display: Rubrik Security Cloud name: RubrikPolaris category: Data Enrichment & Threat Intelligence provider: Rubrik commonfields: id: RubrikPolaris version: -1 sectionorder: - Connect - Collect configuration: - display: Service Account JSON name: service_account_json type: 4 required: false section: Connect - display: Rubrik Account (e.g. ${rubrikAccount}.my.rubrik.com) name: url type: 0 required: false section: Connect - display: Email name: email type: 9 required: false section: Connect - defaultvalue: 'false' display: Fetch incidents name: isFetch type: 8 required: false section: Collect - display: Incident type name: incidentType type: 13 required: false section: Collect - defaultvalue: Event,Threat Monitoring Object,DSPM Violation,IR Violation,Sensitive Data Object display: RSC Fetch Types additionalinfo: "Select RSC types to fetch as incidents.\n\nNote: Supports the listed options only. If not provided, it will fetch all listed options." name: rsc_fetch_types options: - Event - Threat Monitoring Object - DSPM Violation - IR Violation - Sensitive Data Object type: 16 required: false section: Collect - defaultvalue: ANOMALY,THREAT_MONITORING display: Event types to fetch as incidents additionalinfo: "Event types to fetch as incidents.\nNote: Supports the listed options only. If not provided, it will fetch events for all listed options. Applies only when RSC fetch type is set to \"Event\"." name: event_types options: - ANOMALY - THREAT_MONITORING type: 16 required: false section: Collect - defaultvalue: SEVERITY_CRITICAL display: Event severities to fetch as incidents additionalinfo: "Event severities to fetch as incidents.\nNote: Supports the listed options only. If not provided, it will fetch events for critical severity level. Applies only when RSC fetch type is set to \"Event\"." name: event_severities options: - SEVERITY_CRITICAL - SEVERITY_WARNING - SEVERITY_INFO type: 16 required: false section: Collect - additionalinfo: "Select Threat Monitoring Match Types to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"Threat Monitoring object\"." display: Threat Monitoring Match Types name: threat_monitoring_match_types options: - INDICATOR_OF_COMPROMISE_TYPE_YARA_RULE - INDICATOR_OF_COMPROMISE_TYPE_PATH_OR_FILENAME - INDICATOR_OF_COMPROMISE_TYPE_HASH type: 16 required: false section: Collect - additionalinfo: "Select Threat Monitoring Object Types to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"Threat Monitoring object\"." display: Threat Monitoring Object Types name: threat_monitoring_object_types options: - ShareFileset - NutanixVirtualMachine - VolumeGroup - HypervVirtualMachine - LinuxFileset - WindowsFileset - VmwareVirtualMachine type: 16 required: false section: Collect - additionalinfo: The time interval for the first fetch (retroactive). Examples of supported values can be found at https://dateparser.readthedocs.io/en/latest/#relative-dates. defaultvalue: 3 days display: First fetch time name: first_fetch type: 0 required: false section: Collect - defaultvalue: "1" display: Incidents Fetch Interval name: incidentFetchInterval required: false section: Collect type: 19 - additionalinfo: "Maximum number of incidents to fetch every time. The maximum value is 1000.\n\nNote: If multiple fetch types (Events, Threat Monitoring objects, DSPM Violations, IR Violations, Sensitive Data Objects) are selected, the limit is distributed optimally among them to fetch all types." defaultvalue: '20' display: Fetch Limit (Maximum of 1000) name: max_fetch type: 0 required: false section: Collect - additionalinfo: When an event of Critical severity is detected and fetched, this setting indicates what severity will get assigned within XSOAR. defaultvalue: XSOAR HIGH display: Event Critical Severity Level Mapping name: radar_critical_severity_mapping options: - XSOAR CRITICAL - XSOAR HIGH - XSOAR MEDIUM - XSOAR LOW type: 15 required: false section: Collect - additionalinfo: When an event of Warning severity is detected and fetched, this setting indicates what severity will get assigned within XSOAR. defaultvalue: XSOAR LOW display: Event Warning Severity Level Mapping name: radar_warning_severity_mapping options: - XSOAR CRITICAL - XSOAR HIGH - XSOAR MEDIUM - XSOAR LOW type: 15 required: false section: Collect - additionalinfo: When a threat monitoring object is fetched, this setting indicates what severity will get assigned within XSOAR. defaultvalue: XSOAR HIGH display: Threat Monitoring Object Severity Level Mapping name: threat_monitoring_severity_mapping options: - XSOAR CRITICAL - XSOAR HIGH - XSOAR MEDIUM - XSOAR LOW type: 15 required: false section: Collect - additionalinfo: "Select DSPM violation statuses to fetch as incidents. Default is OPEN and IN_PROGRESS.\n\nNote: Applies only when RSC fetch type is set to \"DSPM Violation\"." display: DSPM Violation Statuses name: dspm_violation_status options: - OPEN - IN_PROGRESS - REMEDIATED - DISMISSED - CLOSED defaultvalue: "OPEN,IN_PROGRESS" type: 16 required: false section: Collect - additionalinfo: "Select DSPM violation sensitivity levels to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"DSPM Violation\"." display: DSPM Violation Sensitivity Levels name: dspm_violation_sensitivity options: - HIGH - MEDIUM - LOW - NO type: 16 required: false section: Collect - additionalinfo: "Select DSPM violation severity levels to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"DSPM Violation\"." display: DSPM Violation Severity Levels name: dspm_violation_severity options: - CRITICAL - HIGH - MEDIUM - LOW - SEVERITY_UNSPECIFIED type: 16 required: false section: Collect - additionalinfo: "Select DSPM violation categories to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"DSPM Violation\"." display: DSPM Violation Categories name: dspm_violation_category options: - CATEGORY_UNSPECIFIED - MISPLACED - REDUNDANT - OVEREXPOSED - UNPROTECTED type: 16 required: false section: Collect - additionalinfo: "Select DSPM violation object types to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"DSPM Violation\". Values not included in the options can be found in the documentation." display: DSPM Violation Object Types name: dspm_violation_object_type options: - AWS_NATIVE_DYNAMODB_TABLE - AWS_NATIVE_EBS_VOLUME - AWS_NATIVE_RDS_INSTANCE - AWS_NATIVE_S3_BUCKET - AZURE_MANAGED_DISK - AZURE_SQL_DATABASE_DB - AZURE_SQL_MANAGED_INSTANCE_DB - AZURE_STORAGE_ACCOUNT - AZURE_VIRTUAL_MACHINE - GCP_NATIVE_DISK - GCP_NATIVE_GCE_INSTANCE - HYPERV_VIRTUAL_MACHINE - K8S_PROTECTION_SET - K8S_VIRTUAL_MACHINE - LINUX_FILESET - NAS_FILESET - NUTANIX_VIRTUAL_MACHINE - O365_ONEDRIVE - O365_SITE - ORACLE_DATA_GUARD_GROUP - ORACLE_DATABASE - SHARE_FILESET - VOLUME_GROUP - VSPHERE_VIRTUAL_MACHINE - WINDOWS_FILESET type: 16 required: false section: Collect - additionalinfo: "Select IR violation policy types to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"IR Violation\"." display: IR Violation Policy Types name: ir_violation_policy_type options: - IDENTITY - IDP - IDENTITY_EVENT - CROWDSTRIKE - MICROSOFT_DEFENDER type: 16 required: false section: Collect - additionalinfo: "Select IR violation statuses to fetch as incidents. Default is OPEN and IN_PROGRESS.\n\nNote: Applies only when RSC fetch type is set to \"IR Violation\"." display: IR Violation Statuses name: ir_violation_status options: - OPEN - IN_PROGRESS - REMEDIATED - DISMISSED - CLOSED defaultvalue: "OPEN,IN_PROGRESS" type: 16 required: false section: Collect - additionalinfo: "Select IR violation severity levels to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"IR Violation\"." display: IR Violation Severity Levels name: ir_violation_severity options: - CRITICAL - HIGH - MEDIUM - LOW - SEVERITY_UNSPECIFIED type: 16 required: false section: Collect - additionalinfo: "Select IR violation categories to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"IR Violation\"." display: IR Violation Categories name: ir_violation_category options: - CATEGORY_UNSPECIFIED - AUTHENTICATION_AND_SECRET_MANAGEMENT - IDENTITY_HYGIENE - EXCESSIVE_IDENTITY_RIGHTS - IDENTITY_PROVIDER_SECURITY - PRIVILEGED_ACCOUNT_RISK - IDENTITY_RISK - INFRASTRUCTURE_SECURITY - CONFIGURATION_SECURITY - MEMBERSHIP_CHANGE - GPO_CHANGE type: 16 required: false section: Collect - additionalinfo: "Select IR violation identity providers to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"IR Violation\"." display: IR Violation Identity Providers name: ir_violation_identity_provider options: - IDP_UNSPECIFIED - ON_PREM_AD - ENTRA_ID - AWS - LOCAL_AD - SHAREPOINT - SYSTEM - OKTA type: 16 required: false section: Collect - additionalinfo: "Select IR violation identity tags to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"IR Violation\"." display: IR Violation Identity Tags name: ir_violation_identity_tag options: - IDENTITY_TAG_UNSPECIFIED - PRIVILEGED - AT_RISK - SENSITIVE type: 16 required: false section: Collect - additionalinfo: "Select Sensitive Data Object sensitivity levels to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"Sensitive Data Object\"." display: Sensitive Data Object Sensitivity Levels name: sensitive_data_object_sensitivity options: - HIGH - MEDIUM - LOW - NO type: 16 required: false section: Collect - additionalinfo: "Select Sensitive Data Object types to fetch as incidents. Default is all.\n\nNote: Applies only when RSC fetch type is set to \"Sensitive Data Object\". Values not included in the options can be found in the documentation." display: Sensitive Data Object Types name: sensitive_data_object_type options: - VmwareVirtualMachine - LinuxFileset - ShareFileset - WindowsFileset - NutanixVirtualMachine - HypervVirtualMachine - VolumeGroup - NAS_FILESET - OLVM_VIRTUAL_MACHINE - AzureNativeVm - AzureNativeManagedDisk - AZURE_STORAGE_ACCOUNT - AZURE_SQL_DATABASE_DB - AZURE_SQL_MANAGED_INSTANCE_DB - O365Onedrive - O365Site - AWS_NATIVE_S3_BUCKET - AwsNativeEbsVolume - AwsNativeRdsInstance - AWS_NATIVE_DYNAMODB_TABLE - OracleDatabase - ORACLE_DATA_GUARD_GROUP - K8S_VIRTUAL_MACHINE - K8S_PROTECTION_SET - GcpNativeGCEInstance - GcpNativeDisk type: 16 required: false section: Collect - name: integration_reliability display: Source Reliability additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: A - Completely reliable options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: false type: 15 section: Collect - additionalinfo: Whether to use XSOAR's system proxy settings to connect to the API. display: Use system proxy settings name: proxy type: 8 required: false section: Connect - additionalinfo: Whether to allow connections without verifying SSL certificates validity. display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect description: The Rubrik Security Cloud integration will fetch the Rubrik Anomaly Event and is rich with commands to perform the on-demand scans, backups, recoveries and many more features to manage and protect the organizational data. script: commands: - arguments: - description: "The ID of the Polaris Event Series. When used in combination with \"Rubrik Radar Anomaly\" incidents, this value will automatically be looked up using the incident context. Otherwise it is a required value.\n\nNote: Users can retrieve the list of the activity series IDs by executing the \"rubrik-event-list\" command." name: activitySeriesId required: true - description: "The ID of the CDM cluster. When used in combination with \"Rubrik Radar Anomaly\" incidents, this value will automatically be looked up using the incident context. Otherwise, it is a required value.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." name: clusterId required: true deprecated: true description: Check the Radar Event for updates. name: rubrik-radar-analysis-status outputs: - contextPath: Rubrik.Radar.EventComplete description: Flag that indicates whether Radar has finished analysing the object. type: Boolean - contextPath: Rubrik.Radar.Message description: The text, ID, and timestamp of each message in the Activity Series. type: Unknown - contextPath: Rubrik.Radar.ActivitySeriesId description: The ID of the Rubrik Polaris Activity Series. type: String - contextPath: Rubrik.Radar.ClusterId description: The ID of the cluster. type: String - arguments: - description: |- The name of the Rubrik object to check for sensitive hits. When used in combination with "Rubrik Radar Anomaly" incidents, this value will automatically be looked up using the incident context. Otherwise it is a required value. Note: Users can get the list of the object names by executing the "rubrik-polaris-object-list" or "rubrik-polaris-object-search" command. . name: objectName - defaultValue: 7 description: |- The number of days in the past to look for sensitive hits. If no value is provided, then today's data will be returned and, if there is no data for today then the argument will default to 7 days. . name: searchTimePeriod description: Find data classification hits on an object. name: rubrik-sonar-sensitive-hits outputs: - contextPath: Rubrik.Sonar.totalHits description: The total number of data classification hits found on the provided object. type: String - contextPath: Rubrik.Sonar.id description: ID of the sensitive hits object. type: String - contextPath: Rubrik.Sonar.policy_hits description: Information of the policy analyzer group of the sensitive hits object. type: Unknown - contextPath: Rubrik.Sonar.filesWithHits description: The total number of files with hits of the object. type: Number - contextPath: Rubrik.Sonar.openAccessFiles description: The total number of open access files of the object. type: Number - contextPath: Rubrik.Sonar.openAccessFilesWithHits description: The total number of open access files with hits of the object. type: Number - contextPath: Rubrik.Sonar.openAccessFolders description: The total number of open access folders of the object. type: Number - contextPath: Rubrik.Sonar.staleFiles description: The total number of stale files of the object. type: Number - contextPath: Rubrik.Sonar.staleFilesWithHits description: The total number of stale files with hits of the object. type: Number - contextPath: Rubrik.Sonar.openAccessStaleFiles description: The total number of open access stale files of the object. type: Number - contextPath: Rubrik.Radar.Message description: The text, ID, and timestamp of each message in the Activity Series. type: Unknown - contextPath: Rubrik.Radar.ActivitySeriesId description: The ID of the Rubrik Polaris Activity Series. type: String - arguments: - description: "The ID of the CDM cluster. When used in combination with \"Rubrik Radar Anomaly\" incidents, this value will automatically be looked up using the incident context. Otherwise, it is a required value.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." name: clusterId required: true description: Find the CDM GeoLocation of a CDM Cluster. name: rubrik-cdm-cluster-location outputs: - contextPath: Rubrik.CDM.Cluster.Location description: The GeoLocation of the Rubrik CDM Cluster. type: String - contextPath: Rubrik.CDM.ClusterId description: The ID of the cluster. type: String - arguments: - description: "The ID of the CDM cluster. When used in combination with \"Rubrik Radar Anomaly\" incidents, this value will automatically be looked up using the incident context. Otherwise, it is a required value.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." name: clusterId required: true description: Find the CDM Connection State of a CDM Cluster. name: rubrik-cdm-cluster-connection-state outputs: - contextPath: Rubrik.CDM.Cluster.ConnectionState description: The Connection State of the Rubrik CDM Cluster. type: String - contextPath: Rubrik.CDM.ClusterId description: The ID of the cluster. type: String - arguments: - defaultValue: 50 description: Number of results to retrieve in the response. Maximum size allowed is 1000. name: limit - description: 'The name of the object to search for.' name: object_name required: true - defaultValue: ID description: "Specify the field to use for sorting the response.\n\nNote: Supported values are \"ID\" and \"NAME\" only. For any other values, the obtained result is sorted or not is not confirmed." name: sort_by - auto: PREDEFINED defaultValue: ASC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC - description: The next page cursor to retrieve the next set of results. name: next_page_token description: Search for Rubrik discovered objects of any type, return zero or more matches. name: rubrik-polaris-object-search outputs: - contextPath: RubrikPolaris.GlobalSearchObject.id description: The ID of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.name description: The name of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.objectType description: The type of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.physicalPath.fid description: The FID of the physical path of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.physicalPath.name description: The name of the physical path where the object relies. type: String - contextPath: RubrikPolaris.GlobalSearchObject.physicalPath.objectType description: The object type of the physical path where the object relies. type: String - contextPath: RubrikPolaris.GlobalSearchObject.azureRegion description: The azure region of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.awsRegion description: The aws region of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.emailAddress description: The email address of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.isRelic description: Whether the object is relic (historical) or not. type: Boolean - contextPath: RubrikPolaris.GlobalSearchObject.effectiveSlaDomain.id description: The effective SLA domain ID of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.effectiveSlaDomain.name description: The effective SLA domain name of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.effectiveSlaDomain.description description: The effective SLA domain description of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.effectiveSlaDomain.fid description: The FID of the object's effective SLA domain. type: String - contextPath: RubrikPolaris.GlobalSearchObject.effectiveSlaDomain.cluster.id description: The cluster ID of the object's effective SLA domain. type: String - contextPath: RubrikPolaris.GlobalSearchObject.effectiveSlaDomain.cluster.name description: The cluster name of the object's effective SLA domain. type: String - contextPath: RubrikPolaris.GlobalSearchObject.physicalChildConnection.count description: The count of physical child connection of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.physicalChildConnection.edges.node.id description: The ID of physical child connection of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.physicalChildConnection.edges.node.name description: The name of the physical child connection of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.physicalChildConnection.edges.node.replicatedObjects.cluster.id description: The cluster ID of the replicated objects of physical child connection of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.physicalChildConnection.edges.node.replicatedObjects.cluster.name description: The cluster name of the replicated objects of physical child connection of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.cluster.id description: The cluster ID related to the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.cluster.name description: The name of the cluster related to the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.primaryClusterLocation.id description: The primary cluster location ID of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.gcpZone description: The gcp zone of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.gcpRegion description: The gcp region of the object. type: String - contextPath: RubrikPolaris.GlobalSearchObject.gcpNativeProject.name description: The gcp native project name of the object. type: String - contextPath: RubrikPolaris.PageToken.GlobalSearchObject.next_page_token description: Next page token. type: String - contextPath: RubrikPolaris.PageToken.GlobalSearchObject.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.GlobalSearchObject.has_next_page description: Whether the result has the next page or not. type: Boolean - description: Retrieve the list of all the available Sonar policies. name: rubrik-sonar-policies-list outputs: - contextPath: RubrikPolaris.SonarPolicy.id description: Unique ID of the policy. type: String - contextPath: RubrikPolaris.SonarPolicy.name description: Name of the policy. type: String - contextPath: RubrikPolaris.SonarPolicy.description description: Descriptive name of the policy. type: String - contextPath: RubrikPolaris.SonarPolicy.creator.email description: Email of the user who created the policy. type: String - contextPath: RubrikPolaris.SonarPolicy.totalObjects description: Number of total objects present in the policy. type: Number - contextPath: RubrikPolaris.SonarPolicy.numAnalyzers description: Number of analyzers present in the policy. type: Number - contextPath: RubrikPolaris.SonarPolicy.objectStatuses.id description: ID of the object present in the policy. type: String - contextPath: RubrikPolaris.SonarPolicy.objectStatuses.latestSnapshotResult.snapshotFid description: Snapshot ID of the object present in the policy. type: String - contextPath: RubrikPolaris.SonarPolicy.objectStatuses.policyStatuses.policyId description: Policy ID. type: String - contextPath: RubrikPolaris.SonarPolicy.objectStatuses.policyStatuses.status description: Policy status. type: String - description: List the analyzer group policies. name: rubrik-sonar-policy-analyzer-groups-list outputs: - contextPath: RubrikPolaris.SonarAnalyzerGroup.id description: The analyzer group ID. type: String - contextPath: RubrikPolaris.SonarAnalyzerGroup.name description: The name of the analyzer group. type: String - contextPath: RubrikPolaris.SonarAnalyzerGroup.groupType description: The analyzer group type. type: String - contextPath: RubrikPolaris.SonarAnalyzerGroup.analyzers.id description: The ID of the analyzers belong to the group. type: String - contextPath: RubrikPolaris.SonarAnalyzerGroup.analyzers.name description: The name of the analyzers belong to the group. type: String - contextPath: RubrikPolaris.SonarAnalyzerGroup.analyzers.analyzerType description: The type of the analyzers belong to the group. type: String - arguments: - description: "The ID of the object to get details.\n\nNote: Users can get the list of the object IDs by executing the \"rubrik-polaris-vm-objects-list\" command." name: object_id required: true description: Retrieve details for a Vsphere object based on the provided object ID. name: rubrik-polaris-vm-object-metadata-get outputs: - contextPath: RubrikPolaris.VSphereVm.id description: Unique ID of the object. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.authorizedOperations description: List of operations performed by the object. type: Unknown - contextPath: RubrikPolaris.VSphereVm.metadata.name description: The name of the object. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.isRelic description: Whether the object is relic or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.metadata.effectiveSlaDomain.id description: ID of the SLA domain. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.effectiveSlaDomain.name description: Name of the SLA domain. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.effectiveSlaDomain.cluster.id description: ID of the cluster of the SLA domain. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.effectiveSlaDomain.cluster.name description: Name of the cluster of the SLA domain. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.effectiveSlaSourceObject.fid description: SLA Source object FID. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.effectiveSlaSourceObject.name description: SLA source object name. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.effectiveSlaSourceObject.objectType description: SLA source object type. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.protectionDate description: Protection date of the object. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.reportSnappable.id description: The ID of the snappable for a particular report related to an object. Snappable supports backups or filesets of physical machines using the rubrik connector. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.reportSnappable.logicalBytes description: Logical bytes of snappable report. type: Number - contextPath: RubrikPolaris.VSphereVm.metadata.reportSnappable.physicalBytes description: The physical byte of the snappable for a particular report related to an object. type: Number - contextPath: RubrikPolaris.VSphereVm.metadata.reportSnappable.archiveStorage description: The archived storage of the snappable for a particular report related to an object. type: Number - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.id description: Unique ID of the cluster which is the datastore for the recovered virtual machine. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.name description: Cluster name of the VM to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.status description: Cluster status of the VM to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.version description: Cluster version of the VM to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.lastConnectionTime description: Last time when the vm was connected to the cluster. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.defaultAddress description: Default address where the cluster is stored. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.clusterNodeConnection.nodes.id description: Node ID of the node connection related to cluster. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.clusterNodeConnection.nodes.status description: Node status of the node connection related to cluster. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.clusterNodeConnection.nodes.ipAddress description: IP address of the node connection related to cluster. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.state.connectedState description: Connected state of the cluster. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.state.clusterRemovalState description: State of the cluster if it is registered for removal or not. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.passesConnectivityCheck description: Whether the cluster passes connectivity check or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.globalManagerConnectivityStatus.urls.url description: URL of Global Manager Connectivity Status. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.globalManagerConnectivityStatus.urls.isReachable description: Whether the url in global Manager Connectivity Status is reachable or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.metadata.cluster.connectivityLastUpdated description: Date time when the connectivity status of the cluster is lastly updated. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.primaryClusterLocation.id description: The location ID of the primary cluster to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.primaryClusterLocation.name description: The location name of the primary cluster to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.arrayIntegrationEnabled description: Whether the array integration is enabled or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.metadata.snapshotConsistencyMandate description: "Data consistency in recovery points is the snapshot consistency mandate. It is broadly classified into 3 categories: inconsistent, crash-consistent, app-consistent." type: String - contextPath: RubrikPolaris.VSphereVm.metadata.agentStatus.agentStatus description: The status of an agent related to an object. In Rubrik agents are connectors also known as Rubrik Backup Service. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.logicalPath.fid description: The logical path ID of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.logicalPath.objectType description: The logical object type of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.logicalPath.name description: The logical name of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.physicalPath.fid description: The physical path of where the VM resides. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.physicalPath.objectType description: The physical path object type of the VM. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.physicalPath.name description: The physical Name of the VM. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.vsphereTagPath.fid description: FID of Vsphere tag. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.vsphereTagPath.objectType description: Object type of Vsphere tag. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.vphereTagPath.name description: Name of Vsphere tag. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.oldestSnapshot.id description: The ID of the oldest snapshot. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.oldestSnapshot.date description: The date when the oldest snapshot was generated. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.oldestSnapshot.isIndexed description: Whether the oldest snapshot is indexed or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.metadata.totalSnapshots.count description: Total snapshot counts. type: Number - contextPath: RubrikPolaris.VSphereVm.metadata.replicatedObjects.id description: The ID of the object which is replicated in the VM. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.replicatedObjects.primaryClusterLocation.id description: The primary cluster location ID where the replicated object resides. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.replicatedObjects.primaryClusterLocation.name description: The primary cluster location name where the replicated object resides. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.replicatedObjects.cluster.name description: The cluster name where the replicated object resides. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.replicatedObjects.cluster.id description: The cluster ID where the replicated object resides. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestArchivedSnapshot.id description: ID of the newest archived snapshot. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestArchivedSnapshot.date description: The date when the newest archived snapshot was generated. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestArchivedSnapshot.isIndexed description: Whether the newest archived snapshot is indexed or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.metadata.newestArchivedSnapshot.archivalLocations.id description: ID of the archival location of the newest archived snapshot. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestArchivedSnapshot.archivalLocations.name description: Name of the archival location of the newest archival snapshot. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestReplicatedSnapshot.id description: The ID of the newest replicated snapshot. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestReplicatedSnapshot.date description: The date when the newest replicated snapshot was generated. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestReplicatedSnapshot.isIndexed description: Whether the newest replicated snapshot is indexed or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.metadata.newestReplicatedSnapshot.replicationLocations.id description: The ID of the replication locations of the newest replicated snapshot. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestReplicatedSnapshot.replicationLocations.name description: The name of the replication locations of the newest replicated snapshot. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestSnapshot.id description: The ID of the newest snapshot. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestSnapshot.date description: The date when the newest snapshot was generated. type: String - contextPath: RubrikPolaris.VSphereVm.metadata.newestSnapshot.isIndexed description: Whether the newest snapshot is indexed or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.metadata.onDemandSnapshotCount description: Count of how many on demand snapshot created in a VM. type: Number - contextPath: RubrikPolaris.VSphereVm.metadata.vmwareToolsInstalled description: Whether the Vmware tools are installed or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.metadata.cdmLink description: The Cloud Data Management link to navigate to the VM on cloud. type: String - arguments: - auto: PREDEFINED description: "Filter based on whether VM objects are moved to relic/archive or not.\n\nPossible values are: \"True\", \"False\"." name: is_relic predefined: - "True" - "False" - auto: PREDEFINED description: "Filter based on whether VM objects are replicated or not.\n\nPossible values are: \"True\", \"False\"." name: is_replicated predefined: - "True" - "False" - defaultValue: 50 description: Number of results to retrieve in the response. Maximum size allowed is 1000. name: limit - defaultValue: ID description: "Specify the field to use for sorting the response.\n\nNote: Supported values are \"ID\" and \"NAME\" only. For any other values, the obtained result is sorted or not is not confirmed." name: sort_by - auto: PREDEFINED defaultValue: ASC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC - description: The next page cursor to retrieve the next set of results. name: next_page_token description: Retrieve a list of all the objects of the Vsphere Vm known to the Rubrik. name: rubrik-polaris-vm-objects-list outputs: - contextPath: RubrikPolaris.VSphereVm.id description: Unique ID of the object. type: String - contextPath: RubrikPolaris.VSphereVm.name description: Name of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.objectType description: Object type of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.replicatedObjectCount description: Number of objects replicated in the node in which the object relies. type: Number - contextPath: RubrikPolaris.VSphereVm.cluster.id description: ID of the cluster which is the datastore for the recovered virtual machine. type: String - contextPath: RubrikPolaris.VSphereVm.cluster.name description: Cluster name of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.cluster.version description: Cluster version of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.cluster.status description: Cluster status of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.effectiveSlaDomain.id description: ID of the SLA domain which is simply a set of policies that define at what frequencies backups should be performed of the protected objects within Rubrik and for how long they should be either locally or a replication partner or on the archival location. type: String - contextPath: RubrikPolaris.VSphereVm.effectiveSlaDomain.name description: Descriptive name of the SLA domain. type: String - contextPath: RubrikPolaris.VSphereVm.effectiveSlaDomain.description description: Description of the SLA domain. type: String - contextPath: RubrikPolaris.VSphereVm.effectiveSlaDomain.fid description: FID of the SLA domain. type: String - contextPath: RubrikPolaris.VSphereVm.effectiveSlaDomain.cluster.id description: ID of the cluster related to the effective SLA domain. type: String - contextPath: RubrikPolaris.VSphereVm.effectiveSlaDomain.cluster.name description: Name of the cluster related to the effective SLA domain. type: String - contextPath: RubrikPolaris.VSphereVm.effectiveSlaSourceObject.fid description: SLA source object FID. type: String - contextPath: RubrikPolaris.VSphereVm.effectiveSlaSourceObject.name description: SLA source object name. type: String - contextPath: RubrikPolaris.VSphereVm.effectiveSlaSourceObject.objectType description: SLA source object type. type: String - contextPath: RubrikPolaris.VSphereVm.slaAssignment description: A SLA rule when referred at assignment is SLA assignment. type: String - contextPath: RubrikPolaris.VSphereVm.isRelic description: Whether the object is relic or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.authorizedOperations description: List of operations that can be performed on the object. type: Unknown - contextPath: RubrikPolaris.VSphereVm.primaryClusterLocation.id description: The location ID of the primary cluster to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.primaryClusterLocation.name description: The location name of the primary cluster to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.logicalPath.fid description: The logical path ID of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.logicalPath.name description: The logical path name of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.logicalPath.objectType description: The logical object type of the node to which the object belongs. type: String - contextPath: RubrikPolaris.VSphereVm.snapshotDistribution.id description: Rubrik uses a snapshot for powerful data protection. Snapshot distribution ID is the ID of the snapshot distribution node related to a particular object. type: String - contextPath: RubrikPolaris.VSphereVm.snapshotDistribution.onDemandCount description: The demand count of distribution of snapshot related to an object. type: Number - contextPath: RubrikPolaris.VSphereVm.snapshotDistribution.retrievedCount description: The retrieved count of distribution of snapshot related to an object. type: Number - contextPath: RubrikPolaris.VSphereVm.snapshotDistribution.scheduledCount description: The scheduled count of distribution of snapshot related to an object. type: Number - contextPath: RubrikPolaris.VSphereVm.snapshotDistribution.totalCount description: The total count of distribution of snapshot related to an object. type: Number - contextPath: RubrikPolaris.VSphereVm.reportSnappable.id description: The ID of the snappable for a particular report related to an object. Snapple supports backups or filesets of physical machines using the rubrik connector. type: String - contextPath: RubrikPolaris.VSphereVm.reportSnappable.archieveStorage description: The archived storage of the snappable for a particular report related to an object. type: Number - contextPath: RubrikPolaris.VSphereVm.reportSnappable.physicalBytes description: The physical byte of the snappable for a particular report related to an object. type: Number - contextPath: RubrikPolaris.VSphereVm.vmwareToolsInstalled description: Whether the vm tools are installed or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.agentStatus.agentStatus description: The status of an agent related to an object. The Rubrik agents are connectors also known as Rubrik Backup Service. type: String - contextPath: RubrikPolaris.VSphereVm.agentStatus.disconnectReason description: Displays the reason if the agent disconnects. type: String - contextPath: RubrikPolaris.PageToken.VSphereVm.next_page_token description: Next page token. type: String - contextPath: RubrikPolaris.PageToken.VSphereVm.