From 5154a4ebb5bc8de3cb2cf91bd2ceddad2dccc334 Mon Sep 17 00:00:00 2001 From: Michael Elrom Date: Fri, 14 Aug 2026 16:47:57 -0400 Subject: [PATCH] feat(zscaler): add ZIA Integration Model and Studio Project Adds an OpenAPI spec for Zscaler Internet Access, built from Zscaler's official SDK source and verified against real typed schemas, plus 111 workflows covering firewall policies, URL filtering, DLP, cloud app control, file type control, locations, rule labels, and user management. --- .../ZIA/OpenAPIs/zscaler_zia_api-latest.json | 24334 +++++ .../ZIA/OpenAPIs/zscaler_zia_api-v3.8.46.json | 86615 ++++++++++++++++ Zscaler/ZIA/README.md | 118 + .../Studio Projects/Zscaler ZIA.project.json | 25435 +++++ 4 files changed, 136502 insertions(+) create mode 100644 Zscaler/ZIA/OpenAPIs/zscaler_zia_api-latest.json create mode 100644 Zscaler/ZIA/OpenAPIs/zscaler_zia_api-v3.8.46.json create mode 100644 Zscaler/ZIA/README.md create mode 100644 Zscaler/ZIA/Studio Projects/Zscaler ZIA.project.json diff --git a/Zscaler/ZIA/OpenAPIs/zscaler_zia_api-latest.json b/Zscaler/ZIA/OpenAPIs/zscaler_zia_api-latest.json new file mode 100644 index 0000000..4f652b0 --- /dev/null +++ b/Zscaler/ZIA/OpenAPIs/zscaler_zia_api-latest.json @@ -0,0 +1,24334 @@ +{ + "openapi": "3.0.0", + "info": { + "version": "latest", + "x-vendor-api-version": "ZIA REST API v1 (via OneAPI)", + "title": "Zscaler Internet Access (ZIA) API", + "description": "Zscaler Internet Access (ZIA) API provides programmatic access to ZIA policy and configuration objects: firewall filtering rules and their supporting objects, URL filtering and categories, cloud app control, DLP dictionaries/engines/rules, file type control rules, locations, rule labels, and user/group/department management.\n\nAuthentication: OAuth2 client-credentials via Zscaler's unified OneAPI platform (brokered through Zidentity). Requires OneAPI access to be enabled for your organization by your Zscaler account team -- it is not self-service. Generate a client ID/secret at Admin Portal > API Key Management > OneAPI Credentials.\n\nThis spec was built directly from Zscaler's official, actively-maintained zscaler-sdk-go source (github.com/zscaler/zscaler-sdk-go) -- endpoint paths, HTTP verbs, and field-level request/response schemas (including per-field doc comments) were extracted from the SDK's typed Go structs and service functions.\n\nSource: https://github.com/zscaler/zscaler-sdk-go/tree/master/zscaler/zia/services", + "x-itential-curated": "Scoped to ZIA's most commonly automated policy/config areas rather than its full 60+ service surface: Firewall Policies (filtering rules and supporting objects -- network services/applications, IP source/destination groups, time windows, app services), URL Filtering & Categories, Cloud App Control, DLP (dictionaries, engines, web rules, notification templates, ICAP servers), File Type Control, Locations, Rule Labels, and User Management (users, groups, departments) -- 111 operations, all traced to real endpoint constants and typed request/response structs in Zscaler's official SDK. Excludes DNS control, forwarding control, IPS/NAT control, SSL inspection, sandbox, traffic forwarding/GRE, NSS feeds, malware protection, bandwidth control, and ~50 other more specialized ZIA service areas." + }, + "servers": [ + { + "url": "https://api.zsapi.net", + "description": "Default (production) OneAPI host. Non-production clouds use https://api..zsapi.net." + } + ], + "security": [ + { + "oneApiOAuth2": [] + } + ], + "paths": { + "/zia/api/v1/advancedUrlFilterAndCloudAppSettings": { + "get": { + "operationId": "urlfilteringpolicies_GetUrlAndAppSettings", + "summary": "GetUrlAndAppSettings (URL Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "urlfilteringpolicies_UpdateUrlAndAppSettings", + "summary": "UpdateUrlAndAppSettings (URL Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + } + }, + "/zia/api/v1/appServiceGroups/lite": { + "get": { + "operationId": "appservicegroups_GetByName", + "summary": "GetByName (App Service Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "nameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/appServices/lite": { + "get": { + "operationId": "applicationservices_GetByName", + "summary": "GetByName (App Service)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "nameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/customFileTypes": { + "get": { + "operationId": "filetypecontrol_GetCustomFileTypes", + "summary": "GetCustomFileTypes (File Type Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/departments": { + "post": { + "operationId": "departments_Create", + "summary": "Create (Department)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "get": { + "operationId": "departments_GetAll", + "summary": "GetAll (Department)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/departments/{id}": { + "get": { + "operationId": "departments_GetDepartments", + "summary": "GetDepartments (Department)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "departments_Update", + "summary": "Update (Department)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "delete": { + "operationId": "departments_Delete", + "summary": "Delete (Department)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dlpDictionaries": { + "get": { + "operationId": "dlpdictionaries_GetByName", + "summary": "GetByName (DLP Dictionary)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "dlpdictionaries_Create", + "summary": "Create (DLP Dictionary)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpDictionaries/{id}": { + "get": { + "operationId": "dlpdictionaries_Get", + "summary": "Get (DLP Dictionary)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "dlpdictionaries_Update", + "summary": "Update (DLP Dictionary)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + }, + "delete": { + "operationId": "dlpdictionaries_DeleteDlpDictionary", + "summary": "DeleteDlpDictionary (DLP Dictionary)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dlpEngines": { + "post": { + "operationId": "dlp_engines_Create", + "summary": "Create (DLP Engine)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "get": { + "operationId": "dlp_engines_GetAll", + "summary": "GetAll (DLP Engine)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpEngines/lite": { + "get": { + "operationId": "dlp_engines_GetAllEngineLite", + "summary": "GetAllEngineLite (DLP Engine)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpEngines/{id}": { + "get": { + "operationId": "dlp_engines_Get", + "summary": "Get (DLP Engine)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "dlp_engines_Update", + "summary": "Update (DLP Engine)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "delete": { + "operationId": "dlp_engines_Delete", + "summary": "Delete (DLP Engine)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dlpNotificationTemplates": { + "get": { + "operationId": "dlp_notification_templates_GetByName", + "summary": "GetByName (DLP Notification Template)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "dlp_notification_templates_Create", + "summary": "Create (DLP Notification Template)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpNotificationTemplates/{id}": { + "get": { + "operationId": "dlp_notification_templates_Get", + "summary": "Get (DLP Notification Template)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "dlp_notification_templates_Update", + "summary": "Update (DLP Notification Template)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + }, + "delete": { + "operationId": "dlp_notification_templates_Delete", + "summary": "Delete (DLP Notification Template)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/fileTypeCategories": { + "get": { + "operationId": "filetypecontrol_GetFileTypeCategories", + "summary": "GetFileTypeCategories (File Type Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/fileTypeRules": { + "get": { + "operationId": "filetypecontrol_GetByName", + "summary": "GetByName (File Type Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "filetypecontrol_Create", + "summary": "Create (File Type Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + } + }, + "/zia/api/v1/fileTypeRules/{id}": { + "get": { + "operationId": "filetypecontrol_Get", + "summary": "Get (File Type Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "filetypecontrol_Update", + "summary": "Update (File Type Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "delete": { + "operationId": "filetypecontrol_Delete", + "summary": "Delete (File Type Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/firewallFilteringRules": { + "post": { + "operationId": "filteringrules_Create", + "summary": "Create (Firewall Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "get": { + "operationId": "filteringrules_GetAll", + "summary": "GetAll (Firewall Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/firewallFilteringRules/{id}": { + "get": { + "operationId": "filteringrules_Get", + "summary": "Get (Firewall Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "filteringrules_Update", + "summary": "Update (Firewall Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "filteringrules_Delete", + "summary": "Delete (Firewall Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/groups": { + "post": { + "operationId": "groups_Create", + "summary": "Create (Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "get": { + "operationId": "groups_GetAllGroups", + "summary": "GetAllGroups (Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/groups/{id}": { + "get": { + "operationId": "groups_GetGroups", + "summary": "GetGroups (Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "groups_Update", + "summary": "Update (Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "delete": { + "operationId": "groups_Delete", + "summary": "Delete (Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/icapServers": { + "get": { + "operationId": "dlp_icap_servers_GetByName", + "summary": "GetByName (DLP ICAP Server)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP server." + }, + "name": { + "type": "string", + "description": "The DLP server name." + }, + "url": { + "type": "string", + "description": "The DLP server URL." + }, + "status": { + "type": "string", + "description": "The DLP server status" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/icapServers/{id}": { + "get": { + "operationId": "dlp_icap_servers_Get", + "summary": "Get (DLP ICAP Server)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP server." + }, + "name": { + "type": "string", + "description": "The DLP server name." + }, + "url": { + "type": "string", + "description": "The DLP server URL." + }, + "status": { + "type": "string", + "description": "The