|
| 1 | +""" |
| 2 | +Validate an observability pipeline with OCSF mapper custom mapping returns "OK" response |
| 3 | +""" |
| 4 | + |
| 5 | +from datadog_api_client import ApiClient, Configuration |
| 6 | +from datadog_api_client.v2.api.observability_pipelines_api import ObservabilityPipelinesApi |
| 7 | +from datadog_api_client.v2.model.observability_pipeline_config import ObservabilityPipelineConfig |
| 8 | +from datadog_api_client.v2.model.observability_pipeline_config_processor_group import ( |
| 9 | + ObservabilityPipelineConfigProcessorGroup, |
| 10 | +) |
| 11 | +from datadog_api_client.v2.model.observability_pipeline_data_attributes import ObservabilityPipelineDataAttributes |
| 12 | +from datadog_api_client.v2.model.observability_pipeline_datadog_agent_source import ( |
| 13 | + ObservabilityPipelineDatadogAgentSource, |
| 14 | +) |
| 15 | +from datadog_api_client.v2.model.observability_pipeline_datadog_agent_source_type import ( |
| 16 | + ObservabilityPipelineDatadogAgentSourceType, |
| 17 | +) |
| 18 | +from datadog_api_client.v2.model.observability_pipeline_datadog_logs_destination import ( |
| 19 | + ObservabilityPipelineDatadogLogsDestination, |
| 20 | +) |
| 21 | +from datadog_api_client.v2.model.observability_pipeline_datadog_logs_destination_type import ( |
| 22 | + ObservabilityPipelineDatadogLogsDestinationType, |
| 23 | +) |
| 24 | +from datadog_api_client.v2.model.observability_pipeline_ocsf_mapper_processor import ( |
| 25 | + ObservabilityPipelineOcsfMapperProcessor, |
| 26 | +) |
| 27 | +from datadog_api_client.v2.model.observability_pipeline_ocsf_mapper_processor_mapping import ( |
| 28 | + ObservabilityPipelineOcsfMapperProcessorMapping, |
| 29 | +) |
| 30 | +from datadog_api_client.v2.model.observability_pipeline_ocsf_mapper_processor_type import ( |
| 31 | + ObservabilityPipelineOcsfMapperProcessorType, |
| 32 | +) |
| 33 | +from datadog_api_client.v2.model.observability_pipeline_ocsf_mapping_custom import ( |
| 34 | + ObservabilityPipelineOcsfMappingCustom, |
| 35 | +) |
| 36 | +from datadog_api_client.v2.model.observability_pipeline_ocsf_mapping_custom_field_mapping import ( |
| 37 | + ObservabilityPipelineOcsfMappingCustomFieldMapping, |
| 38 | +) |
| 39 | +from datadog_api_client.v2.model.observability_pipeline_ocsf_mapping_custom_lookup import ( |
| 40 | + ObservabilityPipelineOcsfMappingCustomLookup, |
| 41 | +) |
| 42 | +from datadog_api_client.v2.model.observability_pipeline_ocsf_mapping_custom_lookup_table_entry import ( |
| 43 | + ObservabilityPipelineOcsfMappingCustomLookupTableEntry, |
| 44 | +) |
| 45 | +from datadog_api_client.v2.model.observability_pipeline_ocsf_mapping_custom_metadata import ( |
| 46 | + ObservabilityPipelineOcsfMappingCustomMetadata, |
| 47 | +) |
| 48 | +from datadog_api_client.v2.model.observability_pipeline_spec import ObservabilityPipelineSpec |
| 49 | +from datadog_api_client.v2.model.observability_pipeline_spec_data import ObservabilityPipelineSpecData |
| 50 | + |
| 51 | +body = ObservabilityPipelineSpec( |
| 52 | + data=ObservabilityPipelineSpecData( |
| 53 | + attributes=ObservabilityPipelineDataAttributes( |
| 54 | + config=ObservabilityPipelineConfig( |
| 55 | + destinations=[ |
| 56 | + ObservabilityPipelineDatadogLogsDestination( |
| 57 | + id="datadog-logs-destination", |
| 58 | + inputs=[ |
| 59 | + "my-processor-group", |
| 60 | + ], |
| 61 | + type=ObservabilityPipelineDatadogLogsDestinationType.DATADOG_LOGS, |
| 62 | + ), |
| 63 | + ], |
| 64 | + processor_groups=[ |
| 65 | + ObservabilityPipelineConfigProcessorGroup( |
| 66 | + enabled=True, |
| 67 | + id="my-processor-group", |
| 68 | + include="service:my-service", |
| 69 | + inputs=[ |
| 70 | + "datadog-agent-source", |
| 71 | + ], |
| 72 | + processors=[ |
| 73 | + ObservabilityPipelineOcsfMapperProcessor( |
| 74 | + enabled=True, |
| 75 | + id="ocsf-mapper-processor", |
| 76 | + include="service:my-service", |
| 77 | + mappings=[ |
| 78 | + ObservabilityPipelineOcsfMapperProcessorMapping( |
| 79 | + include="source:custom", |
| 80 | + mapping=ObservabilityPipelineOcsfMappingCustom( |
| 81 | + mapping=[ |
| 82 | + ObservabilityPipelineOcsfMappingCustomFieldMapping( |
| 83 | + default="", |
| 84 | + dest="time", |
| 85 | + source="timestamp", |
| 86 | + ), |
| 87 | + ObservabilityPipelineOcsfMappingCustomFieldMapping( |
| 88 | + default="", |
| 89 | + dest="severity", |
| 90 | + source="level", |
| 91 | + ), |
| 92 | + ObservabilityPipelineOcsfMappingCustomFieldMapping( |
| 93 | + default="", |
| 94 | + dest="device.type", |
| 95 | + lookup=ObservabilityPipelineOcsfMappingCustomLookup( |
| 96 | + table=[ |
| 97 | + ObservabilityPipelineOcsfMappingCustomLookupTableEntry( |
| 98 | + contains="Desktop", |
| 99 | + value="desktop", |
| 100 | + ), |
| 101 | + ], |
| 102 | + ), |
| 103 | + source="host.type", |
| 104 | + ), |
| 105 | + ], |
| 106 | + metadata=ObservabilityPipelineOcsfMappingCustomMetadata( |
| 107 | + _class="Device Inventory Info", |
| 108 | + profiles=[ |
| 109 | + "container", |
| 110 | + ], |
| 111 | + version="1.3.0", |
| 112 | + ), |
| 113 | + version=1, |
| 114 | + ), |
| 115 | + ), |
| 116 | + ], |
| 117 | + type=ObservabilityPipelineOcsfMapperProcessorType.OCSF_MAPPER, |
| 118 | + ), |
| 119 | + ], |
| 120 | + ), |
| 121 | + ], |
| 122 | + sources=[ |
| 123 | + ObservabilityPipelineDatadogAgentSource( |
| 124 | + id="datadog-agent-source", |
| 125 | + type=ObservabilityPipelineDatadogAgentSourceType.DATADOG_AGENT, |
| 126 | + ), |
| 127 | + ], |
| 128 | + ), |
| 129 | + name="OCSF Custom Mapper Pipeline", |
| 130 | + ), |
| 131 | + type="pipelines", |
| 132 | + ), |
| 133 | +) |
| 134 | + |
| 135 | +configuration = Configuration() |
| 136 | +with ApiClient(configuration) as api_client: |
| 137 | + api_instance = ObservabilityPipelinesApi(api_client) |
| 138 | + response = api_instance.validate_pipeline(body=body) |
| 139 | + |
| 140 | + print(response) |
0 commit comments