Skip to main content

rules

Creates, updates, deletes, gets or lists a rules resource.

Overview​

Namerules
TypeResource
Idsumologic.logs_data_forwarding.rules

Fields​

The following fields are returned by SELECT queries:

Data forwarding rule that was requested.

NameDatatypeDescription
idstringThe unique identifier of the data forwarding rule. (example: 1)
destination_idstringThe data forwarding destination id. (example: 1) (wire: destinationId)
index_idstringThe id of the Partition or Scheduled View the rule applies to. (example: 1) (wire: indexId)
bucketstring(opaque JSON object)
created_atstring (date-time)Creation timestamp in UTC in [RFC3339](https:​//tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt)
created_bystringIdentifier of the user who created the resource. (example: 0000000006743FDD) (wire: createdBy)
enabledbooleanTrue when the data forwarding rule is enabled.
file_formatstringSpecify the path prefix to a directory in the S3 bucket and how to format the file name. (example: {index}_{day}_{hour}_{minute}_{second}) (wire: fileFormat)
formatstringFormat of the payload. Default format will be "csv". "text" format should be used in conjunction with "raw" payloadSchema and vice-versa. (pattern: <code>^(csv|json|text)$</code>, example: csv, x-pattern-message: should be one of the following: 'csv', 'json' or 'text')
modified_atstring (date-time)Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt)
modified_bystringIdentifier of the user who last modified the resource. (example: 0000000006743FE8) (wire: modifiedBy)
payload_schemastringSchema for the payload. Default value of the payload schema is "allFields" for scheduled view, and "builtInFields" for partition. "raw" payloadSchema should be used in conjunction with "text" format and vice-versa. (pattern: <code>^(builtInFields|allFields|raw)$</code>, example: builtInFields, x-pattern-message: should be one of the following: 'builtInFields', 'allFields' or 'raw') (wire: payloadSchema)

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectindex_id, regionGet the details of an S3 data forwarding rule by its Partition or Scheduled View identifier.
listselectregionlimit, tokenGet a list of all S3 data forwarding rules.
createinsertregion, destination_id, index_idCreate a data forwarding rule to send data from a Partition or Scheduled View to an S3 bucket.
updateupdateindex_id, regionUpdate an S3 data forwarding rule by its Partition or Scheduled View identifier.
deletedeleteindex_id, regionDelete an S3 data forwarding rule by its Partition or Scheduled View identifier.

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
index_idstringThe id of the Partition or Scheduled View with the data forwarding rule to delete. (example: 1) (wire: indexId)
regionstringSumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT)
limitinteger (int32)Limit the number of data forwarding rules returned in the response. The number of data forwarding rules returned may be less than the limit.
tokenstringContinuation token to get the next page of results. A page object with the next continuation token is returned in the response body. Subsequent GET requests should specify the continuation token to get the next page of results. token is set to null when no more pages are left.

SELECT examples​

Get the details of an S3 data forwarding rule by its Partition or Scheduled View identifier.

SELECT
id,
destination_id,
index_id,
bucket,
created_at,
created_by,
enabled,
file_format,
format,
modified_at,
modified_by,
payload_schema
FROM sumologic.logs_data_forwarding.rules
WHERE index_id = '{{ index_id }}' -- required
AND region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
;

INSERT examples​

Create a data forwarding rule to send data from a Partition or Scheduled View to an S3 bucket.

INSERT INTO sumologic.logs_data_forwarding.rules (
index_id,
destination_id,
enabled,
file_format,
payload_schema,
format,
region
)
SELECT
'{{ index_id }}' /* required */,
'{{ destination_id }}' /* required */,
{{ enabled }},
'{{ file_format }}',
'{{ payload_schema }}',
'{{ format }}',
'{{ region }}'
RETURNING
id,
destination_id,
index_id,
created_at,
created_by,
enabled,
file_format,
format,
modified_at,
modified_by,
payload_schema
;

UPDATE examples​

Update an S3 data forwarding rule by its Partition or Scheduled View identifier.

UPDATE sumologic.logs_data_forwarding.rules
SET
destination_id = '{{ destination_id }}',
enabled = {{ enabled }},
file_format = '{{ file_format }}',
payload_schema = '{{ payload_schema }}',
format = '{{ format }}'
WHERE
index_id = '{{ index_id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
RETURNING
id,
destination_id,
index_id,
created_at,
created_by,
enabled,
file_format,
format,
modified_at,
modified_by,
payload_schema;

DELETE examples​

Delete an S3 data forwarding rule by its Partition or Scheduled View identifier.

DELETE FROM sumologic.logs_data_forwarding.rules
WHERE index_id = '{{ index_id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;