Skip to main content

search_audit

Creates, updates, deletes, gets or lists a search_audit resource.

Overview​

Namesearch_audit
TypeResource
Idsumologic.policies.search_audit

Fields​

The following fields are returned by SELECT queries:

The Search Audit policy.

NameDatatypeDescription
enabledbooleanWhether the Search Audit policy is enabled.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectregionGet the Search Audit policy. This policy specifies whether search records for your account are enabled. You can access details about your account's search capacity, queries run by users from the Sumo Search Audit Index. [Learn More](https:​//help.sumologic.com/Manage/Security/Search_Audit_Index)
updateupdateregion, enabledSet the Search Audit policy. This policy specifies whether search records for your account are enabled. You can access details about your account's search capacity, queries run by users from the Sumo Search Audit Index. [Learn More](https:​//help.sumologic.com/Manage/Security/Search_Audit_Index)

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
regionstringSumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT)

SELECT examples​

Get the Search Audit policy. This policy specifies whether search records for your account are enabled. You can access details about your account's search capacity, queries run by users from the Sumo Search Audit Index. Learn More

SELECT
enabled
FROM sumologic.policies.search_audit
WHERE region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
;

UPDATE examples​

Set the Search Audit policy. This policy specifies whether search records for your account are enabled. You can access details about your account's search capacity, queries run by users from the Sumo Search Audit Index. Learn More

UPDATE sumologic.policies.search_audit
SET
enabled = {{ enabled }}
WHERE
region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
AND enabled = {{ enabled }} --required
RETURNING
enabled;