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.VSphereVm.has_next_page description: Whether the result has the next page or not. type: Boolean - arguments: - description: |- Name of the scan. If not provided, it defaults to " Classification". . name: scan_name - description: "List of sonar policies to scan.\n\nNote: Users can get the list of analyzer groups by executing the \"rubrik-sonar-policy-analyzer-groups-list\" command. \n\nFormat Accepted: \n[\n {\n \"id\": \"543dd5e0-c72c-50e2-a3d9-1688343f472c\",\n \"name\": \"HIPAA\",\n \"groupType\": \"HIPAA\",\n \"analyzers\": [\n {\n \"id\": \"9da675b3-944b-5da3-a2da-ed149d300075\",\n \"name\": \"US/UK Passport\",\n \"analyzerType\": \"PASSPORT\"\n },\n {\n \"id\": \"18665533-c28c-5a40-b747-4b6508fecdfa\",\n \"name\": \"US NPI\",\n \"analyzerType\": \"US_HEALTHCARE_NPI\"\n }\n ]\n }\n]." name: sonar_policy_analyzer_groups required: true - description: "List of VM object IDs to scan.\n\nNote: Users can get the list of VM object IDs by executing the \"rubrik-polaris-vm-objects-list\" command." name: objects_to_scan required: true description: "Trigger an on-demand scan of a system. Supports \"Vsphere VM\" object type only.\n\nNote: To know the scan status use the \"rubrik-sonar-ondemand-scan-status\" command. To download the completed request use the \"rubrik-sonar-ondemand-scan-result\" command." name: rubrik-sonar-ondemand-scan outputs: - contextPath: RubrikPolaris.SonarOndemandScan.crawlId description: Unique crawl ID. type: String - arguments: - description: "ID for which scanning status is to be obtained.\n\nNote: Users can get the crawl ID by executing the \"rubrik-sonar-ondemand-scan\" command." name: crawl_id required: true description: "Retrieve the status of a scanned system.\n\nNote: To download the completed request use the \"rubrik-sonar-ondemand-scan-result\" command." name: rubrik-sonar-ondemand-scan-status outputs: - contextPath: RubrikPolaris.SonarOndemandScan.crawlId description: Crawl ID of the scan for which the rubrik-sonar-ondemand-scan command is hit. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.error description: Error description if any. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.snappable.id description: Snappable ID of the scanned object. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.snappable.name description: Snappable Name of the scanned object. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.snappable.objectType description: Snappable object type of the scanned object. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.snapshotTime description: Time when the snapshot is taken. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.status description: Status of the scanning or scanned object. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.progress description: Count of objects that are in progress. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.totalHits description: Number of total hits obtained from an object that is scanned. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.analyzerGroup.groupType description: Group type of the analyzer. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.analyzerGroup.id description: Group ID of the analyzer. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.analyzerGroup.name description: Group Name of the analyzer. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.analyzerResults.hits.totalHits description: Number of total hits obtained from an analyzer that is scanned. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.analyzerResults.hits.violations description: Number of violations obtained from an analyzer that is scanned. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.analyzerResults.hits.permittedHits description: Number of permitted hits obtained from an analyzer that is scanned. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.analyzerResults.analyzer.id description: ID of the analyzer that is scanned. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.analzerGroupResults.analyzerResults.analyzer.name description: Name of the analyzer that is scanned. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.analyzerResults.analyzer.analyzerType description: Type of the analyzer that is scanned. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.hits.totalHits description: Number of total hits obtained from an analyzer group. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.hits.violations description: Number of violations obtained from an analyzer group. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.hits.permittedHits description: Number of permitted hits obtained from an analyzer group. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.hits.violationsDelta description: Number of violation delta obtained from an analyzer group. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.analyzerGroupResults.hits.totalHitsDelta description: Number of total hits delta obtained from an analyzer group. type: Number - contextPath: RubrikPolaris.SonarOndemandScan.Status.cluster.id description: Cluster ID in which the object is getting scanned. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.cluster.name description: Cluster name in which the object is getting scanned. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Status.cluster.type description: Cluster type in which the object is getting scanned. type: String - arguments: - description: "The object ID for which the snapshots are to be searched.\n\nNote: Users can get the list of the object IDs by executing the \"rubrik-polaris-vm-objects-list\" command." name: object_id required: true - auto: PREDEFINED defaultValue: Day description: "Grouping the snapshots on the basis of the selected value.\n\nPossible values are: \"Month\", \"Day\", \"Year\", \"Week\", \"Hour\", \"Quarter\"." name: snapshot_group_by predefined: - Month - Day - Year - Week - Hour - Quarter - auto: PREDEFINED defaultValue: DAY description: "Grouping the missed snapshots on the basis of the selected value.\n\nPossible values are: \"MONTH\", \"DAY\", \"YEAR\", \"WEEK\", \"HOUR\", \"QUARTER\"." name: missed_snapshot_group_by predefined: - MONTH - DAY - YEAR - WEEK - HOUR - QUARTER - description: "The start date to get snapshots from.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc." name: start_date required: true - description: "The end date to get snapshots until.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc." name: end_date required: true - description: "The timezone offset from UTC changes to match the configured time zone. Use this argument to filter the data according to the provided timezone offset.\n\nFormats accepted: 1, 1.5, 2, 2.5, 5.5, etc." name: timezone_offset required: true - auto: PREDEFINED defaultValue: "True" description: "Whether the cluster is connected or not.\n\nPossible values are: \"True\", \"False\"." name: cluster_connected predefined: - "True" - "False" description: "Search for a Rubrik snapshot of an object based on the provided snapshot ID, exact timestamp, or specific value like earliest/latest, or closest before/after a timestamp." name: rubrik-polaris-vm-object-snapshot-list outputs: - contextPath: RubrikPolaris.VSphereVm.id description: Unique ID of the object. type: String - contextPath: RubrikPolaris.VSphereVm.Snapshot.snapshotGroupByConnection.nodes.groupByInfo.unit description: Unit of snapshot group by connection nodes. type: String - contextPath: RubrikPolaris.VSphereVm.Snapshot.snapshotGroupByConnection.nodes.groupByInfo.start description: Start date of snapshot group by connection nodes. type: String - contextPath: RubrikPolaris.VSphereVm.Snapshot.snapshotGroupByConnection.nodes.groupByInfo.end description: End date of snapshot group by connection nodes. type: String - contextPath: RubrikPolaris.VSphereVm.Snapshot.snapshotGroupByConnection.nodes.snapshotConnection.count description: Count of snapshot connections related to the object. type: Number - contextPath: RubrikPolaris.VSphereVm.Snapshot.snapshotGroupByConnection.nodes.snapshotConnection.nodes.id description: ID of snapshot connection related to the object. type: String - contextPath: RubrikPolaris.VSphereVm.Snapshot.snapshotGroupByConnection.nodes.snapshotConnection.nodes.isIndexed description: Whether the node is indexed or not. type: Boolean - contextPath: RubrikPolaris.VSphereVm.Snapshot.snapshotGroupByConnection.nodes.snapshotConnection.nodes.isUnindexable description: Whether the node is unindexable or not. type: Boolean - arguments: - description: "ID for which file needs to be downloaded.\n\nNote: Users can get the crawl_id by executing the \"rubrik-sonar-ondemand-scan\" command." name: crawl_id required: true - auto: PREDEFINED description: |- The type of the file that needs to be downloaded. Possible values are: "ANY", "HITS", "STALE", "OPEN_ACCESS", "STALE_HITS", "OPEN_ACCESS_HITS". name: file_type predefined: - ANY - HITS - STALE - OPEN_ACCESS - STALE_HITS - OPEN_ACCESS_HITS required: true description: Retrieve the download link for the requested scanned file. name: rubrik-sonar-ondemand-scan-result outputs: - contextPath: RubrikPolaris.SonarOndemandScan.crawlId description: Crawl ID of the file that needs to be downloaded. type: String - contextPath: RubrikPolaris.SonarOndemandScan.Result.downloadLink description: Link to download the file when scan status is complete. type: String - arguments: - description: "The unique ID of the cluster.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." name: cluster_id required: true - description: "The CDM snapshot ID.\n\nNote: Users can retrieve the list of snapshot IDs by executing the \"rubrik-polaris-vm-object-snapshot-list\" command.\nUse the \"rubrik-radar-suspicious-file-list\" command to retrieve the actual CDM ID from the Anomaly ID.\nExample format to get the snapshot CDM ID from Anomaly ID: \":::VirtualMachine::::::\"." name: snapshot_id required: true - description: "The VM object ID (Snappable ID).\n\nNote: Users can retrieve the list of Snappable IDs by executing the \"rubrik-polaris-vm-objects-list\" command.\nExample format to get the Snappable ID: \"VirtualMachine:::\"." name: object_id required: true - auto: PREDEFINED defaultValue: "False" description: If set to True, the command downloads the anomaly analysis CSV file directly on XSOAR server. name: download_file predefined: - "True" - "False" description: Request for the analysis and retrieve the download link or directly download file for the Radar CSV analyzed file. name: rubrik-radar-anomaly-csv-analysis outputs: - contextPath: RubrikPolaris.RadarAnomalyCSV.clusterId description: Cluster ID of the CSV. type: String - contextPath: RubrikPolaris.RadarAnomalyCSV.snapshotId description: Snapshot ID of the CSV. type: String - contextPath: RubrikPolaris.RadarAnomalyCSV.objectId description: Object ID of the CSV. type: String - contextPath: RubrikPolaris.RadarAnomalyCSV.investigationCsvDownloadLink.downloadLink description: The download link of the CSV analysis. type: String - contextPath: File.Size description: File size in bytes. type: String - contextPath: File.SHA1 description: SHA1 hash of file. type: String - contextPath: File.SHA256 description: SHA256 hash of file. type: String - contextPath: File.SHA512 description: SHA512 hash of file. type: String - contextPath: File.Name description: File name. type: String - contextPath: File.SSDeep description: SSDeep hash of the file. type: String - contextPath: File.EntryID description: The entry ID of the file. type: Unknown - contextPath: File.Info description: File information. type: String - contextPath: File.Type description: The file type. type: String - contextPath: File.MD5 description: MD5 hash of the file. type: String - contextPath: File.Extension description: The file extension. type: String - arguments: - description: "ID of the snapshot.\n\nNote: Users can retrieve the list of snapshot IDs by executing the \"rubrik-polaris-vm-object-snapshot-list\" command." name: snapshot_id required: true - description: "Object ID.\n\nNote: Users can retrieve the list of object IDs by executing \"rubrik-polaris-vm-objects-list\" command." name: object_id required: true - auto: PREDEFINED description: "The type of the file that needs to be downloaded.\n\nPossible values are: \"ANY\", \"HITS\", \"STALE\", \"OPEN_ACCESS\", \"STALE_HITS\", \"OPEN_ACCESS_HITS\"." name: file_type predefined: - ANY - HITS - STALE - OPEN_ACCESS - STALE_HITS - OPEN_ACCESS_HITS description: "Request to download the Sonar CSV Snapshot results file.\n\nNote: To know the ID and status of the download, use the \"rubrik-user-downloads-list\" command. To download the file, use the \"rubrik-sonar-csv-result-download\" command." name: rubrik-sonar-csv-download outputs: - contextPath: RubrikPolaris.SonarCSVDownload.snapshotId description: Snapshot ID of the CSV requested to download. type: String - contextPath: RubrikPolaris.SonarCSVDownload.objectId description: Object ID of the CSV requested to download. type: String - contextPath: RubrikPolaris.SonarCSVDownload.downloadSnapshotResultsCsv.isSuccessful description: The status of the download. type: Boolean - arguments: - description: "The Snapshot ID of the file that needs to be downloaded.\n\nNote: Users can retrieve the list of the snapshot IDs by executing the \"rubrik-polaris-vm-object-snapshot-list\" command." name: snapshot_id required: true - description: "The path of the folder to list the sub-files. If not provided the root directory files will be returned.\n\nFormat accepted : \"//\"\n\nExample: \"/C:\", \"/C:/Users\"." name: path - description: "Provide a keyword to search in the file names.\n\nExample: \"admin\"." name: search_prefix - defaultValue: 50 description: Number of results to retrieve in the response. Maximum size allowed is 1000. name: limit - description: The next page cursor to retrieve the next set of results. name: next_page_token description: "Retrieve the list of the available files that can be downloaded.\n\nNote: To initiate the file download request use the \"rubrik-gps-snapshot-files-download\" command." name: rubrik-gps-snapshot-files-list outputs: - contextPath: RubrikPolaris.GPSSnapshotFile.snapshotId description: Snapshot ID provided as an argument to retrieve the files. type: String - contextPath: RubrikPolaris.GPSSnapshotFile.node.absolutePath description: The absolute path of the file. type: String - contextPath: RubrikPolaris.GPSSnapshotFile.node.displayPath description: The display path of the file. type: String - contextPath: RubrikPolaris.GPSSnapshotFile.node.path description: The path of the file. type: String - contextPath: RubrikPolaris.GPSSnapshotFile.node.filename description: The name of the file. type: String - contextPath: RubrikPolaris.GPSSnapshotFile.node.fileMode description: The mode of the file. type: String - contextPath: RubrikPolaris.GPSSnapshotFile.node.size description: The size of the file. type: String - contextPath: RubrikPolaris.GPSSnapshotFile.node.lastModified description: The last modified time of the file. type: String - contextPath: RubrikPolaris.PageToken.GPSSnapshotFile.next_page_token description: Next page token. type: String - contextPath: RubrikPolaris.PageToken.GPSSnapshotFile.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.GPSSnapshotFile.has_next_page description: Whether the result has the next page or not. type: Boolean - arguments: - description: Name given to the VM that runs the snapshot. If not provided the name will be " ". name: vm_name - description: "The VM object ID whose snapshot needs to be exported.\n\nNote: Users can get the list of object IDs by executing the \"rubrik-polaris-vm-objects-list\" command." name: object_id required: true - description: "The ID of the snapshot that is to be exported.\n\nNote: Users can get the list of snapshot IDs by executing the \"rubrik-polaris-vm-object-snapshot-list\" command." name: snapshot_id required: true - description: "The ID of the datastore which will be used by the new VM.\n\nNote: Users can get the list of datastore IDs by executing the \"rubrik-gps-vm-datastore-list\" command." name: datastore_id required: true - description: "The ID of the Vsphere ESXi host on which the new VM will be made. Either host_id or host_compute_cluster_id must be provided.\\n\nNote: Users can get the list of host IDs by executing the \"rubrik-gps-vm-host-list\" command." name: host_id - description: "The ID of the VSphere Compute Cluster of a host. Either host_id or host_compute_cluster_id must be provided. \n\nNote: Users can get the list of Compute Cluster IDs by executing the \"rubrik-gps-vm-host-list\" command. The ID must belong to the VSphereComputeCluster objectType." name: host_compute_cluster_id - auto: PREDEFINED description: |- Whether to turn on the new VM or not. Possible values are: "True", "False". name: power_on predefined: - 'True' - 'False' - auto: PREDEFINED description: |- Whether the mac addresses of network devices of the new VM be removed or not. Possible values are: "True", "False". name: keep_mac_addresses predefined: - 'True' - 'False' - auto: PREDEFINED description: |- Whether the network devices on the original VM be kept or not. Possible values are: "True", "False". name: remove_network_devices predefined: - 'True' - 'False' - auto: PREDEFINED description: |- Whether to keep vSphere tags associated with the original VM or not. Possible values are: "True", "False". name: recover_tags predefined: - 'True' - 'False' - auto: PREDEFINED description: |- Whether to disable networking on the new VM or not. Possible values are: "True", "False". name: disable_network predefined: - 'True' - 'False' description: "Request to initiate an export of a snapshot of a virtual machine.\n\nNote: To know about the exported VM's status, use the \"rubrik-gps-async-result\" command." name: rubrik-gps-vm-export outputs: - contextPath: RubrikPolaris.GPSVMSnapshotExport.id description: Snapshot export request ID. type: String - description: "Retrieve the user downloads. This would return the current and past download history.\n\nNote: To download the requested Sonar CSV Snapshot results file use the \"rubrik-sonar-csv-result-download\" command." name: rubrik-user-downloads-list outputs: - contextPath: RubrikPolaris.UserDownload.id description: The ID of the download. type: Number - contextPath: RubrikPolaris.UserDownload.name description: The name of the download. type: String - contextPath: RubrikPolaris.UserDownload.status description: The status of the download. type: String - contextPath: RubrikPolaris.UserDownload.progress description: The progress of the download. type: Number - contextPath: RubrikPolaris.UserDownload.identifier description: The identifier of the download or the type of download requested. type: String - contextPath: RubrikPolaris.UserDownload.createTime description: The creation time of the download. type: String - contextPath: RubrikPolaris.UserDownload.completeTime description: The completion time of the download. type: String - arguments: - description: Name of the SLA Domain to search for. name: name - description: "Cluster, the SLA domain is managed by.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." name: cluster_id - auto: PREDEFINED description: "Filters SLA domain based on the provided object types. Supports comma separated values. \n\nPossible values are: \"FILESET_OBJECT_TYPE\", \"VSPHERE_OBJECT_TYPE\"." isArray: true name: object_type - auto: PREDEFINED defaultValue: 'True' description: "Whether to show Cluster SLAs and not Global SLAs. \"False\" value will result in showing only Global SLAs. \n\nPossible values are: \"True\", \"False\"." name: show_cluster_slas_only predefined: - 'True' - 'False' - auto: PREDEFINED defaultValue: NAME description: "Specify the field to use for sorting the response.\n\nPossible values are: \"NAME\", \"PROTECTED_OBJECT_COUNT\"." name: sort_by predefined: - NAME - PROTECTED_OBJECT_COUNT - auto: PREDEFINED defaultValue: ASC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC description: Enumerates the available SLA Domains to apply to the on-demand snapshot as a retention policy. name: rubrik-gps-sla-domain-list outputs: - contextPath: RubrikPolaris.GPSSLADomain.name description: Name of the SLA domain. type: String - contextPath: RubrikPolaris.GPSSLADomain.id description: ID of the SLA domain. type: String - contextPath: RubrikPolaris.GPSSLADomain.description description: Description of the SLA domain. type: String - contextPath: RubrikPolaris.GPSSLADomain.protectedObjectCount description: Number of objects under the SLA Domain. type: Number - contextPath: RubrikPolaris.GPSSLADomain.baseFrequency.duration description: Base snapshot frequency duration. type: Number - contextPath: RubrikPolaris.GPSSLADomain.baseFrequency.unit description: Base snapshot frequency unit (HOURS, DAYS etc). type: String - contextPath: RubrikPolaris.GPSSLADomain.archivalSpec.archivalLocationName description: Location where the archives are stored. type: String - contextPath: RubrikPolaris.GPSSLADomain.archivalSpecs.storageSetting.id description: ID of the archival target. type: String - contextPath: RubrikPolaris.GPSSLADomain.archivalSpecs.storageSetting.name description: Name of the archival target. type: String - contextPath: RubrikPolaris.GPSSLADomain.archivalSpecs.storageSetting.groupType description: Group type of the archival target. type: String - contextPath: RubrikPolaris.GPSSLADomain.archivalSpecs.storageSetting.targetType description: Target type of the archival target. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpec.replicationType description: 'Enum value representing the type of replication. Values: UNKNOWN_REPLICATION_TYPE, UNIDIRECTIONAL_REPLICATION_TO_CLUSTER, REPLICATION_TO_CLOUD_REGION, REPLICATION_TO_CLOUD_LOCATION.' type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpec.specificReplicationSpec.unidirectionalSpec.replicationTargetName description: Cloud replication target name. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpec.specificReplicationSpec.cloudRegionSpec.replicationTargetRegion description: Cloud replication target region. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpec.specificReplicationSpec.cloudRegionSpec.cloudProvider description: 'Cloud replication service provider. Values: AWS, AZURE.' type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpec.specificReplicationSpec.cloudLocationSpec.targetMapping.id description: ID of the cloud target where replication takes place. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpec.specificReplicationSpec.cloudLocationSpec.targetMapping.name description: Name of the cloud target where replication takes place. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpecsV2.cluster.id description: ID of the cluster where replication takes place. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpecsV2.cluster.name description: Name of the cluster where replication takes place. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpecsV2.awsTarget.accountId description: Account ID on AWS where the replication happens. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpecsV2.awsTarget.accountName description: Account name on AWS where the replication happens. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpecsV2.awsTarget.region description: Account region on AWS where the replication happens. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpecsV2.azureTarget.region description: Account region on Azure where the replication happens. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpecsV2.retentionDuration.duration description: Replication retention duration. type: Number - contextPath: RubrikPolaris.GPSSLADomain.replicationSpecsV2.retentionDuration.unit description: Replication retention duration unit. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpecsV2.targetMapping.id description: ID of the object target where replication takes place. type: String - contextPath: RubrikPolaris.GPSSLADomain.replicationSpecsV2.targetMapping.name description: Name of the object target where replication takes place. type: String - contextPath: RubrikPolaris.GPSSLADomain.localRetentionLimit.duration description: Local retention limit duration. type: Number - contextPath: RubrikPolaris.GPSSLADomain.localRetentionLimit.unit description: Local retention limit duration unit. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.minute.basicSchedule.frequency description: Snapshot frequency every minute. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.minute.basicSchedule.retention description: Snapshot retention value per minute snapshots. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.minute.basicSchedule.retentionUnit description: Snapshot retention time unit per minute snapshots. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.hourly.basicSchedule.frequency description: Snapshot hourly frequency. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.hourly.basicSchedule.retention description: Snapshot retention value per hour snapshots. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.hourly.basicSchedule.retentionUnit description: Snapshot retention time unit per hour snapshots. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.daily.basicSchedule.frequency description: Snapshot daily frequency. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.daily.basicSchedule.retention description: Snapshot retention value per day snapshots. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.daily.basicSchedule.retentionUnit description: Snapshot retention unit per day snapshots. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.weekly.basicSchedule.frequency description: Snapshot weekly frequency. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.weekly.basicSchedule.retention description: Snapshot retention value per week snapshots. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.weekly.basicSchedule.retentionUnit description: Snapshot retention unit per week snapshots. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.weekly.dayOfWeek description: Starting day of the weekly snapshot. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.monthly.basicSchedule.frequency description: Snapshot monthly frequency. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.monthly.basicSchedule.retention description: Snapshot retention value per month snapshots. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.monthly.basicSchedule.retentionUnit description: Snapshot retention unit per month snapshots. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.monthly.dayOfMonth description: Starting day of the month snapshot. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.quarterly.basicSchedule.frequency description: Snapshot quarterly frequency. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.quarterly.basicSchedule.retention description: Snapshot retention value per quarter snapshots. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.quarterly.basicSchedule.retentionUnit description: Snapshot retention unit per quarter snapshots. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.quarterly.dayOfQuarter description: Starting day of the quarterly snapshot. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.quarterly.quarterStartMonth description: Starting month of the quarterly snapshot. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.yearly.basicSchedule.frequency description: Snapshot yearly frequency. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.yearly.basicSchedule.retention description: Snapshot retention value per year snapshots. type: Number - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.yearly.basicSchedule.retentionUnit description: Snapshot retention unit per year snapshots. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.yearly.dayOfYear description: Starting day of the yearly snapshot. type: String - contextPath: RubrikPolaris.GPSSLADomain.snapshotSchedule.yearly.yearStartMonth description: Starting month of the yearly snapshot. type: String - contextPath: RubrikPolaris.GPSSLADomain.objectSpecificConfigs.awsRdsConfig.logRetention.duration description: Duration of retentioning AWS Relational database logs. type: Number - contextPath: RubrikPolaris.GPSSLADomain.objectSpecificConfigs.awsRdsConfig.logRetention.unit description: Unit of duration of retentioning AWS Relational database logs. type: String - contextPath: RubrikPolaris.GPSSLADomain.objectSpecificConfigs.sapHanaConfig.incrementalFrequency.duration description: Duration of retentioning SAP HANA incremental backups. type: Number - contextPath: RubrikPolaris.GPSSLADomain.objectSpecificConfigs.sapHanaConfig.incrementalFrequency.unit description: Unit of duration of retentioning SAP HANA incremental backups. type: String - contextPath: RubrikPolaris.GPSSLADomain.objectSpecificConfigs.sapHanaConfig.differentialFrequency.duration description: Duration of retentioning SAP HANA differential backups. type: Number - contextPath: RubrikPolaris.GPSSLADomain.objectSpecificConfigs.sapHanaConfig.differentialFrequency.unit description: Unit of duration of retentioning SAP HANA differential backups. type: String - contextPath: RubrikPolaris.GPSSLADomain.objectSpecificConfigs.sapHanaConfig.logRetention.duration description: Duration of retensioning SAP HANA Database logs. type: Number - contextPath: RubrikPolaris.GPSSLADomain.objectSpecificConfigs.sapHanaConfig.logRetention.unit description: Unit of duration of retentioning SAP HANA Database logs. type: String - contextPath: RubrikPolaris.GPSSLADomain.objectSpecificConfigs.vmwareVmConfig.logRetentionSeconds description: Seconds of retentioning VMWare virtual machine logs. type: Number - contextPath: RubrikPolaris.GPSSLADomain.objectTypes description: List of object types associated with this SLA Domain. type: Unknown - arguments: - description: "The ID of the download, requested using \"rubrik-sonar-csv-download\" command.\n\nNote: Users can retrieve the list of downloads containing ID by executing the \"rubrik-user-downloads-list\" command." name: download_id required: true description: Retrieve the download link for the requested Sonar CSV Snapshot file. name: rubrik-sonar-csv-result-download outputs: - contextPath: RubrikPolaris.SonarCSVDownload.downloadId description: The download ID of the download request. type: String - contextPath: RubrikPolaris.SonarCSVDownload.getDownloadUrl.url description: The link of the file that needs to be downloaded. type: String - arguments: - description: "The ID of the object whose snapshot is to be created. \n\nNote: Users can get the list of object IDs by executing the \"rubrik-polaris-vm-objects-list\" command." name: object_id required: true - description: "The ID of the SLA domain retention policy to be applied on the object.\n\nNote: Users can get the list of SLA Domain IDs by executing the \"rubrik-gps-sla-domain-list\" command." name: sla_domain_id description: "Triggers an on-demand snapshot of a system.\n\nNote: To know about the status of the on-demand snapshot creation, use the \"rubrik-gps-async-result\" command." name: rubrik-gps-vm-snapshot-create outputs: - contextPath: RubrikPolaris.GPSOndemandSnapshot.id description: ID of the requested snapshot. type: String - contextPath: RubrikPolaris.GPSOndemandSnapshot.status description: Status of the requested snapshot. type: String - arguments: - description: "The Snapshot ID of the file that needs to be downloaded.\n\nNote: Users can retrieve the list of the snapshot IDs by executing the \"rubrik-polaris-vm-object-snapshot-list\" command." name: snapshot_id required: true - description: "The absolute path of the file to be downloaded. A list of files can be downloaded as a zip folder. Multiple file paths can be separated with comma(,).\n\nNote: Users can retrieve the list of the files with absolute path by executing the \"rubrik-gps-snapshot-files-list\" command.\n\nFormat accepted: \"//\"\n\nExample: \"/C:/PerfLogs/Admin\", \"/C:/Windows/Microsoft.NET\"." name: file_path isArray: true required: true - description: "The type of object for which the file to be downloaded.\n\nPossible values are: \"WindowsFileset\", \"LinuxFileset\", \"VolumeGroup\", \"VmwareVm\"." defaultValue: 'VmwareVm' name: object_type predefined: - 'WindowsFileset' - 'LinuxFileset' - 'VolumeGroup' - 'VmwareVm' description: "Request to download the snapshot file from the backup.\n\nNote: To know about the file information and which file can be downloaded, use the \"rubrik-gps-snapshot-files-list\" command. To know about the status of the downloadable files, use the \"rubrik-gps-async-result\" command." name: rubrik-gps-snapshot-files-download outputs: - contextPath: RubrikPolaris.GPSSnapshotFileDownload.id description: The ID of the download. type: String - contextPath: RubrikPolaris.GPSSnapshotFileDownload.status description: Status of the download. type: String - contextPath: RubrikPolaris.GPSSnapshotFileDownload.links.href description: Link of the download. type: String - contextPath: RubrikPolaris.GPSSnapshotFileDownload.links.rel description: Relationship of the download. type: String - arguments: - description: The snappable ID. name: snappable_id required: true - auto: PREDEFINED defaultValue: 'True' description: |- Whether to recover tags. Possible values are: "True", "False". name: should_recover_tags predefined: - 'True' - 'False' - auto: PREDEFINED defaultValue: 'True' description: |- Whether to power on. Possible values are: "True", "False". name: power_on predefined: - 'True' - 'False' - auto: PREDEFINED defaultValue: 'False' description: |- Whether to keep MAC addresses. Possible values are: "True", "False". name: keep_mac_addresses predefined: - 'True' - 'False' - auto: PREDEFINED defaultValue: 'False' description: |- Whether to remove network interfaces from the VM. Possible values are: "True", "False". name: remove_network_devices predefined: - 'True' - 'False' - description: |- ID of the ESXi host to mount the new VM on. Note: Users can get the list of host IDs by executing the "rubrik-gps-vm-host-list" command. name: host_id - description: ID of the compute cluster where the new VM will be mounted. name: cluster_id - description: ID of the resource pool where the new VM will be mounted. name: resource_pool_id - description: |- ID of the snapshot to recover. Note: Users can get the snapshot ID by executing the "rubrik-polaris-vm-object-snapshot-list" command. name: snapshot_fid - description: Name of the new VM. If not provided the name will be " ". name: vm_name - description: |- List of network bindings for vNIC of the VM. e.g. [ { "backingNetworkInfo": { "moid": , "name": }, "networkDeviceInfo": { "key": , "name": } } ]. name: vnic_bindings - description: |- Point in time to recover to, e.g.: "2023-03-04T05:06:07.890". name: recovery_point description: "Performs a live mount of a virtual machine snapshot.