DLP server status" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/ipDestinationGroups": { + "post": { + "operationId": "ipdestinationgroups_Create", + "summary": "Create (IP Destination Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "get": { + "operationId": "ipdestinationgroups_GetAll", + "summary": "GetAll (IP Destination Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/ipDestinationGroups/{id}": { + "get": { + "operationId": "ipdestinationgroups_Get", + "summary": "Get (IP Destination Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "ipdestinationgroups_Update", + "summary": "Update (IP Destination Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "delete": { + "operationId": "ipdestinationgroups_Delete", + "summary": "Delete (IP Destination Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/ipSourceGroups": { + "get": { + "operationId": "ipsourcegroups_GetByName", + "summary": "GetByName (IP Source Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "ipsourcegroups_Create", + "summary": "Create (IP Source Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + } + }, + "/zia/api/v1/ipSourceGroups/{id}": { + "get": { + "operationId": "ipsourcegroups_Get", + "summary": "Get (IP Source Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "ipsourcegroups_Update", + "summary": "Update (IP Source Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "delete": { + "operationId": "ipsourcegroups_Delete", + "summary": "Delete (IP Source Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/locations": { + "post": { + "operationId": "locationmanagement_Create", + "summary": "Create (Location)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "get": { + "operationId": "locationmanagement_GetAll", + "summary": "GetAll (Location)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/locations/groups": { + "get": { + "operationId": "locationgroups_GetGroupType", + "summary": "GetGroupType (Location Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the location group" + }, + "name": { + "type": "string", + "description": "Location group name" + }, + "deleted": { + "type": "boolean", + "description": "Indicates the location group was deleted" + }, + "groupType": { + "type": "string", + "description": "The location group's type (i.e., Static or Dynamic)" + }, + "dynamicLocationGroupCriteria": { + "type": "object", + "properties": { + "name": { + "type": "object", + "properties": { + "matchString": { + "type": "string", + "description": "String value to be matched or partially matched" + }, + "matchType": { + "type": "string", + "description": "Operator that performs match action" + } + }, + "description": "A sub-string to match location name. Valid operators are contains, starts with, and ends with\"," + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "One or more countries from a predefined set" + }, + "city": { + "type": "object", + "properties": { + "matchString": { + "type": "string", + "description": "String value to be matched or partially matched" + }, + "matchType": { + "type": "string", + "description": "Operator that performs match action" + } + }, + "description": "A sub-string to match city. Valid operators are starts with, ends with, contains, and exact match operators." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "One or more values from a predefined set of SD-WAN partner list to display partner names." + }, + "enforceAuthentication": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "enforceAup": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location." + }, + "enforceFirewallControl": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "enableXffForwarding": { + "type": "boolean", + "description": "Enable XFF Forwarding. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header." + }, + "enableCaution": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location." + }, + "enableBandwidthControl": { + "type": "boolean", + "description": "Enable Bandwidth Control. When set to true, Bandwidth Control is enabled for the location." + }, + "profiles": { + "type": "array", + "items": { + "type": "string" + }, + "description": "One or more location profiles from a predefined set" + } + }, + "description": "A dynamic location group's criteria. This is ignored if the groupType is Static." + }, + "comments": { + "type": "string", + "description": "Additional information about the location group" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of the locations that are assigned to the static location group. This is ignored if the groupType is Dynamic." + }, + "lastModUser": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Automatically populated with the current ZIA admin user, after a successful POST or PUT request." + }, + "lastModTime": { + "type": "integer", + "description": "Automatically populated with the current time, after a successful POST or PUT request." + }, + "predefined": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/locations/groups/{id}": { + "get": { + "operationId": "locationgroups_GetLocationGroup", + "summary": "GetLocationGroup (Location Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the location group" + }, + "name": { + "type": "string", + "description": "Location group name" + }, + "deleted": { + "type": "boolean", + "description": "Indicates the location group was deleted" + }, + "groupType": { + "type": "string", + "description": "The location group's type (i.e., Static or Dynamic)" + }, + "dynamicLocationGroupCriteria": { + "type": "object", + "properties": { + "name": { + "type": "object", + "properties": { + "matchString": { + "type": "string", + "description": "String value to be matched or partially matched" + }, + "matchType": { + "type": "string", + "description": "Operator that performs match action" + } + }, + "description": "A sub-string to match location name. Valid operators are contains, starts with, and ends with\"," + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "One or more countries from a predefined set" + }, + "city": { + "type": "object", + "properties": { + "matchString": { + "type": "string", + "description": "String value to be matched or partially matched" + }, + "matchType": { + "type": "string", + "description": "Operator that performs match action" + } + }, + "description": "A sub-string to match city. Valid operators are starts with, ends with, contains, and exact match operators." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "One or more values from a predefined set of SD-WAN partner list to display partner names." + }, + "enforceAuthentication": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "enforceAup": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location." + }, + "enforceFirewallControl": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "enableXffForwarding": { + "type": "boolean", + "description": "Enable XFF Forwarding. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header." + }, + "enableCaution": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location." + }, + "enableBandwidthControl": { + "type": "boolean", + "description": "Enable Bandwidth Control. When set to true, Bandwidth Control is enabled for the location." + }, + "profiles": { + "type": "array", + "items": { + "type": "string" + }, + "description": "One or more location profiles from a predefined set" + } + }, + "description": "A dynamic location group's criteria. This is ignored if the groupType is Static." + }, + "comments": { + "type": "string", + "description": "Additional information about the location group" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of the locations that are assigned to the static location group. This is ignored if the groupType is Dynamic." + }, + "lastModUser": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Automatically populated with the current ZIA admin user, after a successful POST or PUT request." + }, + "lastModTime": { + "type": "integer", + "description": "Automatically populated with the current time, after a successful POST or PUT request." + }, + "predefined": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/locations/{id}": { + "get": { + "operationId": "locationmanagement_GetLocation", + "summary": "GetLocation (Location)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "locationmanagement_Update", + "summary": "Update (Location)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "locationmanagement_Delete", + "summary": "Delete (Location)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/locations/{id}/sublocations": { + "get": { + "operationId": "locationmanagement_GetSublocations", + "summary": "GetSublocations (Location)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/networkApplicationGroups": { + "get": { + "operationId": "networkapplicationgroups_GetNetworkApplicationGroupsByName", + "summary": "GetNetworkApplicationGroupsByName (Network Application Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "networkapplicationgroups_Create", + "summary": "Create (Network Application Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + } + }, + "/zia/api/v1/networkApplicationGroups/{id}": { + "get": { + "operationId": "networkapplicationgroups_GetNetworkApplicationGroups", + "summary": "GetNetworkApplicationGroups (Network Application Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "networkapplicationgroups_Update", + "summary": "Update (Network Application Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "delete": { + "operationId": "networkapplicationgroups_Delete", + "summary": "Delete (Network Application Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/networkApplications": { + "get": { + "operationId": "networkapplications_GetByName", + "summary": "GetByName (Network Application)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "parentCategory": { + "type": "string" + }, + "description": { + "type": "string" + }, + "deprecated": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/networkApplications/{id}": { + "get": { + "operationId": "networkapplications_GetNetworkApplication", + "summary": "GetNetworkApplication (Network Application)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "parentCategory": { + "type": "string" + }, + "description": { + "type": "string" + }, + "deprecated": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/networkServiceGroups": { + "get": { + "operationId": "networkservicegroups_GetNetworkServiceGroupsByName", + "summary": "GetNetworkServiceGroupsByName (Network Service Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "networkservicegroups_CreateNetworkServiceGroups", + "summary": "CreateNetworkServiceGroups (Network Service Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + } + }, + "/zia/api/v1/networkServiceGroups/{id}": { + "get": { + "operationId": "networkservicegroups_GetNetworkServiceGroups", + "summary": "GetNetworkServiceGroups (Network Service Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "networkservicegroups_UpdateNetworkServiceGroups", + "summary": "UpdateNetworkServiceGroups (Network Service Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "delete": { + "operationId": "networkservicegroups_DeleteNetworkServiceGroups", + "summary": "DeleteNetworkServiceGroups (Network Service Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/networkServices": { + "get": { + "operationId": "networkservices_GetByName", + "summary": "GetByName (Network Service)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "networkservices_Create", + "summary": "Create (Network Service)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "/zia/api/v1/networkServices/{id}": { + "get": { + "operationId": "networkservices_Get", + "summary": "Get (Network Service)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "networkservices_Update", + "summary": "Update (Network Service)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + }, + "delete": { + "operationId": "networkservices_Delete", + "summary": "Delete (Network Service)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/ruleLabels": { + "post": { + "operationId": "rule_labels_Create", + "summary": "Create (Rule Label)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "get": { + "operationId": "rule_labels_GetAll", + "summary": "GetAll (Rule Label)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/ruleLabels/{id}": { + "get": { + "operationId": "rule_labels_Get", + "summary": "Get (Rule Label)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "rule_labels_Update", + "summary": "Update (Rule Label)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "delete": { + "operationId": "rule_labels_Delete", + "summary": "Delete (Rule Label)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/timeWindows": { + "get": { + "operationId": "timewindow_GetAll", + "summary": "GetAll (Time Window)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "startTime": { + "type": "integer" + }, + "endTime": { + "type": "integer" + }, + "dayOfWeek": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/urlCategories": { + "get": { + "operationId": "urlcategories_GetCustomURLCategories", + "summary": "GetCustomURLCategories (URL Category)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "urlcategories_CreateURLCategories", + "summary": "CreateURLCategories (URL Category)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + } + }, + "/zia/api/v1/urlCategories/{id}": { + "get": { + "operationId": "urlcategories_Get", + "summary": "Get (URL Category)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "urlcategories_UpdateURLCategories", + "summary": "UpdateURLCategories (URL Category)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + }, + "delete": { + "operationId": "urlcategories_DeleteURLCategories", + "summary": "DeleteURLCategories (URL Category)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/urlFilteringRules": { + "get": { + "operationId": "urlfilteringpolicies_GetByName", + "summary": "GetByName (URL Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "urlfilteringpolicies_Create", + "summary": "Create (URL Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + } + }, + "/zia/api/v1/urlFilteringRules/{id}": { + "get": { + "operationId": "urlfilteringpolicies_Get", + "summary": "Get (URL Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "urlfilteringpolicies_Update", + "summary": "Update (URL Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "delete": { + "operationId": "urlfilteringpolicies_Delete", + "summary": "Delete (URL Filtering Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/users": { + "post": { + "operationId": "users_Create", + "summary": "Create (User)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "get": { + "operationId": "users_GetAllUsers", + "summary": "GetAllUsers (User)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/users/{id}": { + "get": { + "operationId": "users_Get", + "summary": "Get (User)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "users_Update", + "summary": "Update (User)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "delete": { + "operationId": "users_Delete", + "summary": "Delete (User)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/webApplicationRules": { + "get": { + "operationId": "cloudappcontrol_GetRuleTypeMapping", + "summary": "GetRuleTypeMapping (Web Application Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/webApplicationRules/{ruleType}": { + "get": { + "operationId": "cloudappcontrol_GetByRuleType", + "summary": "GetByRuleType (Web Application Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "ruleType", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "post": { + "operationId": "cloudappcontrol_Create", + "summary": "Create (Web Application Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "ruleType", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + } + }, + "/zia/api/v1/webApplicationRules/{ruleType}/{ruleId}": { + "get": { + "operationId": "cloudappcontrol_GetByRuleID", + "summary": "GetByRuleID (Web Application Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "ruleType", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "ruleId", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "cloudappcontrol_Update", + "summary": "Update (Web Application Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "ruleType", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "ruleId", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "delete": { + "operationId": "cloudappcontrol_Delete", + "summary": "Delete (Web Application Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "ruleType", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "ruleId", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/webDlpRules": { + "get": { + "operationId": "dlp_web_rules_GetByName", + "summary": "GetByName (DLP Web Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "dlp_web_rules_Create", + "summary": "Create (DLP Web Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "/zia/api/v1/webDlpRules/{id}": { + "get": { + "operationId": "dlp_web_rules_Get", + "summary": "Get (DLP Web Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "dlp_web_rules_Update", + "summary": "Update (DLP Web Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "delete": { + "operationId": "dlp_web_rules_Delete", + "summary": "Delete (DLP Web Rule)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + } + }, + "components": { + "securitySchemes": { + "oneApiOAuth2": { + "type": "oauth2", + "description": "OneAPI OAuth2 client-credentials flow via Zidentity. Token URL uses your organization's vanity domain: https://.zslogin.net/oauth2/v1/token. The token request also requires a fixed audience parameter (audience=https://api.zscaler.com) alongside client_id/client_secret -- configure this as an extra static token-request parameter on the integration if your platform version supports it.", + "flows": { + "clientCredentials": { + "tokenUrl": "https://VANITY-DOMAIN.zslogin.net/oauth2/v1/token", + "scopes": {} + } + } + } + } + } +} \ No newline at end of file diff --git a/Zscaler/ZIA/OpenAPIs/zscaler_zia_api-v3.8.46.json b/Zscaler/ZIA/OpenAPIs/zscaler_zia_api-v3.8.46.json new file mode 100644 index 0000000..55e4104 --- /dev/null +++ b/Zscaler/ZIA/OpenAPIs/zscaler_zia_api-v3.8.46.json @@ -0,0 +1,86615 @@ +{ + "openapi": "3.0.0", + "info": { + "version": "3.8.46", + "x-vendor-api-version": "zscaler-sdk-go v3.8.46", + "title": "Zscaler Internet Access (ZIA) API", + "description": "Full Zscaler Internet Access (ZIA) API surface, extracted from Zscaler's official zscaler-sdk-go source (github.com/zscaler/zscaler-sdk-go, release v3.8.46) -- endpoint paths, HTTP verbs, and field-level request/response schemas were derived directly from the SDK's typed Go structs and service functions. Preserved as-is (uncurated) for reference; see zscaler_zia_api-latest.json for the curated subset covering common CRUD automation.\n\nAuthentication: OAuth2 client-credentials via Zscaler's unified OneAPI platform (brokered through Zidentity), or legacy per-product obfuscated-API-key + session-cookie auth (not modeled here).\n\nSource: https://github.com/zscaler/zscaler-sdk-go/tree/v3.8.46/zscaler/zia/services" + }, + "servers": [ + { + "url": "https://api.zsapi.net" + } + ], + "security": [ + { + "oneApiOAuth2": [] + } + ], + "paths": { + "/zia/api/v1/adaptiveAccessProfiles": { + "get": { + "operationId": "adaptive_access_GetProfileRules", + "summary": "GetProfileRules (Adaptive Access)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The Adaptive Access profile ID" + }, + "name": { + "type": "string", + "description": "The Adaptive Access profile name" + }, + "type": { + "type": "string", + "description": "The Adaptive Access profile type" + }, + "aapIndex": { + "type": "integer", + "description": "The Adaptive Access profile index" + }, + "iamAapId": { + "type": "string", + "description": "The Adaptive Access profile ID that is used by the API for policy configuration.\nThis field allows you to specify which Adaptive Access profiles are applied in the access policy criteria." + }, + "deleted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the Adaptive Access profile is deleted" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/adminRoles": { + "get": { + "operationId": "adminuserrolemgmt__roles_GetByName", + "summary": "GetByName (Adminuserrolemgmt / Roles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin role Id" + }, + "rank": { + "type": "integer", + "description": "Admin rank of this admin role. This is applicable only when admin rank is enabled in the advanced settings. Default value is 7 (the lowest rank). The assigned admin rank determines the roles or admin users this user can manage, and which rule orders this admin can access." + }, + "name": { + "type": "string", + "description": "Name of the admin role" + }, + "policyAccess": { + "type": "string", + "description": "Policy access permission" + }, + "alertingAccess": { + "type": "string", + "description": "Alerting access permission" + }, + "usernameAccess": { + "type": "string", + "description": "Username access permission. When set to NONE, the username will be obfuscated" + }, + "deviceInfoAccess": { + "type": "string", + "description": "Device information access permission. When set to NONE, device information is obfuscated." + }, + "dashboardAccess": { + "type": "string", + "description": "Dashboard access permission" + }, + "reportAccess": { + "type": "string", + "description": "Report access permission" + }, + "analysisAccess": { + "type": "string", + "description": "Insights logs access permission" + }, + "adminAcctAccess": { + "type": "string", + "description": "Admin and role management access permission" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether this is an auditor role" + }, + "permissions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of functional areas to which this role has access. This attribute is subject to change" + }, + "featurePermissions": { + "type": "object", + "description": "Feature access permission. Indicates which features an admin role can access and if the admin has both read and write access, or read-only access." + }, + "extFeaturePermissions": { + "type": "object", + "description": "External feature access permission." + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not this admin user is editable/deletable" + }, + "logsLimit": { + "type": "string", + "description": "Log range limit" + }, + "roleType": { + "type": "string", + "description": "The admin role type. ()This attribute is subject to change.)" + }, + "reportTimeDuration": { + "type": "integer", + "description": "The admin role type. ()This attribute is subject to change.)" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "adminuserrolemgmt__roles_Create", + "summary": "Create (Adminuserrolemgmt / Roles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin role Id" + }, + "rank": { + "type": "integer", + "description": "Admin rank of this admin role. This is applicable only when admin rank is enabled in the advanced settings. Default value is 7 (the lowest rank). The assigned admin rank determines the roles or admin users this user can manage, and which rule orders this admin can access." + }, + "name": { + "type": "string", + "description": "Name of the admin role" + }, + "policyAccess": { + "type": "string", + "description": "Policy access permission" + }, + "alertingAccess": { + "type": "string", + "description": "Alerting access permission" + }, + "usernameAccess": { + "type": "string", + "description": "Username access permission. When set to NONE, the username will be obfuscated" + }, + "deviceInfoAccess": { + "type": "string", + "description": "Device information access permission. When set to NONE, device information is obfuscated." + }, + "dashboardAccess": { + "type": "string", + "description": "Dashboard access permission" + }, + "reportAccess": { + "type": "string", + "description": "Report access permission" + }, + "analysisAccess": { + "type": "string", + "description": "Insights logs access permission" + }, + "adminAcctAccess": { + "type": "string", + "description": "Admin and role management access permission" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether this is an auditor role" + }, + "permissions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of functional areas to which this role has access. This attribute is subject to change" + }, + "featurePermissions": { + "type": "object", + "description": "Feature access permission. Indicates which features an admin role can access and if the admin has both read and write access, or read-only access." + }, + "extFeaturePermissions": { + "type": "object", + "description": "External feature access permission." + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not this admin user is editable/deletable" + }, + "logsLimit": { + "type": "string", + "description": "Log range limit" + }, + "roleType": { + "type": "string", + "description": "The admin role type. ()This attribute is subject to change.)" + }, + "reportTimeDuration": { + "type": "integer", + "description": "The admin role type. ()This attribute is subject to change.)" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin role Id" + }, + "rank": { + "type": "integer", + "description": "Admin rank of this admin role. This is applicable only when admin rank is enabled in the advanced settings. Default value is 7 (the lowest rank). The assigned admin rank determines the roles or admin users this user can manage, and which rule orders this admin can access." + }, + "name": { + "type": "string", + "description": "Name of the admin role" + }, + "policyAccess": { + "type": "string", + "description": "Policy access permission" + }, + "alertingAccess": { + "type": "string", + "description": "Alerting access permission" + }, + "usernameAccess": { + "type": "string", + "description": "Username access permission. When set to NONE, the username will be obfuscated" + }, + "deviceInfoAccess": { + "type": "string", + "description": "Device information access permission. When set to NONE, device information is obfuscated." + }, + "dashboardAccess": { + "type": "string", + "description": "Dashboard access permission" + }, + "reportAccess": { + "type": "string", + "description": "Report access permission" + }, + "analysisAccess": { + "type": "string", + "description": "Insights logs access permission" + }, + "adminAcctAccess": { + "type": "string", + "description": "Admin and role management access permission" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether this is an auditor role" + }, + "permissions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of functional areas to which this role has access. This attribute is subject to change" + }, + "featurePermissions": { + "type": "object", + "description": "Feature access permission. Indicates which features an admin role can access and if the admin has both read and write access, or read-only access." + }, + "extFeaturePermissions": { + "type": "object", + "description": "External feature access permission." + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not this admin user is editable/deletable" + }, + "logsLimit": { + "type": "string", + "description": "Log range limit" + }, + "roleType": { + "type": "string", + "description": "The admin role type. ()This attribute is subject to change.)" + }, + "reportTimeDuration": { + "type": "integer", + "description": "The admin role type. ()This attribute is subject to change.)" + } + } + } + } + } + } + } + }, + "/zia/api/v1/adminRoles/{id}": { + "get": { + "operationId": "adminuserrolemgmt__roles_Get", + "summary": "Get (Adminuserrolemgmt / Roles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin role Id" + }, + "rank": { + "type": "integer", + "description": "Admin rank of this admin role. This is applicable only when admin rank is enabled in the advanced settings. Default value is 7 (the lowest rank). The assigned admin rank determines the roles or admin users this user can manage, and which rule orders this admin can access." + }, + "name": { + "type": "string", + "description": "Name of the admin role" + }, + "policyAccess": { + "type": "string", + "description": "Policy access permission" + }, + "alertingAccess": { + "type": "string", + "description": "Alerting access permission" + }, + "usernameAccess": { + "type": "string", + "description": "Username access permission. When set to NONE, the username will be obfuscated" + }, + "deviceInfoAccess": { + "type": "string", + "description": "Device information access permission. When set to NONE, device information is obfuscated." + }, + "dashboardAccess": { + "type": "string", + "description": "Dashboard access permission" + }, + "reportAccess": { + "type": "string", + "description": "Report access permission" + }, + "analysisAccess": { + "type": "string", + "description": "Insights logs access permission" + }, + "adminAcctAccess": { + "type": "string", + "description": "Admin and role management access permission" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether this is an auditor role" + }, + "permissions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of functional areas to which this role has access. This attribute is subject to change" + }, + "featurePermissions": { + "type": "object", + "description": "Feature access permission. Indicates which features an admin role can access and if the admin has both read and write access, or read-only access." + }, + "extFeaturePermissions": { + "type": "object", + "description": "External feature access permission." + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not this admin user is editable/deletable" + }, + "logsLimit": { + "type": "string", + "description": "Log range limit" + }, + "roleType": { + "type": "string", + "description": "The admin role type. ()This attribute is subject to change.)" + }, + "reportTimeDuration": { + "type": "integer", + "description": "The admin role type. ()This attribute is subject to change.)" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "adminuserrolemgmt__roles_Update", + "summary": "Update (Adminuserrolemgmt / Roles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin role Id" + }, + "rank": { + "type": "integer", + "description": "Admin rank of this admin role. This is applicable only when admin rank is enabled in the advanced settings. Default value is 7 (the lowest rank). The assigned admin rank determines the roles or admin users this user can manage, and which rule orders this admin can access." + }, + "name": { + "type": "string", + "description": "Name of the admin role" + }, + "policyAccess": { + "type": "string", + "description": "Policy access permission" + }, + "alertingAccess": { + "type": "string", + "description": "Alerting access permission" + }, + "usernameAccess": { + "type": "string", + "description": "Username access permission. When set to NONE, the username will be obfuscated" + }, + "deviceInfoAccess": { + "type": "string", + "description": "Device information access permission. When set to NONE, device information is obfuscated." + }, + "dashboardAccess": { + "type": "string", + "description": "Dashboard access permission" + }, + "reportAccess": { + "type": "string", + "description": "Report access permission" + }, + "analysisAccess": { + "type": "string", + "description": "Insights logs access permission" + }, + "adminAcctAccess": { + "type": "string", + "description": "Admin and role management access permission" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether this is an auditor role" + }, + "permissions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of functional areas to which this role has access. This attribute is subject to change" + }, + "featurePermissions": { + "type": "object", + "description": "Feature access permission. Indicates which features an admin role can access and if the admin has both read and write access, or read-only access." + }, + "extFeaturePermissions": { + "type": "object", + "description": "External feature access permission." + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not this admin user is editable/deletable" + }, + "logsLimit": { + "type": "string", + "description": "Log range limit" + }, + "roleType": { + "type": "string", + "description": "The admin role type. ()This attribute is subject to change.)" + }, + "reportTimeDuration": { + "type": "integer", + "description": "The admin role type. ()This attribute is subject to change.)" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin role Id" + }, + "rank": { + "type": "integer", + "description": "Admin rank of this admin role. This is applicable only when admin rank is enabled in the advanced settings. Default value is 7 (the lowest rank). The assigned admin rank determines the roles or admin users this user can manage, and which rule orders this admin can access." + }, + "name": { + "type": "string", + "description": "Name of the admin role" + }, + "policyAccess": { + "type": "string", + "description": "Policy access permission" + }, + "alertingAccess": { + "type": "string", + "description": "Alerting access permission" + }, + "usernameAccess": { + "type": "string", + "description": "Username access permission. When set to NONE, the username will be obfuscated" + }, + "deviceInfoAccess": { + "type": "string", + "description": "Device information access permission. When set to NONE, device information is obfuscated." + }, + "dashboardAccess": { + "type": "string", + "description": "Dashboard access permission" + }, + "reportAccess": { + "type": "string", + "description": "Report access permission" + }, + "analysisAccess": { + "type": "string", + "description": "Insights logs access permission" + }, + "adminAcctAccess": { + "type": "string", + "description": "Admin and role management access permission" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether this is an auditor role" + }, + "permissions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of functional areas to which this role has access. This attribute is subject to change" + }, + "featurePermissions": { + "type": "object", + "description": "Feature access permission. Indicates which features an admin role can access and if the admin has both read and write access, or read-only access." + }, + "extFeaturePermissions": { + "type": "object", + "description": "External feature access permission." + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not this admin user is editable/deletable" + }, + "logsLimit": { + "type": "string", + "description": "Log range limit" + }, + "roleType": { + "type": "string", + "description": "The admin role type. ()This attribute is subject to change.)" + }, + "reportTimeDuration": { + "type": "integer", + "description": "The admin role type. ()This attribute is subject to change.)" + } + } + } + } + } + } + }, + "delete": { + "operationId": "adminuserrolemgmt__roles_Delete", + "summary": "Delete (Adminuserrolemgmt / Roles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin role Id" + }, + "rank": { + "type": "integer", + "description": "Admin rank of this admin role. This is applicable only when admin rank is enabled in the advanced settings. Default value is 7 (the lowest rank). The assigned admin rank determines the roles or admin users this user can manage, and which rule orders this admin can access." + }, + "name": { + "type": "string", + "description": "Name of the admin role" + }, + "policyAccess": { + "type": "string", + "description": "Policy access permission" + }, + "alertingAccess": { + "type": "string", + "description": "Alerting access permission" + }, + "usernameAccess": { + "type": "string", + "description": "Username access permission. When set to NONE, the username will be obfuscated" + }, + "deviceInfoAccess": { + "type": "string", + "description": "Device information access permission. When set to NONE, device information is obfuscated." + }, + "dashboardAccess": { + "type": "string", + "description": "Dashboard access permission" + }, + "reportAccess": { + "type": "string", + "description": "Report access permission" + }, + "analysisAccess": { + "type": "string", + "description": "Insights logs access permission" + }, + "adminAcctAccess": { + "type": "string", + "description": "Admin and role management access permission" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether this is an auditor role" + }, + "permissions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of functional areas to which this role has access. This attribute is subject to change" + }, + "featurePermissions": { + "type": "object", + "description": "Feature access permission. Indicates which features an admin role can access and if the admin has both read and write access, or read-only access." + }, + "extFeaturePermissions": { + "type": "object", + "description": "External feature access permission." + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not this admin user is editable/deletable" + }, + "logsLimit": { + "type": "string", + "description": "Log range limit" + }, + "roleType": { + "type": "string", + "description": "The admin role type. ()This attribute is subject to change.)" + }, + "reportTimeDuration": { + "type": "integer", + "description": "The admin role type. ()This attribute is subject to change.)" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/adminUsers": { + "post": { + "operationId": "adminuserrolemgmt__admins_CreateAdminUser", + "summary": "CreateAdminUser (Adminuserrolemgmt / Admins)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin or auditor's user ID" + }, + "loginName": { + "type": "string", + "description": "Admin or auditor's login name. loginName is in email format and uses the domain name associated to the Zscaler account" + }, + "userName": { + "type": "string", + "description": "Admin or auditor's username" + }, + "email": { + "type": "string", + "description": "Admin or auditor's email address" + }, + "comments": { + "type": "string", + "description": "Additional information about the admin or auditor" + }, + "disabled": { + "type": "boolean", + "description": "Indicates whether or not the admin account is disabled" + }, + "password": { + "type": "string", + "description": "The admin's password. If admin single sign-on (SSO) is disabled, then this field is mandatory for POST requests. This information is not provided in a GET response.\"" + }, + "pwdLastModifiedTime": { + "type": "integer" + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not the admin can be edited or deleted" + }, + "isPasswordLoginAllowed": { + "type": "boolean", + "description": "The default is true when SAML Authentication is disabled. When SAML Authentication is enabled, this can be set to false in order to force the admin to login via SSO only." + }, + "isPasswordExpired": { + "type": "boolean", + "description": "Indicates whether or not an admin's password has expired" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether the user is an auditor. This attribute is subject to change." + }, + "isSecurityReportCommEnabled": { + "type": "boolean", + "description": "Communication for Security Report is enabled." + }, + "isServiceUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Service Update" + }, + "isProductUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Product Update" + }, + "isExecMobileAppEnabled": { + "type": "boolean", + "description": "Indicates whether or not Executive Insights App access is enabled for the admin" + }, + "adminScopescopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change" + }, + "adminScopeScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change" + }, + "adminScopeType": { + "type": "string", + "description": "The admin's scope. A scope is required for admins, but not applicable to auditors. This attribute is subject to change" + }, + "role": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "extensions": { + "type": "object" + } + }, + "description": "Role of the admin. This is not required for an auditor" + }, + "execMobileAppTokens": { + "type": "array", + "items": { + "type": "object", + "properties": { + "cloud": { + "type": "string" + }, + "orgId": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tokenId": { + "type": "string" + }, + "token": { + "type": "string" + }, + "tokenExpiry": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "deviceId": { + "type": "string" + }, + "deviceName": { + "type": "string" + } + } + }, + "description": "Read-only information about a Executive Insights App token, if it exists" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin or auditor's user ID" + }, + "loginName": { + "type": "string", + "description": "Admin or auditor's login name. loginName is in email format and uses the domain name associated to the Zscaler account" + }, + "userName": { + "type": "string", + "description": "Admin or auditor's username" + }, + "email": { + "type": "string", + "description": "Admin or auditor's email address" + }, + "comments": { + "type": "string", + "description": "Additional information about the admin or auditor" + }, + "disabled": { + "type": "boolean", + "description": "Indicates whether or not the admin account is disabled" + }, + "password": { + "type": "string", + "description": "The admin's password. If admin single sign-on (SSO) is disabled, then this field is mandatory for POST requests. This information is not provided in a GET response.