import { APIResource } from "../../../core/resource.mjs"; import * as AggregateAPI from "./aggregate.mjs"; import { Aggregate, AggregateListParams, AggregateListResponse, BaseAggregate } from "./aggregate.mjs"; import * as AttackersAPI from "./attackers.mjs"; import { AttackerListParams, AttackerListResponse, Attackers, BaseAttackers } from "./attackers.mjs"; import * as CountriesAPI from "./countries.mjs"; import { BaseCountries, Countries, CountryListParams, CountryListResponse } from "./countries.mjs"; import * as CronsAPI from "./crons.mjs"; import { BaseCrons, Crons } from "./crons.mjs"; import * as EventTagsAPI from "./event-tags.mjs"; import { BaseEventTags, EventTagCreateParams, EventTagCreateResponse, EventTagDeleteParams, EventTagDeleteResponse, EventTags } from "./event-tags.mjs"; import * as GraphAPI from "./graph.mjs"; import { BaseGraph, Graph, GraphListParams, GraphListResponse } from "./graph.mjs"; import * as GraphqlAPI from "./graphql.mjs"; import { BaseGraphql, Graphql, GraphqlCreateParams, GraphqlCreateResponse } from "./graphql.mjs"; import * as InsightsAPI from "./insights.mjs"; import { BaseInsights, Insights } from "./insights.mjs"; import * as QueriesAPI from "./queries.mjs"; import { BaseQueries, Queries, QueryCreateParams, QueryCreateResponse, QueryDeleteParams, QueryEditParams, QueryEditResponse, QueryGetParams, QueryGetResponse, QueryListParams, QueryListResponse } from "./queries.mjs"; import * as RawAPI from "./raw.mjs"; import { BaseRaw, Raw as RawAPIRaw, RawEditParams, RawEditResponse, RawGetParams, RawGetResponse } from "./raw.mjs"; import * as RelateAPI from "./relate.mjs"; import { BaseRelate, Relate, RelateDeleteParams, RelateDeleteResponse } from "./relate.mjs"; import * as RelationshipsAPI from "./relationships.mjs"; import { BaseRelationships, RelationshipListParams, RelationshipListResponse, Relationships } from "./relationships.mjs"; import * as CategoriesAPI from "./categories/categories.mjs"; import { BaseCategories, Categories, CategoryCreateParams, CategoryCreateResponse, CategoryDeleteParams, CategoryDeleteResponse, CategoryEditParams, CategoryEditResponse, CategoryGetParams, CategoryGetResponse, CategoryListParams, CategoryListResponse } from "./categories/categories.mjs"; import * as DatasetsAPI from "./datasets/datasets.mjs"; import { BaseDatasets, DatasetCreateParams, DatasetCreateResponse, DatasetDeleteParams, DatasetDeleteResponse, DatasetEditParams, DatasetEditResponse, DatasetGetParams, DatasetGetResponse, DatasetListParams, DatasetListResponse, DatasetRawParams, DatasetRawResponse, Datasets } from "./datasets/datasets.mjs"; import * as IndicatorsAPI from "./indicators/indicators.mjs"; import { BaseIndicators, IndicatorListParams, IndicatorListResponse, Indicators } from "./indicators/indicators.mjs"; import * as TagsAPI from "./tags/tags.mjs"; import { BaseTags, TagCreateParams, TagCreateResponse, TagDeleteParams, TagDeleteResponse, TagEditParams, TagEditResponse, TagListParams, TagListResponse, Tags } from "./tags/tags.mjs"; import * as TargetIndustriesAPI from "./target-industries/target-industries.mjs"; import { BaseTargetIndustries, TargetIndustries, TargetIndustryListParams, TargetIndustryListResponse } from "./target-industries/target-industries.mjs"; import { APIPromise } from "../../../core/api-promise.mjs"; import { RequestOptions } from "../../../internal/request-options.mjs"; export declare class BaseThreatEvents extends APIResource { static readonly _key: readonly ['cloudforceOne', 'threatEvents']; /** * To create a dataset, see the * [`Create Dataset`](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/create/) * endpoint. When `datasetId` parameter is unspecified, it will be created in a * default dataset named `Cloudforce One Threat Events`. * * @example * ```ts * const threatEvent = * await client.cloudforceOne.threatEvents.create({ * account_id: 'account_id', * category: 'Domain Resolution', * date: '2022-04-01T00:00:00Z', * event: 'An attacker registered the domain domain.com', * raw: { data: { foo: 'bar' } }, * tlp: 'amber', * }); * ``` */ create(params: ThreatEventCreateParams, options?: RequestOptions): APIPromise; /** * Use `datasetId=all` or `datasetId=*` to query all event datasets for the account * (limited to 50). When `datasetId` is unspecified, events are listed from the * default Cloudforce One Threat Events dataset. To list existing datasets, use the * [`List Datasets`](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/list/) * endpoint. * * @example * ```ts * const