\n\nNote: To know about the live mount status, use the \"rubrik-gps-async-result\" command." name: rubrik-gps-vm-livemount outputs: - contextPath: RubrikPolaris.GPSVMLiveMount.id description: ID of the Live mount request. type: String - arguments: - description: The name of the host to search for. name: name - description: "To list hosts from the specific cluster.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." name: cluster_id - defaultValue: 50 description: Number of results to retrieve in the response. Maximum size allowed is 1000. name: limit - description: The next page cursor to retrieve the next set of results. name: next_page_token - defaultValue: ID description: "Specify the field to use for sorting the response.\n\nNote: Supported values are \"ID\" and \"NAME\" only. For any other values, the obtained result is sorted or not is not confirmed." name: sort_by - auto: PREDEFINED defaultValue: ASC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC description: "Retrieve the list of available Vsphere Hosts." name: rubrik-gps-vm-host-list outputs: - contextPath: RubrikPolaris.GPSVMHost.id description: ID of the Vsphere host. type: String - contextPath: RubrikPolaris.GPSVMHost.name description: Name of the Vsphere host. type: String - contextPath: RubrikPolaris.GPSVMHost.physicalPath.fid description: ID of a physical path of a node. type: String - contextPath: RubrikPolaris.GPSVMHost.physicalPath.name description: Name of a physical path of a node. type: String - contextPath: RubrikPolaris.GPSVMHost.physicalPath.objectType description: "Type of a physical path of a node, for example, VSphereComputeCluster, VSphereDatacenter etc." type: String - contextPath: RubrikPolaris.PageToken.GPSVMHost.next_page_token description: Next page token. type: String - contextPath: RubrikPolaris.PageToken.GPSVMHost.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.GPSVMHost.has_next_page description: Whether the result has the next page or not. type: Boolean - arguments: - description: The name of the datastore to search for. name: name - description: "The ID of a Vsphere host whose datastores are to be listed.\n\nNote: Users can get the list of host IDs by executing the \"rubrik-gps-vm-host-list\" command." name: host_id required: true - defaultValue: 50 description: Number of results to retrieve in the response. Maximum size allowed is 1000. name: limit - description: The next page cursor to retrieve the next set of results. name: next_page_token - defaultValue: ID description: "Specify the field to use for sorting the response.\n\nNote: Supported values are \"ID\" and \"NAME\" only. For any other values, the obtained result is sorted or not is not confirmed." name: sort_by - auto: PREDEFINED defaultValue: ASC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC description: "Retrieve the list of the available datastores on a Vsphere Host." name: rubrik-gps-vm-datastore-list outputs: - contextPath: RubrikPolaris.GPSVMHost.id description: ID of the Vsphere host. type: String - contextPath: RubrikPolaris.GPSVMHost.Datastore.id description: ID of the Vsphere datastore. type: String - contextPath: RubrikPolaris.GPSVMHost.Datastore.name description: Name of the Vsphere datastore. type: String - contextPath: RubrikPolaris.GPSVMHost.Datastore.capacity description: Datastore capacity in bytes. type: Number - contextPath: RubrikPolaris.GPSVMHost.Datastore.isLocal description: Whether the datastore is local or remote. type: Boolean - contextPath: RubrikPolaris.GPSVMHost.Datastore.freeSpace description: Free space on the datastore in bytes. type: Number - contextPath: RubrikPolaris.GPSVMHost.Datastore.datastoreType description: Type of datastore, for example, "NFS", "VMFS" etc. type: String - contextPath: RubrikPolaris.PageToken.GPSVMHost.Datastore.next_page_token description: Next page token. type: String - contextPath: RubrikPolaris.PageToken.GPSVMHost.Datastore.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.GPSVMHost.Datastore.has_next_page description: Whether the result has the next page or not. type: Boolean - arguments: - description: "Filter the events based on the provided activity statuses. Supports comma separated values.\n\nPossible values are: \"UNKNOWN_EVENT_STATUS\", \"TASK_FAILURE\", \"PARTIAL_SUCCESS\", \"TASK_SUCCESS\", \"INFO\", \"FAILURE\", \"RUNNING\", \"QUEUED\", \"WARNING\", \"CANCELED\", \"SUCCESS\"." name: activity_status - description: "Filter the events based on provided activity types. Supports comma separated values.\n\nPossible values are: \"SYNC\", \"LOCAL_RECOVERY\", \"TEST_FAILOVER\", \"ANOMALY\", \"RANSOMWARE_INVESTIGATION_ANALYSIS\", \"ARCHIVE\", \"VOLUME_GROUP\", \"VCENTER\", \"INDEX\", \"CLOUD_NATIVE_VIRTUAL_MACHINE\", \"STORM_RESOURCE\", \"HOST_EVENT\", \"RECOVERY\", \"CONVERSION\", \"CLOUD_NATIVE_VM\", \"EMBEDDED_EVENT\", \"MAINTENANCE\", \"FAILOVER\", \"AUTH_DOMAIN\", \"LEGAL_HOLD\", \"VCD\", \"INSTANTIATE\", \"CONFIGURATION\", \"FILESET\", \"DISCOVERY\", \"SYSTEM\", \"HDFS\", \"CLASSIFICATION\", \"STORAGE_ARRAY\", \"STORAGE\", \"BACKUP\", \"HARDWARE\", \"HYPERV_SERVER\", \"HYPERV_SCVMM\", \"DIAGNOSTIC\", \"UNKNOWN_EVENT_TYPE\", \"UPGRADE\", \"NUTANIX_CLUSTER\", \"REPLICATION\", \"AWS_EVENT\", \"SUPPORT\", \"CLOUD_NATIVE_SOURCE\", \"DOWNLOAD\", \"CONNECTION\", \"RESOURCE_OPERATIONS\"." name: activity_type - description: "Filter the events based on provided severities. Supports comma separated values.\n\nPossible values are: \"SEVERITY_CRITICAL\", \"SEVERITY_WARNING\", \"SEVERITY_INFO\"." name: severity - description: "Filter out events based on object name.\n\nNote: Users can get the object names by executing the \"rubrik-polaris-vm-objects-list\" or \"rubrik-polaris-object-search\" command." name: object_name - description: "Filter the events based on provided object types. Supports comma separated values.\n\nPossible values are: \"SHARE_FILESET\", \"NUTANIX_VM\", \"STORAGE_ARRAY_VOLUME_GROUP\", \"HYPERV_VM\", \"LINUX_FILESET\", \"WINDOWS_FILESET\", \"VMWARE_VM\".\n\nAdditional values can be found in the documentation." name: object_type - description: "Filter the events based on provided cluster IDs. Supports comma separated values.\n\nNote: Users can get the list of cluster IDs by executing the \"rubrik-gps-cluster-list\" command." name: cluster_id - description: "The start date to fetch updated events from.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc." name: start_date - description: "The end date to fetch updated events until.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc." name: end_date - defaultValue: 50 description: Number of results to retrieve in the response. Maximum size allowed is 1000. name: limit - description: The next page cursor to retrieve the next set of results. name: next_page_token - auto: PREDEFINED defaultValue: LAST_UPDATED description: "Specify the field to use for sorting the response.\n\nNote: Possible values are: \"LAST_UPDATED\", \"LOCATION\", \"OBJECT_TYPE\", \"CLUSTER_NAME\", \"OBJECT_NAME\", \"START_TIME\", \"ACTIVITY_TYPE\", \"SEVERITY\", \"ACTIVITY_STATUS\"." name: sort_by predefined: - LAST_UPDATED - LOCATION - OBJECT_TYPE - CLUSTER_NAME - OBJECT_NAME - START_TIME - ACTIVITY_TYPE - SEVERITY - ACTIVITY_STATUS - auto: PREDEFINED defaultValue: DESC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC description: "Retrieve the list of events." name: rubrik-event-list outputs: - contextPath: RubrikPolaris.Event.id description: ID of the event. type: Number - contextPath: RubrikPolaris.Event.startTime description: Start time of the event. type: String - contextPath: RubrikPolaris.Event.fid description: FID of the event. type: String - contextPath: RubrikPolaris.Event.activitySeriesId description: Activity Series ID of the event. type: String - contextPath: RubrikPolaris.Event.lastUpdated description: Date time when the event was last updated. type: String - contextPath: RubrikPolaris.Event.lastActivityType description: Last Activity Type of the event. type: String - contextPath: RubrikPolaris.Event.lastActivityStatus description: Last Activity Status of the event. type: String - contextPath: RubrikPolaris.Event.location description: Location of the event. type: String - contextPath: RubrikPolaris.Event.objectId description: ID of the object. type: String - contextPath: RubrikPolaris.Event.objectName description: Name of the object. type: String - contextPath: RubrikPolaris.Event.objectType description: Type of the object. type: String - contextPath: RubrikPolaris.Event.severity description: Severity of the event. type: String - contextPath: RubrikPolaris.Event.progress description: Progress of the event. type: String - contextPath: RubrikPolaris.Event.cluster.id description: The ID of the cluster. type: String - contextPath: RubrikPolaris.Event.cluster.name description: The name of the cluster. type: String - contextPath: RubrikPolaris.Event.activityConnection.nodes.id description: ID of the activity connection. type: String - contextPath: RubrikPolaris.Event.activityConnection.nodes.message description: Message of the activity connection. type: String - contextPath: RubrikPolaris.Event.activityConnection.nodes.severity description: Severity of the activity connection. type: String - contextPath: RubrikPolaris.Event.activityConnection.nodes.time description: Date time when the activity connection was last updated. type: String - contextPath: RubrikPolaris.PageToken.Event.next_page_token description: Next page token. type: String - contextPath: RubrikPolaris.PageToken.Event.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.Event.has_next_page description: Whether the result has the next page or not. type: Boolean - arguments: - description: "Filter the objects based on the provided object types. Supports comma separated values.\n\nPossible values are: \"ShareFileset\", \"NutanixVirtualMachine\", \"VolumeGroup\", \"HypervVirtualMachine\", \"LinuxFileset\", \"WindowsFileset\", \"VmwareVirtualMachine\".\n\nAdditional values can be found in the documentation." name: type_filter required: true - description: "Filter the objects based on the provided cluster IDs. Supports comma separated values.\n\nNote: Users can get the list of cluster IDs by executing the \"rubrik-gps-cluster-list\" command." name: cluster_id - defaultValue: 50 description: Number of results to retrieve in the response. Maximum size allowed is 1000. name: limit - description: The next page cursor to retrieve the next set of results. name: next_page_token - defaultValue: ID description: "Specify the field to use for sorting the response.\n\nNote: Supported values are \"ID\" and \"NAME\" only. For any other values, the obtained result is sorted or not is not confirmed." name: sort_by - auto: PREDEFINED defaultValue: ASC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC description: "Retrieve the list of Rubrik objects, based on the provided filters." name: rubrik-polaris-object-list outputs: - contextPath: RubrikPolaris.Object.id description: ID of the object. type: String - contextPath: RubrikPolaris.Object.effectiveSlaDomain.name description: Name of the SLA domain of the object. type: String - contextPath: RubrikPolaris.Object.effectiveSlaDomain.id description: ID of the SLA domain of the object. type: String - contextPath: RubrikPolaris.Object.effectiveSlaDomain.description description: Description of the SLA domain of the object. type: String - contextPath: RubrikPolaris.Object.effectiveSlaDomain.cluster.id description: Cluster ID of effective SLA domain of the object. type: String - contextPath: RubrikPolaris.Object.effectiveSlaDomain.cluster.name description: Cluster name of effective SLA domain of the object. type: String - contextPath: RubrikPolaris.Object.effectiveSlaDomain.fid description: FID of effective SLA domain of the object. type: String - contextPath: RubrikPolaris.Object.isPassthrough description: Whether the object is passthrough or not. type: Boolean - contextPath: RubrikPolaris.Object.cluster.id description: Cluster ID of the object. type: String - contextPath: RubrikPolaris.Object.cluster.name description: Cluster name of the object. type: String - contextPath: RubrikPolaris.Object.primaryClusterLocation.id description: ID of the primary cluster location of the object. type: String - contextPath: RubrikPolaris.Object.logicalPath.name description: Name of the logical path of the object. type: String - contextPath: RubrikPolaris.Object.logicalPath.objectType description: Object Type of the logical path of the object. type: String - contextPath: RubrikPolaris.Object.physicalPath.name description: Name of the physical path of the object. type: String - contextPath: RubrikPolaris.Object.physicalPath.objectType description: Object Type of the physical path of the object. type: String - contextPath: RubrikPolaris.Object.name description: Name of the object. type: String - contextPath: RubrikPolaris.Object.objectType description: Type of the object. type: String - contextPath: RubrikPolaris.PageToken.Object.has_next_page description: Whether the result has the next page or not. type: Boolean - contextPath: RubrikPolaris.PageToken.Object.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.Object.next_page_token description: Next page token. type: String - arguments: - description: "The object ID for which the snapshots are to be searched.\n\nNote: Users can get the list of the object IDs by executing the \"rubrik-polaris-object-list\" command." name: object_id required: true - description: "The start date to get snapshots from.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc.\n\nNote: start_date and end_date both or none must be initialized." name: start_date - description: "The end date to get snapshots until.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc.\n\nNote: start_date and end_date both or none must be initialized." name: end_date - defaultValue: 50 description: Number of results to retrieve in the response. Maximum size allowed is 1000. name: limit - description: The next page cursor to retrieve the next set of results. name: next_page_token - description: "List of snapshot types to filter snapshots. Supports comma separated values.\n\nPossible values are: \"SCHEDULED\", \"ON_DEMAND\", \"DOWNLOADED\"." name: snapshot_type - auto: PREDEFINED defaultValue: ASC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC description: "Retrieve Rubrik snapshot(s) of an object, based on the provided object ID." name: rubrik-polaris-object-snapshot-list outputs: - contextPath: RubrikPolaris.Object.id description: ID of the object. type: String - contextPath: RubrikPolaris.Object.Snapshot.id description: ID of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.date description: Date of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.isArchivalCopy description: Whether the snapshot is an archival copy or not. type: Boolean - contextPath: RubrikPolaris.Object.Snapshot.isReplica description: Whether the snapshot is a replica or not. type: Boolean - contextPath: RubrikPolaris.Object.Snapshot.isOnDemandSnapshot description: Whether the snapshot is on demand or not. type: Boolean - contextPath: RubrikPolaris.Object.Snapshot.isDownloadedSnapshot description: Whether the snapshot is downloaded or not. type: Boolean - contextPath: RubrikPolaris.Object.Snapshot.cluster.id description: Cluster ID of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.cluster.name description: Cluster name of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.cluster.version description: Cluster version of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.cluster.status description: Cluster status of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.slaDomain.name description: Name of the SLA domain of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.slaDomain.fid description: FID of the SLA domain of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.slaDomain.cluster.id description: Cluster ID of the SLA domain of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.slaDomain.cluster.name description: Cluster name of the SLA domain of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.slaDomain.id description: ID of the SLA domain of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.snapshotRetentionInfo.archivalInfos.name description: Archival name of snapshot retention of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.snapshotRetentionInfo.archivalInfos.isExpirationDateCalculated description: Whether archival expiration date of snapshot retention of the snapshot is calculated or not. type: String - contextPath: RubrikPolaris.Object.Snapshot.snapshotRetentionInfo.archivalInfos.expirationTime description: Archival expiration time of snapshot retention of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.snapshotRetentionInfo.localInfo.name description: Name of snapshot retention of the snapshot. type: String - contextPath: RubrikPolaris.Object.Snapshot.snapshotRetentionInfo.localInfo.isExpirationDateCalculated description: Whether the expiration date is calculated or not. type: Boolean - contextPath: RubrikPolaris.Object.Snapshot.snapshotRetentionInfo.localInfo.expirationTime description: Expiration time of snapshot retention of the snapshot. type: String - contextPath: RubrikPolaris.PageToken.Object.Snapshot.has_next_page description: Whether the result has the next page or not. type: Boolean - contextPath: RubrikPolaris.PageToken.Object.Snapshot.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.Object.Snapshot.next_page_token description: Next Page Token. type: String - arguments: - description: |- ID of the cluster on which to perform a scan. Note: Users can retrieve the list of the cluster IDs by executing the "rubrik-gps-cluster-list" command. name: cluster_id required: true - description: |- Object ID of the system on which to perform the scan. Supports comma separated values. Note: Users can get the list of object IDs by executing the "rubrik-polaris-vm-objects-list" command. isArray: true name: object_id required: true - defaultValue: PAXSOAR-1.1.0 description: Name of the scan. name: scan_name - auto: PREDEFINED description: |- The type of the indicator to scan for. Possible values are: "INDICATOR_OF_COMPROMISE_TYPE_PATH_OR_FILENAME", "INDICATOR_OF_COMPROMISE_TYPE_HASH", "INDICATOR_OF_COMPROMISE_TYPE_YARA_RULE". Note: To provide multiple IOCs use the argument "advance_ioc". name: ioc_type predefined: - INDICATOR_OF_COMPROMISE_TYPE_PATH_OR_FILENAME - INDICATOR_OF_COMPROMISE_TYPE_HASH - INDICATOR_OF_COMPROMISE_TYPE_YARA_RULE - description: |- Value of the indicator to scan for. Note: To provide multiple IOCs use the argument "advance_ioc". name: ioc_value - description: "Json encoded Indicators Of Compromise to scan. Json keys signify the type of IOC and the corresponding list of values are the values of the IOC's. If provided, will ignore the ioc_type and ioc_value arguments.\n\nPossible keys to indicate type of indicator: \nINDICATOR_OF_COMPROMISE_TYPE_PATH_OR_FILENAME, INDICATOR_OF_COMPROMISE_TYPE_HASH, INDICATOR_OF_COMPROMISE_TYPE_YARA_RULE\n\nFormat Accepted:\n{\n\"\": [\"\", \"\"],\n\"\": \"\"\n}\n\nExample:\n{\n\"INDICATOR_OF_COMPROMISE_TYPE_PATH_OR_FILENAME\": [\"C:\\Users\\Malware_Executible.ps1\", \"\\bin\\Malware_Executible\"],\n\"INDICATOR_OF_COMPROMISE_TYPE_HASH\": [\"e5c1b9c44be582f895eaea3d3738c5b4\", \"f541b9844be897f895eaea3d3738cfb2\"],\n\"INDICATOR_OF_COMPROMISE_TYPE_YARA_RULE\": \"rule match_everything {condition:true}\"\n}." name: advance_ioc - description: |- Filter the snapshots from the provided date. Any snapshots taken before the provided date-time will be excluded. Formats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc. Examples of more supported values can be found at https://dateparser.readthedocs.io/en/latest/#relative-dates. name: start_date - description: |- Filter the snapshots until the provided date. Any snapshots taken after the provided date-time will be excluded. Formats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc. Examples of more supported values can be found at https://dateparser.readthedocs.io/en/latest/#relative-dates. name: end_date - description: Maximum number of snapshots to scan per object. name: max_snapshots_per_object - description: Maximum size of the file in bytes that will be included in the scan. The maximum allowed size is 15000000 bytes. defaultValue: 5000000 name: max_file_size - description: |- Provide comma separated snapshot IDs on which to perform a scan separated by colon for each object ID (in the same order). Supports comma separated values. Format accepted: object_1_snapshot_id_1, object_1_snapshot_id_2: object_2_snapshot_id_1 Example: B405e8c0-1fcd-401c-a6f6-42f758aad6df, e179eb47-534b-4624-b155-f33d188902e2: 1e1681bf-4479-4339-a4bb-59901598caa5 Note: Users can retrieve the list of snapshot IDs by executing the "rubrik-polaris-vm-object-snapshot-list" command. Note: Do not provide "snapshot_start_date", "snapshot_end_date" and, "max_snapshots_per_object" arguments if snapshot ID is provided. isArray: true name: snapshot_id - description: |- Paths to include in the scan. Supports comma separated values. Format accepted: path_to_include_1, path_to_include_2. isArray: true name: paths_to_include - description: |- Paths to exclude from the scan. Supports comma separated values. Format accepted: path_to_exclude_1, path_to_exclude_2. isArray: true name: paths_to_exclude - description: |- Paths to exempt from exclusion. Supports comma separated values. Format accepted: path_to_exempt_1, path_to_exempt_2. isArray: true name: paths_to_exempt - description: |- The type of hash values of the matched files to return in the result. Supports comma separated values. Possible values are: "HASH_TYPE_M_D5", "HASH_TYPE_SH_A1", "HASH_TYPE_SH_A256". isArray: true name: requested_hash_types description: |- Triggers an IOC scan of a system. Note: To know the results of the scan use the "rubrik-radar-ioc-scan-results" command and to list the running/completed IOC scans on a cluster use the "rubrik-radar-ioc-scan-list" command. name: rubrik-radar-ioc-scan outputs: - contextPath: RubrikPolaris.RadarIOCScan.id description: ID of the IOC scan. type: String - contextPath: RubrikPolaris.RadarIOCScan.status description: Status of the IOC scan trigger request. type: String - arguments: - description: |- ID of the IOC scan whose results are to be retrieved. Note: Users can get the scan ID by executing the "rubrik-radar-ioc-scan" command. name: scan_id required: true - description: |- ID of the cluster on which the scan was performed. Note: Users can retrieve the list of the cluster IDs by executing the "rubrik-gps-cluster-list" command. name: cluster_id required: true description: |- Retrieves the results of IOC scan of a system. Note: To initiate a scan use the "rubrik-radar-ioc-scan" command and to list the running/completed scans on a cluster use the "rubrik-radar-ioc-scan-list" command. name: rubrik-radar-ioc-scan-results outputs: - contextPath: RubrikPolaris.RadarIOCScan.id description: ID of the IOC scan. type: String - contextPath: RubrikPolaris.RadarIOCScan.status description: Overall status of the scan. type: String - contextPath: RubrikPolaris.RadarIOCScan.indicatorsOfCompromise.iocType description: Type of IOC that was scanned. type: String - contextPath: RubrikPolaris.RadarIOCScan.indicatorsOfCompromise.iocValue description: Value of the IOC that was scanned. type: String - contextPath: RubrikPolaris.RadarIOCScan.results.objectId description: ID of the system that was scanned. type: String - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.status description: 'Status of the scan on the snapshot. Values: MALWARE_SCAN_IN_SNAPSHOT_STATUS_PENDING, MALWARE_SCAN_IN_SNAPSHOT_STATUS_FINISHED, MALWARE_SCAN_IN_SNAPSHOT_STATUS_ERROR.' type: String - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.snapshotDate description: The date-time at which the snapshot was taken. type: String - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.snapshotId description: ID of the snapshot that was scanned. type: String - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.scanStats.numFiles description: Number of files encountered during scan. type: Number - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.scanStats.numFilesScanned description: Number of files that were scanned on that snapshot. type: Number - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.scanStats.totalFilesScannedSizeBytes description: The total file size of the files scanned. type: Number - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.matches.indicatorIndex description: Index of indicator in inputs for the scan. type: Number - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.matches.paths.aclDetails description: JSON encoded file access control list (ACL) information. type: String - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.matches.paths.creationTime description: File creation date-time. type: String - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.matches.paths.modificationTime description: File modification date-time. type: String - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.matches.paths.path description: File path that matched the malware Indicator Of Compromise. type: String - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.matches.paths.yaraMatchDetails.name description: The name of the matching YARA rule. type: String - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.matches.paths.yaraMatchDetails.tags description: Optional YARA tags. Described in https://yara.readthedocs.io/en/latest/writingrules.html#rule-tags. type: Unknown - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.matches.paths.requestedHashDetails.hashType description: Hash algorithm type. type: String - contextPath: RubrikPolaris.RadarIOCScan.results.snapshotResults.matches.paths.requestedHashDetails.hashValue description: Hash value of the content at path. type: String - arguments: - description: "ID of the request.\n\nNote: Users can get the request ID by executing any of the commands that make a request. Possible commands are mentioned in the command description." name: request_id required: true - description: "ID of the cluster on which request was made.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." name: cluster_id required: true - description: "IP address of the cluster node to access the download link. Only required to retrieve the results of the command \"rubrik-gps-snapshot-files-download\".\n\nNote: Users can retrieve the list of the IP addresses by executing the \"rubrik-gps-cluster-list\" command." name: cluster_ip_address description: "Retrieve the result of an asynchronous request. This command will retrieve the result of requests made by commands \"rubrik-gps-snapshot-files-download\", \"rubrik-gps-vm-livemount\", \"rubrik-gps-vm-export\", \"rubrik-gps-vm-snapshot-create\" and \"rubrik-gps-vm-recover-files\"." name: rubrik-gps-async-result outputs: - contextPath: RubrikPolaris.GPSAsyncResult.id description: The ID of the request. type: String - contextPath: RubrikPolaris.GPSAsyncResult.status description: Status of the request. type: String - contextPath: RubrikPolaris.GPSAsyncResult.nodeId description: ID of the node. type: String - contextPath: RubrikPolaris.GPSAsyncResult.progress description: Progress of the request in range 0 to 100. type: Number - contextPath: RubrikPolaris.GPSAsyncResult.error.message description: JSON stringified message object when an error occurs. type: String - contextPath: RubrikPolaris.GPSAsyncResult.links.href description: Link to a resource. type: String - contextPath: RubrikPolaris.GPSAsyncResult.links.rel description: Type of the resource pointed by the link. type: String - arguments: - description: "Filter out clusters based on their type. Supports comma separated values.\n\nPossible values are: \"Cloud\", \"Robo\", \"ExoCompute\", \"OnPrem\", \"Polaris\", \"Unknown\"." name: type - description: "Filter out clusters based on name. Supports comma separated values." name: name - defaultValue: ClusterName description: "Specify the field to use for sorting the response.\n\nPossible values are: \"ClusterName\", \"ClusterType\", \"RegisteredAt\".\nAdditional values can be found in the documentation." name: sort_by - auto: PREDEFINED defaultValue: ASC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC description: "Retrieve the list of the available rubrik clusters." name: rubrik-gps-cluster-list outputs: - contextPath: RubrikPolaris.GPSCluster.id description: ID of the cluster. type: String - contextPath: RubrikPolaris.GPSCluster.name description: Name of the cluster. type: String - contextPath: RubrikPolaris.GPSCluster.type description: Type of the cluster. Values are Cloud, Robo, ExoCompute, OnPrem, Unknown, Polaris. type: String - contextPath: RubrikPolaris.GPSCluster.status description: Status of the cluster. Values are Connected, Disconnected, Initializing. type: String - contextPath: RubrikPolaris.GPSCluster.version description: Version of the cluster. type: String - contextPath: RubrikPolaris.GPSCluster.defaultAddress description: Default address assigned to the cluster. type: String - contextPath: RubrikPolaris.GPSCluster.cdmUpgradeInfo.clusterStatus.message description: Message about the cluster upgrade/current condition. type: String - contextPath: RubrikPolaris.GPSCluster.cdmUpgradeInfo.clusterStatus.status description: Upgrade/current status of the cluster. It provides information like -- upgrading, upgrade scheduled, stable, downloading packages, pre-checks running and many more. type: String - contextPath: RubrikPolaris.GPSCluster.cdmUpgradeInfo.overallProgress description: Progress (in percentage) of an upgrade, if running. type: Number - contextPath: RubrikPolaris.GPSCluster.cdmUpgradeInfo.scheduleUpgradeAt description: Shows the date-time of a scheduled upgrade. type: String - contextPath: RubrikPolaris.GPSCluster.cdmUpgradeInfo.downloadedVersion description: The version that was downloaded but not yet installed. type: String - contextPath: RubrikPolaris.GPSCluster.cdmUpgradeInfo.version description: The current version of the cluster. type: String - contextPath: RubrikPolaris.GPSCluster.productType description: The product type. Values are CDM, DATOS, POLARIS. type: String - contextPath: RubrikPolaris.GPSCluster.estimatedRunway description: Estimated number of days remaining before additional data storage space is required on the cluster. type: Number - contextPath: RubrikPolaris.GPSCluster.snapshotCount description: The total number of snapshots that are taken of different objects in the cluster. type: Number - contextPath: RubrikPolaris.GPSCluster.geoLocation.address description: Geological address of the cluster. type: String - contextPath: RubrikPolaris.GPSCluster.lastConnectionTime description: Time when the cluster was last polled. type: String - contextPath: RubrikPolaris.GPSCluster.metric.totalCapacity description: Total storage capacity of the cluster in Bytes. type: Number - contextPath: RubrikPolaris.GPSCluster.metric.availableCapacity description: Available storage capacity of the cluster in Bytes. type: Number - contextPath: RubrikPolaris.GPSCluster.snappableConnection.count description: The number of objects in the cluster whose snapshots can be taken. type: Number - contextPath: RubrikPolaris.GPSCluster.state.connectedState description: Status of the cluster. Values are Connected, Disconnected, Initializing. type: String - contextPath: RubrikPolaris.GPSCluster.state.clusterRemovalState description: State of the cluster when it is being removed from the platform. Values are DATA_DELETING, WAITING_FOR_DATA_DELETION, UNREGISTERED, FAILED, DISCONNECTING, REGISTERED. type: String - contextPath: RubrikPolaris.GPSCluster.clusterNodeConnection.nodes.id description: ID of a node in a cluster. type: String - contextPath: RubrikPolaris.GPSCluster.clusterNodeConnection.nodes.status description: Status of a node in a cluster. type: String - contextPath: RubrikPolaris.GPSCluster.clusterNodeConnection.nodes.ipAddress description: IP Address of a node in a cluster. type: String - contextPath: RubrikPolaris.GPSCluster.passesConnectivityCheck description: Whether the cluster passes the connectivity check. type: Boolean - contextPath: RubrikPolaris.GPSCluster.globalManagerConnectivityStatus.urls.url description: URL of a global manager of the cluster. type: String - contextPath: RubrikPolaris.GPSCluster.globalManagerConnectivityStatus.urls.isReachable description: Whether the global manager is reachable. type: Boolean - contextPath: RubrikPolaris.GPSCluster.connectivityLastUpdated description: The date-time of when the cluster was last polled for connectivity. type: String - contextPath: RubrikPolaris.GPSCluster.lambdaFeatureHistory.wasRadarEverEnabled description: Whether Polaris Radar was ever enabled on the cluster. type: Boolean - contextPath: RubrikPolaris.GPSCluster.lambdaFeatureHistory.wasSonarEverEnabled description: Whether Polaris Sonar was ever enabled on the cluster. type: Boolean - arguments: - description: |- ID of the cluster whose IOC scans are to be listed. Note: Users can retrieve the list of the cluster IDs by executing the "rubrik-gps-cluster-list" command. name: cluster_id required: true description: |- Lists the running/completed IOC scans on a cluster. Note: To know the results of the scan use the "rubrik-radar-ioc-scan-results" command. To initiate a scan use the "rubrik-radar-ioc-scan" command. name: rubrik-radar-ioc-scan-list outputs: - contextPath: RubrikPolaris.RadarIOCScan.id description: ID of the IOC scan. type: String - contextPath: RubrikPolaris.RadarIOCScan.startTime description: Start time of the scan. type: String - contextPath: RubrikPolaris.RadarIOCScan.endTime description: End time of the scan. type: String - contextPath: RubrikPolaris.RadarIOCScan.snapshots.id description: Object ID of the system. type: String - contextPath: RubrikPolaris.RadarIOCScan.snapshots.snapshots description: List of snapshot IDs that are included in the scan. type: Unknown - arguments: - description: |- ID of the snapshot from which to recover files. Note: Users can get the snapshot ID by executing the "rubrik-polaris-vm-object-snapshot-list" command. name: snapshot_id required: true - description: |- ID of the cluster where the snapshot resides. Note: Users can get the cluster ID by executing the "rubrik-gps-cluster-list" command. name: cluster_id required: true - description: |- Comma separated paths of files and directories that will be recovered from the snapshot. Note: Users can get the list of paths in a snapshot by executing the "rubrik-gps-snapshot-files-list" command. isArray: true name: paths_to_recover required: true - description: Path on the destination object on which recovery will be done. name: restore_path required: true - description: |- ID of the object where the files will be restored into. If not provided, Rubrik will use the snapshots object. Note: Users can get the object ID by executing the "rubrik-polaris-vm-objects-list" command. name: destination_object_id description: |- Recovers files from a snapshot backup, back into a system. Note: To know about the recovery status, use the "rubrik-gps-async-result" command. name: rubrik-gps-vm-recover-files outputs: - contextPath: RubrikPolaris.GPSVMRecoverFiles.id description: Recover files request ID. type: String - arguments: - description: 'The name of the user to search for.' name: user_name - description: 'The email or the UPN of the user to search for.' name: user_email - defaultValue: 7 days description: "Specify the search time period to look for user access.\n\nSupported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 May 2023, 01 Mar 2023 04:45:33, 2023-04-17T14:05:44Z." name: search_time_period - auto: PREDEFINED isArray: true description: "The comma-separated list of risk levels.\n\nSupported values are: UNKNOWN_RISK, HIGH_RISK, MEDIUM_RISK, LOW_RISK, NO_RISK.\n\nNote: For any other values, whether the obtained result is filtered or not, is not confirmed." name: risk_levels predefined: - UNKNOWN_RISK - HIGH_RISK - MEDIUM_RISK - LOW_RISK - NO_RISK - description: 'Specify the group ID to filter with.' name: group_id - auto: PREDEFINED defaultValue: "False" description: "The boolean indicates to include the whitelisted results.