\"" + }, + "pwdLastModifiedTime": { + "type": "integer" + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not the admin can be edited or deleted" + }, + "isPasswordLoginAllowed": { + "type": "boolean", + "description": "The default is true when SAML Authentication is disabled. When SAML Authentication is enabled, this can be set to false in order to force the admin to login via SSO only." + }, + "isPasswordExpired": { + "type": "boolean", + "description": "Indicates whether or not an admin's password has expired" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether the user is an auditor. This attribute is subject to change." + }, + "isSecurityReportCommEnabled": { + "type": "boolean", + "description": "Communication for Security Report is enabled." + }, + "isServiceUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Service Update" + }, + "isProductUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Product Update" + }, + "isExecMobileAppEnabled": { + "type": "boolean", + "description": "Indicates whether or not Executive Insights App access is enabled for the admin" + }, + "adminScopescopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change" + }, + "adminScopeScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change" + }, + "adminScopeType": { + "type": "string", + "description": "The admin's scope. A scope is required for admins, but not applicable to auditors. This attribute is subject to change" + }, + "role": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "extensions": { + "type": "object" + } + }, + "description": "Role of the admin. This is not required for an auditor" + }, + "execMobileAppTokens": { + "type": "array", + "items": { + "type": "object", + "properties": { + "cloud": { + "type": "string" + }, + "orgId": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tokenId": { + "type": "string" + }, + "token": { + "type": "string" + }, + "tokenExpiry": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "deviceId": { + "type": "string" + }, + "deviceName": { + "type": "string" + } + } + }, + "description": "Read-only information about a Executive Insights App token, if it exists" + } + } + } + } + } + } + }, + "get": { + "operationId": "adminuserrolemgmt__admins_GetAllAdminUsers", + "summary": "GetAllAdminUsers (Adminuserrolemgmt / Admins)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin or auditor's user ID" + }, + "loginName": { + "type": "string", + "description": "Admin or auditor's login name. loginName is in email format and uses the domain name associated to the Zscaler account" + }, + "userName": { + "type": "string", + "description": "Admin or auditor's username" + }, + "email": { + "type": "string", + "description": "Admin or auditor's email address" + }, + "comments": { + "type": "string", + "description": "Additional information about the admin or auditor" + }, + "disabled": { + "type": "boolean", + "description": "Indicates whether or not the admin account is disabled" + }, + "password": { + "type": "string", + "description": "The admin's password. If admin single sign-on (SSO) is disabled, then this field is mandatory for POST requests. This information is not provided in a GET response.\"" + }, + "pwdLastModifiedTime": { + "type": "integer" + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not the admin can be edited or deleted" + }, + "isPasswordLoginAllowed": { + "type": "boolean", + "description": "The default is true when SAML Authentication is disabled. When SAML Authentication is enabled, this can be set to false in order to force the admin to login via SSO only." + }, + "isPasswordExpired": { + "type": "boolean", + "description": "Indicates whether or not an admin's password has expired" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether the user is an auditor. This attribute is subject to change." + }, + "isSecurityReportCommEnabled": { + "type": "boolean", + "description": "Communication for Security Report is enabled." + }, + "isServiceUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Service Update" + }, + "isProductUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Product Update" + }, + "isExecMobileAppEnabled": { + "type": "boolean", + "description": "Indicates whether or not Executive Insights App access is enabled for the admin" + }, + "adminScopescopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change" + }, + "adminScopeScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change" + }, + "adminScopeType": { + "type": "string", + "description": "The admin's scope. A scope is required for admins, but not applicable to auditors. This attribute is subject to change" + }, + "role": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "extensions": { + "type": "object" + } + }, + "description": "Role of the admin. This is not required for an auditor" + }, + "execMobileAppTokens": { + "type": "array", + "items": { + "type": "object", + "properties": { + "cloud": { + "type": "string" + }, + "orgId": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tokenId": { + "type": "string" + }, + "token": { + "type": "string" + }, + "tokenExpiry": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "deviceId": { + "type": "string" + }, + "deviceName": { + "type": "string" + } + } + }, + "description": "Read-only information about a Executive Insights App token, if it exists" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/adminUsers/{id}": { + "get": { + "operationId": "adminuserrolemgmt__admins_GetAdminUsers", + "summary": "GetAdminUsers (Adminuserrolemgmt / Admins)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin or auditor's user ID" + }, + "loginName": { + "type": "string", + "description": "Admin or auditor's login name. loginName is in email format and uses the domain name associated to the Zscaler account" + }, + "userName": { + "type": "string", + "description": "Admin or auditor's username" + }, + "email": { + "type": "string", + "description": "Admin or auditor's email address" + }, + "comments": { + "type": "string", + "description": "Additional information about the admin or auditor" + }, + "disabled": { + "type": "boolean", + "description": "Indicates whether or not the admin account is disabled" + }, + "password": { + "type": "string", + "description": "The admin's password. If admin single sign-on (SSO) is disabled, then this field is mandatory for POST requests. This information is not provided in a GET response.\"" + }, + "pwdLastModifiedTime": { + "type": "integer" + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not the admin can be edited or deleted" + }, + "isPasswordLoginAllowed": { + "type": "boolean", + "description": "The default is true when SAML Authentication is disabled. When SAML Authentication is enabled, this can be set to false in order to force the admin to login via SSO only." + }, + "isPasswordExpired": { + "type": "boolean", + "description": "Indicates whether or not an admin's password has expired" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether the user is an auditor. This attribute is subject to change." + }, + "isSecurityReportCommEnabled": { + "type": "boolean", + "description": "Communication for Security Report is enabled." + }, + "isServiceUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Service Update" + }, + "isProductUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Product Update" + }, + "isExecMobileAppEnabled": { + "type": "boolean", + "description": "Indicates whether or not Executive Insights App access is enabled for the admin" + }, + "adminScopescopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change" + }, + "adminScopeScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change" + }, + "adminScopeType": { + "type": "string", + "description": "The admin's scope. A scope is required for admins, but not applicable to auditors. This attribute is subject to change" + }, + "role": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "extensions": { + "type": "object" + } + }, + "description": "Role of the admin. This is not required for an auditor" + }, + "execMobileAppTokens": { + "type": "array", + "items": { + "type": "object", + "properties": { + "cloud": { + "type": "string" + }, + "orgId": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tokenId": { + "type": "string" + }, + "token": { + "type": "string" + }, + "tokenExpiry": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "deviceId": { + "type": "string" + }, + "deviceName": { + "type": "string" + } + } + }, + "description": "Read-only information about a Executive Insights App token, if it exists" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "adminuserrolemgmt__admins_UpdateAdminUser", + "summary": "UpdateAdminUser (Adminuserrolemgmt / Admins)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin or auditor's user ID" + }, + "loginName": { + "type": "string", + "description": "Admin or auditor's login name. loginName is in email format and uses the domain name associated to the Zscaler account" + }, + "userName": { + "type": "string", + "description": "Admin or auditor's username" + }, + "email": { + "type": "string", + "description": "Admin or auditor's email address" + }, + "comments": { + "type": "string", + "description": "Additional information about the admin or auditor" + }, + "disabled": { + "type": "boolean", + "description": "Indicates whether or not the admin account is disabled" + }, + "password": { + "type": "string", + "description": "The admin's password. If admin single sign-on (SSO) is disabled, then this field is mandatory for POST requests. This information is not provided in a GET response.\"" + }, + "pwdLastModifiedTime": { + "type": "integer" + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not the admin can be edited or deleted" + }, + "isPasswordLoginAllowed": { + "type": "boolean", + "description": "The default is true when SAML Authentication is disabled. When SAML Authentication is enabled, this can be set to false in order to force the admin to login via SSO only." + }, + "isPasswordExpired": { + "type": "boolean", + "description": "Indicates whether or not an admin's password has expired" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether the user is an auditor. This attribute is subject to change." + }, + "isSecurityReportCommEnabled": { + "type": "boolean", + "description": "Communication for Security Report is enabled." + }, + "isServiceUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Service Update" + }, + "isProductUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Product Update" + }, + "isExecMobileAppEnabled": { + "type": "boolean", + "description": "Indicates whether or not Executive Insights App access is enabled for the admin" + }, + "adminScopescopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change" + }, + "adminScopeScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change" + }, + "adminScopeType": { + "type": "string", + "description": "The admin's scope. A scope is required for admins, but not applicable to auditors. This attribute is subject to change" + }, + "role": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "extensions": { + "type": "object" + } + }, + "description": "Role of the admin. This is not required for an auditor" + }, + "execMobileAppTokens": { + "type": "array", + "items": { + "type": "object", + "properties": { + "cloud": { + "type": "string" + }, + "orgId": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tokenId": { + "type": "string" + }, + "token": { + "type": "string" + }, + "tokenExpiry": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "deviceId": { + "type": "string" + }, + "deviceName": { + "type": "string" + } + } + }, + "description": "Read-only information about a Executive Insights App token, if it exists" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin or auditor's user ID" + }, + "loginName": { + "type": "string", + "description": "Admin or auditor's login name. loginName is in email format and uses the domain name associated to the Zscaler account" + }, + "userName": { + "type": "string", + "description": "Admin or auditor's username" + }, + "email": { + "type": "string", + "description": "Admin or auditor's email address" + }, + "comments": { + "type": "string", + "description": "Additional information about the admin or auditor" + }, + "disabled": { + "type": "boolean", + "description": "Indicates whether or not the admin account is disabled" + }, + "password": { + "type": "string", + "description": "The admin's password. If admin single sign-on (SSO) is disabled, then this field is mandatory for POST requests. This information is not provided in a GET response.