threatEvents = * await client.cloudforceOne.threatEvents.list({ * account_id: 'account_id', * }); * ``` */ list(params: ThreatEventListParams, options?: RequestOptions): APIPromise; /** * The `datasetId` parameter must be defined. To list existing datasets (and their * IDs) in your account, use the * [`List Datasets`](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/list/) * endpoint. * * @example * ```ts * const response = * await client.cloudforceOne.threatEvents.bulkCreate({ * account_id: 'account_id', * data: [ * { * category: 'Domain Resolution', * date: '2022-04-01T00:00:00Z', * event: * 'An attacker registered the domain domain.com', * raw: { data: { foo: 'bar' } }, * tlp: 'amber', * }, * ], * datasetId: 'durableObjectName', * }); * ``` */ bulkCreate(params: ThreatEventBulkCreateParams, options?: RequestOptions): APIPromise; /** * This method is deprecated. Please use `event_create_bulk` instead * * @deprecated This endpoint is deprecated and will be removed in a future version. */ bulkCreateRelationships(params: ThreatEventBulkCreateRelationshipsParams, options?: RequestOptions): APIPromise; /** * Partially updates a threat event in Cloudforce One, modifying specific fields * without replacing the entire event. * * @example * ```ts * const response = * await client.cloudforceOne.threatEvents.edit('event_id', { * account_id: 'account_id', * datasetId: '9b769969-a211-466c-8ac3-cb91266a066a', * }); * ``` */ edit(eventID: string, params: ThreatEventEditParams, options?: RequestOptions): APIPromise; /** * This Method is deprecated. Please use * /events/dataset/:dataset_id/events/:event_id instead. * * @deprecated Use datasets.events.get instead (GET /accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/events/{event_id}). */ get(eventID: string, params: ThreatEventGetParams, options?: RequestOptions): APIPromise; } export declare class ThreatEvents extends BaseThreatEvents { aggregate: AggregateAPI.Aggregate; graphql: GraphqlAPI.Graphql; graph: GraphAPI.Graph; queries: QueriesAPI.Queries; relationships: RelationshipsAPI.Relationships; indicators: IndicatorsAPI.Indicators; attackers: AttackersAPI.Attackers; categories: CategoriesAPI.Categories; countries: CountriesAPI.Countries; crons: CronsAPI.Crons; datasets: DatasetsAPI.Datasets; raw: RawAPI.Raw; relate: RelateAPI.Relate; tags: TagsAPI.Tags; eventTags: EventTagsAPI.EventTags; targetIndustries: TargetIndustriesAPI.TargetIndustries; insights: InsightsAPI.Insights; } export interface ThreatEventCreateResponse { attacker: string; attackerCountry: string; attackerCountryAlpha3: string; category: string; datasetId: string; date: string; event: string; hasChildren: boolean; indicator: string; indicatorType: string; indicatorTypeId: number; killChain: number; mitreAttack: Array; mitreCapec: Array; numReferenced: number; numReferences: number; rawId: string; referenced: Array; referencedIds: Array; references: Array; referencesIds: Array; tags: Array; targetCountry: string; targetCountryAlpha3: string; targetIndustry: string; tlp: string; uuid: string; insight?: string; releasabilityId?: string; } export type ThreatEventListResponse = Array; export declare namespace ThreatEventListResponse { interface ThreatEventListResponseItem { attacker: string; attackerCountry: string; attackerCountryAlpha3: string; category: string; datasetId: string; date: string; event: string; hasChildren: boolean; indicator: string; indicatorType: string; indicatorTypeId: number; killChain: number; mitreAttack: Array; mitreCapec: Array; numReferenced: number; numReferences: number; rawId: string; referenced: Array; referencedIds: Array; references: Array; referencesIds: Array; tags: Array; targetCountry: string; targetCountryAlpha3: string; targetIndustry: string; tlp: string; uuid: string; insight?: string; releasabilityId?: string; } } /** * Detailed result of bulk event creation with auto-tag management */ export interface ThreatEventBulkCreateResponse { /** * Number of events created */ createdEventsCount: number; /** * Number of new tags created in SoT */ createdTagsCount: number; /** * Number of errors encountered */ errorCount: number; /** * Number of indicators queued for async processing */ queuedIndicatorsCount: number; /** * Correlation ID for async indicator processing */ createBulkEventsRequestId?: string; /** * Array of created events with UUIDs and shard locations. Only present when * includeCreatedEvents=true */ createdEvents?: Array; /** * Array of error details */ errors?: Array; } export declare namespace