\n\nPossible values are: \"True\", \"False\"." name: include_whitelisted_results predefined: - "True" - "False" - auto: PREDEFINED defaultValue: USERS_WITH_SENSITIVE_ACCESS description: "Specify the principal summary category to filter with.\n\nSupported values are: PRINCIPAL_SUMMARY_CATEGORY_UNSPECIFIED, USERS_WITH_SENSITIVE_ACCESS, NEW_USERS_WITH_SENSITIVE_ACCESS, USERS_WITH_RISK_LEVEL_INCREASE.\n\nNote: For any other values, whether the obtained result is filtered or not, is not confirmed." name: principal_summary_category predefined: - PRINCIPAL_SUMMARY_CATEGORY_UNSPECIFIED - USERS_WITH_SENSITIVE_ACCESS - NEW_USERS_WITH_SENSITIVE_ACCESS - USERS_WITH_RISK_LEVEL_INCREASE - defaultValue: 50 description: Number of results to retrieve in the response. The maximum allowed size is 1000. name: limit - defaultValue: 1 description: "Specify the page number to get the particular page of results in the response.\n\nNote: This argument is only applicable when provided with the \"user_email\" argument." name: page_number - auto: PREDEFINED defaultValue: RISK_LEVEL description: "Specify the field to use for sorting the response.\n\nSupported values are: RISK_LEVEL, RISK_SENSITIVE_FILES, RISK_SENSITIVE_HITS, TOTAL_SENSITIVE_HITS, TOTAL_SENSITIVE_FILES, SID, TOTAL_SENSITIVE_OBJECTS.\n\nNote: For any other values, whether the obtained result is filtered or not, is not confirmed." name: sort_by predefined: - RISK_LEVEL - RISK_SENSITIVE_FILES - RISK_SENSITIVE_HITS - TOTAL_SENSITIVE_HITS - TOTAL_SENSITIVE_FILES - SID - TOTAL_SENSITIVE_OBJECTS - auto: PREDEFINED defaultValue: DESC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC - description: The next page cursor to retrieve the next set of results. name: next_page_token description: Retrieve the user access information. name: rubrik-sonar-user-access-list outputs: - contextPath: RubrikPolaris.UserAccess.principalId description: The ID of the user. type: String - contextPath: RubrikPolaris.UserAccess.fullName description: The full name of the user. type: String - contextPath: RubrikPolaris.UserAccess.upn description: The user principal name. type: String - contextPath: RubrikPolaris.UserAccess.riskLevel description: The risk level of the user. type: String - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.highRiskFileCount.totalCount description: The total number of high-risk files. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.highRiskFileCount.violatedCount description: The number of high-risk files that violate policies. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.highRiskFileCount.__typename description: The high-risk file count field type. type: String - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.mediumRiskFileCount.totalCount description: Total number of medium-risk files. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.mediumRiskFileCount.violatedCount description: The number of medium-risk files that violate policies. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.mediumRiskFileCount.__typename description: The type of the medium risk file count field. type: String - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.lowRiskFileCount.totalCount description: The total number of low-risk files. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.lowRiskFileCount.violatedCount description: The number of low-risk files that violate policies. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.lowRiskFileCount.__typename description: The type of the low-risk file count field. type: String - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.__typename description: The type of the sensitive files field. type: String - contextPath: RubrikPolaris.UserAccess.totalSensitiveHits.totalHits description: The total number of sensitive hits. type: Number - contextPath: RubrikPolaris.UserAccess.totalSensitiveHits.violatedHits description: The number of sensitive hits that violate policies. type: Number - contextPath: RubrikPolaris.UserAccess.totalSensitiveHits.__typename description: The type of the total sensitive hits field. type: String - contextPath: RubrikPolaris.UserAccess.sensitiveObjectCount.totalCount description: The total number of sensitive objects. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveObjectCount.violatedCount description: The Number of sensitive objects that violate policies. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveObjectCount.__typename description: The type of the sensitive object count field. type: String - contextPath: RubrikPolaris.UserAccess.numDescendants description: The number of descendant users associated with this user. type: Number - contextPath: RubrikPolaris.UserAccess.domainName description: The domain name associated with this user. type: String - contextPath: RubrikPolaris.UserAccess.__typename description: The type of the User Access field. type: String - contextPath: RubrikPolaris.PageToken.UserAccess.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.UserAccess.startCursor description: The start cursor for the current page. type: String - contextPath: RubrikPolaris.PageToken.UserAccess.endCursor description: The end cursor for the current page. type: String - contextPath: RubrikPolaris.PageToken.UserAccess.hasNextPage description: Whether the result has the next page or not. type: Boolean - contextPath: RubrikPolaris.PageToken.UserAccess.hasPreviousPage description: Whether the result has the previous page or not. type: Boolean - contextPath: RubrikPolaris.PageToken.UserAccess.next_upn_page_number description: The next UPN page number. type: String - contextPath: RubrikPolaris.PageToken.UserAccess.has_next_upn_page description: Whether the result has the next UPN page or not. type: Boolean - arguments: - description: "Specify the user_id to retrieve the user access information.\n\nNote: Users can get the list of the user IDs by executing the \"rubrik-sonar-user-access-list\" command." name: user_id required: true - defaultValue: 7 days description: "Specify the search time period to look for user access.\n\nSupported formats: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 May 2023, 01 Mar 2023 04:45:33, 2023-04-17T14:05:44Z." name: search_time_period - defaultValue: 7 description: "Specify the number of days in the past to collect delta for the sensitive hits." name: historical_delta_days - auto: PREDEFINED defaultValue: "False" description: "The boolean indicates to include the whitelisted results.\n\nPossible values are: \"True\", \"False\"." name: include_whitelisted_results predefined: - "True" - "False" description: Retrieve the user access information based on the provided user ID. name: rubrik-sonar-user-access-get outputs: - contextPath: RubrikPolaris.UserAccess.principalId description: The ID of the user. type: String - contextPath: RubrikPolaris.UserAccess.fullName description: The full name of the user. type: String - contextPath: RubrikPolaris.UserAccess.upn description: The user principal name. type: String - contextPath: RubrikPolaris.UserAccess.riskLevel description: The risk level of the user. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.__typename description: The type of object representing the policy hits summary. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.policyId description: The unique identifier of the policy associated with the hits summary. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.policyName description: The human-readable name of the policy associated with the hits summary. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.__typename description: The type of object representing the analyzer hits for a specific SID. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.highRiskHits.__typename description: The type of object representing high-risk hits for the analyzer. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.highRiskHits.totalHits description: The total number of high-risk hits detected by the analyzer. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.highRiskHits.violatedHits description: The number of high-risk hits that violated security policies. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.lowRiskHits.__typename description: The type of object representing low-risk hits for the analyzer. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.lowRiskHits.totalHits description: The total number of low-risk hits detected by the analyzer. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.lowRiskHits.violatedHits description: The number of low-risk hits that violated security policies. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.mediumRiskHits.__typename description: The type of object representing medium-risk hits for the analyzer. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.mediumRiskHits.totalHits description: The total number of medium-risk hits detected by the analyzer. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.mediumRiskHits.violatedHits description: The number of medium-risk hits that violated security policies. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.totalHits.__typename description: The type of object representing the total number of hits for the analyzer. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.totalHits.totalHits description: The total number of hits detected by the analyzer (all risk levels combined). type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidAnalyzerHits.totalHits.violatedHits description: The number of hits detected by the analyzer that violated security policies (all risk levels combined). type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.__typename description: The type of object representing the difference in analyzer hits between the current and previous periods. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.highRiskHits.__typename description: The type of object representing the difference in high-risk hits for the analyzer between the current and previous periods. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.highRiskHits.totalHits description: The difference in the total number of high-risk hits detected by the analyzer between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.highRiskHits.violatedHits description: The difference in the number of high-risk hits that violated security policies between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.lowRiskHits.__typename description: The type of object representing the difference in low-risk hits for the analyzer between the current and previous periods. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.lowRiskHits.totalHits description: The difference in the total number of low-risk hits detected by the analyzer between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.lowRiskHits.violatedHits description: The difference in the number of low-risk hits that violated security policies between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.mediumRiskHits.__typename description: The type of object representing the difference in medium-risk hits for the analyzer between the current and previous periods. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.mediumRiskHits.totalHits description: The difference in the total number of medium-risk hits detected by the analyzer between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.mediumRiskHits.violatedHits description: The difference in the number of medium-risk hits that violated security policies between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.totalHits.__typename description: The type of object representing the total difference in hits for the analyzer between the current and previous periods (all risk levels combined). type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.totalHits.totalHits description: The total difference in the number of hits detected by the analyzer between the current and previous periods (all risk levels combined). type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaAnalyzerHits.totalHits.violatedHits description: The difference in the number of hits detected by the analyzer that violated security policies between the current and previous periods (all risk levels combined). type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.__typename description: The type of object representing the difference in risk hits between the current and previous periods. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.highRiskHits.__typename description: The type of object representing the difference in high-risk hits between the current and previous periods. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.highRiskHits.totalHits description: The difference in the total number of high-risk hits detected between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.highRiskHits.violatedHits description: The difference in the number of high-risk hits that violated security policies between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.lowRiskHits.__typename description: The type of object representing the difference in low-risk hits between the current and previous periods. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.lowRiskHits.totalHits description: The difference in the total number of low-risk hits detected between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.lowRiskHits.violatedHits description: The difference in the number of low-risk hits that violated security policies between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.mediumRiskHits.__typename description: The type of object representing the difference in medium-risk hits between the current and previous periods. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.mediumRiskHits.totalHits description: The difference in the total number of medium-risk hits detected between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.mediumRiskHits.violatedHits description: The difference in the number of medium-risk hits that violated security policies between the current and previous periods. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.totalHits.__typename description: The type of object representing the total difference in risk hits between the current and previous periods (all risk levels combined). type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.totalHits.totalHits description: The total difference in the number of risk hits detected between the current and previous periods (all risk levels combined). type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidDeltaRiskHits.totalHits.violatedHits description: The difference in the number of risk hits detected that violated security policies between the current and previous periods (all risk levels combined). type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.__typename description: The type of object representing the risk hits for a specific SID. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.highRiskHits.__typename description: The type of object representing high-risk hits for the risk engine. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.highRiskHits.totalHits description: The total number of high-risk hits detected by the risk engine for the specific SID. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.highRiskHits.violatedHits description: The number of high-risk hits that violated security policies for the specific SID. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.lowRiskHits.__typename description: The type of object representing low-risk hits for the risk engine. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.lowRiskHits.totalHits description: The total number of low-risk hits detected by the risk engine for the specific SID. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.lowRiskHits.violatedHits description: The number of low-risk hits that violated security policies for the specific SID. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.mediumRiskHits.__typename description: The type of object representing medium-risk hits for the risk engine. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.mediumRiskHits.totalHits description: The total number of medium-risk hits detected by the risk engine for the specific SID. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.mediumRiskHits.violatedHits description: The number of medium-risk hits that violated security policies for the specific SID. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.totalHits.__typename description: The type of object representing the total number of risk hits for the specific SID (all risk levels combined). type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.totalHits.totalHits description: The total number of risk hits detected by the risk engine for the specific SID (all risk levels combined). type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidRiskHits.totalHits.violatedHits description: The number of risk hits detected by the risk engine that violated security policies for the specific SID (all risk levels combined). type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidSensitiveFiles.__typename description: The type of object representing the sensitive files associated with the specific SID. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidSensitiveFiles.totalFileCount.__typename description: The type of object representing the total number of sensitive files associated with the specific SID. type: String - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidSensitiveFiles.totalFileCount.totalCount description: The total number of sensitive files associated with the specific SID, including both compliant and non-compliant files. type: Number - contextPath: RubrikPolaris.UserAccess.policy_hits_summary.sidSensitiveFiles.totalFileCount.violatedCount description: The number of sensitive files associated with the specific SID that violate security policies. type: Number - contextPath: RubrikPolaris.UserAccess.riskReasons.accessRiskReasons description: The reasons why the user's access is considered risky. type: Unknown - contextPath: RubrikPolaris.UserAccess.riskReasons.insecureReasons description: The reasons why the user's access is considered insecure. type: Unknown - contextPath: RubrikPolaris.UserAccess.riskReasons.__typename description: The type of the risk reasons field. type: String - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.highRiskFileCount.totalCount description: The total number of high-risk files. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.highRiskFileCount.violatedCount description: The number of high-risk files that violate policies. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.highRiskFileCount.__typename description: The high-risk file count field type. type: String - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.mediumRiskFileCount.totalCount description: Total number of medium-risk files. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.mediumRiskFileCount.violatedCount description: The number of medium-risk files that violate policies. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.mediumRiskFileCount.__typename description: The type of the medium risk file count field. type: String - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.lowRiskFileCount.totalCount description: The total number of low-risk files. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.lowRiskFileCount.violatedCount description: The number of low-risk files that violate policies. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.lowRiskFileCount.__typename description: The type of the low-risk file count field. type: String - contextPath: RubrikPolaris.UserAccess.sensitiveFiles.__typename description: The type of the sensitive files field. type: String - contextPath: RubrikPolaris.UserAccess.totalSensitiveHits.totalHits description: The total number of sensitive hits. type: Number - contextPath: RubrikPolaris.UserAccess.totalSensitiveHits.violatedHits description: The number of sensitive hits that violate policies. type: Number - contextPath: RubrikPolaris.UserAccess.totalSensitiveHits.__typename description: The type of the total sensitive hits field. type: String - contextPath: RubrikPolaris.UserAccess.sensitiveObjectCount.totalCount description: The total number of sensitive objects. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveObjectCount.violatedCount description: The Number of sensitive objects that violate policies. type: Number - contextPath: RubrikPolaris.UserAccess.sensitiveObjectCount.__typename description: The type of the sensitive object count field. type: String - contextPath: RubrikPolaris.UserAccess.numDescendants description: The number of descendant users associated with this user. type: Number - contextPath: RubrikPolaris.UserAccess.domainName description: The domain name associated with this user. type: String - contextPath: RubrikPolaris.UserAccess.directGroups.name description: The name of the direct group. type: String - contextPath: RubrikPolaris.UserAccess.directGroups.sid description: The security identifier (SID) of the direct group. type: String - contextPath: RubrikPolaris.UserAccess.directGroups.__typename description: The type of the direct groups field. type: String - contextPath: RubrikPolaris.UserAccess.__typename description: The type of the User Access field. type: String - arguments: - description: "The Object ID or the Snappable ID.\n\nNote: Users can get the list of the object IDs by executing the \"rubrik-polaris-object-list\" command." name: object_id required: true - description: "The Snapshot ID of the object.\n\nNote: Users can get the list of the snapshot IDs by executing the \"rubrik-polaris-object-snapshot-list\" command." name: snapshot_id required: true - description: 'Specify the name of the file, folder, or file share object.' name: file_name - description: 'Specify the standard file path to filter with.' name: file_path - description: "Specify the user ID to filter with.\n\nNote: Users can get the list of the user IDs by executing the \"rubrik-sonar-user-access-list\" command." name: user_id - auto: PREDEFINED defaultValue: "False" description: "The boolean indicates to include the whitelisted results.\n\nPossible values are: \"True\", \"False\"." name: include_whitelisted_results predefined: - "True" - "False" - defaultValue: 50 description: Number of results to retrieve in the response. The maximum allowed size is 1000. name: limit - auto: PREDEFINED defaultValue: HITS description: "Specify the field to use for sorting the response.\n\nSupported values are: HITS, NAME, DAILY_CHANGE, LAST_ACCESS_TIME, OPEN_ACCESS_TYPE, FILES_WITH_HITS, FILES_WITH_OPEN_ACCESS_HITS, STALE_FILES_WITH_HITS, CLUSTER, OBJECT_NAME, OBJECT_LOCATION, SNAPSHOT_TIME, NUM_ACTIVITIES, NUM_ACTIVITIES_DELTA, NATIVE_PATH.\n\nNote: For any other values, whether the obtained result is filtered or not, is not confirmed." name: sort_by predefined: - HITS - NAME - DAILY_CHANGE - LAST_ACCESS_TIME - OPEN_ACCESS_TYPE - FILES_WITH_HITS - FILES_WITH_OPEN_ACCESS_HITS - STALE_FILES_WITH_HITS - CLUSTER - OBJECT_NAME - OBJECT_LOCATION - SNAPSHOT_TIME - NUM_ACTIVITIES - NUM_ACTIVITIES_DELTA - NATIVE_PATH - auto: PREDEFINED defaultValue: DESC description: "Specify the order to sort the data in.\n\nPossible values are: \"ASC\", \"DESC\"." name: sort_order predefined: - ASC - DESC - description: The next page cursor to retrieve the next set of results. name: next_page_token description: Retrieve the context of the file, folder, or file share for the provided object and the file details. name: rubrik-sonar-file-context-list outputs: - contextPath: RubrikPolaris.FileContext.nativePath description: The native path of the file. type: String - contextPath: RubrikPolaris.FileContext.stdPath description: The standardized path of the file. type: String - contextPath: RubrikPolaris.FileContext.filename description: The filename. type: String - contextPath: RubrikPolaris.FileContext.mode description: The file mode. type: String - contextPath: RubrikPolaris.FileContext.size description: The file size in bytes. type: Number - contextPath: RubrikPolaris.FileContext.lastAccessTime description: The last access time of the file in milliseconds since the epoch. type: Number - contextPath: RubrikPolaris.FileContext.lastModifiedTime description: The last modified time of the file in milliseconds since the epoch. type: Number - contextPath: RubrikPolaris.FileContext.creationTime description: The creation time of the file in milliseconds since the epoch. type: Number - contextPath: RubrikPolaris.FileContext.lastScanTime description: The last scan time of the file in milliseconds since the epoch. type: Number - contextPath: RubrikPolaris.FileContext.directory description: The value of Directory. type: String - contextPath: RubrikPolaris.FileContext.createdBy description: The user who created the file. type: String - contextPath: RubrikPolaris.FileContext.modifiedBy description: The user who last modified the file. type: String - contextPath: RubrikPolaris.FileContext.numDescendantFiles description: The number of descendant files of the file. type: Number - contextPath: RubrikPolaris.FileContext.numDescendantErrorFiles description: The number of descendant files of the file that could not be processed. type: Number - contextPath: RubrikPolaris.FileContext.numDescendantSkippedExtFiles description: The number of descendant files of the file that were skipped because of their file extension. type: Number - contextPath: RubrikPolaris.FileContext.numDescendantSkippedSizeFiles description: The number of descendant files of the file that were skipped because of their file size. type: Number - contextPath: RubrikPolaris.FileContext.errorCode description: The error code, if any, for the file. type: String - contextPath: RubrikPolaris.FileContext.hits.totalHits description: The total number of hits for the file. type: Number - contextPath: RubrikPolaris.FileContext.hits.violations description: The number of violations for the file. type: Number - contextPath: RubrikPolaris.FileContext.hits.violationsDelta description: The change in the number of violations for the file since the last scan. type: Number - contextPath: RubrikPolaris.FileContext.hits.totalHitsDelta description: The change in the total number of hits for the file since the last scan. type: Number - contextPath: RubrikPolaris.FileContext.hits.__typename description: The type of the hits field. type: String - contextPath: RubrikPolaris.FileContext.filesWithHits.totalHits description: The total number of files with hits. type: Number - contextPath: RubrikPolaris.FileContext.filesWithHits.violations description: The number of files with violations. type: Number - contextPath: RubrikPolaris.FileContext.filesWithHits.__typename description: The type of the files with hits field. type: String - contextPath: RubrikPolaris.FileContext.openAccessFilesWithHits.totalHits description: The total number of open access files with hits. type: Number - contextPath: RubrikPolaris.FileContext.openAccessFilesWithHits.violations description: The number of open access files with violations. type: Number - contextPath: RubrikPolaris.FileContext.openAccessFilesWithHits.__typename description: The type of the open access files with hits field. type: String - contextPath: RubrikPolaris.FileContext.staleFilesWithHits.totalHits description: The total number of stale files with hits. type: Number - contextPath: RubrikPolaris.FileContext.staleFilesWithHits.violations description: The number of stale files with violations. type: Number - contextPath: RubrikPolaris.FileContext.staleFilesWithHits.__typename description: The type of the stale files with hits field. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerGroup.groupType description: The type of the analyzer group. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerGroup.id description: The ID of the analyzer group. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerGroup.name description: The name of the analyzer group. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerGroup.__typename description: The type of the analyzer group field. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerResults.hits.totalHits description: The total number of hits for the analyzer results. type: Number - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerResults.hits.violations description: The number of violations for the analyzer results. type: Number - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerResults.hits.__typename description: The type of the hits field. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerResults.analyzer.id description: The ID of the analyzer. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerResults.analyzer.name description: The name of the analyzer. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerResults.analyzer.analyzerType description: The type of the analyzer. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerResults.analyzer.__typename description: The type of the analyzer field. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.analyzerResults.__typename description: The type of the analyzer results field. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.hits.totalHits description: The total number of hits for the analyzer group results. type: Number - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.hits.violations description: The number of violations for the analyzer group results. type: Number - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.hits.violationsDelta description: The change in the number of violations for the analyzer group results since the last scan. type: Number - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.hits.totalHitsDelta description: The change in the total number of hits for the analyzer group results since the last scan. type: Number - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.hits.__typename description: The type of the hits field. type: String - contextPath: RubrikPolaris.FileContext.analyzerGroupResults.__typename description: The type of the analyzer group results field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveFiles.highRiskFileCount.totalCount description: The total number of high-risk files for the policy object. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveFiles.highRiskFileCount.violatedCount description: The number of high-risk files for the policy object that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveFiles.highRiskFileCount.__typename description: The type of the high-risk file count field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveFiles.mediumRiskFileCount.totalCount description: The total number of medium-risk files for the policy object. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveFiles.mediumRiskFileCount.violatedCount description: The number of medium-risk files for the policy object that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveFiles.mediumRiskFileCount.__typename description: The type of the medium risk file count field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveFiles.lowRiskFileCount.totalCount description: The total number of low-risk files for the policy object. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveFiles.lowRiskFileCount.violatedCount description: The number of low-risk files for the policy object that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveFiles.lowRiskFileCount.__typename description: The type of the low-risk file count field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveFiles.noRiskFileCount.totalCount description: The total number of no-risk files for the policy object. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveFiles.noRiskFileCount.violatedCount description: The number of no-risk files for the policy object that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveFiles.noRiskFileCount.__typename description: The type of the no-risk file count field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveFiles.totalFileCount.totalCount description: The total number of files for the policy object. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveFiles.totalFileCount.violatedCount description: The number of files for the policy object that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveFiles.totalFileCount.__typename description: The type of the total file count field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveFiles.__typename description: The type of the sensitive files field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveHits.highRiskHits.totalHits description: The total number of high-risk sensitive hits for the file. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveHits.highRiskHits.violatedHits description: The number of high-risk sensitive hits for the file that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveHits.highRiskHits.__typename description: The type of the high-risk hits field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveHits.mediumRiskHits.totalHits description: The total number of medium-risk sensitive hits for the file. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveHits.mediumRiskHits.violatedHits description: The number of medium-risk sensitive hits for the file that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveHits.mediumRiskHits.__typename description: The type of the medium-risk hits field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveHits.lowRiskHits.totalHits description: The total number of low-risk sensitive hits for the file. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveHits.lowRiskHits.violatedHits description: The number of low-risk sensitive hits for the file that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveHits.lowRiskHits.__typename description: The type of the low-risk hits field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveHits.noRiskHits.totalHits description: The total number of no-risk sensitive hits for the file. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveHits.noRiskHits.violatedHits description: The number of no-risk sensitive hits for the file that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.sensitiveHits.noRiskHits.__typename description: The type of the no-risk hits field. type: String - contextPath: RubrikPolaris.FileContext.sensitiveHits.__typename description: The type of the sensitive hits field. type: String - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.highRiskHits.totalHits description: The total number of high-risk analyzer hits for the file. type: Number - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.highRiskHits.violatedHits description: The number of high-risk analyzer hits for the file that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.highRiskHits.__typename description: The type of the high-risk hits field. type: String - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.mediumRiskHits.totalHits description: The total number of medium-risk analyzer hits for the file. type: Number - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.mediumRiskHits.violatedHits description: The number of medium-risk analyzer hits for the file that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.mediumRiskHits.__typename description: The type of the medium-risk hits field. type: String - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.lowRiskHits.totalHits description: The total number of low-risk analyzer hits for the file. type: Number - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.lowRiskHits.violatedHits description: The number of low-risk analyzer hits for the file that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.lowRiskHits.__typename description: The type of the low-risk hits field. type: String - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.noRiskHits.totalHits description: The total number of no-risk analyzer hits for the file. type: Number - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.noRiskHits.violatedHits description: The number of no-risk analyzer hits for the file that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.noRiskHits.__typename description: The type of the no-risk hits field. type: String - contextPath: RubrikPolaris.FileContext.analyzerRiskHits.__typename description: The type of the analyzer risk hits field. type: String - contextPath: RubrikPolaris.FileContext.analyzerResults.hits.totalHits description: The total number of hits for the analyzer results. type: Number - contextPath: RubrikPolaris.FileContext.analyzerResults.hits.violations description: The number of violations for the analyzer results. type: Number - contextPath: RubrikPolaris.FileContext.analyzerResults.hits.