rules
Creates, updates, deletes, gets or lists a rules resource.
Overview​
| Name | rules |
| Type | Resource |
| Id | sumologic.logs_data_forwarding.rules |
Fields​
The following fields are returned by SELECT queries:
- get
- list
Data forwarding rule that was requested.
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier of the data forwarding rule. (example: 1) |
destination_id | string | The data forwarding destination id. (example: 1) (wire: destinationId) |
index_id | string | The id of the Partition or Scheduled View the rule applies to. (example: 1) (wire: indexId) |
bucket | string | (opaque JSON object) |
created_at | string (date-time) | Creation timestamp in UTC in [RFC3339](https:​//tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt) |
created_by | string | Identifier of the user who created the resource. (example: 0000000006743FDD) (wire: createdBy) |
enabled | boolean | True when the data forwarding rule is enabled. |
file_format | string | Specify the path prefix to a directory in the S3 bucket and how to format the file name. (example: {index}_{day}_{hour}_{minute}_{second}) (wire: fileFormat) |
format | string | Format of the payload. Default format will be "csv". "text" format should be used in conjunction with "raw" payloadSchema and vice-versa. (pattern: <code>^(csv|json|text)$</code>, example: csv, x-pattern-message: should be one of the following: 'csv', 'json' or 'text') |
modified_at | string (date-time) | Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt) |
modified_by | string | Identifier of the user who last modified the resource. (example: 0000000006743FE8) (wire: modifiedBy) |
payload_schema | string | Schema for the payload. Default value of the payload schema is "allFields" for scheduled view, and "builtInFields" for partition. "raw" payloadSchema should be used in conjunction with "text" format and vice-versa. (pattern: <code>^(builtInFields|allFields|raw)$</code>, example: builtInFields, x-pattern-message: should be one of the following: 'builtInFields', 'allFields' or 'raw') (wire: payloadSchema) |
List of all S3 data forwarding rules.
| Name | Datatype | Description |
|---|---|---|
id | string | The unique identifier of the data forwarding rule. (example: 1) |
destination_id | string | The data forwarding destination id. (example: 1) (wire: destinationId) |
index_id | string | The id of the Partition or Scheduled View the rule applies to. (example: 1) (wire: indexId) |
bucket | string | (opaque JSON object) |
created_at | string (date-time) | Creation timestamp in UTC in [RFC3339](https:​//tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt) |
created_by | string | Identifier of the user who created the resource. (example: 0000000006743FDD) (wire: createdBy) |
enabled | boolean | True when the data forwarding rule is enabled. |
file_format | string | Specify the path prefix to a directory in the S3 bucket and how to format the file name. (example: {index}_{day}_{hour}_{minute}_{second}) (wire: fileFormat) |
format | string | Format of the payload. Default format will be "csv". "text" format should be used in conjunction with "raw" payloadSchema and vice-versa. (pattern: <code>^(csv|json|text)$</code>, example: csv, x-pattern-message: should be one of the following: 'csv', 'json' or 'text') |
modified_at | string (date-time) | Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt) |
modified_by | string | Identifier of the user who last modified the resource. (example: 0000000006743FE8) (wire: modifiedBy) |
payload_schema | string | Schema for the payload. Default value of the payload schema is "allFields" for scheduled view, and "builtInFields" for partition. "raw" payloadSchema should be used in conjunction with "text" format and vice-versa. (pattern: <code>^(builtInFields|allFields|raw)$</code>, example: builtInFields, x-pattern-message: should be one of the following: 'builtInFields', 'allFields' or 'raw') (wire: payloadSchema) |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | index_id, region | Get the details of an S3 data forwarding rule by its Partition or Scheduled View identifier. | |
list | select | region | limit, token | Get a list of all S3 data forwarding rules. |
create | insert | region, destination_id, index_id | Create a data forwarding rule to send data from a Partition or Scheduled View to an S3 bucket. | |
update | update | index_id, region | Update an S3 data forwarding rule by its Partition or Scheduled View identifier. | |
delete | delete | index_id, region | Delete an S3 data forwarding rule by its Partition or Scheduled View identifier. |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
index_id | string | The id of the Partition or Scheduled View with the data forwarding rule to delete. (example: 1) (wire: indexId) |
region | string | Sumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT) |
limit | integer (int32) | Limit the number of data forwarding rules returned in the response. The number of data forwarding rules returned may be less than the limit. |
token | string | Continuation token to get the next page of results. A page object with the next continuation token is returned in the response body. Subsequent GET requests should specify the continuation token to get the next page of results. token is set to null when no more pages are left. |
SELECT examples​
- get
- list
Get the details of an S3 data forwarding rule by its Partition or Scheduled View identifier.
