import { Construct } from 'constructs'; import * as cdktf from 'cdktf'; export interface CloudSecurityCustomRuleConfig extends cdktf.TerraformMetaArguments { /** * A list of the alert logic and detection criteria for rule violations. Do not include numbering within this list. The Falcon console will automatically add numbering.When `alert_info` is not defined and `parent_rule_id` is defined, this field will inherit the parent rule's `alert_info`. * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#alert_info CloudSecurityCustomRule#alert_info} */ readonly alertInfo?: string[]; /** * Specific attack types associated with the rule. If `parent_rule_id` is defined, `attack_types` will be inherited from the parent rule and cannot be specified using this field. * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#attack_types CloudSecurityCustomRule#attack_types} */ readonly attackTypes?: string[]; /** * Cloud provider for the policy rule. * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#cloud_provider CloudSecurityCustomRule#cloud_provider} */ readonly cloudProvider: string; /** * Security framework and compliance rule information. Utilize the `crowdstrike_cloud_compliance_framework_controls` data source to obtain this information. When `controls` is not defined and `parent_rule_id` is defined, this field will inherit the parent rule's `controls`. * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#controls CloudSecurityCustomRule#controls} */ readonly controls?: CloudSecurityCustomRuleControls[] | cdktf.IResolvable; /** * Description of the policy rule. * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#description CloudSecurityCustomRule#description} */ readonly description: string; /** * Rego logic for the rule. Either `logic` or `parent_rule_id` must be defined. When `parent_rule_id` is set, the rule inherits the Rego logic from the parent rule. Note: The API does not return Rego logic for rules created from a parent rule, so this field will not appear in state when using `parent_rule_id`. * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#logic CloudSecurityCustomRule#logic} */ readonly logic?: string; /** * Name of the policy rule. * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#name CloudSecurityCustomRule#name} */ readonly name: string; /** * Id of the parent rule to inherit properties from. The `crowdstrike_cloud_security_rules` data source can be used to query Falcon for parent rule information to use in this field. Required if `logic` is not specified. * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#parent_rule_id CloudSecurityCustomRule#parent_rule_id} */ readonly parentRuleId?: string; /** * Information about how to remediate issues detected by this rule. Do not include numbering within this list. The Falcon console will automatically add numbering. When `remediation_info` is not defined and `parent_rule_id` is defined, this field will inherit the parent rule's `remediation_info`. * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#remediation_info CloudSecurityCustomRule#remediation_info} */ readonly remediationInfo?: string[]; /** * The full resource type. Examples: `AWS::IAM::CredentialReport`, `Microsoft.Compute/virtualMachines`, `container.googleapis.com/Cluster` * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#resource_type CloudSecurityCustomRule#resource_type} */ readonly resourceType: string; /** * Severity of the rule. Valid values are `critical`, `high`, `medium`, `informational`. * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#severity CloudSecurityCustomRule#severity} */ readonly severity?: string; } export interface CloudSecurityCustomRuleControls { /** * The compliance framework * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#authority CloudSecurityCustomRule#authority} */ readonly authority?: string; /** * The compliance framework rule code * * Docs at Terraform Registry: {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#code CloudSecurityCustomRule#code} */ readonly code?: string; } export declare function cloudSecurityCustomRuleControlsToTerraform(struct?: CloudSecurityCustomRuleControls | cdktf.IResolvable): any; export declare function cloudSecurityCustomRuleControlsToHclTerraform(struct?: CloudSecurityCustomRuleControls | cdktf.IResolvable): any; export declare class CloudSecurityCustomRuleControlsOutputReference extends cdktf.ComplexObject { private isEmptyObject; private resolvableValue?; /** * @param terraformResource The parent resource * @param terraformAttribute The attribute on the parent resource this class is referencing * @param complexObjectIndex the index of this