__typename description: The type of the hits field. type: String - contextPath: RubrikPolaris.FileContext.analyzerResults.analyzer.id description: The ID of the analyzer. type: String - contextPath: RubrikPolaris.FileContext.analyzerResults.analyzer.name description: The name of the analyzer. type: String - contextPath: RubrikPolaris.FileContext.analyzerResults.analyzer.analyzerType description: The type of the analyzer. type: String - contextPath: RubrikPolaris.FileContext.analyzerResults.analyzer.__typename description: The type of the analyzer field. type: String - contextPath: RubrikPolaris.FileContext.analyzerResults.__typename description: The type of the analyzer results field. type: String - contextPath: RubrikPolaris.FileContext.openAccessType description: The open access type for the file. type: String - contextPath: RubrikPolaris.FileContext.stalenessType description: The staleness type for the file. type: String - contextPath: RubrikPolaris.FileContext.numActivities description: The number of activities for the file. type: Number - contextPath: RubrikPolaris.FileContext.numActivitiesDelta description: The change in the number of activities for the file since the last time it was checked. type: Number - contextPath: RubrikPolaris.FileContext.exposureSummary.exposureType description: The exposure type of the file. type: String - contextPath: RubrikPolaris.FileContext.exposureSummary.fileCount.totalCount description: The total number of files with this exposure type. type: Number - contextPath: RubrikPolaris.FileContext.exposureSummary.fileCount.violatedCount description: The number of files with this exposure type that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.exposureSummary.fileCount.__typename description: The type of the file count field. type: String - contextPath: RubrikPolaris.FileContext.exposureSummary.__typename description: The type of the exposure summary field. type: String - contextPath: RubrikPolaris.FileContext.dbEntityType description: The database entity type of the file. type: String - contextPath: RubrikPolaris.FileContext.mipLabelsSummary.mipLabel.siteId description: The site ID of the MIP label. type: String - contextPath: RubrikPolaris.FileContext.mipLabelsSummary.mipLabel.labelName description: The name of the MIP label. type: String - contextPath: RubrikPolaris.FileContext.mipLabelsSummary.mipLabel.labelId description: The ID of the MIP label. type: String - contextPath: RubrikPolaris.FileContext.mipLabelsSummary.mipLabel.hasProtection description: Whether the MIP label has protection applied. type: Boolean - contextPath: RubrikPolaris.FileContext.mipLabelsSummary.mipLabel.__typename description: The type of the MIP label field. type: String - contextPath: RubrikPolaris.FileContext.mipLabelsSummary.filesCount.violatedCount description: The number of files with this MIP label that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.mipLabelsSummary.filesCount.totalCount description: The total number of files with this MIP label. type: Number - contextPath: RubrikPolaris.FileContext.mipLabelsSummary.filesCount.__typename description: The type of the files count field. type: String - contextPath: RubrikPolaris.FileContext.mipLabelsSummary.__typename description: The type of the MIP labels summary field. type: String - contextPath: RubrikPolaris.FileContext.documentTypesSummary.id description: The ID of the document type. type: String - contextPath: RubrikPolaris.FileContext.documentTypesSummary.name description: The name of the document type. type: String - contextPath: RubrikPolaris.FileContext.documentTypesSummary.filesCount.totalCount description: The total number of files of this document type. type: Number - contextPath: RubrikPolaris.FileContext.documentTypesSummary.filesCount.violatedCount description: The number of files of this document type that violates policies. type: Number - contextPath: RubrikPolaris.FileContext.documentTypesSummary.filesCount.__typename description: The type of the files count field. type: String - contextPath: RubrikPolaris.FileContext.documentTypesSummary.__typename description: The type of the document types summary field. type: String - contextPath: RubrikPolaris.FileContext.__typename description: The type of the file context field. type: String - contextPath: RubrikPolaris.PageToken.FileContext.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.FileContext.startCursor description: The start cursor for the current page. type: String - contextPath: RubrikPolaris.PageToken.FileContext.endCursor description: The end cursor for the current page. type: String - contextPath: RubrikPolaris.PageToken.FileContext.hasNextPage description: Whether the result has the next page or not. type: Boolean - contextPath: RubrikPolaris.PageToken.FileContext.hasPreviousPage description: Whether the result has the previous page or not. type: Boolean - arguments: - description: "The Snapshot ID of the object or Activity Series ID.\n\nNote: Users can get the list of the snapshot IDs by executing the \"rubrik-polaris-object-snapshot-list\" command. For the Activity Series ID, the users can execute the \"rubrik-event-list\" command with the \"activity_type\" argument set to \"ANOMALY\"." name: snapshot_id required: true description: Retrieve the suspicious list of files for a snapshot ID with detected file anomalies. name: rubrik-radar-suspicious-file-list outputs: - contextPath: RubrikPolaris.SuspiciousFile.id description: 'The anomaly result ID.' type: String - contextPath: RubrikPolaris.SuspiciousFile.snapshotFid description: 'The snapshot ID.' type: String - contextPath: RubrikPolaris.SuspiciousFile.cluster.id description: 'The cluster ID.' type: String - contextPath: RubrikPolaris.SuspiciousFile.cluster.defaultAddress description: 'The default address of the cluster.' type: String - contextPath: RubrikPolaris.SuspiciousFile.cluster.systemStatusAffectedNodes.ipAddress description: 'The IP address of the affected node.' type: String - contextPath: RubrikPolaris.SuspiciousFile.cluster.name description: 'The cluster name.' type: String - contextPath: RubrikPolaris.SuspiciousFile.cluster.version description: 'The cluster version.' type: String - contextPath: RubrikPolaris.SuspiciousFile.cluster.status description: 'The cluster status.' type: String - contextPath: RubrikPolaris.SuspiciousFile.cluster.__typename description: 'The type name of the cluster response.' type: String - contextPath: RubrikPolaris.SuspiciousFile.cdmId description: 'The snapshot CDM ID.' type: String - contextPath: RubrikPolaris.SuspiciousFile.managedId description: 'The managed object ID.' type: String - contextPath: RubrikPolaris.SuspiciousFile.anomalyProbability description: 'The probability of the anomaly.' type: Number - contextPath: RubrikPolaris.SuspiciousFile.workloadId description: 'The workload ID.' type: String - contextPath: RubrikPolaris.SuspiciousFile.location description: 'The location of the anomaly.' type: String - contextPath: RubrikPolaris.SuspiciousFile.isAnomaly description: 'Indicates if the file is an anomaly.' type: Boolean - contextPath: RubrikPolaris.SuspiciousFile.objectType description: 'The object type.' type: String - contextPath: RubrikPolaris.SuspiciousFile.snappableNew.objectType description: 'The object type of the snapshot.' type: String - contextPath: RubrikPolaris.SuspiciousFile.severity description: 'The severity of the anomaly.' type: String - contextPath: RubrikPolaris.SuspiciousFile.detectionTime description: 'The detection time of the anomaly.' type: Date - contextPath: RubrikPolaris.SuspiciousFile.snapshotDate description: 'The snapshot date of the anomaly.' type: Date - contextPath: RubrikPolaris.SuspiciousFile.encryption description: 'The encryption standard of the anomaly.' type: String - contextPath: RubrikPolaris.SuspiciousFile.resolutionStatus description: 'The resolution status of the anomaly.' type: String - contextPath: RubrikPolaris.SuspiciousFile.anomalyType description: 'The type of the anomaly.' type: String - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.strainId description: 'The ID of the Ransomware Strain.' type: String - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.totalAffectedFiles description: 'The total number of affected files.' type: Number - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.totalRansomwareNotes description: 'The total number of ransomware notes.' type: Number - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.sampleAffectedFilesInfo.filePath description: 'The path of the affected file.' type: String - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.sampleAffectedFilesInfo.lastModified description: 'The last modified time of the affected file.' type: Date - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.sampleAffectedFilesInfo.fileSizeBytes description: 'The size of the affected file in bytes.' type: Number - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.sampleAffectedFilesInfo.__typename description: 'The type name of the affected file response.' type: String - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.sampleRansomwareNoteFilesInfo.filePath description: 'The path of the ransomware note file.' type: String - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.sampleRansomwareNoteFilesInfo.lastModified description: 'The last modified time of the ransomware note file.' type: Date - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.sampleRansomwareNoteFilesInfo.fileSizeBytes description: 'The size of the ransomware note file in bytes.' type: Number - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.sampleRansomwareNoteFilesInfo.__typename description: 'The type name of the ransomware note file response.' type: String - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.strainAnalysisInfo.__typename description: 'The type name of the strain analysis response.' type: String - contextPath: RubrikPolaris.SuspiciousFile.anomalyInfo.__typename description: 'The type name of the anomaly response.' type: String - contextPath: RubrikPolaris.SuspiciousFile.__typename description: 'The type name of the suspicious file response.' type: String - name: ip description: Retrieve the sensitive information available for the given IP address(es). arguments: - name: ip description: The IP address(es) for which to retrieve sensitive information. required: true isArray: true default: true outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: IP.Address description: IP address. type: String - contextPath: IP.Relationships.EntityA description: The source of the relationship. type: String - contextPath: IP.Relationships.EntityB description: The destination of the relationship. type: String - contextPath: IP.Relationships.Relationship description: The name of the relationship. type: String - contextPath: IP.Relationships.EntityAType description: The type of the source of the relationship. type: String - contextPath: IP.Relationships.EntityBType description: The type of the destination of the relationship. type: String - contextPath: IP.ASN description: 'The autonomous system name for the IP address, for example: "AS8948".' type: String - contextPath: IP.Hostname description: The hostname that is mapped to this IP address. type: String - contextPath: IP.Geo.Location description: 'The geolocation where the IP address is located, in the format: latitude:longitude.' type: String - contextPath: IP.Geo.Country description: The country in which the IP address is located. type: String - contextPath: IP.Geo.Description description: Additional information about the location. type: String - contextPath: IP.DetectionEngines description: The total number of engines that checked the indicator. type: Number - contextPath: IP.PositiveDetections description: The number of engines that positively detected the indicator as malicious. type: Number - contextPath: IP.Malicious.Vendor description: The vendor reporting the IP address as malicious. type: String - contextPath: IP.Malicious.Description description: A description explaining why the IP address was reported as malicious. type: String - contextPath: IP.Tags description: Tags of the IP address. type: Unknown - contextPath: IP.FeedRelatedIndicators.value description: Indicators that are associated with the IP address. type: String - contextPath: IP.FeedRelatedIndicators.type description: The type of the indicators that are associated with the IP address. type: String - contextPath: IP.FeedRelatedIndicators.description description: The description of the indicators that are associated with the IP address. type: String - contextPath: IP.MalwareFamily description: The malware family associated with the IP address. type: String - contextPath: IP.Organization.Name description: The organization of the IP address. type: String - contextPath: IP.Organization.Type description: The organization type of the IP address. type: String - contextPath: IP.ASOwner description: The autonomous system owner of the IP address. type: String - contextPath: IP.Region description: The region in which the IP address is located. type: String - contextPath: IP.Port description: Ports that are associated with the IP address. type: String - contextPath: IP.Internal description: Whether the IP address is internal or external. type: Boolean - contextPath: IP.UpdatedDate description: The date that the IP address was last updated. type: Date - contextPath: IP.Registrar.Abuse.Name description: The name of the contact for reporting abuse. type: String - contextPath: IP.Registrar.Abuse.Address description: The address of the contact for reporting abuse. type: String - contextPath: IP.Registrar.Abuse.Country description: The country of the contact for reporting abuse. type: String - contextPath: IP.Registrar.Abuse.Network description: The network of the contact for reporting abuse. type: String - contextPath: IP.Registrar.Abuse.Phone description: The phone number of the contact for reporting abuse. type: String - contextPath: IP.Registrar.Abuse.Email description: The email address of the contact for reporting abuse. type: String - contextPath: IP.Campaign description: The campaign associated with the IP address. type: String - contextPath: IP.TrafficLightProtocol description: The Traffic Light Protocol (TLP) color that is suitable for the IP address. type: String - contextPath: IP.CommunityNotes.note description: Notes on the IP address that were given by the community. type: String - contextPath: IP.CommunityNotes.timestamp description: The time in which the note was published. type: Date - contextPath: IP.Publications.source description: The source in which the article was published. type: String - contextPath: IP.Publications.title description: The name of the article. type: String - contextPath: IP.Publications.link description: A link to the original article. type: String - contextPath: IP.Publications.timestamp description: The time in which the article was published. type: Date - contextPath: IP.ThreatTypes.threatcategory description: The threat category associated to this indicator by the source vendor. For example, Phishing, Control, TOR, etc. type: String - contextPath: IP.ThreatTypes.threatcategoryconfidence description: The confidence level provided by the vendor for the threat type category For example, a confidence of 90 for the threat type category 'malware' means that the vendor rates that this is 90% confidence of being a malware. type: String - contextPath: RubrikPolaris.IP.ip description: 'IP address of the object.' type: String - contextPath: RubrikPolaris.IP.generalInfo.fid description: 'The foreign ID of the object.' type: String - contextPath: RubrikPolaris.IP.generalInfo.name description: 'The name of the object.' type: String - contextPath: RubrikPolaris.IP.generalInfo.objectType description: 'The type of the object.' type: String - contextPath: RubrikPolaris.IP.generalInfo.protectionStatus description: 'The protection status of the object.' type: String - contextPath: RubrikPolaris.IP.generalInfo.lastSnapshot description: 'The timestamp of the last snapshot of the object.' type: Date - contextPath: RubrikPolaris.IP.generalInfo.redirectLink description: 'The link to the object in the Rubrik UI.' type: String - contextPath: RubrikPolaris.IP.sensitiveInfo.riskLevel description: 'The risk level of the object.' type: String - contextPath: RubrikPolaris.IP.sensitiveInfo.sensitiveFiles.mediumCount description: 'The number of sensitive files of medium risk level.' type: String - contextPath: RubrikPolaris.IP.sensitiveInfo.sensitiveHits description: 'The number of sensitive files.' type: Number - contextPath: RubrikPolaris.IP.sensitiveInfo.openAccessFiles description: 'The number of open access files.' type: Number - contextPath: RubrikPolaris.IP.sensitiveInfo.staleFiles description: 'The number of stale files.' type: Number - contextPath: RubrikPolaris.IP.sensitiveInfo.redirectLink description: 'The link to the sensitive information in the Rubrik UI.' type: String - contextPath: RubrikPolaris.IP.sensitiveInfo.policyNames description: 'The names of the policies associated with the object.' type: String - contextPath: RubrikPolaris.IP.anomalyInfo.severity description: 'The severity of the anomaly.' type: String - contextPath: RubrikPolaris.IP.anomalyInfo.detectionTime description: 'The timestamp of the anomaly detection.' type: Date - contextPath: RubrikPolaris.IP.anomalyInfo.createdFileCount description: 'The number of created files.' type: String - contextPath: RubrikPolaris.IP.anomalyInfo.deletedFileCount description: 'The number of deleted files.' type: String - contextPath: RubrikPolaris.IP.anomalyInfo.modifiedFileCount description: 'The number of modified files.' type: String - contextPath: RubrikPolaris.IP.anomalyInfo.suspiciousFileCount description: 'The number of suspicious files.' type: String - contextPath: RubrikPolaris.IP.anomalyInfo.redirectLink description: 'The link to the anomaly information in the Rubrik UI.' type: String - contextPath: RubrikPolaris.IP.threatHuntInfo.latestThreatHunt.huntId description: 'The ID of the latest threat hunt.' type: String - contextPath: RubrikPolaris.IP.threatHuntInfo.latestThreatHunt.huntStartTime description: 'The timestamp of the latest threat hunt.' type: Date - contextPath: RubrikPolaris.IP.threatHuntInfo.latestThreatHunt.isMalicious description: 'Whether the latest threat hunt is malicious.' type: String - contextPath: RubrikPolaris.IP.threatHuntInfo.latestMaliciousThreatHunt.huntId description: 'The ID of the latest malicious threat hunt.' type: String - contextPath: RubrikPolaris.IP.threatHuntInfo.latestMaliciousThreatHunt.huntStartTime description: 'The timestamp of the latest malicious threat hunt.' type: Date - contextPath: RubrikPolaris.IP.threatHuntInfo.latestMaliciousThreatHunt.isMalicious description: 'Whether the latest malicious threat hunt is malicious.' type: String - contextPath: RubrikPolaris.IP.threatHuntInfo.redirectLink description: 'The link to the threat hunt information in the Rubrik UI.' type: String - contextPath: RubrikPolaris.IP.threatMonitoringInfo.latestThreatMonitoring.snapshotFid description: 'The foreign ID of the latest threat monitoring snapshot.' type: String - contextPath: RubrikPolaris.IP.threatMonitoringInfo.latestThreatMonitoring.monitoringScanTime description: 'The timestamp of the latest threat monitoring scan.' type: Date - contextPath: RubrikPolaris.IP.threatMonitoringInfo.latestThreatMonitoring.isMalicious description: 'Whether the latest threat monitoring snapshot is malicious.' type: String - contextPath: RubrikPolaris.IP.threatMonitoringInfo.latestMaliciousThreatMonitoring.snapshotFid description: 'The foreign ID of the latest malicious threat monitoring snapshot.' type: String - contextPath: RubrikPolaris.IP.threatMonitoringInfo.latestMaliciousThreatMonitoring.monitoringScanTime description: 'The timestamp of the latest malicious threat monitoring scan.' type: Date - contextPath: RubrikPolaris.IP.threatMonitoringInfo.latestMaliciousThreatMonitoring.isMalicious description: 'Whether the latest malicious threat monitoring snapshot is malicious.' type: String - contextPath: RubrikPolaris.IP.threatMonitoringInfo.redirectLink description: 'The link to the threat monitoring information in the Rubrik UI.' type: String - name: domain description: Retrieve the sensitive information available for the given domain(s). arguments: - name: domain description: The domain(s) for which to retrieve sensitive information. required: true isArray: true default: true outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: Domain.Name description: 'The domain name, for example: "google.com".' type: String - contextPath: Domain.Relationships.EntityA description: The source of the relationship. type: string - contextPath: Domain.Relationships.EntityB description: The destination of the relationship. type: string - contextPath: Domain.Relationships.Relationship description: The name of the relationship. type: string - contextPath: Domain.Relationships.EntityAType description: The type of the source of the relationship. type: string - contextPath: Domain.Relationships.EntityBType description: The type of the destination of the relationship. type: string - contextPath: Domain.DNS description: A list of IP objects resolved by DNS. type: String - contextPath: Domain.DetectionEngines description: The total number of engines that checked the indicator. type: Number - contextPath: Domain.PositiveDetections description: The number of engines that positively detected the indicator as malicious. type: Number - contextPath: Domain.CreationDate description: The date that the domain was created. type: Date - contextPath: Domain.UpdatedDate description: The date that the domain was last updated. type: String - contextPath: Domain.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.DomainStatus description: The status of the domain. type: Datte - contextPath: Domain.NameServers description: (List) Name servers of the domain. type: Unknown - contextPath: Domain.Organization description: The organization of the domain. type: String - contextPath: Domain.Subdomains description: (List) Subdomains of the domain. type: Unknown - contextPath: Domain.Admin.Country description: The country of the domain administrator. type: String - contextPath: Domain.Admin.Email description: The email address of the domain administrator. type: String - contextPath: Domain.Admin.Name description: The name of the domain administrator. type: String - contextPath: Domain.Admin.Phone description: The phone number of the domain administrator. type: String - contextPath: Domain.Registrant.Country description: The country of the registrant. type: String - contextPath: Domain.Registrant.Email description: The email address of the registrant. type: String - contextPath: Domain.Registrant.Name description: The name of the registrant. type: String - contextPath: Domain.Registrant.Phone description: The phone number for receiving abuse reports. type: String - contextPath: Domain.Tags description: Tags of the domain. type: Unknown - contextPath: Domain.FeedRelatedIndicators.value description: Indicators that are associated with the domain. type: String - contextPath: Domain.FeedRelatedIndicators.type description: The type of the indicators that are associated with the domain. type: String - contextPath: Domain.FeedRelatedIndicators.description description: The description of the indicators that are associated with the domain. type: String - contextPath: Domain.MalwareFamily description: The malware family associated with the domain. type: String - contextPath: Domain.WHOIS.DomainStatus description: The status of the domain. type: String - contextPath: Domain.WHOIS.NameServers description: (List) Name servers of the domain. type: String - contextPath: Domain.WHOIS.CreationDate description: The date that the domain was created. type: Date - contextPath: Domain.WHOIS.UpdatedDate description: The date that the domain was last updated. type: Date - contextPath: Domain.WHOIS.ExpirationDate description: The expiration date of the domain. type: Date - contextPath: Domain.WHOIS.Registrant.Name description: The name of the registrant. type: String - contextPath: Domain.WHOIS.Registrant.Email description: The email address of the registrant. type: String - contextPath: Domain.WHOIS.Registrant.Phone description: The phone number of the registrant. type: String - contextPath: Domain.WHOIS.Registrar.Name description: 'The name of the registrar, for example: "GoDaddy".' type: String - contextPath: Domain.WHOIS.Registrar.AbuseEmail description: The email address of the contact for reporting abuse. type: String - contextPath: Domain.WHOIS.Registrar.AbusePhone description: The phone number of contact for reporting abuse. type: String - contextPath: Domain.WHOIS.Admin.Name description: The name of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Email description: The email address of the domain administrator. type: String - contextPath: Domain.WHOIS.Admin.Phone description: The phone number of the domain administrator. type: String - contextPath: Domain.WHOIS/History description: List of Whois objects. type: String - contextPath: Domain.Malicious.Vendor description: The vendor reporting the domain as malicious. type: String - contextPath: Domain.Malicious.Description description: A description explaining why the domain was reported as malicious. type: String - contextPath: Domain.DomainIDNName description: The internationalized domain name (IDN) of the domain. type: String - contextPath: Domain.Port description: Ports that are associated with the domain. type: String - contextPath: Domain.Internal description: Whether or not the domain is internal or external. type: Bool - contextPath: Domain.Category description: The category associated with the indicator. type: String - contextPath: Domain.Campaign description: The campaign associated with the domain. type: String - contextPath: Domain.TrafficLightProtocol description: The Traffic Light Protocol (TLP) color that is suitable for the domain. type: String - contextPath: Domain.ThreatTypes.threatcategory description: The threat category associated to this indicator by the source vendor. For example, Phishing, Control, TOR, etc. type: String - contextPath: Domain.ThreatTypes.threatcategoryconfidence description: Threat Category Confidence is the confidence level provided by the vendor for the threat type category For example a confidence of 90 for threat type category 'malware' means that the vendor rates that this is 90% confidence of being a malware. type: String - contextPath: Domain.Geo.Location description: 'The geolocation where the domain address is located, in the format: latitude:longitude.' type: String - contextPath: Domain.Geo.Country description: The country in which the domain address is located. type: String - contextPath: Domain.Geo.Description description: Additional information about the location. type: String - contextPath: Domain.Tech.Country description: The country of the domain technical contact. type: String - contextPath: Domain.Tech.Name description: The name of the domain technical contact. type: String - contextPath: Domain.Tech.Organization description: The organization of the domain technical contact. type: String - contextPath: Domain.Tech.Email description: The email address of the domain technical contact. type: String - contextPath: Domain.CommunityNotes.note description: Notes on the domain that were given by the community. type: String - contextPath: Domain.CommunityNotes.timestamp description: The time in which the note was published. type: Date - contextPath: Domain.Publications.source description: The source in which the article was published. type: String - contextPath: Domain.Publications.title description: The name of the article. type: String - contextPath: Domain.Publications.link description: A link to the original article. type: String - contextPath: Domain.Publications.timestamp description: The time in which the article was published. type: Date - contextPath: Domain.Billing description: The billing address of the domain. type: String - contextPath: RubrikPolaris.Domain.domain description: 'The domain of the object.' type: String - contextPath: RubrikPolaris.Domain.generalInfo.fid description: 'The foreign ID of the object.' type: String - contextPath: RubrikPolaris.Domain.generalInfo.name description: 'The name of the object.' type: String - contextPath: RubrikPolaris.Domain.generalInfo.objectType description: 'The type of the object.' type: String - contextPath: RubrikPolaris.Domain.generalInfo.protectionStatus description: 'The protection status of the object.' type: String - contextPath: RubrikPolaris.Domain.generalInfo.lastSnapshot description: 'The timestamp of the last snapshot of the object.' type: Date - contextPath: RubrikPolaris.Domain.generalInfo.redirectLink description: 'The link to the object in the Rubrik UI.' type: String - contextPath: RubrikPolaris.Domain.sensitiveInfo.riskLevel description: 'The risk level of the object.' type: String - contextPath: RubrikPolaris.Domain.sensitiveInfo.sensitiveFiles.mediumCount description: 'The number of sensitive files of medium risk level.' type: String - contextPath: RubrikPolaris.Domain.sensitiveInfo.sensitiveHits description: 'The number of sensitive files.' type: Number - contextPath: RubrikPolaris.Domain.sensitiveInfo.openAccessFiles description: 'The number of open access files.' type: Number - contextPath: RubrikPolaris.Domain.sensitiveInfo.staleFiles description: 'The number of stale files.' type: Number - contextPath: RubrikPolaris.Domain.sensitiveInfo.redirectLink description: 'The link to the sensitive information in the Rubrik UI.' type: String - contextPath: RubrikPolaris.Domain.sensitiveInfo.policyNames description: 'The names of the policies associated with the object.' type: String - contextPath: RubrikPolaris.Domain.anomalyInfo.severity description: 'The severity of the anomaly.' type: String - contextPath: RubrikPolaris.Domain.anomalyInfo.detectionTime description: 'The timestamp of the anomaly detection.' type: Date - contextPath: RubrikPolaris.Domain.anomalyInfo.createdFileCount description: 'The number of created files.' type: String - contextPath: RubrikPolaris.Domain.anomalyInfo.deletedFileCount description: 'The number of deleted files.' type: String - contextPath: RubrikPolaris.Domain.anomalyInfo.modifiedFileCount description: 'The number of modified files.' type: String - contextPath: RubrikPolaris.Domain.anomalyInfo.suspiciousFileCount description: 'The number of suspicious files.' type: String - contextPath: RubrikPolaris.Domain.anomalyInfo.redirectLink description: 'The link to the anomaly information in the Rubrik UI.' type: String - contextPath: RubrikPolaris.Domain.threatHuntInfo.latestThreatHunt.huntId description: 'The ID of the latest threat hunt.' type: String - contextPath: RubrikPolaris.Domain.threatHuntInfo.latestThreatHunt.huntStartTime description: 'The timestamp of the latest threat hunt.' type: Date - contextPath: RubrikPolaris.Domain.threatHuntInfo.latestThreatHunt.isMalicious description: 'Whether the latest threat hunt is malicious.' type: String - contextPath: RubrikPolaris.Domain.threatHuntInfo.latestMaliciousThreatHunt.huntId description: 'The ID of the latest malicious threat hunt.' type: String - contextPath: RubrikPolaris.Domain.threatHuntInfo.latestMaliciousThreatHunt.huntStartTime description: 'The timestamp of the latest malicious threat hunt.' type: Date - contextPath: RubrikPolaris.Domain.threatHuntInfo.latestMaliciousThreatHunt.isMalicious description: 'Whether the latest malicious threat hunt is malicious.' type: String - contextPath: RubrikPolaris.Domain.threatHuntInfo.redirectLink description: 'The link to the threat hunt information in the Rubrik UI.' type: String - contextPath: RubrikPolaris.Domain.threatMonitoringInfo.latestThreatMonitoring.snapshotFid description: 'The foreign ID of the latest threat monitoring snapshot.' type: String - contextPath: RubrikPolaris.Domain.threatMonitoringInfo.latestThreatMonitoring.monitoringScanTime description: 'The timestamp of the latest threat monitoring scan.' type: Date - contextPath: RubrikPolaris.Domain.threatMonitoringInfo.latestThreatMonitoring.isMalicious description: 'Whether the latest threat monitoring snapshot is malicious.' type: String - contextPath: RubrikPolaris.Domain.threatMonitoringInfo.latestMaliciousThreatMonitoring.snapshotFid description: 'The foreign ID of the latest malicious threat monitoring snapshot.' type: String - contextPath: RubrikPolaris.Domain.threatMonitoringInfo.latestMaliciousThreatMonitoring.monitoringScanTime description: 'The timestamp of the latest malicious threat monitoring scan.' type: Date - contextPath: RubrikPolaris.Domain.threatMonitoringInfo.latestMaliciousThreatMonitoring.isMalicious description: 'Whether the latest malicious threat monitoring snapshot is malicious.' type: String - contextPath: RubrikPolaris.Domain.threatMonitoringInfo.redirectLink description: 'The link to the threat monitoring information in the Rubrik UI.' type: String - name: rubrik-radar-anomaly-status-update description: "Updates the status of the Anomaly detection.\n\nNote: Run the \"rubrik-radar-suspicious-file-list\" command first to check the resolution status of the Anomaly Detection snapshot before executing this command." arguments: - name: anomaly_type description: "The type of the anomaly.\n\nNote: For Anomaly Type, users can execute the \"rubrik-radar-suspicious-file-list\" command." required: true auto: PREDEFINED predefined: - 'FILESYSTEM' - 'HYPERVISOR' - name: anomaly_id description: "The ID of the Anomaly or Activity Series ID.\n\nNote: For Activity Series ID, users can execute the \"rubrik-event-list\" command with the \"activity_type\" argument set to \"ANOMALY\"." required: true - name: workload_id description: "The workload ID (Snappable ID).\n\nNote: Users can execute the \"rubrik-event-list\" command with the \"activity_type\" argument set to \"ANOMALY\" and get the value of \"fid\" from the context." required: true - name: false_positive_type description: The type for marking the anomaly as a false positive. auto: PREDEFINED predefined: - 'FP_TYPE_UNSPECIFIED' - 'OS_UPDATE' - 'APPLICATION_UPDATE' - 'LOG_ROTATION' - 'OTHER' - 'NFA_SCHEDULED_MAINTENANCE' - 'NFA_UNSCHEDULED_MAINTENANCE' - name: false_positive_reason description: "The reason for marking the anomaly as a false positive when the \"false_positive_type\" argument is set to OTHER." outputs: - contextPath: RubrikPolaris.AnomalyStatus.command_name description: The name of the command. type: String - contextPath: RubrikPolaris.AnomalyStatus.anomaly_type description: The type of the Anomaly. type: String - contextPath: RubrikPolaris.AnomalyStatus.anomaly_id description: The ID of the Anomaly. type: String - contextPath: RubrikPolaris.AnomalyStatus.workload_id description: The workload ID. type: String - contextPath: RubrikPolaris.AnomalyStatus.is_resloved description: Whether the Anomaly is resolved. type: Boolean - contextPath: RubrikPolaris.AnomalyStatus.false_positive_type description: The type of the false positive. type: String - contextPath: RubrikPolaris.AnomalyStatus.false_positive_reason description: The reason for marking the Anomaly detection snapshot as a false positive. type: String - name: rubrik-threat-monitoring-matched-object-list description: "List the matched objects for Threat Monitoring." arguments: - name: cluster_id description: "The unique ID of the cluster. Supports comma separated values.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." isArray: true - name: object_type description: "Filter the objects based on the provided object types. Supports comma separated values.\n\nNote: Values not included in the options can be found in the documentation." auto: PREDEFINED predefined: - ShareFileset - NutanixVirtualMachine - VolumeGroup - HypervVirtualMachine - LinuxFileset - WindowsFileset - VmwareVirtualMachine isArray: true - name: object_name description: "Filter objects by their name. Supports partial matches." - name: match_type description: Filter the objects by the match type. Supports comma separated values. auto: PREDEFINED predefined: - INDICATOR_OF_COMPROMISE_TYPE_PATH_OR_FILENAME - INDICATOR_OF_COMPROMISE_TYPE_HASH - INDICATOR_OF_COMPROMISE_TYPE_YARA_RULE isArray: true - name: start_time defaultValue: "7 days" description: "Filter the objects detected after this time.