\"" + }, + "pwdLastModifiedTime": { + "type": "integer" + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not the admin can be edited or deleted" + }, + "isPasswordLoginAllowed": { + "type": "boolean", + "description": "The default is true when SAML Authentication is disabled. When SAML Authentication is enabled, this can be set to false in order to force the admin to login via SSO only." + }, + "isPasswordExpired": { + "type": "boolean", + "description": "Indicates whether or not an admin's password has expired" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether the user is an auditor. This attribute is subject to change." + }, + "isSecurityReportCommEnabled": { + "type": "boolean", + "description": "Communication for Security Report is enabled." + }, + "isServiceUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Service Update" + }, + "isProductUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Product Update" + }, + "isExecMobileAppEnabled": { + "type": "boolean", + "description": "Indicates whether or not Executive Insights App access is enabled for the admin" + }, + "adminScopescopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change" + }, + "adminScopeScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change" + }, + "adminScopeType": { + "type": "string", + "description": "The admin's scope. A scope is required for admins, but not applicable to auditors. This attribute is subject to change" + }, + "role": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "extensions": { + "type": "object" + } + }, + "description": "Role of the admin. This is not required for an auditor" + }, + "execMobileAppTokens": { + "type": "array", + "items": { + "type": "object", + "properties": { + "cloud": { + "type": "string" + }, + "orgId": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tokenId": { + "type": "string" + }, + "token": { + "type": "string" + }, + "tokenExpiry": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "deviceId": { + "type": "string" + }, + "deviceName": { + "type": "string" + } + } + }, + "description": "Read-only information about a Executive Insights App token, if it exists" + } + } + } + } + } + } + }, + "delete": { + "operationId": "adminuserrolemgmt__admins_DeleteAdminUser", + "summary": "DeleteAdminUser (Adminuserrolemgmt / Admins)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin or auditor's user ID" + }, + "loginName": { + "type": "string", + "description": "Admin or auditor's login name. loginName is in email format and uses the domain name associated to the Zscaler account" + }, + "userName": { + "type": "string", + "description": "Admin or auditor's username" + }, + "email": { + "type": "string", + "description": "Admin or auditor's email address" + }, + "comments": { + "type": "string", + "description": "Additional information about the admin or auditor" + }, + "disabled": { + "type": "boolean", + "description": "Indicates whether or not the admin account is disabled" + }, + "password": { + "type": "string", + "description": "The admin's password. If admin single sign-on (SSO) is disabled, then this field is mandatory for POST requests. This information is not provided in a GET response.\"" + }, + "pwdLastModifiedTime": { + "type": "integer" + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not the admin can be edited or deleted" + }, + "isPasswordLoginAllowed": { + "type": "boolean", + "description": "The default is true when SAML Authentication is disabled. When SAML Authentication is enabled, this can be set to false in order to force the admin to login via SSO only." + }, + "isPasswordExpired": { + "type": "boolean", + "description": "Indicates whether or not an admin's password has expired" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether the user is an auditor. This attribute is subject to change." + }, + "isSecurityReportCommEnabled": { + "type": "boolean", + "description": "Communication for Security Report is enabled." + }, + "isServiceUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Service Update" + }, + "isProductUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Product Update" + }, + "isExecMobileAppEnabled": { + "type": "boolean", + "description": "Indicates whether or not Executive Insights App access is enabled for the admin" + }, + "adminScopescopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change" + }, + "adminScopeScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change" + }, + "adminScopeType": { + "type": "string", + "description": "The admin's scope. A scope is required for admins, but not applicable to auditors. This attribute is subject to change" + }, + "role": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "extensions": { + "type": "object" + } + }, + "description": "Role of the admin. This is not required for an auditor" + }, + "execMobileAppTokens": { + "type": "array", + "items": { + "type": "object", + "properties": { + "cloud": { + "type": "string" + }, + "orgId": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tokenId": { + "type": "string" + }, + "token": { + "type": "string" + }, + "tokenExpiry": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "deviceId": { + "type": "string" + }, + "deviceName": { + "type": "string" + } + } + }, + "description": "Read-only information about a Executive Insights App token, if it exists" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/advancedSettings": { + "get": { + "operationId": "advanced_settings_GetAdvancedSettings", + "summary": "GetAdvancedSettings (Advanced Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "authBypassUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs that are exempted from cookie authentication for users" + }, + "kerberosBypassUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs that are exempted from Kerberos authentication" + }, + "digestAuthBypassUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs that are exempted from Digest authentication" + }, + "dnsResolutionOnTransparentProxyExemptUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs to which DNS optimization on transparent proxy mode applies" + }, + "enableDnsResolutionOnTransparentProxy": { + "type": "boolean", + "description": "A Boolean value indicating whether DNS optimization is enabled or disabled for Z-Tunnel 2.0 and transparent proxy mode traffic (e.g., traffic via GRE or IPSec tunnels without a PAC file)." + }, + "enableIPv6DnsResolutionOnTransparentProxy": { + "type": "boolean", + "description": "A Boolean value indicating whether DNS optimization is enabled or disabled for IPv6 traffic sent via Z-Tunnel 2.0 and transparent proxy mode traffic (e.g., traffic via GRE or IPSec tunnels without a PAC file)." + }, + "enableIPv6DnsOptimizationOnAllTransparentProxy": { + "type": "boolean", + "description": "A Boolean value indicating whether DNS optimization is enabled or disabled for all IPv6 transparent proxy traffic" + }, + "enableEvaluatePolicyOnGlobalSSLBypass": { + "type": "boolean", + "description": "A Boolean value indicating whether policy evaluation for global SSL bypass traffic is enabled or not" + }, + "enableOffice365": { + "type": "boolean", + "description": "A Boolean value indicating whether Microsoft Office 365 One Click Configuration is enabled or not" + }, + "logInternalIp": { + "type": "boolean", + "description": "A Boolean value indicating whether to log internal IP address present in X-Forwarded-For (XFF) proxy header or not" + }, + "enforceSurrogateIpForWindowsApp": { + "type": "boolean", + "description": "Enforce Surrogate IP authentication for Windows app traffic" + }, + "trackHttpTunnelOnHttpPorts": { + "type": "boolean", + "description": "A Boolean value indicating whether to apply configured policies on tunneled HTTP traffic sent via a CONNECT method request on port 80" + }, + "blockHttpTunnelOnNonHttpPorts": { + "type": "boolean", + "description": "A Boolean value indicating whether HTTP CONNECT method requests to non-standard ports are allowed or not (i.e., requests directed to ports other than the standard HTTP and HTTPS ports, 80 and 443)" + }, + "blockDomainFrontingOnHostHeader": { + "type": "boolean", + "description": "A Boolean value indicating whether to block HTTP and HTTPS transactions that have an FQDN mismatch" + }, + "zscalerClientConnector1AndPacRoadWarriorInFirewall": { + "type": "boolean", + "description": "A Boolean value indicating whether to apply the Firewall rules configured without a specified location criteria (or with the Road Warrior location) to remote user traffic forwarded via Z-Tunnel 1.0 or PAC files" + }, + "cascadeUrlFiltering": { + "type": "boolean", + "description": "A Boolean value indicating whether to apply the URL Filtering policy even when the Cloud App Control policy already allows a transaction explicitly" + }, + "enablePolicyForUnauthenticatedTraffic": { + "type": "boolean", + "description": "A Boolean value indicating whether policies that include user and department criteria can be configured and applied for unauthenticated traffic" + }, + "blockNonCompliantHttpRequestOnHttpPorts": { + "type": "boolean", + "description": "A Boolean value indicating whether to allow or block traffic that is not compliant with RFC HTTP protocol standards" + }, + "enableAdminRankAccess": { + "type": "boolean", + "description": "A Boolean value indicating whether ranks are enabled for admins to allow admin ranks in policy configuration and management" + }, + "http2NonbrowserTrafficEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether or not HTTP/2 should be the default web protocol for accessing various applications at your organizational level" + }, + "ecsForAllEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether or not to include the ECS option in all DNS queries, originating from all locations and remote users." + }, + "dynamicUserRiskEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether to dynamically update user risk score by tracking risky user activities in real time" + }, + "blockConnectHostSniMismatch": { + "type": "boolean", + "description": "A Boolean value indicating whether CONNECT host and SNI mismatch (i.e., CONNECT host doesn't match the SSL/TLS client hello SNI) is blocked or