ThreatEventBulkCreateResponse { interface CreatedEvent { /** * Original index in the input data array */ eventIndex: number; /** * Dataset ID of the shard where the event was created */ shardId: string; /** * UUID of the created event */ uuid: string; } interface Error { /** * Error message */ error: string; /** * Index of the event that caused the error */ eventIndex: number; } } /** * Result of bulk relationship creation operation */ export interface ThreatEventBulkCreateRelationshipsResponse { /** * Number of events created */ createdEventsCount: number; /** * Number of indicators created */ createdIndicatorsCount: number; /** * Number of relationships created */ createdRelationshipsCount: number; /** * Number of errors encountered */ errorCount: number; /** * Array of error details */ errors?: Array; } export declare namespace ThreatEventBulkCreateRelationshipsResponse { interface Error { /** * Error message */ error: string; /** * Index of the event that caused the error */ eventIndex: number; } } export interface ThreatEventEditResponse { attacker: string; attackerCountry: string; attackerCountryAlpha3: string; category: string; datasetId: string; date: string; event: string; hasChildren: boolean; indicator: string; indicatorType: string; indicatorTypeId: number; killChain: number; mitreAttack: Array; mitreCapec: Array; numReferenced: number; numReferences: number; rawId: string; referenced: Array; referencedIds: Array; references: Array; referencesIds: Array; tags: Array; targetCountry: string; targetCountryAlpha3: string; targetIndustry: string; tlp: string; uuid: string; insight?: string; releasabilityId?: string; } export interface ThreatEventGetResponse { attacker: string; attackerCountry: string; attackerCountryAlpha3: string; category: string; datasetId: string; date: string; event: string; hasChildren: boolean; indicator: string; indicatorType: string; indicatorTypeId: number; killChain: number; mitreAttack: Array; mitreCapec: Array; numReferenced: number; numReferences: number; rawId: string; referenced: Array; referencedIds: Array; references: Array; referencesIds: Array; tags: Array; targetCountry: string; targetCountryAlpha3: string; targetIndustry: string; tlp: string; uuid: string; insight?: string; releasabilityId?: string; } export interface ThreatEventCreateParams { /** * Path param: Account ID. */ account_id: string; /** * Body param */ category: string; /** * Body param */ date: string; /** * Body param */ event: string; /** * Body param */ raw: ThreatEventCreateParams.Raw; /** * Body param */ tlp: string; /** * Body param */ accountId?: number; /** * Body param */ attacker?: string | null; /** * Body param */ attackerCountry?: string; /** * Body param */ datasetId?: string; /** * Body param */ indicator?: string; /** * Body param: Array of indicators for this event. Supports multiple indicators per * event for complex scenarios. */ indicators?: Array; /** * Body param */ indicatorType?: string; /** * Body param */ insight?: string; /** * Body param */ tags?: Array; /** * Body param */ targetCountry?: string; /** * Body param */ targetIndustry?: string; } export declare namespace ThreatEventCreateParams { interface Raw { data: { [key: string]: unknown; } | null; source?: string; tlp?: string; } interface Indicator { /** * The type of indicator (e.g., DOMAIN, IP, JA3, HASH) */ indicatorType: string; /** * The indicator value (e.g., domain name, IP address, hash) */ value: string; } } export interface ThreatEventListParams { /** * Path param: Account ID. */ account_id: string; /** * Query param: Cache strategy. 'from-graph' serves results from the graph-node KV * cache when all requested UUIDs are cached; falls back to normal path on * partial/zero hit. */ cache?: 'from-graph'; /** * Query param: Cursor for pagination. When provided, filters are embedded in the * cursor so you only need to pass cursor and pageSize. Returned in the previous * response's result_info.cursor field. Use cursor-based pagination for deep * pagination (beyond 100,000 records) or for optimal performance. */ cursor?: string; /** * Query param: Dataset IDs to query events from (array of UUIDs), or special value * 'all' or '\*' to query all event datasets for the account. If not provided, uses * the default dataset. */ datasetId?: Array; /** * Query param */ forceRefresh?: boolean; /** * Query param */ format?: 'json' | 'stix2' | 'taxii'; /** * Query param */ order?: 'asc' | 'desc'; /** * Query param */ orderBy?: string; /** * Query param: Page number (1-indexed) for