Skip to content
Open
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
61 commits
Select commit Hold shift + click to select a range
101f3b2
create event_import v1alpha
dandye Mar 7, 2025
3ab7f99
add events_get
dandye Mar 7, 2025
3db7cf9
events_batch_get
dandye Mar 7, 2025
f0b9300
udm_events_find
dandye Mar 7, 2025
a8ebfdb
find assets and raw logs
dandye Mar 7, 2025
a0581fd
url_always_prepend_region
dandye Mar 7, 2025
7d55b44
get_detection
dandye Mar 7, 2025
a380a96
Add SDK wrapper
dandye Mar 7, 2025
94e317e
expand coverage of SDK
dandye Mar 7, 2025
9719f81
Use dotenv
dandye Mar 7, 2025
b856aac
Update readme with dotenv
dandye Mar 7, 2025
f0389a2
Code cleanup
dandye Mar 7, 2025
02c9d52
Google style guide
dandye Mar 7, 2025
d072b74
Update copyright year
dandye Mar 7, 2025
95d6673
Update copyright year throughout
dandye Mar 7, 2025
10856a7
SDK fixes
dandye Mar 7, 2025
ccd58e3
Makefile for wheel
dandye Mar 7, 2025
e009618
update docs with .env and build
dandye Mar 7, 2025
c8cb534
Bug fixes with packaging
dandye Mar 7, 2025
09fc059
2 space indent
dandye Mar 7, 2025
031ed85
2 space indent
dandye Mar 7, 2025
e64d3b0
isort imports
dandye Mar 7, 2025
b654695
Style fixes
dandye Mar 7, 2025
33e45fc
Presubmit fixes
dandye Mar 8, 2025
5ff9ba9
cover the search query get v1alpha api resource
dandye Mar 8, 2025
cee0332
revert changes to v2 py files
dandye Mar 11, 2025
b43aea3
Add IoC API resources
dandye Mar 11, 2025
70619b6
Revert changes to access_control
dandye Mar 11, 2025
0911b3a
revert updates to non-v1alpha py files
dandye Mar 11, 2025
4f92aa9
revert updates to non-v1alpha py files
dandye Mar 11, 2025
239ff30
yapf format to 2 spaces; isort imports
dandye Mar 11, 2025
7e897d5
refactor; lint
dandye Mar 11, 2025
1998d3d
Revert non-v1alpha file changes
dandye Mar 11, 2025
3a05a0f
Lint fixes
dandye Mar 11, 2025
08103ad
Linting fixes
dandye Mar 11, 2025
0b3399e
fix line-too-long
dandye Mar 11, 2025
2f563e7
linting; rm MCP files
dandye Mar 11, 2025
3021362
rm reference_lists (MCP files)
dandye Mar 11, 2025
809c978
linting
dandye Mar 11, 2025
9ecd908
linting
dandye Mar 11, 2025
ab00567
linting
dandye Mar 11, 2025
880bcd6
SDK bugs
dandye Mar 12, 2025
e1f79a0
linting
dandye Mar 12, 2025
1d95a08
linting
dandye Mar 12, 2025
1cf8368
linting
dandye Mar 12, 2025
3016298
Lint the ReadMe
dandye Mar 12, 2025
42061c4
lint
dandye Mar 12, 2025
39a2c9f
lint the ReadMe
dandye Mar 12, 2025
a932393
lint readme
dandye Mar 12, 2025
c8caa8b
ReadMe lint
dandye Mar 12, 2025
f2034bc
Fix .env in ReadMe
dandye Mar 12, 2025
2acac25
remove relative imports from tests
dandye Mar 12, 2025
3d92b96
import order
dandye Mar 12, 2025
59e8dd1
revert changes to regions and test
dandye Mar 12, 2025
daea913
revert changes to common/ files
dandye Mar 12, 2025
96fdbba
revert changes to create_list.py
dandye Mar 12, 2025
d3b0577
revert changes to get_udm_event
dandye Mar 12, 2025
1eaeb1a
Fix the build and release v0.1.3 to Artifacts
dandye Mar 12, 2025
52d13f8
Consistent quotes
dandye Mar 12, 2025
24f6b68
Add copyright and License
dandye Mar 20, 2025
69a4dbd
Rebrand as Chronicle API CLI
dandye Mar 20, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
expand coverage of SDK
  • Loading branch information
dandye committed Mar 7, 2025
commit 94e317e434d6a51c857fcbd96d88f508eea64c86
74 changes: 74 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,80 @@ python -m lists.v1alpha.get_list -h
python -m lists.v1alpha.patch_list -h
```

## Using the SDK CLI Wrapper

The SDK provides a unified command-line interface for Chronicle APIs. The CLI follows this pattern:
```
chronicle [common options] COMMAND_GROUP COMMAND [command options]
