import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * This data source provides the list of Audit Events in Oracle Cloud Infrastructure Data Safe service. * * The ListAuditEvents operation returns specified `compartmentId` audit Events only. * The list does not include any audit Events associated with the `subcompartments` of the specified `compartmentId`. * * The parameter `accessLevel` specifies whether to return only those compartments for which the * requestor has INSPECT permissions on at least one resource directly * or indirectly (ACCESSIBLE) (the resource can be in a subcompartment) or to return Not Authorized if * Principal doesn't have access to even one of the child compartments. This is valid only when * `compartmentIdInSubtree` is set to `true`. * * The parameter `compartmentIdInSubtree` applies when you perform ListAuditEvents on the * `compartmentId` passed and when it is set to true, the entire hierarchy of compartments can be returned. * To get a full list of all compartments and subcompartments in the tenancy (root compartment), * set the parameter `compartmentIdInSubtree` to true and `accessLevel` to ACCESSIBLE. * * ## Example Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as oci from "@pulumi/oci"; * * const testAuditEvents = oci.datasafe.getAuditEvents({ * compartmentId: compartmentId, * accessLevel: auditEventAccessLevel, * compartmentIdInSubtree: auditEventCompartmentIdInSubtree === "true", * scimQuery: auditEventScimQuery, * }); * ``` */ export declare function getAuditEvents(args: GetAuditEventsArgs, opts?: pulumi.InvokeOptions): Promise; /** * A collection of arguments for invoking getAuditEvents. */ export interface GetAuditEventsArgs { /** * Valid values are RESTRICTED and ACCESSIBLE. Default is RESTRICTED. Setting this to ACCESSIBLE returns only those compartments for which the user has INSPECT permissions directly or indirectly (permissions can be on a resource in a subcompartment). When set to RESTRICTED permissions are checked and no partial results are displayed. */ accessLevel?: string; /** * A filter to return only resources that match the specified compartment OCID. */ compartmentId: string; /** * Default is false. When set to true, the hierarchy of compartments is traversed and all compartments and subcompartments in the tenancy are returned. Depends on the 'accessLevel' setting. */ compartmentIdInSubtree?: boolean; filters?: inputs.DataSafe.GetAuditEventsFilter[]; /** * The scimQuery query parameter accepts filter expressions that use the syntax described in Section 3.2.2.2 of the System for Cross-Domain Identity Management (SCIM) specification, which is available at [RFC3339](https://tools.ietf.org/html/draft-ietf-scim-api-12). In SCIM filtering expressions, text, date, and time values must be enclosed in quotation marks, with date and time values using ISO-8601 format. (Numeric and boolean values should not be quoted.) * * **Example:** (auditEventTime ge "2021-06-04T01:00:26.000Z") and (eventName eq "LOGON") The attrExp or the field (for example, operationTime and eventName in above example) which is used to filter can be any of the fields returned by AuditEventSummary. adminUser, commonUser, sensitiveActivity, dsActivity can only have eq operation and value 1. These define admin user activity, common user activity, sensitive data activity and data safe activity **Example:** (adminUser eq 1) */ scimQuery?: string; } /** * A collection of values returned by getAuditEvents. */ export interface GetAuditEventsResult { readonly accessLevel?: string; /** * The list of audit_event_collection. */ readonly auditEventCollections: outputs.DataSafe.GetAuditEventsAuditEventCollection[]; /** * The OCID of the compartment containing the audit event. The compartment is the same as that of audit profile of the target database resource. */ readonly compartmentId: string; readonly compartmentIdInSubtree?: boolean; readonly filters?: outputs.DataSafe.GetAuditEventsFilter[]; /** * The provider-assigned unique ID for this managed resource. */ readonly id: string; readonly scimQuery?: string; } /** * This data source provides the list of Audit Events in Oracle Cloud Infrastructure Data Safe service. * * The ListAuditEvents operation returns specified `compartmentId` audit Events only. * The list does not include any audit Events associated with the `subcompartments` of the specified `compartmentId`. * * The parameter `accessLevel` specifies whether to return only those compartments for which the * requestor has INSPECT permissions on at least one resource directly * or indirectly (ACCESSIBLE) (the resource can be in a subcompartment) or to return Not Authorized if * Principal doesn't have access to even one of the child compartments. This is valid only when * `compartmentIdInSubtree` is set to `true`. * * The parameter `compartmentIdInSubtree` applies when you perform ListAuditEvents on the * `compartmentId` passed and when it is set to true, the entire hierarchy of compartments can be returned. * To get a full list of all compartments and subcompartments in the tenancy (root compartment), * set the parameter `compartmentIdInSubtree` to true and `accessLevel` to ACCESSIBLE. * * ## Example Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as oci from "@pulumi/oci"; * * const testAuditEvents = oci.datasafe.getAuditEvents({ * compartmentId: compartmentId, * accessLevel: auditEventAccessLevel, * compartmentIdInSubtree: auditEventCompartmentIdInSubtree === "true", * scimQuery: auditEventScimQuery, * }); * ``` */ export declare function getAuditEventsOutput(args: GetAuditEventsOutputArgs, opts?: pulumi.InvokeOutputOptions): pulumi.Output; /** * A collection of arguments for invoking getAuditEvents. */ export interface GetAuditEventsOutputArgs { /** * Valid values are RESTRICTED and ACCESSIBLE. Default is RESTRICTED. Setting this to ACCESSIBLE returns only those compartments for which the user has INSPECT permissions directly or indirectly (permissions can be on a resource in a subcompartment). When set to RESTRICTED permissions are checked and no partial results are displayed. */ accessLevel?: pulumi.Input; /** * A filter to return only resources that match the specified compartment OCID. */ compartmentId: pulumi.Input; /** * Default is false. When set to true, the hierarchy of compartments is traversed and all compartments and subcompartments in the tenancy are returned. Depends on the 'accessLevel' setting. */ compartmentIdInSubtree?: pulumi.Input; filters?: pulumi.Input[] | undefined>; /** * The scimQuery query parameter accepts filter expressions that use the syntax described in Section 3.2.2.2 of the System for Cross-Domain Identity Management (SCIM) specification, which is available at [RFC3339](https://tools.ietf.org/html/draft-ietf-scim-api-12). In SCIM filtering expressions, text, date, and time values must be enclosed in quotation marks, with date and time values using ISO-8601 format. (Numeric and boolean values should not be quoted.) * * **Example:** (auditEventTime ge "2021-06-04T01:00:26.000Z") and (eventName eq "LOGON") The attrExp or the field (for example, operationTime and eventName in above example) which is used to filter can be any of the fields returned by AuditEventSummary. adminUser, commonUser, sensitiveActivity, dsActivity can only have eq operation and value 1. These define admin user activity, common user activity, sensitive data activity and data safe activity **Example:** (adminUser eq 1) */ scimQuery?: pulumi.Input; } //# sourceMappingURL=getAuditEvents.d.ts.map