offset-based pagination. Limited to * offset of 100,000 records. For deep pagination, use cursor-based pagination * instead. */ page?: number; /** * Query param: Number of results per page. Maximum 25,000. */ pageSize?: number; /** * Query param */ search?: Array; } export declare namespace ThreatEventListParams { interface Search { /** * Event field to search on. Allowed: attacker, attackerCountry, category, * createdAt, date, event, indicator, indicatorType, killChain, mitreAttack, tags, * targetCountry, targetIndustry, tlp, uuid. */ field?: string; /** * Search operator. Use 'in' for bulk lookup of up to 100 values at once, e.g. * {field:'tags', op:'in', value:['malware','apt']}. */ op?: 'equals' | 'not' | 'gt' | 'gte' | 'lt' | 'lte' | 'like' | 'contains' | 'startsWith' | 'endsWith' | 'in' | 'find'; /** * Search value. String or number for most operators. Array for 'in' operator (max * 100 items). */ value?: string | number | Array; } } export interface ThreatEventBulkCreateParams { /** * Path param: Account ID. */ account_id: string; /** * Body param */ data: Array; /** * Body param */ datasetId: string; /** * Body param: When true, response includes array of created event UUIDs and shard * IDs. Useful for tracking which events were created and where. */ includeCreatedEvents?: boolean; } export declare namespace ThreatEventBulkCreateParams { interface Data { category: string; date: string; event: string; raw: Data.Raw; tlp: string; accountId?: number; attacker?: string | null; attackerCountry?: string; datasetId?: string; indicator?: string; /** * Array of indicators for this event. Supports multiple indicators per event for * complex scenarios. */ indicators?: Array; indicatorType?: string; insight?: string; tags?: Array; targetCountry?: string; targetIndustry?: string; } namespace Data { interface Raw { data: { [key: string]: unknown; } | null; source?: string; tlp?: string; } interface Indicator { /** * The type of indicator (e.g., DOMAIN, IP, JA3, HASH) */ indicatorType: string; /** * The indicator value (e.g., domain name, IP address, hash) */ value: string; } } } export interface ThreatEventBulkCreateRelationshipsParams { /** * Path param: Account ID. */ account_id: string; /** * Body param */ data: Array; /** * Body param */ datasetId: string; } export declare namespace ThreatEventBulkCreateRelationshipsParams { interface Data { category: string; date: string; event: string; raw: Data.Raw; tlp: string; accountId?: number; attacker?: string | null; attackerCountry?: string; datasetId?: string; indicator?: string; /** * Array of indicators for this event. Supports multiple indicators per event for * complex scenarios. */ indicators?: Array; indicatorType?: string; insight?: string; tags?: Array; targetCountry?: string; targetIndustry?: string; } namespace Data { interface Raw { data: { [key: string]: unknown; } | null; source?: string; tlp?: string; } interface Indicator { /** * The type of indicator (e.g., DOMAIN, IP, JA3, HASH) */ indicatorType: string; /** * The indicator value (e.g., domain name, IP address, hash) */ value: string; } } } export interface ThreatEventEditParams { /** * Path param: Account ID. */ account_id: string; /** * Body param: Dataset ID containing the event to update. */ datasetId: string; /** * Body param */ attacker?: string | null; /** * Body param */ attackerCountry?: string; /** * Body param */ category?: string; /** * Body param */ createdAt?: string; /** * Body param */ date?: string; /** * Body param */ event?: string; /** * Body param */ indicator?: string; /** * Body param */ indicatorType?: string; /** * Body param */ insight?: string; /** * Body param */ raw?: ThreatEventEditParams.Raw; /** * Body param */ targetCountry?: string; /** * Body param */ targetIndustry?: string; /** * Body param */ tlp?: string; } export declare namespace ThreatEventEditParams { interface Raw { data?: { [key: string]: unknown; } | null; source?: string; tlp?: string; } } export interface ThreatEventGetParams { /** * Account ID. */ account_id: string; } export declare namespace ThreatEvents { export { type ThreatEventCreateResponse as ThreatEventCreateResponse, type ThreatEventListResponse as ThreatEventListResponse, type ThreatEventBulkCreateResponse as ThreatEventBulkCreateResponse, type ThreatEventBulkCreateRelationshipsResponse as ThreatEventBulkCreateRelationshipsResponse, type ThreatEventEditResponse as ThreatEventEditResponse, type ThreatEventGetResponse as ThreatEventGetResponse, type ThreatEventCreateParams as ThreatEventCreateParams, type