Class: SDM::Query

Inherits:
Object
  • Object
show all
Defined in:
lib/models/porcelain.rb

Overview

A Query is a record of a single client request to a resource, such as a SQL query. Longer-running queries including long-running SSH commands and SSH, RDP, or Kubernetes interactive sessions will return two Query records with the same identifier, one record at the start of the query and a second record upon the completion of the query with additional detail.

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(account_email: nil, account_first_name: nil, account_id: nil, account_last_name: nil, account_tags: nil, authzjson: nil, capture: nil, client_ip: nil, completed_at: nil, duration: nil, egress_node_id: nil, encrypted: nil, id: nil, identity_alias_username: nil, query_body: nil, query_category: nil, query_hash: nil, query_key: nil, record_count: nil, remote_identity_username: nil, replayable: nil, resource_id: nil, resource_name: nil, resource_tags: nil, resource_type: nil, source_ip: nil, target: nil, timestamp: nil) ⇒ Query

Returns a new instance of Query.



8465
8466
8467
8468
8469
8470
8471
8472
8473
8474
8475
8476
8477
8478
8479
8480
8481
8482
8483
8484
8485
8486
8487
8488
8489
8490
8491
8492
8493
8494
8495
8496
8497
8498
8499
8500
8501
8502
8503
8504
8505
8506
8507
8508
8509
8510
8511
8512
8513
8514
8515
8516
8517
8518
8519
8520
8521
8522
8523
# File 'lib/models/porcelain.rb', line 8465

def initialize(
  account_email: nil,
  account_first_name: nil,
  account_id: nil,
  account_last_name: nil,
  account_tags: nil,
  authzjson: nil,
  capture: nil,
  client_ip: nil,
  completed_at: nil,
  duration: nil,
  egress_node_id: nil,
  encrypted: nil,
  id: nil,
  identity_alias_username: nil,
  query_body: nil,
  query_category: nil,
  query_hash: nil,
  query_key: nil,
  record_count: nil,
  remote_identity_username: nil,
  replayable: nil,
  resource_id: nil,
  resource_name: nil,
  resource_tags: nil,
  resource_type: nil,
  source_ip: nil,
  target: nil,
  timestamp: nil
)
  @account_email =  == nil ? "" : 
  @account_first_name =  == nil ? "" : 
  @account_id =  == nil ? "" : 
  @account_last_name =  == nil ? "" : 
  @account_tags =  == nil ? SDM::_porcelain_zero_value_tags() : 
  @authzjson = authzjson == nil ? "" : authzjson
  @capture = capture == nil ? nil : capture
  @client_ip = client_ip == nil ? "" : client_ip
  @completed_at = completed_at == nil ? nil : completed_at
  @duration = duration == nil ? nil : duration
  @egress_node_id = egress_node_id == nil ? "" : egress_node_id
  @encrypted = encrypted == nil ? false : encrypted
  @id = id == nil ? "" : id
  @identity_alias_username = identity_alias_username == nil ? "" : identity_alias_username
  @query_body = query_body == nil ? "" : query_body
  @query_category = query_category == nil ? "" : query_category
  @query_hash = query_hash == nil ? "" : query_hash
  @query_key = query_key == nil ? "" : query_key
  @record_count = record_count == nil ? 0 : record_count
  @remote_identity_username = remote_identity_username == nil ? "" : remote_identity_username
  @replayable = replayable == nil ? false : replayable
  @resource_id = resource_id == nil ? "" : resource_id
  @resource_name = resource_name == nil ? "" : resource_name
  @resource_tags = resource_tags == nil ? SDM::_porcelain_zero_value_tags() : resource_tags
  @resource_type = resource_type == nil ? "" : resource_type
  @source_ip = source_ip == nil ? "" : source_ip
  @target = target == nil ? "" : target
  @timestamp = timestamp == nil ? nil : timestamp
end

Instance Attribute Details

#account_emailObject

The email of the account performing this query, at the time the query was executed. If the account email is later changed, that change will not be reflected via this field.



8398
8399
8400
# File 'lib/models/porcelain.rb', line 8398

def 
  @account_email
end

#account_first_nameObject

The given name of the account performing this query, at the time the query was executed. If the account is later renamed, that change will not be reflected via this field.



8401
8402
8403
# File 'lib/models/porcelain.rb', line 8401

def 
  @account_first_name
end

#account_idObject

Unique identifier of the Account that performed the Query.



8403
8404
8405
# File 'lib/models/porcelain.rb', line 8403

def 
  @account_id
end

#account_last_nameObject

The family name of the account performing this query, at the time the query was executed. If the account is later renamed, that change will not be reflected via this field.



8406
8407
8408
# File 'lib/models/porcelain.rb', line 8406

def 
  @account_last_name
end

#account_tagsObject

The tags of the account accessed, at the time the query was executed. If the account tags are later changed, that change will not be reflected via this field.



8409
8410
8411
# File 'lib/models/porcelain.rb', line 8409

def 
  @account_tags
end

#authzjsonObject

Authorization metadata associated with this query.