```

Common options required for all commands:
- `--credentials-file`: Path to service account credentials file
- `--project-id`: GCP project id or number
- `--project-instance`: Chronicle instance ID (uuid with dashes)
- `--region`: Region where the project is located

### Command Groups

#### Detection API (`detect`)
- Alert Management (`alerts`)
- `get`: Get alert by ID
- `update`: Update an alert
- `bulk-update`: Bulk update alerts matching a filter

- Detection Management (`detections`)
- `get`: Get detection by ID
- `list`: List detections

- Rule Management (`rules`)
- `create`: Create a new rule
- `get`: Get rule by ID
- `delete`: Delete a rule
- `enable`: Enable a rule
- `list`: List rules

- Retrohunt Management (`retrohunts`)
- `create`: Create a new retrohunt
- `get`: Get retrohunt by ID

- Error Management (`errors`)
- `list`: List errors

- Rule Set Management (`rulesets`)
- `batch-update`: Batch update rule set deployments

#### Ingestion API (`ingestion`)
- `import-events`: Import events into Chronicle
- `get-event`: Get event details
- `batch-get-events`: Batch retrieve events

#### Search API (`search`)
- `find-asset-events`: Find events for an asset
- `find-raw-logs`: Search raw logs
- `find-udm-events`: Find UDM events

#### Lists API (`lists`)
- `create`: Create a new list
- `get`: Get list by ID
- `patch`: Update an existing list

### Examples

Get an alert:
```bash
chronicle --credentials-file creds.json --project-id proj --project-instance inst --region reg detect alerts get --alert-id id
```

Create a list:
```bash
chronicle --credentials-file creds.json --project-id proj --project-instance inst --region reg lists create --name "blocklist" --description "Blocked IPs" --lines '["1.1.1.1", "2.2.2.2"]'
```

Search for events:
```bash
chronicle --credentials-file creds.json --project-id proj --project-instance inst --region reg search find-raw-logs --filter "timestamp.seconds > 1600000000"
```

## SDK CLI Wrapper

In addition to running individual sample scripts, you can use the unified CLI wrapper that provides access to all Chronicle APIs through a single command-line interface.
Expand Down
4 changes: 3 additions & 1 deletion sdk/cli.py
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@

from sdk.commands import detect
from sdk.commands import ingestion
from sdk.commands import lists
from sdk.commands import search


Expand Down Expand Up @@ -55,14 +56,15 @@ def add_common_options(func):
def cli():
"""Chronicle API Command Line Interface.

This CLI provides access to Chronicle's detection, ingestion, and search APIs.
This CLI provides access to Chronicle's detection, ingestion, search, and lists APIs.
"""
pass


# Add command groups
cli.add_command(detect.detect)
cli.add_command(ingestion.ingestion)
cli.add_command(lists.lists)
cli.add_command(search.search)


Expand Down
28 changes: 28 additions & 0 deletions sdk/commands/common.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
"""Common utilities for CLI commands."""

import click


def add_common_options(func):
"""Add common options to a command."""
func = click.option(
"--credentials-file",
required=True,
help="Path to service account credentials file.",
)(func)
func = click.option(
"--project-id",
required=True,
help="GCP project id or number to which the target instance belongs.",
)(func)
func = click.option(
"--project-instance",
required=True,
help="Customer ID (uuid with dashes) for the Chronicle instance.",
)(func)
func = click.option(
"--region",
required=True,
help="Region in which the target project is located.",
)(func)
return func
Loading