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 June 2025, 01 June 2025 04:45:33, 2025-06-17T14:05:44Z." - name: limit defaultValue: "50" description: "Number of results to retrieve in the response. The maximum allowed size is 1000." - name: next_page_token description: "The next page cursor to retrieve the next set of results." outputs: - contextPath: RubrikPolaris.ThreatMonitoring.objectFid description: The unique identifier (FID) of the object. type: String - contextPath: RubrikPolaris.ThreatMonitoring.objectName description: The name of the matched object. type: String - contextPath: RubrikPolaris.ThreatMonitoring.objectType description: The type of the matched object. type: String - contextPath: RubrikPolaris.ThreatMonitoring.matchType description: A list of match types found for the object. type: Unknown - contextPath: RubrikPolaris.ThreatMonitoring.filesMatched description: The number of files matched with the threat monitoring object. type: Number - contextPath: RubrikPolaris.ThreatMonitoring.lastDetection description: The timestamp of the most recent detection. type: Date - contextPath: RubrikPolaris.ThreatMonitoring.cluster.name description: The name of the cluster the object belongs to. type: String - contextPath: RubrikPolaris.ThreatMonitoring.cluster.id description: The unique identifier of the cluster. type: String - contextPath: RubrikPolaris.ThreatMonitoring.cluster.__typename description: The GraphQL typename of the cluster object. type: String - contextPath: RubrikPolaris.ThreatMonitoring.__typename description: The GraphQL typename of the matched object. type: String - contextPath: RubrikPolaris.PageToken.ThreatMonitoring.endCursor description: The end cursor of the threat monitoring data. type: String - contextPath: RubrikPolaris.PageToken.ThreatMonitoring.hasNextPage description: A flag indicating if there is a next page of threat monitoring data. type: Boolean - contextPath: RubrikPolaris.PageToken.ThreatMonitoring.hasPreviousPage description: A flag indicating if there is a previous page of threat monitoring data. type: Boolean - contextPath: RubrikPolaris.PageToken.ThreatMonitoring.name description: The name of the threat monitoring data. type: String - contextPath: RubrikPolaris.PageToken.ThreatMonitoring.total_matched_count description: The total number of matched objects. type: Number - contextPath: RubrikPolaris.PageToken.ThreatMonitoring.startCursor description: The start cursor of the threat monitoring data. type: String - name: rubrik-threat-monitoring-matched-object-get description: "Get the matched object for Threat Monitoring." arguments: - name: object_id description: "The object ID for the threat monitoring object.\n\nNote: Users can retrieve the object ID by executing the \"rubrik-threat-monitoring-matched-object-list\" command." required: true outputs: - contextPath: RubrikPolaris.ThreatMonitoring.id description: The ID of the threat monitoring data. type: String - contextPath: RubrikPolaris.ThreatMonitoring.name description: The name of the threat monitoring data. type: String - contextPath: RubrikPolaris.ThreatMonitoring.objectType description: The object type of the threat monitoring data. type: String - contextPath: RubrikPolaris.ThreatMonitoring.slaAssignment description: The SLA assignment of the threat monitoring data. type: String - contextPath: RubrikPolaris.ThreatMonitoring.slaPauseStatus description: The SLA pause status of the threat monitoring data. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveSlaDomain.id description: The ID of the effective SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveSlaDomain.name description: The name of the effective SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveSlaDomain.version description: The version of the effective SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveSlaDomain.__typename description: The type name of the effective SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.snapshotDistribution.id description: The ID of the snapshot distribution. type: String - contextPath: RubrikPolaris.ThreatMonitoring.snapshotDistribution.totalCount description: The total count of the snapshot distribution. type: Integer - contextPath: RubrikPolaris.ThreatMonitoring.snapshotDistribution.scheduledCount description: The scheduled count of the snapshot distribution. type: Integer - contextPath: RubrikPolaris.ThreatMonitoring.snapshotDistribution.onDemandCount description: The on-demand count of the snapshot distribution. type: Integer - contextPath: RubrikPolaris.ThreatMonitoring.snapshotDistribution.retrievedCount description: The retrieved count of the snapshot distribution. type: Integer - contextPath: RubrikPolaris.ThreatMonitoring.snapshotDistribution.__typename description: The type name of the snapshot distribution. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveRetentionSlaDomain.id description: The ID of the effective retention SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveRetentionSlaDomain.name description: The name of the effective retention SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveRetentionSlaDomain.version description: The version of the effective retention SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveRetentionSlaDomain.__typename description: The type name of the effective retention SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.configuredSlaDomain.id description: The ID of the configured SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.configuredSlaDomain.name description: The name of the configured SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.configuredSlaDomain.version description: The version of the configured SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.configuredSlaDomain.__typename description: The type name of the configured SLA domain. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveSlaSourceObject.fid description: The FID of the effective SLA source object. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveSlaSourceObject.name description: The name of the effective SLA source object. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveSlaSourceObject.objectType description: The object type of the effective SLA source object. type: String - contextPath: RubrikPolaris.ThreatMonitoring.effectiveSlaSourceObject.__typename description: The type name of the effective SLA source object. type: String - contextPath: RubrikPolaris.ThreatMonitoring.logicalPath.fid description: The FID of the logical path. type: String - contextPath: RubrikPolaris.ThreatMonitoring.logicalPath.name description: The name of the logical path. type: String - contextPath: RubrikPolaris.ThreatMonitoring.logicalPath.objectType description: The object type of the logical path. type: String - contextPath: RubrikPolaris.ThreatMonitoring.logicalPath.__typename description: The type name of the logical path. type: String - contextPath: RubrikPolaris.ThreatMonitoring.physicalPath.fid description: The FID of the physical path. type: String - contextPath: RubrikPolaris.ThreatMonitoring.physicalPath.name description: The name of the physical path. type: String - contextPath: RubrikPolaris.ThreatMonitoring.physicalPath.objectType description: The object type of the physical path. type: String - contextPath: RubrikPolaris.ThreatMonitoring.physicalPath.__typename description: The type name of the physical path. type: String - contextPath: RubrikPolaris.ThreatMonitoring.numWorkloadDescendants description: The number of workload descendants. type: Integer - contextPath: RubrikPolaris.ThreatMonitoring.allOrgs.id description: The ID of the organization. type: String - contextPath: RubrikPolaris.ThreatMonitoring.allOrgs.name description: The name of the organization. type: String - contextPath: RubrikPolaris.ThreatMonitoring.allOrgs.description description: The description of the organization. type: String - contextPath: RubrikPolaris.ThreatMonitoring.allOrgs.mfaStatus description: The MFA status of the organization. type: String - contextPath: RubrikPolaris.ThreatMonitoring.allOrgs.allUrls description: The all URLs of the organization. type: String - contextPath: RubrikPolaris.ThreatMonitoring.allOrgs.__typename description: The type name of the organization. type: String - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.lowSensitiveHits description: The low sensitive hits of the security metadata. type: Integer - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.mediumSensitiveHits description: The medium sensitive hits of the security metadata. type: Integer - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.highSensitiveHits description: The high sensitive hits of the security metadata. type: Integer - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.sensitivityStatus description: The sensitivity status of the security metadata. type: String - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.isLaminarEnabled description: A flag indicating whether laminar is enabled for the security metadata. type: Boolean - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.dataTypeResults.id description: The ID of the data type result. type: String - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.dataTypeResults.name description: The name of the data type result. type: String - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.dataTypeResults.totalHits description: The total hits of the data type result. type: Integer - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.dataTypeResults.totalViolatedHits description: The total violated hits of the data type result. type: Integer - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.dataTypeResults.__typename description: The type name of the data type result. type: String - contextPath: RubrikPolaris.ThreatMonitoring.securityMetadata.__typename description: The type name of the security metadata. type: String - contextPath: RubrikPolaris.ThreatMonitoring.__typename description: The type name of the threat monitoring data. type: String - name: rubrik-threat-monitoring-matched-file-list description: List the matched files for the Threat Monitoring object. arguments: - name: object_id description: "The object ID for the threat monitoring object.\n\nNote: Users can retrieve the object ID by executing the \"rubrik-threat-monitoring-matched-object-list\" command." required: true - name: file_name description: Filter files by their name. Supports partial matches. - name: limit description: Number of results to retrieve in the response. The maximum allowed size is 1000. defaultValue: 50 - name: next_page_token description: The next page cursor to retrieve the next set of results. outputs: - contextPath: RubrikPolaris.ThreatMonitoringFile.filepath description: The full path of the matched file. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.detectedTime description: The timestamp when the file was detected. type: Date - contextPath: RubrikPolaris.ThreatMonitoringFile.fileName description: The name of the matched file. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.fileSize description: The size of the matched file in bytes. type: Number - contextPath: RubrikPolaris.ThreatMonitoringFile.matchedSnapshotDate description: The date of the snapshot where the match occurred. type: Date - contextPath: RubrikPolaris.ThreatMonitoringFile.matchedSnapshotFid description: The FID of the snapshot where the match occurred. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.isMatchedSnapshotExpired description: A flag indicating whether the matched snapshot has expired. type: Boolean - contextPath: RubrikPolaris.ThreatMonitoringFile.isFirstObservedSnapshotExpired description: A flag indicating whether the first observed snapshot has expired. type: Boolean - contextPath: RubrikPolaris.ThreatMonitoringFile.matchType description: The type of indicator match. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.isQuarantinedInFirstObservedSnapshot description: A flag indicating whether the file is quarantined in the first observed snapshot. type: Boolean - contextPath: RubrikPolaris.ThreatMonitoringFile.objectFid description: The FID of the associated object. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.firstObservedSnapshotFid description: The FID of the first observed snapshot. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.firstObservedSnapshotDate description: The date of the first observed snapshot. type: Date - contextPath: RubrikPolaris.ThreatMonitoringFile.objectType description: The type of the associated object. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.objectName description: The name of the associated object. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.matchId description: The ID of the match event. type: Number - contextPath: RubrikPolaris.ThreatMonitoringFile.__typename description: The GraphQL typename of the file match object. type: String - contextPath: RubrikPolaris.PageToken.ThreatMonitoringFile.endCursor description: The end cursor of the threat monitoring file data. type: String - contextPath: RubrikPolaris.PageToken.ThreatMonitoringFile.hasNextPage description: A flag indicating if there is a next page of threat monitoring file data. type: Boolean - contextPath: RubrikPolaris.PageToken.ThreatMonitoringFile.hasPreviousPage description: A flag indicating if there is a previous page of threat monitoring file data. type: Boolean - contextPath: RubrikPolaris.PageToken.ThreatMonitoringFile.name description: The name of the threat monitoring file data. type: String - contextPath: RubrikPolaris.PageToken.ThreatMonitoringFile.total_matched_count description: The total number of matched files. type: Number - contextPath: RubrikPolaris.PageToken.ThreatMonitoringFile.startCursor description: The start cursor of the threat monitoring file data. type: String - name: rubrik-threat-monitoring-matched-file-get description: Get the matched file for the Threat Monitoring object. arguments: - name: matched_snapshot_id description: "ID of the snapshot where the threat monitoring match was found.\n\nNote: Users can retrieve the matched snapshot ID by executing the \"rubrik-threat-monitoring-matched-file-list\" command." required: true - name: file_path description: "Path of the file.\n\nNote: Users can retrieve the file path by executing the \"rubrik-threat-monitoring-matched-file-list\" command." required: true outputs: - contextPath: RubrikPolaris.ThreatMonitoringFile.matchedFileMd5 description: The MD5 hash of the matched file. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.matchedFileSha1 description: The SHA1 hash of the matched file. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.matchedFileSha256 description: The SHA256 hash of the matched file. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.iocDetails.matchType description: The type of IOC match. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.iocDetails.intelFeedName description: The name of the intelligence feed that provided the IOC. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.iocDetails.malwareName description: The name of the malware associated with the IOC. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.iocDetails.iocRuleAuthor description: The author of the IOC rule. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.iocDetails.malwareDescription description: The description of the malware associated with the IOC. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.iocDetails.iocHashHex description: The hash value of the IOC in hexadecimal format. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.iocDetails.iocStatus description: The status of the IOC. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.iocDetails.__typename description: The GraphQL typename of the IOC details. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.isQuarantinedInFirstObservedSnapshot description: A flag indicating whether the file was quarantined in the first observed snapshot. type: Boolean - contextPath: RubrikPolaris.ThreatMonitoringFile.detectedSnapshotDate description: The date when the file was detected in the snapshot. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.firstDetectedSnapshotFid description: The ID of the first snapshot where the file was detected. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.filePath description: The full path of the file. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.fileName description: The name of the file. type: String - contextPath: RubrikPolaris.ThreatMonitoringFile.__typename description: The GraphQL typename of the threat monitoring file. type: String - name: rubrik-ioc-scan-list-v2 description: List details of the Turbo and Advance Threat Hunt. arguments: - name: cluster_id description: "The ID of the cluster whose IOC scans are to be listed. Supports comma separated values.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." isArray: true - name: ioc_match description: Filter hunts on any matches. auto: PREDEFINED predefined: - MATCHES_FOUND - NO_MATCHES - UNSCANNED - name: hunt_status description: Filter by hunt status. auto: PREDEFINED predefined: - ABORTED - CANCELED - CANCELING - FAILED - IN_PROGRESS - PARTIALLY_SUCCEEDED - PENDING - SUCCEEDED - name: quarantine_status description: Filter by quarantine matches. auto: PREDEFINED predefined: - QUARANTINED_MATCHES - NO_QUARANTINED_MATCHES - name: start_time description: "Filter the threat hunts that started after this time.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 June 2025, 01 June 2025 04:45:33, 2025-06-17T14:05:44Z." defaultValue: "7 days" - name: end_time description: "Filter the threat hunts that ended before this time.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 June 2025, 01 June 2025 04:45:33, 2025-06-17T14:05:44Z." - name: limit description: Number of results to retrieve in the response. The maximum allowed size is 1000. defaultValue: 50 - name: next_page_token description: The next page cursor to retrieve the next set of results. outputs: - contextPath: RubrikPolaris.IOCScan.huntId description: The unique identifier for the threat hunt. type: string - contextPath: RubrikPolaris.IOCScan.name description: The name of the threat hunt. type: string - contextPath: RubrikPolaris.IOCScan.createdBy.id description: The ID of the user who initiated the hunt. type: string - contextPath: RubrikPolaris.IOCScan.createdBy.username description: The username of the user who initiated the hunt. type: string - contextPath: RubrikPolaris.IOCScan.createdBy.email description: The email of the user who initiated the hunt. type: string - contextPath: RubrikPolaris.IOCScan.createdBy.__typename description: The GraphQL typename of the user object. type: string - contextPath: RubrikPolaris.IOCScan.huntType description: The type of the threat hunt. type: string - contextPath: RubrikPolaris.IOCScan.startTime description: The start time of the threat hunt. type: date - contextPath: RubrikPolaris.IOCScan.status description: The current status of the threat hunt. type: string - contextPath: RubrikPolaris.IOCScan.stats.totalProcessedSnapshots description: The total number of processed snapshots. type: number - contextPath: RubrikPolaris.IOCScan.stats.totalAffectedObjects description: The total number of affected objects. type: number - contextPath: RubrikPolaris.IOCScan.stats.totalAffectedSnapshots description: The total number of affected snapshots. type: number - contextPath: RubrikPolaris.IOCScan.stats.totalUniqueMatchedPaths description: The total number of unique matched file paths. type: number - contextPath: RubrikPolaris.IOCScan.stats.totalSucceededScans description: The total number of successful scans. type: number - contextPath: RubrikPolaris.IOCScan.stats.totalSnapshotsScanned description: The total number of snapshots scanned. type: number - contextPath: RubrikPolaris.IOCScan.stats.totalUniqueQuarantinedPaths description: The total number of unique quarantined file paths. type: number - contextPath: RubrikPolaris.IOCScan.stats.totalObjectsScanned description: The total number of objects scanned. type: number - contextPath: RubrikPolaris.IOCScan.stats.totalIocs description: The total number of IOCs used in the scan. type: number - contextPath: RubrikPolaris.IOCScan.stats.__typename description: The GraphQL typename of the stats object. type: string - contextPath: RubrikPolaris.IOCScan.huntDetails.startTime description: The start time of the detailed threat hunt process. type: date - contextPath: RubrikPolaris.IOCScan.huntDetails.endTime description: The end time of the detailed threat hunt process. type: date - contextPath: RubrikPolaris.IOCScan.huntDetails.cluster.id description: The ID of the cluster used in the hunt. type: string - contextPath: RubrikPolaris.IOCScan.huntDetails.cluster.name description: The name of the cluster used in the hunt. type: string - contextPath: RubrikPolaris.IOCScan.huntDetails.cluster.__typename description: The GraphQL typename of the cluster object. type: string - contextPath: RubrikPolaris.IOCScan.huntDetails.config.name description: The name of the configuration used in the hunt. type: string - contextPath: RubrikPolaris.IOCScan.huntDetails.config.indicatorsOfCompromise description: The list of indicators of compromise. type: unknown - contextPath: RubrikPolaris.IOCScan.huntDetails.config.__typename description: The GraphQL typename of the hunt config object. type: string - contextPath: RubrikPolaris.IOCScan.huntDetails.__typename description: The GraphQL typename of the hunt details object. type: string - contextPath: RubrikPolaris.IOCScan.__typename description: The GraphQL typename of the top-level threat hunt object. type: string - contextPath: RubrikPolaris.PageToken.IOCScan.endCursor description: The end cursor of the IOC scan data. type: string - contextPath: RubrikPolaris.PageToken.IOCScan.hasNextPage description: A flag indicating if there is a next page of IOC scan data. type: boolean - contextPath: RubrikPolaris.PageToken.IOCScan.hasPreviousPage description: A flag indicating if there is a previous page of IOC scan data. type: boolean - contextPath: RubrikPolaris.PageToken.IOCScan.name description: The name of the IOC scan data. type: string - contextPath: RubrikPolaris.PageToken.IOCScan.startCursor description: The start cursor of the IOC scan data. type: string - contextPath: RubrikPolaris.PageToken.IOCScan.total_matched_count description: The total number of matched IOC scans. type: number - name: rubrik-ioc-scan-results-v2 description: Retrieve details of the Turbo and Advance Threat Hunt. arguments: - name: hunt_id description: "The ID of the threat hunt.\n\nNote: Users can retrieve the hunt ID by executing the \"rubrik-ioc-scan-list-v2\" command." required: true outputs: - contextPath: RubrikPolaris.IOCScan.hunt_id description: The ID of the threat hunt. type: string - contextPath: RubrikPolaris.IOCScan.totalObjectFids description: The total number of object FIDs involved in the threat hunt. type: number - contextPath: RubrikPolaris.IOCScan.startTime description: The start time of the threat hunt. type: date - contextPath: RubrikPolaris.IOCScan.endTime description: The end time of the threat hunt. type: date - contextPath: RubrikPolaris.IOCScan.status description: The current status of the threat hunt. type: string - contextPath: RubrikPolaris.IOCScan.totalMatchedSnapshots description: The total number of matched snapshots. type: number - contextPath: RubrikPolaris.IOCScan.totalScannedSnapshots description: The total number of scanned snapshots. type: number - contextPath: RubrikPolaris.IOCScan.totalUniqueFileMatches description: The total number of unique file matches. type: number - contextPath: RubrikPolaris.IOCScan.clusters.id description: The ID of the cluster. type: string - contextPath: RubrikPolaris.IOCScan.clusters.name description: The name of the cluster. type: string - contextPath: RubrikPolaris.IOCScan.clusters.type description: The type of the cluster. type: string - contextPath: RubrikPolaris.IOCScan.clusters.__typename description: The GraphQL typename of the cluster object. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.name description: The name of the base configuration used in the threat hunt. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.notes description: The notes added to the hunt configuration. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.maxMatchesPerSnapshot description: The maximum number of matches allowed per snapshot. type: number - contextPath: RubrikPolaris.IOCScan.baseConfig.threatHuntType description: The type of the threat hunt. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.__typename description: The GraphQL typename of the base configuration object. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.ioc.__typename description: The GraphQL typename of the IOC object. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.ioc.iocList.__typename description: The GraphQL typename of the IOC list container. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.ioc.iocList.indicatorsOfCompromise.iocKind description: The type of IOC. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.ioc.iocList.indicatorsOfCompromise.iocValue description: The value of the IOC indicator. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.ioc.iocList.indicatorsOfCompromise.__typename description: The GraphQL typename of the IOC indicator. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.snapshotScanLimit.__typename description: The GraphQL typename of the snapshot scan limit object. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.snapshotScanLimit.scanLimit.__typename description: The GraphQL typename of the scan limit configuration. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.snapshotScanLimit.scanLimit.scanConfig.maxSnapshotsPerObject description: The maximum snapshots to scan per object. type: number - contextPath: RubrikPolaris.IOCScan.baseConfig.snapshotScanLimit.scanLimit.scanConfig.startTime description: The start time for the snapshot scan window. type: date - contextPath: RubrikPolaris.IOCScan.baseConfig.snapshotScanLimit.scanLimit.scanConfig.endTime description: The end time for the snapshot scan window. type: date - contextPath: RubrikPolaris.IOCScan.baseConfig.snapshotScanLimit.scanLimit.scanConfig.__typename description: The GraphQL typename of the scan limit configuration. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.snapshotScanLimit.scanLimit.objectSnapshotConfig description: An object snapshot configuration. type: string - contextPath: RubrikPolaris.IOCScan.baseConfig.fileScanCriteria description: A file scan criteria. type: string - contextPath: RubrikPolaris.IOCScan.threatHuntObjectMetrics.totalObjectsScanned description: The total number of objects scanned during the hunt. type: number - contextPath: RubrikPolaris.IOCScan.threatHuntObjectMetrics.totalAffectedObjects description: The total number of affected objects. type: number - contextPath: RubrikPolaris.IOCScan.threatHuntObjectMetrics.totalUnaffectedObjects description: The total number of unaffected objects. type: number - contextPath: RubrikPolaris.IOCScan.threatHuntObjectMetrics.totalObjectsUnscannable description: The total number of objects that couldn't be scanned. type: number - contextPath: RubrikPolaris.IOCScan.threatHuntObjectMetrics.unaffectedObjectsFromDb description: The number of clean objects retrieved from the database. type: number - contextPath: RubrikPolaris.IOCScan.threatHuntObjectMetrics.cleanRecoverableObjectLimit description: The maximum number of clean recoverable objects allowed. type: number - contextPath: RubrikPolaris.IOCScan.threatHuntObjectMetrics.__typename description: The GraphQL typename of the object metrics reply. type: string - contextPath: RubrikPolaris.IOCScan.__typename description: The GraphQL typename of the root hunt details object. type: string - name: rubrik-turbo-ioc-scan description: Start a new turbo threat hunt. arguments: - name: ioc description: "The value of the indicator to scan for. Supports comma separated values.\n\nNote: Users can retrieve the Md5, SHA1 or SHA256 by executing the \"rubrik-threat-monitoring-matched-file-get\" command." required: true isArray: true - name: scan_name description: Name of the new turbo threat hunt scan. defaultValue: "PAXSOAR-1.6.0" - name: cluster_id description: "The ID of the cluster on which to perform a scan. If not provided, all the clusters will be scanned.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." isArray: true - name: start_time description: "Filter the snapshots from the provided date. Any snapshots taken before the provided date-time will be excluded.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc.\n\nFor example: 01 June 2025, 01 June 2025 04:45:33, 2025-06-17T14:05:44Z." - name: end_time description: "Filter the snapshots until the provided date. Any snapshots taken after the provided date-time will be excluded.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc.\n\nFor example: 01 June 2025, 01 June 2025 04:45:33, 2025-06-17T14:05:44Z." - name: max_snapshots_per_object description: Maximum number of snapshots to scan per object. outputs: - contextPath: RubrikPolaris.TurboIOCScan.huntId description: The ID of the new turbo threat hunt. type: String - contextPath: RubrikPolaris.TurboIOCScan.__typename description: The type of the new turbo threat hunt. type: String - name: rubrik-advance-ioc-scan description: Start a new advance threat hunt. arguments: - name: object_id description: "The Object ID of the system on which to perform the scan. Supports comma separated values.\n\nNote: Users can get the list of object IDs by executing the \"rubrik-polaris-object-list\" command." required: true isArray: true - name: ioc_type description: "The type of the indicator to scan.\n\nNote: To provide multiple IOCs use the argument \"advance_ioc\"." auto: PREDEFINED predefined: - INDICATOR_OF_COMPROMISE_TYPE_PATH_OR_FILENAME - INDICATOR_OF_COMPROMISE_TYPE_HASH - INDICATOR_OF_COMPROMISE_TYPE_YARA_RULE - name: ioc_value description: "The value of the indicator to scan.\n\nNote: To provide multiple IOCs use the argument \"advance_ioc\"." - name: scan_name description: Name of the new advanced threat hunt scan. defaultValue: PAXSOAR-1.6.0 - name: advance_ioc description: "Json encoded Indicators Of Compromise to scan. Json keys signify the type of IOC and the corresponding list of values are the values of the IOC's. If provided, will ignore the ioc_type and ioc_value arguments.\n\nPossible keys to indicate type of indicator: \nINDICATOR_OF_COMPROMISE_TYPE_PATH_OR_FILENAME, INDICATOR_OF_COMPROMISE_TYPE_HASH, INDICATOR_OF_COMPROMISE_TYPE_YARA_RULE\n\nFormat Accepted:\n{\n\"\": [\"\", \"\"],\n\"\": \"\"\n}\n\nExample:\n{\n\"INDICATOR_OF_COMPROMISE_TYPE_PATH_OR_FILENAME\": [\"C:\\\\Users\\\\Malware_Executible.ps1\", \"\\\\bin\\\\Malware_Executible\"],\n\"INDICATOR_OF_COMPROMISE_TYPE_HASH\": [\"e5c1b9c44be582f895eaea3d3738c5b4\", \"f541b9844be897f895eaea3d3738cfb2\"],\n\"INDICATOR_OF_COMPROMISE_TYPE_YARA_RULE\": \"rule match_everything {condition:true}\"\n}." - name: max_matches_per_snapshot description: Maximum number of IOC matches allowed per snapshot. - name: start_date description: "Filter the snapshots from the provided date. Any snapshots taken before the provided date-time will be excluded.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc.\n\nFor example: 01 June 2025, 01 June 2025 04:45:33, 2025-06-17T14:05:44Z." - name: end_date description: "Filter the snapshots until the provided date. Any snapshots taken after the provided date-time will be excluded.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ, etc.\n\nFor example: 01 June 2025, 01 June 2025 04:45:33, 2025-06-17T14:05:44Z." - name: max_snapshots_per_object description: Maximum number of snapshots to scan per object. - name: min_file_size description: Minimum size of the file in bytes that will be included in the scan. - name: max_file_size description: Maximum size of the file in bytes that will be included in the scan. - name: paths_to_include description: "Paths to include in the scan. Supports comma separated values.\n\nFormat accepted: \"path_to_include_1, path_to_include_2\"." isArray: true - name: paths_to_exclude description: "Paths to exclude from the scan. Supports comma separated values.\n\nFormat accepted: \"path_to_exclude_1, path_to_exclude_2\"." isArray: true - name: paths_to_exempt description: "Paths to exempt from exclusion. Supports comma separated values.\n\nFormat accepted: \"path_to_exempt_1, path_to_exempt_2\"." isArray: true outputs: - contextPath: RubrikPolaris.AdvanceIOCScan.huntId description: The ID of the new advance threat hunt. type: string - contextPath: RubrikPolaris.AdvanceIOCScan.huntName description: The name or label of the advanced threat hunt. type: string - contextPath: RubrikPolaris.AdvanceIOCScan.config.huntType description: The type of threat hunt configuration. type: string - contextPath: RubrikPolaris.AdvanceIOCScan.config.clusterUuids description: The list of cluster UUIDs included in the hunt config. type: unknown - contextPath: RubrikPolaris.AdvanceIOCScan.config.objectFids description: The list of object FIDs targeted by the hunt. type: unknown - contextPath: RubrikPolaris.AdvanceIOCScan.config.__typename description: The GraphQL typename for the HuntConfig object. type: string - contextPath: RubrikPolaris.AdvanceIOCScan.status description: The status of the threat hunt execution. type: string - contextPath: RubrikPolaris.AdvanceIOCScan.__typename description: The GraphQL typename for the HuntResponse object. type: string - arguments: - description: "The unique ID of the cluster.\n\nNote: Users can retrieve the list of the cluster IDs by executing the \"rubrik-gps-cluster-list\" command." name: cluster_id required: true - description: "The CDM snapshot ID.\n\nNote: Use the \"rubrik-radar-suspicious-file-list\" command to retrieve the actual CDM ID from the Anomaly ID.\nExample format to get the snapshot CDM ID from Anomaly ID: \":::VirtualMachine::::::\"." name: snapshot_id required: true - description: "The VM object ID (Snappable ID).\n\nNote: Users can retrieve the list of Snappable IDs by executing the \"rubrik-polaris-vm-objects-list\" command.\nExample format to get the Snappable ID: \"VirtualMachine:::\"." name: object_id required: true - name: polling description: "Whether to poll for the command." required: false hidden: true description: Request for the analysis and directly download the anomaly CSV analyzed file. name: rubrik-anomaly-csv-analysis-v2 polling: true outputs: - contextPath: RubrikPolaris.AnomalyCSVv2.clusterId description: The ID of the cluster. type: String - contextPath: RubrikPolaris.AnomalyCSVv2.snapshotId description: The ID of the snapshot. type: String - contextPath: RubrikPolaris.AnomalyCSVv2.objectId description: The ID of the object. type: String - contextPath: RubrikPolaris.AnomalyCSVv2.externalId description: The external ID of the CSV file. type: String - contextPath: RubrikPolaris.AnomalyCSVv2.isSuccessful description: Whether the CSV analysis was successful or not. type: Boolean - contextPath: InfoFile.Name description: FileName. type: string - contextPath: InfoFile.EntryID description: The EntryID of the report. type: string - contextPath: InfoFile.Size description: File Size. type: number - contextPath: InfoFile.Type description: File type e.g. "PE". type: string - contextPath: InfoFile.Info description: Basic information of the file. type: string - name: rubrik-data-security-violation-list description: Retrieve the list of DSPM violations. arguments: - name: object_type description: "Filter the violations based on object types. Supports comma separated values.