8411
8412
8413
# File 'lib/models/porcelain.rb', line 8411

def authzjson
  @authzjson
end

#captureObject

For queries against SSH, Kubernetes, and RDP resources, this contains additional information about the captured query.



8414
8415
8416
# File 'lib/models/porcelain.rb', line 8414

def capture
  @capture
end

#client_ipObject

The IP address the Query was performed from, as detected at the StrongDM control plane.



8416
8417
8418
# File 'lib/models/porcelain.rb', line 8416

def client_ip
  @client_ip
end

#completed_atObject

The time at which the Query was completed. Empty if this record indicates the start of a long-running query.



8419
8420
8421
# File 'lib/models/porcelain.rb', line 8419

def completed_at
  @completed_at
end

#durationObject

The duration of the Query.



8421
8422
8423
# File 'lib/models/porcelain.rb', line 8421

def duration
  @duration
end

#egress_node_idObject

The unique ID of the node through which the Resource was accessed.



8423
8424
8425
# File 'lib/models/porcelain.rb', line 8423

def egress_node_id
  @egress_node_id
end

#encryptedObject

Indicates that the body of the Query is encrypted.



8425
8426
8427
# File 'lib/models/porcelain.rb', line 8425

def encrypted
  @encrypted
end

#idObject

Unique identifier of the Query.



8427
8428
8429
# File 'lib/models/porcelain.rb', line 8427

def id
  @id
end

#identity_alias_usernameObject

The username of the IdentityAlias used to access the Resource.



8429
8430
8431
# File 'lib/models/porcelain.rb', line 8429

def identity_alias_username
  @identity_alias_username
end

#query_bodyObject

The captured content of the Query. For queries against SSH, Kubernetes, and RDP resources, this contains a JSON representation of the QueryCapture.



8432
8433
8434
# File 'lib/models/porcelain.rb', line 8432

def query_body
  @query_body
end

#query_categoryObject

The general category of Resource against which Query was performed, e.g. "web" or "cloud".



8434
8435
8436
# File 'lib/models/porcelain.rb', line 8434

def query_category
  @query_category
end

#query_hashObject

The hash of the body of the Query.



8436
8437
8438
# File 'lib/models/porcelain.rb', line 8436

def query_hash
  @query_hash
end

#query_keyObject

The symmetric key used to encrypt the body of this Query and its replay if replayable. If the Query is encrypted, this field contains an encrypted symmetric key in base64 encoding. This key must be decrypted with the organization's private key to obtain the symmetric key needed to decrypt the body. If the Query is not encrypted, this field is empty.



8441
8442
8443
# File 'lib/models/porcelain.rb', line 8441

def query_key
  @query_key
end

#record_countObject

The number of records returned by the Query, for a database Resource.



8443
8444
8445
# File 'lib/models/porcelain.rb', line 8443

def record_count
  @record_count
end

#remote_identity_usernameObject

The username of the RemoteIdentity used to access the Resource.



8445
8446
8447
# File 'lib/models/porcelain.rb', line 8445

def remote_identity_username
  @remote_identity_username
end

#replayableObject

Indicates that the Query is replayable, e.g. for some SSH or K8s sessions.



8447
8448
8449
# File 'lib/models/porcelain.rb', line 8447

def replayable
  @replayable
end

#resource_idObject

Unique identifier of the Resource against which the Query was performed.



8449
8450
8451
# File 'lib/models/porcelain.rb', line 8449

def resource_id
  @resource_id
end

#resource_nameObject

The name of the resource accessed, at the time the query was executed. If the resource is later renamed, that change will not be reflected via this field.



8452
8453
8454
# File 'lib/models/porcelain.rb', line 8452

def resource_name
  @resource_name
end

#resource_tagsObject

The tags of the resource accessed, at the time the query was executed. If the resource tags are later changed, that change will not be reflected via this field.



8455
8456
8457
# File 'lib/models/porcelain.rb', line 8455

def resource_tags
  @resource_tags
end

#resource_typeObject

The specific type of Resource against which the Query was performed, e.g. "ssh" or "postgres".



8457
8458
8459
# File 'lib/models/porcelain.rb', line 8457

def resource_type
  @resource_type
end

#source_ipObject

The IP address the Query was performed from, as detected at the ingress gateway.



8459
8460
8461
# File 'lib/models/porcelain.rb', line 8459

def source_ip
  @source_ip
end

#targetObject

The target destination of the query, in host:port format.



8461
8462
8463
# File 'lib/models/porcelain.rb', line 8461

def target
  @target
end

#timestampObject

The time at which the Query was started.



8463
8464
8465
# File 'lib/models/porcelain.rb', line 8463

def timestamp
  @timestamp
end

Instance Method Details

#to_json(options = {}) ⇒ Object



8525
8526
8527
8528
8529
8530
8531
# File 'lib/models/porcelain.rb', line 8525

def to_json(options = {})
  hash = {}
  self.instance_variables.each do |var|
    hash[var.id2name.delete_prefix("@")] = self.instance_variable_get var
  end
  hash.to_json
end