item in the list * @param complexObjectIsFromSet whether the list is wrapping a set (will add tolist() to be able to access an item via an index) */ constructor(terraformResource: cdktf.IInterpolatingParent, terraformAttribute: string, complexObjectIndex: number, complexObjectIsFromSet: boolean); get internalValue(): CloudSecurityCustomRuleControls | cdktf.IResolvable | undefined; set internalValue(value: CloudSecurityCustomRuleControls | cdktf.IResolvable | undefined); private _authority?; get authority(): string; set authority(value: string); resetAuthority(): void; get authorityInput(): string; private _code?; get code(): string; set code(value: string); resetCode(): void; get codeInput(): string; } export declare class CloudSecurityCustomRuleControlsList extends cdktf.ComplexList { protected terraformResource: cdktf.IInterpolatingParent; protected terraformAttribute: string; protected wrapsSet: boolean; internalValue?: CloudSecurityCustomRuleControls[] | cdktf.IResolvable; /** * @param terraformResource The parent resource * @param terraformAttribute The attribute on the parent resource this class is referencing * @param wrapsSet whether the list is wrapping a set (will add tolist() to be able to access an item via an index) */ constructor(terraformResource: cdktf.IInterpolatingParent, terraformAttribute: string, wrapsSet: boolean); /** * @param index the index of the item to return */ get(index: number): CloudSecurityCustomRuleControlsOutputReference; } /** * Represents a {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule crowdstrike_cloud_security_custom_rule} */ export declare class CloudSecurityCustomRule extends cdktf.TerraformResource { static readonly tfResourceType = "crowdstrike_cloud_security_custom_rule"; /** * Generates CDKTF code for importing a CloudSecurityCustomRule resource upon running "cdktf plan " * @param scope The scope in which to define this construct * @param importToId The construct id used in the generated config for the CloudSecurityCustomRule to import * @param importFromId The id of the existing CloudSecurityCustomRule that should be imported. Refer to the {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule#import import section} in the documentation of this resource for the id to use * @param provider? Optional instance of the provider where the CloudSecurityCustomRule to import is found */ static generateConfigForImport(scope: Construct, importToId: string, importFromId: string, provider?: cdktf.TerraformProvider): any; /** * Create a new {@link https://registry.terraform.io/providers/crowdstrike/crowdstrike/0.0.53/docs/resources/cloud_security_custom_rule crowdstrike_cloud_security_custom_rule} Resource * * @param scope The scope in which to define this construct * @param id The scoped construct ID. Must be unique amongst siblings in the same scope * @param options CloudSecurityCustomRuleConfig */ constructor(scope: Construct, id: string, config: CloudSecurityCustomRuleConfig); private _alertInfo?; get alertInfo(): string[]; set alertInfo(value: string[]); resetAlertInfo(): void; get alertInfoInput(): string[]; private _attackTypes?; get attackTypes(): string[]; set attackTypes(value: string[]); resetAttackTypes(): void; get attackTypesInput(): string[]; get cloudPlatform(): any; private _cloudProvider?; get cloudProvider(): string; set cloudProvider(value: string); get cloudProviderInput(): string; private _controls; get controls(): CloudSecurityCustomRuleControlsList; putControls(value: CloudSecurityCustomRuleControls[] | cdktf.IResolvable): void; resetControls(): void; get controlsInput(): any; private _description?; get description(): string; set description(value: string); get descriptionInput(): string; get domain(): any; get id(): any; private _logic?; get logic(): string; set logic(value: string); resetLogic(): void; get logicInput(): string; private _name?; get name(): string; set name(value: string); get nameInput(): string; private _parentRuleId?; get parentRuleId(): string; set parentRuleId(value: string); resetParentRuleId(): void; get parentRuleIdInput(): string; private _remediationInfo?; get remediationInfo(): string[]; set remediationInfo(value: string[]); resetRemediationInfo(): void; get remediationInfoInput(): string[]; private _resourceType?; get resourceType(): string; set resourceType(value: string); get resourceTypeInput(): string; private _severity?; get severity(): string; set severity(value: string); resetSeverity(): void; get severityInput(): string; get subdomain(): any; protected synthesizeAttributes(): { [name: string]: any; }; protected synthesizeHclAttributes(): { [name: string]: any; }; }