelineRoutingDrop
dropped_bytesdropped_gbinput_idpipeline_idroutesV2.RegenerateAPIKeyRequest
expiration_timeOmitted (nil) keeps the key's existing expiration — rotating the secret does not extend the key's term on its own.
routesV2.SecretResponse
created_atdescriptionidnameorganization_idShareDetails is set when the enrichment is involved in org-to-org sharing.
updated_atroutesV2.SecretWithComponentsResponse
created_atdescriptionidnameorganization_idShareDetails is set when the enrichment is involved in org-to-org sharing.
updated_atroutesV2.StorageTypeDetailsResponse
end_atorganization_idorganization_namePipelines that dropped records at routing over the window (matched no edge). Those bytes are in no output's baseline; this is where they can be seen.
start_atroutesV2.StorageTypeOutputDetailResponse
baseline_methodcost_per_gbegress_bytesegress_gbhas_own_priceingress_bytesingress_gbinput_idnode_idoutput_deletedoutput_idoutput_namepipeline_idstorage_typetotal_costroutesV2.TestNodeConnectionRequest
component_typebase type (input, output, enrichment)
typeconnector subtype (e.g. "s3")
versionroutesV2.UpdateBillingAccountRequest
billing_emailEmail address for billing. Nil preserves the current value.
descriptionDescription of the billing account. Nil preserves the current value.
nameName of the billing account. Nil preserves the current value.
routesV2.UpdateBillingAccountRoleRequest
descriptionDescription of the role. Nil preserves the current value.
nameName of the role. Nil preserves the current value.
permissionsPermission slugs for the role. Nil preserves the current value; an empty slice clears all permissions.
routesV2.UpdatePipelineRequest
descriptionenablednametagsTags: nil leaves tags unchanged; a set replaces them; [] clears them.
routesV2.organizationOverview
disabledhealthyunhealthyroutesV2.pipelineStatus
pipeline_idpipeline_namestatusroutesV2.pipelineWithStatus
idstatuslast_ingested_timeroutesV3.AlertRuleWithMetadata
activecreated_atdescriptionidinvert_selectionInvertSelection flips the meaning of PipelineIDs from an include-list to an exclude-list, so the rule monitors every pipeline except those listed. It only applies to pipeline-granularity rule types; billing- and organization-scoped types never consult PipelineIDs.
managed_bynameorganization_idpipeline_idsseveritytypeupdated_atroutesV3.CreateAlertRuleRequest
activeActive indicates whether the alert rule is active
descriptionDescription of the alert rule
invert_selectionInvertSelection reads pipeline_ids as an exclude-list instead of an include-list, so the rule applies to all pipelines except those listed. An empty pipeline_ids still means all pipelines either way.
nameName of the alert rule
pipeline_idsPipeline IDs that this alert rule applies to
RuleConfig contains the configuration for the alert rule
severitySeverity level of the alert. Must be one of "critical", "high", "medium", "low", "info".
typeType of the alert rule
routesV3.CreateChildOrganizationRequest
namedescriptionfriendly_nameroutesV3.CreateConnectionRequest
descriptionDescription of the connection
email_domainsEmailDomains associated with the connection for SP-initiated SSO discovery. Optional; empty/unset falls through to the column default (empty array).
nameName of the connection
public_namePublicName is the customer-controlled label shown to end users in the
SSO discovery picker. Optional; empty/unset falls through to the
column default (an auto-generated sso-<hex> value).
SAML is the configuration for SAML connections
SessionSettings controls the session length for logins through this connection. Optional; nil preserves the existing value, non-nil overwrites.
routesV3.CreateSessionRequest
organization_idOrganizationID, when set, pins the token to that single org via the
scoped_org claim. Omit to inherit the parent key's org access. Not
verified at mint time — the org-access middleware returns 403 at
request time if the parent key has no role in it.
ttl_secondsTTLSeconds is the requested session lifetime in seconds. Defaults to 1800 (30 min). Clamped to [300, 3600] (5 min – 1 hr); a value that would outlive the parent API key is rejected with 400.
routesV3.CreateSessionResponse
expires_atExpiresAt is the token expiry as an RFC 3339 timestamp.
session_tokenSessionToken is the minted short-lived JWT. Send it as a Bearer token.
ttl_secondsTTLSeconds is the effective lifetime applied after clamping.
routesV3.CreateTagRequest
colorColor is an optional hex color (e.g. "#1a2b3c").
descriptionDescription is an optional free-text description.
nameName of the tag: lowercase letters, numbers, hyphens, underscores; <=128 chars.
routesV3.EnrichmentWithMetadata
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
typeupdated_atversionroutesV3.GetEnrichmentResponse
created_atdescriptionidmanaged_bynameorganization_idResourceReferences are the resources (e.g. secrets) referenced only via the override delta, tracked so deletion/rotation see them like component refs.
