pub struct JobQuery {Show 38 fields
pub activity_id: JobQueryActivityId,
pub activity_name: Option<String>,
pub actor: Option<Actor>,
pub api: Option<Api>,
pub category_name: Option<String>,
pub category_uid: i64,
pub class_name: Option<String>,
pub class_uid: i64,
pub cloud: Cloud,
pub count: Option<i64>,
pub device: Option<Device>,
pub duration: Option<i64>,
pub end_time: Option<i64>,
pub end_time_dt: Option<String>,
pub enrichments: Vec<Enrichment>,
pub job: Job,
pub message: Option<String>,
pub metadata: Metadata,
pub observables: Vec<Observable>,
pub osint: Vec<Osint>,
pub query_info: Option<QueryInfo>,
pub query_result: Option<String>,
pub query_result_id: JobQueryQueryResultId,
pub raw_data: Option<String>,
pub severity: Option<String>,
pub severity_id: JobQuerySeverityId,
pub start_time: Option<i64>,
pub start_time_dt: Option<String>,
pub status: Option<String>,
pub status_code: Option<String>,
pub status_detail: Option<String>,
pub status_id: Option<JobQueryStatusId>,
pub time: i64,
pub time_dt: Option<String>,
pub timezone_offset: Option<i64>,
pub type_name: Option<String>,
pub type_uid: i64,
pub unmapped: Option<Object>,
}
Expand description
JobQuery
JSON schema
{
"$id": "https://schema.ocsf.io/schema/classes/job_query",
"type": "object",
"required": [
"activity_id",
"category_uid",
"class_uid",
"cloud",
"job",
"metadata",
"osint",
"query_result_id",
"severity_id",
"time",
"type_uid"
],
"properties": {
"activity_id": {
"type": "integer",
"enum": [
0,
1,
99
]
},
"activity_name": {
"type": "string"
},
"actor": {
"$ref": "#/$defs/actor"
},
"api": {
"$ref": "#/$defs/api"
},
"category_name": {
"type": "string"
},
"category_uid": {
"type": "integer",
"const": 5
},
"class_name": {
"type": "string"
},
"class_uid": {
"type": "integer",
"const": 5010
},
"cloud": {
"$ref": "#/$defs/cloud"
},
"count": {
"type": "integer"
},
"device": {
"$ref": "#/$defs/device"
},
"duration": {
"type": "integer"
},
"end_time": {
"type": "integer"
},
"end_time_dt": {
"type": "string"
},
"enrichments": {
"type": "array",
"items": {
"$ref": "#/$defs/enrichment"
}
},
"job": {
"$ref": "#/$defs/job"
},
"message": {
"type": "string"
},
"metadata": {
"$ref": "#/$defs/metadata"
},
"observables": {
"type": "array",
"items": {
"$ref": "#/$defs/observable"
}
},
"osint": {
"type": "array",
"items": {
"$ref": "#/$defs/osint"
}
},
"query_info": {
"$ref": "#/$defs/query_info"
},
"query_result": {
"type": "string"
},
"query_result_id": {
"type": "integer",
"enum": [
3,
0,
1,
2,
99,
4,
5
]
},
"raw_data": {
"type": "string"
},
"severity": {
"type": "string"
},
"severity_id": {
"type": "integer",
"enum": [
3,
6,
0,
1,
2,
99,
4,
5
]
},
"start_time": {
"type": "integer"
},
"start_time_dt": {
"type": "string"
},
"status": {
"type": "string"
},
"status_code": {
"type": "string"
},
"status_detail": {
"type": "string"
},
"status_id": {
"type": "integer",
"enum": [
0,
1,
2,
99
]
},
"time": {
"type": "integer"
},
"time_dt": {
"type": "string"
},
"timezone_offset": {
"type": "integer"
},
"type_name": {
"type": "string"
},
"type_uid": {
"type": "integer"
},
"unmapped": {
"$ref": "#/$defs/object"
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}
Fields§
§activity_id: JobQueryActivityId
§activity_name: Option<String>
§actor: Option<Actor>
§api: Option<Api>
§category_name: Option<String>
§category_uid: i64
§class_name: Option<String>
§class_uid: i64
§cloud: Cloud
§count: Option<i64>
§device: Option<Device>
§duration: Option<i64>
§end_time: Option<i64>
§end_time_dt: Option<String>
§enrichments: Vec<Enrichment>
§job: Job
§message: Option<String>
§metadata: Metadata
§observables: Vec<Observable>
§osint: Vec<Osint>
§query_info: Option<QueryInfo>
§query_result: Option<String>
§query_result_id: JobQueryQueryResultId
§raw_data: Option<String>
§severity: Option<String>
§severity_id: JobQuerySeverityId
§start_time: Option<i64>
§start_time_dt: Option<String>
§status: Option<String>
§status_code: Option<String>
§status_detail: Option<String>
§status_id: Option<JobQueryStatusId>
§time: i64
§time_dt: Option<String>
§timezone_offset: Option<i64>
§type_name: Option<String>
§type_uid: i64
§unmapped: Option<Object>
Implementations§
Trait Implementations§
Source§impl<'de> Deserialize<'de> for JobQuery
impl<'de> Deserialize<'de> for JobQuery
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
Auto Trait Implementations§
impl Freeze for JobQuery
impl RefUnwindSafe for JobQuery
impl Send for JobQuery
impl Sync for JobQuery
impl Unpin for JobQuery
impl UnwindSafe for JobQuery
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more