/*
* CrowdStrike API Specification
*
* Use this API specification as a reference for the API endpoints you can use to interact with your Falcon environment. These endpoints support authentication via OAuth2 and interact with detections and network containment. For detailed usage guides and examples, see our [documentation inside the Falcon console](https://falcon.crowdstrike.com/support/documentation). To use the APIs described below, combine the base URL with the path shown for each API endpoint. For commercial cloud customers, your base URL is `https://api.crowdstrike.com`. Each API endpoint requires authorization via an OAuth2 token. Your first API request should retrieve an OAuth2 token using the `oauth2/token` endpoint, such as `https://api.crowdstrike.com/oauth2/token`. For subsequent requests, include the OAuth2 token in an HTTP authorization header. Tokens expire after 30 minutes, after which you should make a new token request to continue making API requests.
*
* The version of the OpenAPI document: rolling
*
* Generated by: https://openapi-generator.tech
*/
use crate::models;
#[derive(Clone, Default, Debug, PartialEq, Serialize, Deserialize)]
pub struct ItautomationRunLiveQueryRequest {
#[serde(rename = "composite_query", skip_serializing_if = "Option::is_none")]
pub composite_query: Option<Box<models::ItautomationCompositeQuery>>,
/// Whether to discover new hosts for the scheduled task. Example: true
#[serde(rename = "discover_new_hosts", skip_serializing_if = "Option::is_none")]
pub discover_new_hosts: Option<bool>,
/// Whether to discover offline hosts for the scheduled task. Example: true
#[serde(
rename = "discover_offline_hosts",
skip_serializing_if = "Option::is_none"
)]
pub discover_offline_hosts: Option<bool>,
/// Whether to distribute the scheduled task. Example: true
#[serde(rename = "distribute", skip_serializing_if = "Option::is_none")]
pub distribute: Option<bool>,
/// Duration for which the task stays active. Once expired, new and offline hosts won't be targeted. Example: 1m
#[serde(
rename = "expiration_interval",
skip_serializing_if = "Option::is_none"
)]
pub expiration_interval: Option<String>,
#[serde(rename = "guardrails", skip_serializing_if = "Option::is_none")]
pub guardrails: Option<Box<models::FalconforitapiGuardrails>>,
/// OSQuery to execute. Example: select * from users
#[serde(rename = "osquery", skip_serializing_if = "Option::is_none")]
pub osquery: Option<String>,
#[serde(
rename = "output_parser_config",
skip_serializing_if = "Option::is_none"
)]
pub output_parser_config: Option<Box<models::ItautomationOutputParserConfig>>,
#[serde(rename = "queries", skip_serializing_if = "Option::is_none")]
pub queries: Option<Box<models::ItautomationScripts>>,
/// Target filter in FQL format. Example: platform_name: 'Windows'
#[serde(rename = "target")]
pub target: String,
}
impl ItautomationRunLiveQueryRequest {
pub fn new(target: String) -> ItautomationRunLiveQueryRequest {
ItautomationRunLiveQueryRequest {
composite_query: None,
discover_new_hosts: None,
discover_offline_hosts: None,
distribute: None,
expiration_interval: None,
guardrails: None,
osquery: None,
output_parser_config: None,
queries: None,
target,
}
}
}