ShareDetails is set when the enrichment is involved in org-to-org sharing.
typeupdated_atversionroutesV3.ResourceUsageWithMetadata
component_typenameorganization_idorganization_nameresource_idresource_typesub_typeroutesV3.ShareChangesRequest
all_current_childrenShare with every current direct child (future children excluded).
revoke_all_not_in_useRevoke every current share the target org is not using, leaving in-use shares in place (returned in skipped_in_use). Unlike revoke_organization_ids this never 409s on an in-use child — it skips it.
revoke_organization_idsTarget organization ids whose share of this resource should be revoked.
share_organization_idsExplicit direct-child organizations to share with.
share_with_all_new_childrenToggle auto-sharing with new direct children: omit to leave unchanged, true to enable, false to disable.
routesV3.SharedResourceWithMetadata
component_typeComponent kind (input/output/transform/enrichment); components only.
descriptionDescription of the resource, when set.
explicit_target_countNumber of explicit per-child share rows for this resource.
last_shared_atMost recent time any share row for this resource was created.
nameName of the resource.
resource_idIdentifier of the shared secret or component.
resource_typeType of the shared resource: "secret" or "component".
share_with_all_new_childrenWhether the resource's policy auto-shares it with new direct children.
sub_typeConcrete connector kind; components only.
routesV3.UpdateAlertRuleRequest
activeActive indicates whether the alert rule is active
descriptionDescription of the alert rule
invert_selectionInvertSelection reads pipeline_ids as an exclude-list instead of an include-list, so the rule applies to all pipelines except those listed. An empty pipeline_ids still means all pipelines either way.
nameName of the alert rule
pipeline_idsPipeline IDs that this alert rule applies to
RuleConfig contains the configuration for the alert rule
severitySeverity level of the alert. Must be one of "critical", "high", "medium", "low", "info".
routesV3.UpdateConnectionRequest
descriptionConnection Description to be updated
nameConnection Name to be updated
public_namePublicName is the customer-facing label shown to end users in the SSO discovery picker. Optional; nil preserves the existing value, non-nil overwrites.
SAML holds updatable SAML fields; only metadata_url may change (entity ID is immutable).
SessionSettings controls the session length for logins through this connection. Optional; nil preserves the existing value, non-nil overwrites.
routesV3.schemaHistoryEntryResponse
created_atedge_idevent_tagsidroutesV3.schemaStateResponse
edge_idlearning_startmodepipeline_idtotal_records_observedupdated_atrunreveal.SettingsConfig
webhook_idThe RunReveal webhook ID. Only the ID — not the full URL shown in the RunReveal UI.
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
APIKey for GreyNoise Community API
s3.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
s3.SettingsConfig
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
bucketThe name of the S3 bucket where data will be stored
compressionThe compression method to be applied to the data before storing in S3
The format config to use
partition_formatDirectory structure used to partition stored objects. Options: simple date (e.g., '2024/01/01'), hive compliant (e.g., 'year=2024/month=01/day=01'), and flat hive compliant (e.g., 'dt=2024-01-01').
prefixAn optional prefix for S3 object keys to organize data within the bucket
regionThe AWS region where the S3 bucket is located
role_arnThe Amazon Resource Name (ARN) of the IAM role to assume which grants access to the S3 bucket
scanner.AuthConfig
typeAuthentication type: iam_role or static_credentials.
IAM role configuration (required when type is iam_role).
Static credential configuration (required when type is static_credentials).
scanner.DelimitedVariant
delimiterSingle-character field delimiter (e.g. ',').
headersOptional ordered list of column headers.
scanner.FormatConfig
typeOutput format: json, parquet, or delimited.
Delimited (CSV) output configuration (required when type is delimited).
JSON output configuration (required when type is json).
Parquet output configuration (required when type is parquet).
scanner.IAMRoleVariant
role_arnThe ARN of the IAM role to assume (e.g. arn:aws:iam::123456789012:role/MyRole).
scanner.JSONVariant
type'line' writes one JSON object per line (JSON Lines); 'array' writes a JSON array of objects.
scanner.ParquetVariant
schemaJSON schema describing the Parquet columns.
scanner.SettingsConfig
bucketThe S3 bucket in your AWS account that Scanner indexes.
compressionCompression applied before upload. Scanner indexes both uncompressed and gzip objects.
regionThe AWS region where the S3 bucket is located.
Authentication used to write to the bucket (IAM role or static credentials).