\n\nNote: Values not included in the options can be found in the documentation." auto: PREDEFINED predefined: - AWS_NATIVE_DYNAMODB_TABLE - AWS_NATIVE_EBS_VOLUME - AWS_NATIVE_RDS_INSTANCE - AWS_NATIVE_S3_BUCKET - AZURE_MANAGED_DISK - AZURE_SQL_DATABASE_DB - AZURE_SQL_MANAGED_INSTANCE_DB - AZURE_STORAGE_ACCOUNT - AZURE_VIRTUAL_MACHINE - GCP_NATIVE_DISK - GCP_NATIVE_GCE_INSTANCE - HYPERV_VIRTUAL_MACHINE - K8S_PROTECTION_SET - K8S_VIRTUAL_MACHINE - LINUX_FILESET - NAS_FILESET - NUTANIX_VIRTUAL_MACHINE - O365_ONEDRIVE - O365_SITE - ORACLE_DATA_GUARD_GROUP - ORACLE_DATABASE - SHARE_FILESET - VOLUME_GROUP - VSPHERE_VIRTUAL_MACHINE - WINDOWS_FILESET isArray: true - name: detection_start_date description: "Filter the violations detected after this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: detection_start_date and detection_end_date both or none of them should be initialized." - name: detection_end_date description: "Filter the violations detected before this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: detection_start_date and detection_end_date both or none of them should be initialized." - name: resolved_start_date description: "Filter the violations resolved after this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: resolved_start_date and resolved_end_date both or none of them should be initialized." - name: resolved_end_date description: "Filter the violations resolved before this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: resolved_start_date and resolved_end_date both or none of them should be initialized." - name: category description: "Filter the violations by category. Supports comma separated values." auto: PREDEFINED predefined: - CATEGORY_UNSPECIFIED - MISPLACED - REDUNDANT - OVEREXPOSED - UNPROTECTED isArray: true - name: status description: "Filter the violations by status. Supports comma separated values." auto: PREDEFINED predefined: - OPEN - IN_PROGRESS - REMEDIATED - DISMISSED - CLOSED isArray: true - name: severity description: "Filter the violations by severity level. Supports comma separated values." auto: PREDEFINED predefined: - SEVERITY_UNSPECIFIED - LOW - MEDIUM - HIGH - CRITICAL isArray: true - name: sensitivity description: "Filter the violations by sensitivity level. Supports comma separated values." auto: PREDEFINED predefined: - HIGH - MEDIUM - LOW - NO isArray: true - name: limit defaultValue: "50" description: "Number of results to retrieve in the response. The maximum allowed size is 1000." - name: next_page_token description: "The next page cursor to retrieve the next set of results." - name: sort_by defaultValue: "DETECTION_TIME" description: "Specify the field to use for sorting the response." auto: PREDEFINED predefined: - SEVERITY - HITS - DETECTION_TIME - UPDATE_TIME - IDENTITY_TYPE - FILES_AT_RISK - TOTAL_HITS - ACCESSIBLE_OBJECTS - ORIGIN - EVENT_TIME - NAME - TYPE - name: sort_order defaultValue: "DESC" description: "Specify the order to sort the data in." auto: PREDEFINED predefined: - ASC - DESC outputs: - contextPath: RubrikPolaris.DSPMViolation.policyViolationId description: The unique identifier for the policy violation. type: String - contextPath: RubrikPolaris.DSPMViolation.status description: The current status of the policy violation. type: String - contextPath: RubrikPolaris.DSPMViolation.__typename description: The GraphQL typename for the violation object. type: String - contextPath: RubrikPolaris.DSPMViolation.createdAt description: The date and time when the policy violation was created. type: Date - contextPath: RubrikPolaris.DSPMViolation.lastUpdatedAt description: The date and time when the policy violation was last updated. type: Date - contextPath: RubrikPolaris.DSPMViolation.policy.policyId description: The unique identifier of the policy associated with the violation. type: String - contextPath: RubrikPolaris.DSPMViolation.policy.name description: The name of the policy associated with the violation. type: String - contextPath: RubrikPolaris.DSPMViolation.policy.policySeverity description: The severity level assigned to the policy. type: String - contextPath: RubrikPolaris.DSPMViolation.policy.__typename description: The GraphQL typename for the policy object. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceId description: The unique identifier of the resource associated with the violation. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceType description: The type of the resource associated with the violation. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.name description: The name of the resource where the violation occurred. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.objectType description: The object type of the resource. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.platform description: The platform of the resource. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.physicalHost description: The physical host where the resource resides. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.cloudAccountInfo.accountName description: The name of the associated cloud account. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.cloudAccountInfo.__typename description: The GraphQL typename for the cloud account info object. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.__typename description: The GraphQL typename for the resource metadata details object. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.__typename description: The GraphQL typename for the resource metadata object. type: String - contextPath: RubrikPolaris.DSPMViolation.details.dataCategories.id description: The ID of the data category. type: String - contextPath: RubrikPolaris.DSPMViolation.details.dataCategories.name description: The name of the data category. type: String - contextPath: RubrikPolaris.DSPMViolation.details.dataCategories.totalViolatedHits description: The total violated hits of the data category. type: Integer - contextPath: RubrikPolaris.DSPMViolation.details.dataCategories.__typename description: The type name of the data category. type: String - contextPath: RubrikPolaris.DSPMViolation.details.dataTypes.id description: The ID of the data type. type: String - contextPath: RubrikPolaris.DSPMViolation.details.dataTypes.name description: The name of the data type. type: String - contextPath: RubrikPolaris.DSPMViolation.details.dataTypes.totalViolatedHits description: The total violated hits of the data type. type: Integer - contextPath: RubrikPolaris.DSPMViolation.details.dataTypes.__typename description: The type name of the data type. type: String - contextPath: RubrikPolaris.DSPMViolation.details.violatedNoRiskSensitiveHits description: The number of no-risk sensitive hits involved in the violation. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.violatedLowRiskSensitiveHits description: The number of low-risk sensitive hits involved in the violation. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.violatedMediumRiskSensitiveHits description: The number of medium-risk sensitive hits involved in the violation. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.violatedHighRiskSensitiveHits description: The number of high-risk sensitive hits involved in the violation. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.snapshotId description: The ID of the snapshot associated with the violation details. type: String - contextPath: RubrikPolaris.DSPMViolation.details.__typename description: The GraphQL typename for the violation details object. type: String - contextPath: RubrikPolaris.DSPMViolation.remediations.type description: The type of the remediation action. type: String - contextPath: RubrikPolaris.DSPMViolation.remediations.state description: The state of the remediation action. type: String - contextPath: RubrikPolaris.DSPMViolation.remediations.remediationDetails description: Detailed information about the remediation action. type: Unknown - contextPath: RubrikPolaris.DSPMViolation.remediations.__typename description: The GraphQL typename for the remediation object. type: String - contextPath: RubrikPolaris.DSPMViolation.remediations description: The list of remediations associated with the violation. type: Unknown - contextPath: RubrikPolaris.PageToken.DSPMViolation.next_page_token description: Next page token. type: String - contextPath: RubrikPolaris.PageToken.DSPMViolation.name description: Name of the command. type: String - contextPath: RubrikPolaris.PageToken.DSPMViolation.has_next_page description: Whether the result has the next page or not. type: Boolean - arguments: - description: "The ID of the DSPM violation.\n\nNote: Users can get the violation ID by executing the \"rubrik-data-security-violation-list\" command." name: violation_id required: true description: Retrieve the details of DSPM violation based on the provided violation ID. name: rubrik-data-security-violation-get outputs: - contextPath: RubrikPolaris.DSPMViolation.policyViolationId description: The unique identifier for the policy violation. type: String - contextPath: RubrikPolaris.DSPMViolation.status description: The current status of the policy violation. type: String - contextPath: RubrikPolaris.DSPMViolation.__typename description: The GraphQL typename for the violation object. type: String - contextPath: RubrikPolaris.DSPMViolation.createdAt description: The date and time when the policy violation was created. type: Date - contextPath: RubrikPolaris.DSPMViolation.lastUpdatedAt description: The date and time when the policy violation was last updated. type: Date - contextPath: RubrikPolaris.DSPMViolation.policy.policyId description: The unique identifier of the policy associated with the violation. type: String - contextPath: RubrikPolaris.DSPMViolation.policy.name description: The name of the policy associated with the violation. type: String - contextPath: RubrikPolaris.DSPMViolation.policy.policySeverity description: The severity level assigned to the policy. type: String - contextPath: RubrikPolaris.DSPMViolation.policy.__typename description: The GraphQL typename for the policy object. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceId description: The unique identifier of the resource associated with the violation. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.name description: The name of the resource where the violation occurred. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.objectType description: The object type of the resource. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.platform description: The platform of the resource. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.physicalHost description: The physical host where the resource resides. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.cloudAccountInfo.accountName description: The name of the associated cloud account. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.cloudAccountInfo.__typename description: The GraphQL typename for the cloud account info object. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.__typename description: The GraphQL typename for the resource metadata details object. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.clusterInfo.clusterName description: The name of the cluster. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.clusterInfo.clusterUuid description: The UUID of the cluster. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.clusterInfo.__typename description: The GraphQL typename for the cluster info object. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.creationTime description: The creation time of the metadata. type: Number - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.lastAccessTime description: The last access time of the metadata. type: Number - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.snapshotTimestamp description: The snapshot timestamp. type: Number - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.isDeleted description: Whether the resource is deleted. type: Boolean - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.metadata.region description: The region of the resource. type: String - contextPath: RubrikPolaris.DSPMViolation.resourceMetadata.__typename description: The GraphQL typename for the resource metadata object. type: String - contextPath: RubrikPolaris.DSPMViolation.details.violatedNoRiskSensitiveHits description: The number of no-risk sensitive hits involved in the violation. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.violatedLowRiskSensitiveHits description: The number of low-risk sensitive hits involved in the violation. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.violatedMediumRiskSensitiveHits description: The number of medium-risk sensitive hits involved in the violation. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.violatedHighRiskSensitiveHits description: The number of high-risk sensitive hits involved in the violation. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.violatedSensitiveHits description: The total number of violated sensitive hits. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.dataTypes.id description: The ID of the data type. type: String - contextPath: RubrikPolaris.DSPMViolation.details.dataTypes.name description: The name of the data type. type: String - contextPath: RubrikPolaris.DSPMViolation.details.dataTypes.totalViolatedHits description: The total violated hits for the data type. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.dataTypes.__typename description: The GraphQL typename for the data type stats. type: String - contextPath: RubrikPolaris.DSPMViolation.details.mipLabels description: The MIP labels associated with the details. type: Unknown - contextPath: RubrikPolaris.DSPMViolation.details.documentTypes description: The document types associated with the details. type: Unknown - contextPath: RubrikPolaris.DSPMViolation.details.dataCategories.id description: The ID of the data category. type: String - contextPath: RubrikPolaris.DSPMViolation.details.dataCategories.name description: The name of the data category. type: String - contextPath: RubrikPolaris.DSPMViolation.details.dataCategories.totalViolatedHits description: The total violated hits for the data category. type: Number - contextPath: RubrikPolaris.DSPMViolation.details.dataCategories.__typename description: The GraphQL typename for the data category stats. type: String - contextPath: RubrikPolaris.DSPMViolation.details.snapshotId description: The ID of the snapshot associated with the violation details. type: String - contextPath: RubrikPolaris.DSPMViolation.details.__typename description: The GraphQL typename for the violation details object. type: String - contextPath: RubrikPolaris.DSPMViolation.policy.description description: The description of the policy. type: String - contextPath: RubrikPolaris.DSPMViolation.policy.policyCategory description: The category of the policy. type: String - contextPath: RubrikPolaris.DSPMViolation.policy.containsAccessFilters description: Whether the policy contains access filters. type: Boolean - contextPath: RubrikPolaris.DSPMViolation.remediations.state description: The state of the remediation action. type: String - contextPath: RubrikPolaris.DSPMViolation.remediations.remediationId description: The ID of the remediation. type: String - contextPath: RubrikPolaris.DSPMViolation.remediations.remediationDetails description: Detailed information about the remediation action. type: Unknown - contextPath: RubrikPolaris.DSPMViolation.remediations.__typename description: The GraphQL typename for the remediation object. type: String - name: rubrik-data-security-violation-status-update description: Updates the status of the DSPM violation. arguments: - name: violation_id description: "The ID of the DSPM violation.\n\nNote: Users can get the violation ID by executing the \"rubrik-data-security-violation-list\" command." required: true - name: status description: The status to update for violation. required: true auto: PREDEFINED predefined: - OPEN - IN_PROGRESS - REMEDIATED - DISMISSED - CLOSED outputs: - contextPath: RubrikPolaris.DSPMViolation.policyViolationId description: The ID of the violation. type: String - contextPath: RubrikPolaris.DSPMViolation.status description: The status of the violation. type: String - name: rubrik-data-security-violation-file-list description: Retrieve the file information of data security violation based on the provided violation ID. arguments: - name: violation_id description: "The ID of the DSPM violation.\n\nNote: Users can get the violation ID by executing the \"rubrik-data-security-violation-list\" command." required: true - name: snapshot_id description: "The snapshot ID.\n\nNote: Users can get the snapshot ID by executing the \"rubrik-polaris-object-snapshot-list\" command." required: true - name: object_id description: "The object ID.\n\nNote: Users can get the Object ID by executing the \"rubrik-polaris-objects-list\" command." required: true - name: limit description: Number of results to retrieve in the response. The maximum allowed size is 1000. defaultValue: 25 required: false - name: next_page_token description: The next page cursor to retrieve the next set of results. required: false - name: file_name description: Filter files by their name. required: false - name: last_access_start_date description: "Filter files with last access after this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: last_access_start_date and last_access_end_date both or none of them should be initialized." required: false - name: last_access_end_date description: "Filter files with last access before this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: last_access_start_date and last_access_end_date both or none of them should be initialized." required: false - name: last_modified_start_date description: "Filter files with last modified after this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: last_modified_start_date and last_modified_end_date both or none of them should be initialized." required: false - name: last_modified_end_date description: "Filter files with last modified before this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: last_modified_start_date and last_modified_end_date both or none of them should be initialized." required: false - name: creation_start_date description: "Filter files created after this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: creation_date_start_date and creation_date_start_date both or none of them should be initialized." required: false - name: creation_end_date description: "Filter files created before this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: creation_date_start_date and creation_date_start_date both or none of them should be initialized." required: false - name: last_scan_start_date description: "Filter files with last scan after this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: last_scan_start_date and last_scan_end_date both or none of them should be initialized." required: false - name: last_scan_end_date description: "Filter files with last scan before this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: last_scan_start_date and last_scan_end_date both or none of them should be initialized." required: false - name: sensitivity description: Filter files by sensitivity level. Supports comma separated values. auto: PREDEFINED isArray: true predefined: - HIGH - MEDIUM - LOW - NO required: false - name: exposure description: Filter files by exposure type. Supports comma separated values. auto: PREDEFINED isArray: true predefined: - EXPLICIT - INHERITED - NOT_OPEN - PUBLIC required: false - name: access_via description: Filter files by access type. auto: PREDEFINED defaultValue: ACCESS_TYPE_UNSPECIFIED predefined: - ACCESS_TYPE_UNSPECIFIED - DIRECT - GROUP - ROLE required: false - name: sort_order description: Specify the order to sort the data in. auto: PREDEFINED defaultValue: DESC predefined: - ASC - DESC required: false - name: sort_by description: Specify the field to use for sorting the response. defaultValue: HITS auto: PREDEFINED predefined: - CLUSTER - CREATION_TIME - DAILY_CHANGE - DATA_CATEGORY - DATA_TYPE - DOCUMENT_TYPE - EXPOSED_FILES - FILES_WITH_HITS - FILES_WITH_OPEN_ACCESS_HITS - HITS - HITS_BY_SENSITIVITY - LAST_ACCESS_TIME - LAST_MODIFIED - LAST_SCAN_TIME - NAME - NATIVE_PATH - NUM_ACTIVITIES - NUM_ACTIVITIES_DELTA - OBJECT_LOCATION - OBJECT_NAME - OPEN_ACCESS_TYPE - SNAPSHOT_TIME - STALE_FILES_WITH_HITS - TOTAL_SENSITIVE_HITS required: false outputs: - contextPath: Rubrik.DSPMViolationFile.nativePath description: The native path of the file. type: String - contextPath: Rubrik.DSPMViolationFile.stdPath description: The standardized path of the file. type: String - contextPath: Rubrik.DSPMViolationFile.filename description: The name of the file. type: String - contextPath: Rubrik.DSPMViolationFile.mode description: The file mode. type: String - contextPath: Rubrik.DSPMViolationFile.size description: The file size in bytes. type: Number - contextPath: Rubrik.DSPMViolationFile.lastAccessTime description: The last access time of the file. type: Number - contextPath: Rubrik.DSPMViolationFile.lastModifiedTime description: The last modified time of the file. type: Number - contextPath: Rubrik.DSPMViolationFile.creationTime description: The creation time of the file. type: Number - contextPath: Rubrik.DSPMViolationFile.lastScanTime description: The last scan time of the file. type: Number - contextPath: Rubrik.DSPMViolationFile.directory description: The directory of the file. type: String - contextPath: Rubrik.DSPMViolationFile.createdBy description: The user who created the file. type: String - contextPath: Rubrik.DSPMViolationFile.modifiedBy description: The user who last modified the file. type: String - contextPath: Rubrik.DSPMViolationFile.numDescendantFiles description: The number of descendant files. type: Number - contextPath: Rubrik.DSPMViolationFile.numDescendantErrorFiles description: The number of descendant files with errors. type: Number - contextPath: Rubrik.DSPMViolationFile.numDescendantSkippedExtFiles description: The number of descendant files skipped due to extension. type: Number - contextPath: Rubrik.DSPMViolationFile.numDescendantSkippedSizeFiles description: The number of descendant files skipped due to size. type: Number - contextPath: Rubrik.DSPMViolationFile.errorCode description: The error code. type: String - contextPath: Rubrik.DSPMViolationFile.hits.totalHits description: The total number of hits. type: Number - contextPath: Rubrik.DSPMViolationFile.hits.violations description: The number of violations. type: Number - contextPath: Rubrik.DSPMViolationFile.hits.violationsDelta description: The change in the number of violations. type: Number - contextPath: Rubrik.DSPMViolationFile.hits.totalHitsDelta description: The change in the total number of hits. type: Number - contextPath: Rubrik.DSPMViolationFile.hits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.filesWithHits.totalHits description: The total number of hits in files. type: Number - contextPath: Rubrik.DSPMViolationFile.filesWithHits.violations description: The number of violations in files. type: Number - contextPath: Rubrik.DSPMViolationFile.filesWithHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.openAccessFilesWithHits.totalHits description: The total number of hits in open access files. type: Number - contextPath: Rubrik.DSPMViolationFile.openAccessFilesWithHits.violations description: The number of violations in open access files. type: Number - contextPath: Rubrik.DSPMViolationFile.openAccessFilesWithHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.staleFilesWithHits.totalHits description: The total number of hits in stale files. type: Number - contextPath: Rubrik.DSPMViolationFile.staleFilesWithHits.violations description: The number of violations in stale files. type: Number - contextPath: Rubrik.DSPMViolationFile.staleFilesWithHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerGroup.groupType description: The type of the analyzer group. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerGroup.id description: The ID of the analyzer group. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerGroup.name description: The name of the analyzer group. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerGroup.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerResults.hits.totalHits description: The total number of hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerResults.hits.violations description: The number of violations. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerResults.hits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerResults.analyzer.id description: The ID of the analyzer. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerResults.analyzer.name description: The name of the analyzer. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerResults.analyzer.analyzerType description: The type of the analyzer. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerResults.analyzer.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.analyzerResults.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.hits.totalHits description: The total number of hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.hits.violations description: The number of violations. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.hits.violationsDelta description: The change in the number of violations. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.hits.totalHitsDelta description: The change in the total number of hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.hits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerGroupResults.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.highRiskFileCount.totalCount description: The total count of high risk files. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.highRiskFileCount.violatedCount description: The count of high risk files with violations. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.highRiskFileCount.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.mediumRiskFileCount.totalCount description: The total count of medium risk files. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.mediumRiskFileCount.violatedCount description: The count of medium risk files with violations. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.mediumRiskFileCount.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.lowRiskFileCount.totalCount description: The total count of low risk files. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.lowRiskFileCount.violatedCount description: The count of low risk files with violations. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.lowRiskFileCount.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.noRiskFileCount description: The count of files with no risk. type: Unknown - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.totalFileCount.totalCount description: The total count of files. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.totalFileCount.violatedCount description: The count of files with violations. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.totalFileCount.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.sensitiveFiles.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.highRiskHits.totalHits description: The total number of high risk hits. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.highRiskHits.violatedHits description: The number of violated high risk hits. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.highRiskHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.mediumRiskHits.totalHits description: The total number of medium risk hits. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.mediumRiskHits.violatedHits description: The number of violated medium risk hits. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.mediumRiskHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.lowRiskHits.totalHits description: The total number of low risk hits. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.lowRiskHits.violatedHits description: The number of violated low risk hits. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.lowRiskHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.noRiskHits.totalHits description: The total number of no risk hits. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.noRiskHits.violatedHits description: The number of violated no risk hits. type: Number - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.noRiskHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.sensitiveHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.highRiskHits.totalHits description: The total number of high risk analyzer hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.highRiskHits.violatedHits description: The number of violated high risk analyzer hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.highRiskHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.mediumRiskHits.totalHits description: The total number of medium risk analyzer hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.mediumRiskHits.violatedHits description: The number of violated medium risk analyzer hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.mediumRiskHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.lowRiskHits.totalHits description: The total number of low risk analyzer hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.lowRiskHits.violatedHits description: The number of violated low risk analyzer hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.lowRiskHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.noRiskHits.totalHits description: The total number of no risk analyzer hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.noRiskHits.violatedHits description: The number of violated no risk analyzer hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.noRiskHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerRiskHits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerResults.hits.totalHits description: The total number of hits. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerResults.hits.violations description: The number of violations. type: Number - contextPath: Rubrik.DSPMViolationFile.analyzerResults.hits.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerResults.analyzer.id description: The ID of the analyzer. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerResults.analyzer.name description: The name of the analyzer. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerResults.analyzer.analyzerType description: The type of the analyzer. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerResults.analyzer.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.analyzerResults.__typename description: The GraphQL type name. type: String - contextPath: Rubrik.DSPMViolationFile.openAccessType description: The open access type. type: String - contextPath: Rubrik.DSPMViolationFile.stalenessType description: The staleness type. type: String - contextPath: Rubrik.DSPMViolationFile.numActivities description: The number of activities. type: Number - contextPath: Rubrik.DSPMViolationFile.numActivitiesDelta description: The change in the number of activities. type: Number - contextPath: Rubrik.DSPMViolationFile.exposureSummary description: The exposure summary. type: Unknown - contextPath: Rubrik.DSPMViolationFile.dbEntityType description: The database entity type. type: String - contextPath: Rubrik.DSPMViolationFile.mipLabelsSummary description: The MIP labels summary. type: Unknown - contextPath: Rubrik.DSPMViolationFile.documentTypesSummary description: The document types summary. type: Unknown - contextPath: Rubrik.DSPMViolationFile.__typename description: The GraphQL type name. type: String - name: rubrik-data-security-violation-csv-download description: Download all files at risk as CSV file for the specified data security violation. arguments: - name: violation_id description: "The ID of the DSPM violation.\n\nNote: Users can get the violation ID by executing the \"rubrik-data-security-violation-list\" command." required: true - name: snapshot_id description: "The snapshot ID.\n\nNote: Users can retrieve the snapshot ID by executing the \"rubrik-polaris-object-snapshot-list\" command." required: true - name: object_id description: "The object ID.\n\nNote: Users can retrieve the object ID by executing the \"rubrik-polaris-objects-list\" command." required: true - name: object_name description: "The object Name.\n\nNote: If not specified command will retrieve it using the \"rubrik-data-security-violation-get\" command." - name: polling description: "Whether to poll for the command." required: false hidden: true polling: true outputs: - contextPath: RubrikPolaris.DSPMViolationCSVDownload.violationId description: The ID of the violation. type: String - contextPath: RubrikPolaris.DSPMViolationCSVDownload.snapshotId description: The ID of the snapshot. type: String - contextPath: RubrikPolaris.DSPMViolationCSVDownload.objectId description: The ID of the object. type: String - contextPath: RubrikPolaris.DSPMViolationCSVDownload.objectName description: The Name of the object. type: String - contextPath: RubrikPolaris.DSPMViolationCSVDownload.externalId description: The external ID of the CSV file. type: String - contextPath: RubrikPolaris.DSPMViolationCSVDownload.isSuccessful description: Whether the CSV analysis was successful or not. type: Boolean - contextPath: InfoFile.Name description: FileName. type: string - contextPath: InfoFile.EntryID description: The EntryID of the report. type: string - contextPath: InfoFile.Size description: File Size. type: number - contextPath: InfoFile.Type description: File type e.g. "PE". type: string - contextPath: InfoFile.Info description: Basic information of the file. type: string - name: rubrik-data-security-violation-log-download description: Download remediation logs as CSV file for the specified data security violation. arguments: - name: violation_id description: "The ID of the DSPM violation.\n\nNote: Users can get the violation ID by executing the \"rubrik-data-security-violation-list\" command." required: true - name: object_id description: "The object ID.\n\nNote: Users can retrieve the object ID by executing the \"rubrik-polaris-objects-list\" command." required: true - name: object_name description: "The object Name.\n\nNote: If not specified command will retrieve it using the \"rubrik-data-security-violation-get\" command." - name: polling description: "Whether to poll for the command." required: false hidden: true polling: true outputs: - contextPath: RubrikPolaris.DSPMViolationRemediationLogDownload.violationId description: The ID of the violation. type: String - contextPath: RubrikPolaris.DSPMViolationRemediationLogDownload.objectId description: The ID of the object. type: String - contextPath: RubrikPolaris.DSPMViolationRemediationLogDownload.remediationId description: The ID of the remediation. type: String - contextPath: RubrikPolaris.DSPMViolationRemediationLogDownload.objectName description: The Name of the object. type: String - contextPath: RubrikPolaris.DSPMViolationRemediationLogDownload.externalId description: The external ID of the file. type: String - contextPath: RubrikPolaris.DSPMViolationRemediationLogDownload.isSuccessful description: Whether the command was successful or not. type: Boolean - contextPath: InfoFile.Name description: FileName. type: string - contextPath: InfoFile.EntryID description: The EntryID of the report. type: string - contextPath: InfoFile.Size description: File Size. type: number - contextPath: InfoFile.Type description: File type e.g. "PE". type: string - contextPath: InfoFile.Info description: Basic information of the file. type: string - name: rubrik-identity-resilience-violation-list description: Retrieves the list of Identity Resilience (IR) violations. arguments: - name: policy_type description: Filter the violations by policy type. Supports comma separated values. auto: PREDEFINED predefined: - IDENTITY - IDP - IDENTITY_EVENT - CROWDSTRIKE - MICROSOFT_DEFENDER isArray: true - name: detection_start_date description: "Filter the violations detected after this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: detection_start_date and detection_end_date both or none of them should be initialized." - name: detection_end_date description: "Filter the violations detected before this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: detection_start_date and detection_end_date both or none of them should be initialized." - name: resolved_start_date description: "Filter the violations resolved after this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: resolved_start_date and resolved_end_date both or none of them should be initialized." - name: resolved_end_date description: "Filter the violations resolved before this date.\n\nFormats accepted: 2 minutes, 2 hours, 2 days, 2 weeks, 2 months, 2 years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ.\n\nFor example: 01 Jan 2026, 01 Jan 2026 04:45:33, 2026-01-01T14:05:44Z.