ThreatEventListParams as ThreatEventListParams, type ThreatEventBulkCreateParams as ThreatEventBulkCreateParams, type ThreatEventBulkCreateRelationshipsParams as ThreatEventBulkCreateRelationshipsParams, type ThreatEventEditParams as ThreatEventEditParams, type ThreatEventGetParams as ThreatEventGetParams, }; export { Aggregate as Aggregate, BaseAggregate as BaseAggregate, type AggregateListResponse as AggregateListResponse, type AggregateListParams as AggregateListParams, }; export { Graphql as Graphql, BaseGraphql as BaseGraphql, type GraphqlCreateResponse as GraphqlCreateResponse, type GraphqlCreateParams as GraphqlCreateParams, }; export { Graph as Graph, BaseGraph as BaseGraph, type GraphListResponse as GraphListResponse, type GraphListParams as GraphListParams, }; export { Queries as Queries, BaseQueries as BaseQueries, type QueryCreateResponse as QueryCreateResponse, type QueryListResponse as QueryListResponse, type QueryEditResponse as QueryEditResponse, type QueryGetResponse as QueryGetResponse, type QueryCreateParams as QueryCreateParams, type QueryListParams as QueryListParams, type QueryDeleteParams as QueryDeleteParams, type QueryEditParams as QueryEditParams, type QueryGetParams as QueryGetParams, }; export { Relationships as Relationships, BaseRelationships as BaseRelationships, type RelationshipListResponse as RelationshipListResponse, type RelationshipListParams as RelationshipListParams, }; export { Indicators as Indicators, BaseIndicators as BaseIndicators, type IndicatorListResponse as IndicatorListResponse, type IndicatorListParams as IndicatorListParams, }; export { Attackers as Attackers, BaseAttackers as BaseAttackers, type AttackerListResponse as AttackerListResponse, type AttackerListParams as AttackerListParams, }; export { Categories as Categories, BaseCategories as BaseCategories, type CategoryCreateResponse as CategoryCreateResponse, type CategoryListResponse as CategoryListResponse, type CategoryDeleteResponse as CategoryDeleteResponse, type CategoryEditResponse as CategoryEditResponse, type CategoryGetResponse as CategoryGetResponse, type CategoryCreateParams as CategoryCreateParams, type CategoryListParams as CategoryListParams, type CategoryDeleteParams as CategoryDeleteParams, type CategoryEditParams as CategoryEditParams, type CategoryGetParams as CategoryGetParams, }; export { Countries as Countries, BaseCountries as BaseCountries, type CountryListResponse as CountryListResponse, type CountryListParams as CountryListParams, }; export { Crons as Crons, BaseCrons as BaseCrons }; export { Datasets as Datasets, BaseDatasets as BaseDatasets, type DatasetCreateResponse as DatasetCreateResponse, type DatasetListResponse as DatasetListResponse, type DatasetDeleteResponse as DatasetDeleteResponse, type DatasetEditResponse as DatasetEditResponse, type DatasetGetResponse as DatasetGetResponse, type DatasetRawResponse as DatasetRawResponse, type DatasetCreateParams as DatasetCreateParams, type DatasetListParams as DatasetListParams, type DatasetDeleteParams as DatasetDeleteParams, type DatasetEditParams as DatasetEditParams, type DatasetGetParams as DatasetGetParams, type DatasetRawParams as DatasetRawParams, }; export { RawAPIRaw as Raw, BaseRaw as BaseRaw, type RawEditResponse as RawEditResponse, type RawGetResponse as RawGetResponse, type RawEditParams as RawEditParams, type RawGetParams as RawGetParams, }; export { Relate as Relate, BaseRelate as BaseRelate, type RelateDeleteResponse as RelateDeleteResponse, type RelateDeleteParams as RelateDeleteParams, }; export { Tags as Tags, BaseTags as BaseTags, type TagCreateResponse as TagCreateResponse, type TagListResponse as TagListResponse, type TagDeleteResponse as TagDeleteResponse, type TagEditResponse as TagEditResponse, type TagCreateParams as TagCreateParams, type TagListParams as TagListParams, type TagDeleteParams as TagDeleteParams, type TagEditParams as TagEditParams, }; export { EventTags as EventTags, BaseEventTags as BaseEventTags, type EventTagCreateResponse as EventTagCreateResponse, type EventTagDeleteResponse as EventTagDeleteResponse, type EventTagCreateParams as EventTagCreateParams, type EventTagDeleteParams as EventTagDeleteParams, }; export { TargetIndustries as TargetIndustries, BaseTargetIndustries as BaseTargetIndustries, type TargetIndustryListResponse as TargetIndustryListResponse, type TargetIndustryListParams as TargetIndustryListParams, }; export { Insights as Insights, BaseInsights as BaseInsights }; } //# sourceMappingURL=threat-events.d.mts.map