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
The on-disk format Scanner will index.
partition_formatDirectory structure used to partition stored objects.
prefixOptional prefix for S3 object keys. Should match the prefix on the Scanner source.
scanner.StaticCredentialsVariant
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
security_lake.SettingsConfig
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
bucket_urlThe name of the S3 bucket where data will be stored
Configuration for formatting data in Apache Parquet format
role_arnThe Amazon Resource Name (ARN) of the IAM role to assume which grants access to the S3 bucket
Details about the source AWS account and region for Security Lake
security_lake.SourceAccountDetails
source_account_idSource AWS Account ID
source_regionSource AWS Region
sentinel_threat_intelligence.SettingsConfig
client_idThe application (client) ID registered in Microsoft Entra.
APIKey for GreyNoise Community API
source_systemFree-form label identifying the source system in Sentinel. Must NOT be "Microsoft Sentinel" — that value is restricted by the API.
tenant_idThe Microsoft Entra tenant (directory) ID.
workspace_idThe Log Analytics workspace ID (GUID) that will store the STIX objects.
sentinelv2.DCRConfig
typesentinelv2.ManagedDCRVariant
dcr_resource_idThe full ARM resource ID of the customer's DCR, cloned per pod.
e.g. /subscriptions//resourceGroups/
sentinelv2.ManualDCRVariant
rule_idThe immutable identifier (rule id) of the Data Collection Rule (DCR).
sentinelv2.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
sentinelv2.SettingsConfig
How the destination DCR is provided: a single manual DCR, or a managed pool.
endpointThe Azure Monitor Data Collection Rule (DCR) ingestion endpoint URL.
stream_nameThe name of the data stream defined in the Data Collection Rule.
snowflake_output.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
snowflake_output.SettingsConfig
accountThe unique identifier for your Snowflake account, typically in the form of 'organization-account_name'.
auth_typeControls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
case_insensitivityTreat column names as case-insensitive (convert to uppercase) to match Snowflake's default behavior.
databaseThe name of the Snowflake database to connect to and perform operations on
roleThe name of the Role your service account was granted which can access your resources.
schemaThe schema within the Snowflake database where the target table resides.
stageThe name of the Snowflake stage where the data will be copied to. The connector creates or replaces the stage.
tableThe name of the table in Snowflake where the data will be written. If the table doesn't exist, the connector will create it.
userThe username of the Snowflake account used to establish the connection.
warehouseThe Snowflake virtual warehouse to use for executing queries and processing data.
snowflake_snowpipe_streaming.SettingsConfig
accountThe unique identifier for your Snowflake account, e.g. 'orgname-account_name'.
databaseThe Snowflake database that contains the target pipe.
pipeThe name of the pre-existing STREAMING pipe (created with DATA_SOURCE(TYPE => 'STREAMING')).
APIKey for GreyNoise Community API
schemaThe schema within the database that contains the target pipe.
userThe username of the Snowflake account used to authenticate. The user's DEFAULT_ROLE must be set to a role with access to the pipe.
Controls when a batch of records is sent by limiting the number of records, total size, and maximum time elapsed.
channel_prefixOptional prefix for the channel name. Channels are named "{prefix}{instanceID}{i}" where instanceID is a fresh random ID per connector instance.
splunk.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
splunk.SettingsConfig
portThe port of the Splunk instance.
urlThe URL of the Splunk instance (must start with http or https).
allow_insecureWhether to allow insecure connections (not recommended for production).
indexThe index you want to send data to. If left empty, data is sent to the default index associated with the token. If specified, please read our docs for more context on Splunk token & Index scoping.
to_createEnsure this is selected if you want the connector to create the index for you. If you are using a pre-existing index, please leave this deselected. Read our docs for more context on Splunk token & Index scoping.
usernameRepresents an administrative account to manage indices. Used to create an index, hence can be left empty if default index is to be used.
sqs_s3_base.FilterVariant
modeoperatorvaluesqs_s3_base.KeyFilter
typesumologic.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
sumologic.SettingsConfig
Additional metadata to send with each source.
urlThe URL of the Sumo Logic instance.
sumologic.SourceMetadata
custom_source_categoryDesired source category. Useful if you want to override the source category configured for the source.
custom_source_hostDesired source host. Useful if you want to override the source host configured for the source.
custom_source_nameDesired source name. Useful if you want to override the source name configured for the source.
sumologic.SumoField
field_nameName of the field to reference.
field_valueValue of the field to reference.
synthetic_data.SettingsConfig
rateThe rate at which to generate records (between 1 and 1000) per second
record_typeThe type of record to generate
synthetic_data_custom.SettingsConfig
custom_templateA custom template using the functions we provide to generate demo data
rateThe rate at which to generate records (between 1 and 1000) per second
tanium_graphql_input.SettingsConfig
base_urlThe base URL of your GraphQL endpoint including the path
enable_paginationEnable pagination support
graphql_queryThe GraphQL query to execute against the endpoint to fetch data
has_next_page_pathJSONPath location to check if there are more pages
interval_secondsTime interval in seconds between consecutive GraphQL API calls
pagination_cursor_pathJSONPath location for pagination cursor/token
record_locationJSONPath location of the records array in the GraphQL response
GraphQL query variables to pass with each request
tines_audit_logs.SecretsConfig
APIKey for GreyNoise Community API
tines_audit_logs.SettingsConfig
tenant_domainThe Tines tenant domain (e.g., your-org.tines.com)
backfill_start_timeDate to start fetching data from. If not specified, will fetch from the most recent data available.