\n\nNote: resolved_start_date and resolved_end_date both or none of them should be initialized." - name: category description: Filter the violations by category. Supports comma separated values. auto: PREDEFINED predefined: - CATEGORY_UNSPECIFIED - AUTHENTICATION_AND_SECRET_MANAGEMENT - IDENTITY_HYGIENE - EXCESSIVE_IDENTITY_RIGHTS - IDENTITY_PROVIDER_SECURITY - PRIVILEGED_ACCOUNT_RISK - IDENTITY_RISK - INFRASTRUCTURE_SECURITY - CONFIGURATION_SECURITY - MEMBERSHIP_CHANGE - GPO_CHANGE isArray: true - name: status description: Filter the violations by status. Supports comma separated values. auto: PREDEFINED predefined: - OPEN - IN_PROGRESS - REMEDIATED - DISMISSED - CLOSED isArray: true - name: severity description: Filter the violations by severity level. Supports comma separated values. auto: PREDEFINED predefined: - SEVERITY_UNSPECIFIED - LOW - MEDIUM - HIGH - CRITICAL isArray: true - name: identity_provider description: Filter the violations by identity provider type. Supports comma separated values. auto: PREDEFINED predefined: - IDP_UNSPECIFIED - ON_PREM_AD - ENTRA_ID - AWS - LOCAL_AD - SHAREPOINT - SYSTEM - OKTA isArray: true - name: identity_tag description: Filter the violations by identity tag. Supports comma separated values. auto: PREDEFINED predefined: - IDENTITY_TAG_UNSPECIFIED - PRIVILEGED - AT_RISK - SENSITIVE isArray: true - name: limit defaultValue: "50" description: Number of results to retrieve in the response. The maximum allowed size is 1000. - name: next_page_token description: The next page cursor to retrieve the next set of results. - name: sort_by description: Specify the field to use for sorting the response. defaultValue: DETECTION_TIME auto: PREDEFINED predefined: - SEVERITY - HITS - DETECTION_TIME - UPDATE_TIME - IDENTITY_TYPE - TOTAL_HITS - EVENT_TIME - NAME - TYPE - name: sort_order defaultValue: DESC description: Specify the order to sort the data in. auto: PREDEFINED predefined: - ASC - DESC outputs: - contextPath: RubrikPolaris.IRViolation.policyViolationId description: The unique identifier for the policy violation. type: String - contextPath: RubrikPolaris.IRViolation.name description: The name of the policy violation. type: String - contextPath: RubrikPolaris.IRViolation.violationSeverity description: The severity level of the policy violation. type: String - contextPath: RubrikPolaris.IRViolation.status description: The current status of the policy violation. type: String - contextPath: RubrikPolaris.IRViolation.createdAt description: The date and time when the policy violation was created. type: Date - contextPath: RubrikPolaris.IRViolation.lastUpdatedAt description: The date and time when the policy violation was last updated. type: Date - contextPath: RubrikPolaris.IRViolation.resourceId description: The unique identifier of the resource associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.resourceType description: The type of the resource associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.policyId description: The unique identifier of the policy associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.name description: The name of the policy associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.description description: The description of the policy associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.policySeverity description: The severity level assigned to the policy. type: String - contextPath: RubrikPolaris.IRViolation.policy.policyCategory description: The category of the policy associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.policyType description: The type of the policy associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.frameworks description: The compliance frameworks associated with the policy. type: String - contextPath: RubrikPolaris.IRViolation.policy.manualRemediationProcess description: The manual remediation process recommended for the policy violation. type: String - contextPath: RubrikPolaris.IRViolation.details.domainUniqueId description: The unique identifier of the domain associated with the violation details. type: String - contextPath: RubrikPolaris.IRViolation.details.detectionTime description: The time at which the threat was detected. type: Date - contextPath: RubrikPolaris.IRViolation.details.startTime description: The start time of the alert event. type: Date - contextPath: RubrikPolaris.IRViolation.details.endTime description: The end time of the alert event. type: Date - contextPath: RubrikPolaris.IRViolation.details.mitreTactic description: The MITRE ATT&CK tactic associated with the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.displayName description: The display name of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.domainName description: The domain name of the resource associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.domainUniqueId description: The unique identifier of the domain of the resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.idpType description: The identity provider type of the resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.principalType description: The principal type of the identity resource (e.g. USER, COMPUTER). type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.privilegeType description: The privilege type of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.userPrincipalName description: The user principal name of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.status description: The status of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.title description: The job title of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.source description: The source of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.identityTags description: The list of tags associated with the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.uniqueId description: The unique identifier of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.nativeType description: The native type of the identity resource (e.g. User). type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.rootDomainName description: The root domain name of the resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.rootDomainId description: The unique identifier of the root domain of the resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.actorIdentityId description: The unique identifier of the actor identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.actorIdentityName description: The name of the actor identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.actorIdentityType description: The type of the actor identity involved in the alert (e.g. USER). type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.actorPrivilegeType description: The privilege type of the actor identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.actorState description: The state of the actor identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.entityName description: The name of the entity associated with the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.entityId description: The unique identifier of the entity associated with the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdentityUniqueIdentifier description: The unique identifier of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdentityName description: The name of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdentitySource description: The source domain of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdentityStatus description: The status of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdentityType description: The type of the target identity involved in the alert (e.g. COMPUTER). type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdpType description: The identity provider type of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetPrivilegeType description: The privilege type of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.eventTime description: The time at which the identity event occurred. type: Date - contextPath: RubrikPolaris.PageToken.IRViolation.next_page_token description: The next page token. type: String - contextPath: RubrikPolaris.PageToken.IRViolation.name description: The name of the command. type: String - contextPath: RubrikPolaris.PageToken.IRViolation.has_next_page description: Whether the result has the next page or not. type: Boolean - arguments: - description: "The ID of the IR violation.\n\nNote: Users can get the violation ID by executing the \"rubrik-identity-resilience-violation-list\" command." name: violation_id required: true - description: "The policy type of the IR violation.\n\nNote: Users can get the policy type by executing the \"rubrik-identity-resilience-violation-list\" command." name: policy_type required: false auto: PREDEFINED predefined: - IDENTITY - IDP - IDENTITY_EVENT - CROWDSTRIKE - MICROSOFT_DEFENDER description: Retrieves the details of the Identity Resilience (IR) violation based on the provided violation ID. name: rubrik-identity-resilience-violation-get outputs: - contextPath: RubrikPolaris.IRViolation.policyViolationId description: The unique identifier for the policy violation. type: String - contextPath: RubrikPolaris.IRViolation.name description: The name of the policy violation. type: String - contextPath: RubrikPolaris.IRViolation.violationSeverity description: The severity level of the policy violation. type: String - contextPath: RubrikPolaris.IRViolation.status description: The current status of the policy violation. type: String - contextPath: RubrikPolaris.IRViolation.createdAt description: The date and time when the policy violation was created. type: Date - contextPath: RubrikPolaris.IRViolation.lastUpdatedAt description: The date and time when the policy violation was last updated. type: Date - contextPath: RubrikPolaris.IRViolation.resourceId description: The unique identifier of the resource associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.resourceType description: The type of the resource associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.policyId description: The unique identifier of the policy associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.name description: The name of the policy associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.description description: The description of the policy associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.policySeverity description: The severity level assigned to the policy. type: String - contextPath: RubrikPolaris.IRViolation.policy.policyCategory description: The category of the policy associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.policyType description: The type of the policy associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.policy.frameworks description: The compliance frameworks associated with the policy. type: String - contextPath: RubrikPolaris.IRViolation.policy.manualRemediationProcess description: The manual remediation process recommended for the policy violation. type: String - contextPath: RubrikPolaris.IRViolation.details.domainUniqueId description: The unique identifier of the domain associated with the violation details. type: String - contextPath: RubrikPolaris.IRViolation.details.detectionTime description: The time at which the threat was detected. type: Date - contextPath: RubrikPolaris.IRViolation.details.startTime description: The start time of the alert event. type: Date - contextPath: RubrikPolaris.IRViolation.details.endTime description: The end time of the alert event. type: Date - contextPath: RubrikPolaris.IRViolation.details.mitreTactic description: The MITRE ATT&CK tactic associated with the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.displayName description: The display name of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.domainName description: The domain name of the resource associated with the violation. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.domainUniqueId description: The unique identifier of the domain of the resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.idpType description: The identity provider type of the resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.principalType description: The principal type of the identity resource (e.g. USER, COMPUTER). type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.privilegeType description: The privilege type of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.userPrincipalName description: The user principal name of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.status description: The status of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.title description: The job title of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.source description: The source of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.identityTags description: The list of tags associated with the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.uniqueId description: The unique identifier of the identity resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.nativeType description: The native type of the identity resource (e.g. User). type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.rootDomainName description: The root domain name of the resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.rootDomainId description: The unique identifier of the root domain of the resource. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.actorIdentityId description: The unique identifier of the actor identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.actorIdentityName description: The name of the actor identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.actorIdentityType description: The type of the actor identity involved in the alert (e.g. USER). type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.actorPrivilegeType description: The privilege type of the actor identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.actorState description: The state of the actor identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.entityName description: The name of the entity associated with the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.entityId description: The unique identifier of the entity associated with the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdentityUniqueIdentifier description: The unique identifier of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdentityName description: The name of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdentitySource description: The source domain of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdentityStatus description: The status of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdentityType description: The type of the target identity involved in the alert (e.g. COMPUTER). type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetIdpType description: The identity provider type of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.targetPrivilegeType description: The privilege type of the target identity involved in the alert. type: String - contextPath: RubrikPolaris.IRViolation.resourceMetadata.metadata.eventTime description: The time at which the identity event occurred. type: Date - contextPath: RubrikPolaris.IRViolation.sensitiveHits.highRiskHits.violatedHits description: The number of high risk sensitive hits violated by the identity. type: Number - contextPath: RubrikPolaris.IRViolation.sensitiveHits.mediumRiskHits.violatedHits description: The number of medium risk sensitive hits violated by the identity. type: Number - contextPath: RubrikPolaris.IRViolation.sensitiveHits.lowRiskHits.violatedHits description: The number of low risk sensitive hits violated by the identity. type: Number - contextPath: RubrikPolaris.IRViolation.sensitiveHits.noRiskHits.violatedHits description: The number of no risk sensitive hits violated by the identity. type: Number - contextPath: RubrikPolaris.IRViolation.sensitiveHits.totalHits.violatedHits description: The total number of sensitive hits violated by the identity. type: Number - contextPath: RubrikPolaris.IRViolation.dataCategoryResults.dataCategoryName description: The name of the data category associated with the sensitive hits. type: String - contextPath: RubrikPolaris.IRViolation.dataCategoryResults.dataCategoryHits.dataCategoryId description: The unique identifier of the data category. type: String - contextPath: RubrikPolaris.IRViolation.dataCategoryResults.dataCategoryHits.totalViolatedHits description: The total number of violated hits for the data category. type: Number - name: rubrik-identity-resilience-violation-status-update description: Updates the status of the Identity Resilience (IR) violation. arguments: - name: violation_id description: "The ID of the IR violation.\n\nNote: Users can get the violation ID by executing the \"rubrik-identity-resilience-violation-list\" command." required: true - name: status description: The status to update for the violation. required: true auto: PREDEFINED predefined: - OPEN - IN_PROGRESS - REMEDIATED - DISMISSED - CLOSED outputs: - contextPath: RubrikPolaris.IRViolation.policyViolationId description: The ID of the violation. type: String - contextPath: RubrikPolaris.IRViolation.status description: The status of the violation. type: String - name: rubrik-sensitive-data-object-get arguments: - description: "The ID of the object (snappable FID).\n\nNote: Users can get the object ID by executing the \"rubrik-polaris-object-list\" command." name: object_id required: true - description: "The Snapshot ID of the object.\n\nNote: Users can get the snapshot ID by executing the \"rubrik-polaris-object-snapshot-list\" command." name: snapshot_id required: true - auto: PREDEFINED defaultValue: "False" description: "The boolean indicates to include the whitelisted results." name: include_whitelisted_results predefined: - "True" - "False" description: Retrieve the details of the object based on the provided object ID and snapshot ID. outputs: - contextPath: RubrikPolaris.SensitiveDataObject.id description: The ID of the sensitive data object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snapshotFid description: The FID of the snapshot associated with the object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snapshotTimestamp description: The timestamp of the snapshot. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.shareType description: The share type of the object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.riskLevel description: The risk level of the object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.osType description: The OS type of the object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.isUserAccessEnabledObject description: Whether user access is enabled for the object. type: Boolean - contextPath: RubrikPolaris.SensitiveDataObject.__typename description: The GraphQL type name of the sensitive data object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.objectStatus.latestSnapshotResult.snapshotTime description: The time of the latest snapshot result. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.objectStatus.latestSnapshotResult.snapshotFid description: The FID of the latest snapshot result. type: String - contextPath: RubrikPolaris.SensitiveDataObject.objectStatus.policyStatuses.status description: The status of the policy for the object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.objectStatus.__typename description: The GraphQL type name of the object status. type: String - contextPath: RubrikPolaris.SensitiveDataObject.objectStatus.latestSnapshotResult.__typename description: The GraphQL type name of the latest snapshot result. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.hits.totalHits description: The total number of sensitive data hits in the object. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.hits.violations description: The total number of violations in the object. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.hits.violationsDelta description: The change in violations since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.hits.totalHitsDelta description: The change in total hits since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.__typename description: The GraphQL type name of the root file result. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.hits.__typename description: The GraphQL type name of the root file result hits. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerGroupResults.analyzerGroup.groupType description: The type of the analyzer group. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerGroupResults.analyzerGroup.id description: The ID of the analyzer group. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerGroupResults.analyzerGroup.name description: The name of the analyzer group. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerGroupResults.hits.totalHits description: The total hits for the analyzer group. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerGroupResults.hits.violations description: The violations for the analyzer group. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerGroupResults.hits.violationsDelta description: The change in violations for the analyzer group since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerGroupResults.hits.totalHitsDelta description: The change in total hits for the analyzer group since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerGroupResults.__typename description: The GraphQL type name of the analyzer group result. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerGroupResults.analyzerGroup.__typename description: The GraphQL type name of the analyzer group. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerGroupResults.hits.__typename description: The GraphQL type name of the analyzer group hits. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerResults.analyzer.id description: The ID of the analyzer. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerResults.analyzer.name description: The name of the analyzer. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerResults.hits.totalHits description: The total hits for the analyzer. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerResults.hits.violations description: The violations for the analyzer. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerResults.hits.violationsDelta description: The change in violations for the analyzer since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerResults.hits.totalHitsDelta description: The change in total hits for the analyzer since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.analyzerResults.hits.__typename description: The GraphQL type name of the analyzer result hits. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.filesWithHits.totalHits description: The total number of files with sensitive data hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.filesWithHits.violations description: The number of files with violations. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.filesWithHits.violationsDelta description: The change in files with violations since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.filesWithHits.totalHitsDelta description: The change in files with hits since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.filesWithHits.__typename description: The GraphQL type name of the files with hits. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFiles.totalHits description: The total number of open-access files. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFiles.violations description: The number of open-access files with violations. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFiles.violationsDelta description: The change in open-access files with violations since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFiles.totalHitsDelta description: The change in open-access files hits since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFiles.__typename description: The GraphQL type name of the open access files. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFolders.totalHits description: The total number of open-access folders. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFolders.violations description: The number of open-access folders with violations. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFolders.violationsDelta description: The change in open-access folders with violations since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFolders.totalHitsDelta description: The change in open-access folders hits since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFolders.__typename description: The GraphQL type name of the open access folders. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFilesWithHits.totalHits description: The total number of open-access files with sensitive hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFilesWithHits.violations description: The number of open-access files with hits and violations. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFilesWithHits.violationsDelta description: The change in open-access files with hits violations since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFilesWithHits.totalHitsDelta description: The change in open-access files with hits since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessFilesWithHits.__typename description: The GraphQL type name of the open access files with hits. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.staleFiles.totalHits description: The total number of stale files. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.staleFiles.violations description: The number of stale files with violations. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.staleFiles.violationsDelta description: The change in stale files with violations since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.staleFiles.totalHitsDelta description: The change in stale files hits since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.staleFiles.__typename description: The GraphQL type name of the stale files. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.staleFilesWithHits.totalHits description: The total number of stale files with sensitive hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.staleFilesWithHits.violations description: The number of stale files with hits and violations. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.staleFilesWithHits.violationsDelta description: The change in stale files with hits violations since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.staleFilesWithHits.totalHitsDelta description: The change in stale files with hits since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.staleFilesWithHits.__typename description: The GraphQL type name of the stale files with hits. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessStaleFiles.totalHits description: The total number of open-access stale files. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessStaleFiles.violations description: The number of open-access stale files with violations. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessStaleFiles.violationsDelta description: The change in open-access stale files with violations since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessStaleFiles.totalHitsDelta description: The change in open-access stale files hits since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.openAccessStaleFiles.__typename description: The GraphQL type name of the open access stale files. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.highRiskHits.totalHits description: The total high risk sensitive hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.highRiskHits.violatedHits description: The violated high risk sensitive hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.highRiskHits.__typename description: The GraphQL type name of the high risk hits summary. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.mediumRiskHits.totalHits description: The total medium risk sensitive hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.mediumRiskHits.violatedHits description: The violated medium risk sensitive hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.mediumRiskHits.__typename description: The GraphQL type name of the medium risk hits summary. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.lowRiskHits.totalHits description: The total low risk sensitive hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.lowRiskHits.violatedHits description: The violated low risk sensitive hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.lowRiskHits.__typename description: The GraphQL type name of the low risk hits summary. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.noRiskHits.totalHits description: The total no-risk sensitive hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.noRiskHits.violatedHits description: The violated no-risk sensitive hits. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.noRiskHits.__typename description: The GraphQL type name of the no-risk hits summary. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.totalHits.totalHits description: The total sensitive hits across all risk levels. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.totalHits.violatedHits description: The total violated sensitive hits across all risk levels. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.totalHits.__typename description: The GraphQL type name of the total sensitive hits summary. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.sensitiveHits.__typename description: The GraphQL type name of the sensitive hits. type: String - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.numActivities description: The number of activities associated with the file result. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.rootFileResult.numActivitiesDelta description: The change in number of activities since last scan. type: Number - contextPath: RubrikPolaris.SensitiveDataObject.snappable.id description: The ID of the snappable object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.name description: The name of the snappable object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.objectType description: The type of the snappable object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.slaAssignment description: The SLA assignment of the snappable object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.logicalPath.fid description: The FID of the logical path node. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.logicalPath.name description: The name of the logical path node. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.logicalPath.objectType description: The object type of the logical path node. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.logicalPath.__typename description: The GraphQL type name of the logical path node. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.physicalPath.fid description: The FID of the physical path node. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.physicalPath.name description: The name of the physical path node. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.physicalPath.objectType description: The object type of the physical path node. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.effectiveSlaDomain.id description: The ID of the effective SLA domain. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.effectiveSlaDomain.name description: The name of the effective SLA domain. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.effectiveSlaDomain.isRetentionLockedSla description: Whether the SLA domain has retention lock enabled. type: Boolean - contextPath: RubrikPolaris.SensitiveDataObject.snappable.effectiveSlaDomain.retentionLockMode description: The retention lock mode of the SLA domain. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.effectiveSlaDomain.description description: The description of the effective SLA domain. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.effectiveSlaDomain.__typename description: The GraphQL type name of the effective SLA domain. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.rscNativeObjectPendingSla.id description: The ID of the pending SLA for the native object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.rscNativeObjectPendingSla.name description: The name of the pending SLA for the native object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.snappable.__typename description: The GraphQL type name of the snappable object. type: String - contextPath: RubrikPolaris.SensitiveDataObject.policySummaries.id description: The ID of the classification policy. type: String - contextPath: RubrikPolaris.SensitiveDataObject.policySummaries.name description: The name of the classification policy. type: String - contextPath: RubrikPolaris.SensitiveDataObject.policySummaries.colorEnum description: The color enum of the classification policy. type: String - contextPath: RubrikPolaris.SensitiveDataObject.policySummaries.__typename description: The GraphQL type name of the classification policy summary. type: String - name: rubrik-sensitive-data-object-file-get arguments: - description: "The ID of the object (snappable FID).\n\nNote: Users can get the object ID by executing the \"rubrik-polaris-object-list\" command." name: object_id required: true - description: "The Snapshot ID of the object.\n\nNote: Users can get the snapshot ID by executing the \"rubrik-polaris-object-snapshot-list\" command." name: snapshot_id required: true - description: The full path of the file for which to retrieve information. name: file_path required: true - auto: PREDEFINED defaultValue: "True" description: Whether to resolve SIDs to display names in the file response. name: resolve_sids predefined: - "True" - "False" description: Retrieve the file information for the provided file path in the object. outputs: - contextPath: RubrikPolaris.SensitiveDataObjectFile.objectId description: The unique identifier of the snappable object. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.stdPath description: The standard file path of the sensitive file. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.path description: The full path of the sensitive file from the security descriptor. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.owner description: The SID of the owner of the file. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.permissions.cn description: The display name of the principal with file permissions. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.permissions.principalId description: The SID or identifier of the principal with file permissions. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.permissions.principalOrigin description: The origin of the principal. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.permissions.idpType description: The identity provider type for the principal. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.permissions.principalType description: The type of the principal. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.permissions.resolutionType description: The resolution type of the principal SID. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.permissions.access description: The access level granted to the principal. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.permissions.flags description: The permission flags. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.secInfo.permissions.accessMethodDetails.accessMethod description: The access method used. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.fileMetadata.createdBy.value description: The value of the principal who created the file. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.fileMetadata.creationTime description: The creation time of the file as a Unix timestamp. type: Number - contextPath: RubrikPolaris.SensitiveDataObjectFile.fileMetadata.lastAccessTime description: The last access time of the file as a Unix timestamp. type: Number - contextPath: RubrikPolaris.SensitiveDataObjectFile.fileMetadata.lastModifiedBy.value description: The value of the principal who last modified the file. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.fileMetadata.lastModifiedTime description: The last modified time of the file as a Unix timestamp. type: Number - contextPath: RubrikPolaris.SensitiveDataObjectFile.fileMetadata.lastScanTime description: The last scan time of the file as a Unix timestamp. type: Number - contextPath: RubrikPolaris.SensitiveDataObjectFile.fileMetadata.path description: The full path of the file as recorded in the metadata. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.fileMetadata.size description: The size of the file in bytes. type: Number - contextPath: RubrikPolaris.SensitiveDataObjectFile.exposureSummary.exposureType description: The exposure type of the file. type: String - contextPath: RubrikPolaris.SensitiveDataObjectFile.exposureSummary.fileCount.totalCount description: The total count of files in the exposure summary. type: Number - contextPath: RubrikPolaris.SensitiveDataObjectFile.exposureSummary.fileCount.violatedCount description: The number of files with violations in the exposure summary. type: Number dockerimage: demisto/rubrik-polaris-sdk-py3:1.0.0.10133006 isfetch: true runonce: false script: '-' subtype: python3 type: python tests: - RubrikPolaris-Test defaultmapperin: Rubrik Polaris Radar - Mapping defaultclassifier: Rubrik Polaris Radar - Classification fromversion: 6.0.0