SELECT
id,
destination_id,
index_id,
bucket,
created_at,
created_by,
enabled,
file_format,
format,
modified_at,
modified_by,
payload_schema
FROM sumologic.logs_data_forwarding.rules
WHERE index_id = '{{ index_id }}' -- required
AND region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
;
Get a list of all S3 data forwarding rules.
SELECT
id,
destination_id,
index_id,
bucket,
created_at,
created_by,
enabled,
file_format,
format,
modified_at,
modified_by,
payload_schema
FROM sumologic.logs_data_forwarding.rules
WHERE region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
AND limit = '{{ limit }}'
AND token = '{{ token }}'
;
INSERT examples​
- create
- Manifest
Create a data forwarding rule to send data from a Partition or Scheduled View to an S3 bucket.
INSERT INTO sumologic.logs_data_forwarding.rules (
index_id,
destination_id,
enabled,
file_format,
payload_schema,
format,
region
)
SELECT
'{{ index_id }}' /* required */,
'{{ destination_id }}' /* required */,
{{ enabled }},
'{{ file_format }}',
'{{ payload_schema }}',
'{{ format }}',
'{{ region }}'
RETURNING
id,
destination_id,
index_id,
created_at,
created_by,
enabled,
file_format,
format,
modified_at,
modified_by,
payload_schema
;
# Description fields are for documentation purposes
- name: rules
props:
- name: region
value: "{{ region }}"
description: Required parameter for the rules resource.
- name: index_id
value: "{{ index_id }}"
description: |
The `id` of the Partition or Scheduled View the rule applies to.
- name: destination_id
value: "{{ destination_id }}"
description: |
The data forwarding destination id.
- name: enabled
value: {{ enabled }}
description: |
True when the data forwarding rule is enabled.
- name: file_format
value: "{{ file_format }}"
description: |
Specify the path prefix to a directory in the S3 bucket and how to format the file name.
- name: payload_schema
value: "{{ payload_schema }}"
description: |
Schema for the payload. Default value of the payload schema is "allFields" for scheduled view, and "builtInFields" for partition. "raw" payloadSchema should be used in conjunction with "text" format and vice-versa.
- name: format
value: "{{ format }}"
description: |
Format of the payload. Default format will be "csv". "text" format should be used in conjunction with "raw" payloadSchema and vice-versa.
UPDATE examples​
- update
Update an S3 data forwarding rule by its Partition or Scheduled View identifier.
UPDATE sumologic.logs_data_forwarding.rules
SET
destination_id = '{{ destination_id }}',
enabled = {{ enabled }},
file_format = '{{ file_format }}',
payload_schema = '{{ payload_schema }}',
format = '{{ format }}'
WHERE
index_id = '{{ index_id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
RETURNING
id,
destination_id,
index_id,
created_at,
created_by,
enabled,
file_format,
format,
modified_at,
modified_by,
payload_schema;
DELETE examples​
- delete
Delete an S3 data forwarding rule by its Partition or Scheduled View identifier.
DELETE FROM sumologic.logs_data_forwarding.rules
WHERE index_id = '{{ index_id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;