operation_namesFilter by specific operation names (optional)
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
user_idsFilter by specific user IDs (optional)
tines_events_logs.SecretsConfig
APIKey for GreyNoise Community API
tines_events_logs.SettingsConfig
tenant_urlUnique URL for your Tines instance
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
story_idFilter by the given story.
team_idFilter by the given team.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
twilio_events.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
twilio_events.SettingsConfig
actor_sidOnly includes events initiated by this Actor. Useful for auditing actions taken by specific users or API credentials.
event_typeOnly includes events of a specific event type: https://www.twilio.com/docs/usage/monitor-events#event-types
replication_start_timeOnly include events after this time for the initial sync. If not specified, returns all events from the start. Must be a valid ISO 8601 formatted datetime string: yyyy-MM-dd'T'HH:mm:ss'Z'
resource_sidOnly include events that refer to this resource. Useful for discovering the history of a specific resource.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
twilio_sendgrid_email_activity.SecretsConfig
APIKey for GreyNoise Community API
twilio_sendgrid_email_activity.SettingsConfig
backfill_start_timeDate to start fetching data from. If not specified, a full sync of is fetched on the first sync. All syncs thereafter will be incremental.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
utc_timestamp.ArgumentsConfig
formatThe format of the timestamp
keyThe key to store the timestamp in
utc_timestamp.TimestampFormat
The format of the timestamp
voltio_audit_logs.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
voltio_audit_logs.SettingsConfig
base_urlBase URL of your Volt.io API instance (e.g., https://api.volt.io)
backfill_start_timeDate to start fetching data from. If not specified, defaults to 90 days ago. All syncs thereafter will be incremental.
customer_idOptional: Filter audit logs by specific customer ID
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
vulnerability_findings.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
vulnerability_findings.SettingsConfig
asset_typesAsset types for Wiz. Ex: 'VIRTUAL_MACHINE', 'CONTAINER', etc.
endpoint_urlEndpoint URL for the Wiz API. Ex: 'https://api.wiz.io/v1/vulnerability-findings'.
asset_statusAsset status types for Wiz. Ex: 'ACTIVE', 'INACTIVE'.
backfill_start_timeDate to start fetching data from. If not specified, Data is fetched since one year ago. All syncs thereafter will be of incremental data.
detection_methodDetection method types for Wiz. Ex: 'AGENT', 'CLOUD', 'AGENT_CLOUD'.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
statusStatus types for Wiz. Ex: 'OPEN', 'RESOLVED'.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
vendor_severityVendor severity types for Wiz. Ex: 'CRITICAL', 'HIGH', 'MEDIUM', 'LOW'
wazuh.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
wazuh.SettingsConfig
indexThe name of the index to write to.
urlThe URL of the Wazuh indexer API (must start with https).
usernameThe username for authenticating with the Wazuh indexer.
auth_modeNot exposed in the config meta; present only to reject AWS role auth submitted via the API.
insecure_skip_verifyWhether to skip TLS certificate verification (not recommended for production).
wiz.DetectionMethod
wiz.EntityType
wiz.NoteFilter
@Description Filter Issues with or without a note
wiz.RemediationFilter
@Description Filter Issues with or without remediation
wiz.ResolutionReason
wiz.RiskType
wiz.ServiceTicketFilter
@Description Filter Issues with or without related service ticket
wiz.StackLayer
wiz_audit_logs.SecretsConfig
APIKey for GreyNoise Community API
APIKey for GreyNoise Community API
wiz_audit_logs.SettingsConfig
tenant_data_centerDataCenter represents the tenant's data center location. Enter a tenant data center, e.g., "us1", "us2", "us3"
backfill_start_timeDate to start fetching data from, up to a maximum lookback of 180 days; older values are clamped to 180 days ago. If not specified, no past records are fetched and syncing starts from the current time. All syncs thereafter are incremental.
Optional outbound request rate limit. Falls back to the Wiz default when unset.
use_synthetic_dataGenerate synthetic demo data instead of connecting to the real data source.
xsiam.SettingsConfig
tenant_fqdnThe XSIAM tenant API FQDN, hostname only (no scheme, no path).
allow_insecureSkip TLS verification. Not recommended outside local testing.
APIKey for GreyNoise Community API
enable_compressionBy default the connector gzips the request body and sends
Content-Encoding: gzip. Set true to send uncompressed instead. This
MUST match the HTTP Log Collector's Compression setting in the XSIAM UI.