Skip to content
Open
Changes from 1 commit
Commits
Show all changes
61 commits
Select commit Hold shift + click to select a range
101f3b2
create event_import v1alpha
dandye Mar 7, 2025
3ab7f99
add events_get
dandye Mar 7, 2025
3db7cf9
events_batch_get
dandye Mar 7, 2025
f0b9300
udm_events_find
dandye Mar 7, 2025
a8ebfdb
find assets and raw logs
dandye Mar 7, 2025
a0581fd
url_always_prepend_region
dandye Mar 7, 2025
7d55b44
get_detection
dandye Mar 7, 2025
a380a96
Add SDK wrapper
dandye Mar 7, 2025
94e317e
expand coverage of SDK
dandye Mar 7, 2025
9719f81
Use dotenv
dandye Mar 7, 2025
b856aac
Update readme with dotenv
dandye Mar 7, 2025
f0389a2
Code cleanup
dandye Mar 7, 2025
02c9d52
Google style guide
dandye Mar 7, 2025
d072b74
Update copyright year
dandye Mar 7, 2025
95d6673
Update copyright year throughout
dandye Mar 7, 2025
10856a7
SDK fixes
dandye Mar 7, 2025
ccd58e3
Makefile for wheel
dandye Mar 7, 2025
e009618
update docs with .env and build
dandye Mar 7, 2025
c8cb534
Bug fixes with packaging
dandye Mar 7, 2025
09fc059
2 space indent
dandye Mar 7, 2025
031ed85
2 space indent
dandye Mar 7, 2025
e64d3b0
isort imports
dandye Mar 7, 2025
b654695
Style fixes
dandye Mar 7, 2025
33e45fc
Presubmit fixes
dandye Mar 8, 2025
5ff9ba9
cover the search query get v1alpha api resource
dandye Mar 8, 2025
cee0332
revert changes to v2 py files
dandye Mar 11, 2025
b43aea3
Add IoC API resources
dandye Mar 11, 2025
70619b6
Revert changes to access_control
dandye Mar 11, 2025
0911b3a
revert updates to non-v1alpha py files
dandye Mar 11, 2025
4f92aa9
revert updates to non-v1alpha py files
dandye Mar 11, 2025
239ff30
yapf format to 2 spaces; isort imports
dandye Mar 11, 2025
7e897d5
refactor; lint
dandye Mar 11, 2025
1998d3d
Revert non-v1alpha file changes
dandye Mar 11, 2025
3a05a0f
Lint fixes
dandye Mar 11, 2025
08103ad
Linting fixes
dandye Mar 11, 2025
0b3399e
fix line-too-long
dandye Mar 11, 2025
2f563e7
linting; rm MCP files
dandye Mar 11, 2025
3021362
rm reference_lists (MCP files)
dandye Mar 11, 2025
809c978
linting
dandye Mar 11, 2025
9ecd908
linting
dandye Mar 11, 2025
ab00567
linting
dandye Mar 11, 2025
880bcd6
SDK bugs
dandye Mar 12, 2025
e1f79a0
linting
dandye Mar 12, 2025
1d95a08
linting
dandye Mar 12, 2025
1cf8368
linting
dandye Mar 12, 2025
3016298
Lint the ReadMe
dandye Mar 12, 2025
42061c4
lint
dandye Mar 12, 2025
39a2c9f
lint the ReadMe
dandye Mar 12, 2025
a932393
lint readme
dandye Mar 12, 2025
c8caa8b
ReadMe lint
dandye Mar 12, 2025
f2034bc
Fix .env in ReadMe
dandye Mar 12, 2025
2acac25
remove relative imports from tests
dandye Mar 12, 2025
3d92b96
import order
dandye Mar 12, 2025
59e8dd1
revert changes to regions and test
dandye Mar 12, 2025
daea913
revert changes to common/ files
dandye Mar 12, 2025
96fdbba
revert changes to create_list.py
dandye Mar 12, 2025
d3b0577
revert changes to get_udm_event
dandye Mar 12, 2025
1eaeb1a
Fix the build and release v0.1.3 to Artifacts
dandye Mar 12, 2025
52d13f8
Consistent quotes
dandye Mar 12, 2025
24f6b68
Add copyright and License
dandye Mar 20, 2025
69a4dbd
Rebrand as Chronicle API CLI
dandye Mar 20, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
get_detection
  • Loading branch information
dandye committed Mar 7, 2025
commit 7d55b44c48cd56d36793cd954d2946e34891a0b5
110 changes: 110 additions & 0 deletions detect/v1alpha/get_detection.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,110 @@
#!/usr/bin/env python3

# Copyright 2024 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
r"""Executable and reusable sample for getting a Detection.

Usage:
python -m detect.v1alpha.get_detection \
--project_id=<PROJECT_ID> \
--project_instance=<PROJECT_INSTANCE> \
--detection_id=<DETECTION_ID>

# pylint: disable=line-too-long
API reference:
https://cloud.google.com/chronicle/docs/reference/rest/v1alpha/projects.locations.instances.legacy/legacyGetDetection
# pylint: enable=line-too-long
"""

import argparse
import json
from typing import Any, Mapping

from common import chronicle_auth
from common import project_id
from common import project_instance
from common import regions

from google.auth.transport import requests

CHRONICLE_API_BASE_URL = "https://chronicle.googleapis.com"
SCOPES = [
"https://www.googleapis.com/auth/cloud-platform",
]


def get_detection(
http_session: requests.AuthorizedSession,
proj_id: str,
proj_instance: str,
proj_region: str,
detection_id: str,
) -> Mapping[str, Any]:
"""Gets a Detection.

Args:
http_session: Authorized session for HTTP requests.
proj_id: GCP project id or number to which the target instance belongs.
proj_instance: Customer ID (uuid with dashes) for the Chronicle instance.
proj_region: region in which the target project is located.
detection_id: Identifier for the detection.

Returns:
Dictionary representation of the Detection

Raises:
requests.exceptions.HTTPError: HTTP request resulted in an error
(response.status_code >= 400).
"""
base_url_with_region = regions.url_always_prepend_region(
CHRONICLE_API_BASE_URL,
proj_region
)
parent = f"projects/{proj_id}/locations/{proj_region}/instances/{proj_instance}"
url = f"{base_url_with_region}/v1alpha/{parent}/legacy:legacyGetDetection"

query_params = {"detectionId": detection_id}

response = http_session.request("GET", url, params=query_params)
if response.status_code >= 400:
print(response.text)
response.raise_for_status()
return response.json()


if __name__ == "__main__":
parser = argparse.ArgumentParser()
chronicle_auth.add_argument_credentials_file(parser)
project_instance.add_argument_project_instance(parser)
project_id.add_argument_project_id(parser)
regions.add_argument_region(parser)
parser.add_argument(
"--detection_id", type=str, required=True,
help="identifier for the detection"
)
args = parser.parse_args()

auth_session = chronicle_auth.initialize_http_session(
args.credentials_file,
SCOPES,
)
detection = get_detection(
auth_session,
args.project_id,
args.project_instance,
args.region,
args.detection_id,
)
print(json.dumps(detection, indent=2))