not" + }, + "preferSniOverConnHost": { + "type": "boolean", + "description": "A Boolean value indicating whether or not to use the SSL/TLS client hello Server Name Indication (SNI) for DNS resolution instead of the CONNECT host for forward proxy connections" + }, + "sipaXffHeaderEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether or not to insert XFF header to all traffic forwarded from ZIA to ZPA, including source IP-anchored and ZIA-inspected ZPA application traffic." + }, + "blockNonHttpOnHttpPortEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether non-HTTP Traffic on HTTP and HTTPS ports are allowed or blocked" + }, + "ecsObject": { + "type": "object", + "description": "The ECS prefix that must be used in DNS queries when the ECS option is enabled" + }, + "authBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from cookie authenticatio" + }, + "kerberosBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from Kerberos authentication" + }, + "basicBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from Basic authentication" + }, + "digestAuthBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from Digest authentication" + }, + "dnsResolutionOnTransparentProxyExemptApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyIPv6ExemptApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are excluded from DNS optimization for IPv6 addresses on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications to which DNS optimization on transparent proxy mode applies" + }, + "dnsResolutionOnTransparentProxyIPv6Apps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications to which DNS optimization for IPv6 addresses on transparent proxy mode applies" + }, + "blockDomainFrontingApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Applications that are exempted from domain fronting" + }, + "preferSniOverConnHostApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Applications that are exempted from the preferSniOverConnHost setting" + }, + "dnsResolutionOnTransparentProxyExemptUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyIPv6ExemptUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IPv6 URL categories that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories to which DNS optimization on transparent proxy mode applies" + }, + "dnsResolutionOnTransparentProxyIPv6UrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IPv6 URL categories to which DNS optimization on transparent proxy mode applies" + }, + "authBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from cookie authentication" + }, + "domainFrontingBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from domain fronting" + }, + "kerberosBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from Kerberos authentication" + }, + "basicBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from Basic authentication" + }, + "httpRangeHeaderRemoveUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories for which HTTP range headers must be removed" + }, + "digestAuthBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from Digest authentication" + }, + "sniDnsOptimizationBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are excluded from the preferSniOverConnHost setting (i.e., prefer SSL/TLS client hello SNI for DNS resolution instead of the CONNECT host for forward proxy connections)" + }, + "uiSessionTimeout": { + "type": "integer", + "description": "Specifies the login session timeout for admins accessing the ZIA Admin Portal" + }, + "apiSessionTimeout": { + "type": "integer", + "description": "API Session Timeout Duration (In Minutes)" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "advanced_settings_UpdateAdvancedSettings", + "summary": "UpdateAdvancedSettings (Advanced Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "authBypassUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs that are exempted from cookie authentication for users" + }, + "kerberosBypassUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs that are exempted from Kerberos authentication" + }, + "digestAuthBypassUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs that are exempted from Digest authentication" + }, + "dnsResolutionOnTransparentProxyExemptUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs to which DNS optimization on transparent proxy mode applies" + }, + "enableDnsResolutionOnTransparentProxy": { + "type": "boolean", + "description": "A Boolean value indicating whether DNS optimization is enabled or disabled for Z-Tunnel 2.0 and transparent proxy mode traffic (e.g., traffic via GRE or IPSec tunnels without a PAC file)." + }, + "enableIPv6DnsResolutionOnTransparentProxy": { + "type": "boolean", + "description": "A Boolean value indicating whether DNS optimization is enabled or disabled for IPv6 traffic sent via Z-Tunnel 2.0 and transparent proxy mode traffic (e.g., traffic via GRE or IPSec tunnels without a PAC file)." + }, + "enableIPv6DnsOptimizationOnAllTransparentProxy": { + "type": "boolean", + "description": "A Boolean value indicating whether DNS optimization is enabled or disabled for all IPv6 transparent proxy traffic" + }, + "enableEvaluatePolicyOnGlobalSSLBypass": { + "type": "boolean", + "description": "A Boolean value indicating whether policy evaluation for global SSL bypass traffic is enabled or not" + }, + "enableOffice365": { + "type": "boolean", + "description": "A Boolean value indicating whether Microsoft Office 365 One Click Configuration is enabled or not" + }, + "logInternalIp": { + "type": "boolean", + "description": "A Boolean value indicating whether to log internal IP address present in X-Forwarded-For (XFF) proxy header or not" + }, + "enforceSurrogateIpForWindowsApp": { + "type": "boolean", + "description": "Enforce Surrogate IP authentication for Windows app traffic" + }, + "trackHttpTunnelOnHttpPorts": { + "type": "boolean", + "description": "A Boolean value indicating whether to apply configured policies on tunneled HTTP traffic sent via a CONNECT method request on port 80" + }, + "blockHttpTunnelOnNonHttpPorts": { + "type": "boolean", + "description": "A Boolean value indicating whether HTTP CONNECT method requests to non-standard ports are allowed or not (i.e., requests directed to ports other than the standard HTTP and HTTPS ports, 80 and 443)" + }, + "blockDomainFrontingOnHostHeader": { + "type": "boolean", + "description": "A Boolean value indicating whether to block HTTP and HTTPS transactions that have an FQDN mismatch" + }, + "zscalerClientConnector1AndPacRoadWarriorInFirewall": { + "type": "boolean", + "description": "A Boolean value indicating whether to apply the Firewall rules configured without a specified location criteria (or with the Road Warrior location) to remote user traffic forwarded via Z-Tunnel 1.0 or PAC files" + }, + "cascadeUrlFiltering": { + "type": "boolean", + "description": "A Boolean value indicating whether to apply the URL Filtering policy even when the Cloud App Control policy already allows a transaction explicitly" + }, + "enablePolicyForUnauthenticatedTraffic": { + "type": "boolean", + "description": "A Boolean value indicating whether policies that include user and department criteria can be configured and applied for unauthenticated traffic" + }, + "blockNonCompliantHttpRequestOnHttpPorts": { + "type": "boolean", + "description": "A Boolean value indicating whether to allow or block traffic that is not compliant with RFC HTTP protocol standards" + }, + "enableAdminRankAccess": { + "type": "boolean", + "description": "A Boolean value indicating whether ranks are enabled for admins to allow admin ranks in policy configuration and management" + }, + "http2NonbrowserTrafficEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether or not HTTP/2 should be the default web protocol for accessing various applications at your organizational level" + }, + "ecsForAllEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether or not to include the ECS option in all DNS queries, originating from all locations and remote users." + }, + "dynamicUserRiskEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether to dynamically update user risk score by tracking risky user activities in real time" + }, + "blockConnectHostSniMismatch": { + "type": "boolean", + "description": "A Boolean value indicating whether CONNECT host and SNI mismatch (i.e., CONNECT host doesn't match the SSL/TLS client hello SNI) is blocked or not" + }, + "preferSniOverConnHost": { + "type": "boolean", + "description": "A Boolean value indicating whether or not to use the SSL/TLS client hello Server Name Indication (SNI) for DNS resolution instead of the CONNECT host for forward proxy connections" + }, + "sipaXffHeaderEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether or not to insert XFF header to all traffic forwarded from ZIA to ZPA, including source IP-anchored and ZIA-inspected ZPA application traffic." + }, + "blockNonHttpOnHttpPortEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether non-HTTP Traffic on HTTP and HTTPS ports are allowed or blocked" + }, + "ecsObject": { + "type": "object", + "description": "The ECS prefix that must be used in DNS queries when the ECS option is enabled" + }, + "authBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from cookie authenticatio" + }, + "kerberosBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from Kerberos authentication" + }, + "basicBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from Basic authentication" + }, + "digestAuthBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from Digest authentication" + }, + "dnsResolutionOnTransparentProxyExemptApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyIPv6ExemptApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are excluded from DNS optimization for IPv6 addresses on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications to which DNS optimization on transparent proxy mode applies" + }, + "dnsResolutionOnTransparentProxyIPv6Apps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications to which DNS optimization for IPv6 addresses on transparent proxy mode applies" + }, + "blockDomainFrontingApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Applications that are exempted from domain fronting" + }, + "preferSniOverConnHostApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Applications that are exempted from the preferSniOverConnHost setting" + }, + "dnsResolutionOnTransparentProxyExemptUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyIPv6ExemptUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IPv6 URL categories that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories to which DNS optimization on transparent proxy mode applies" + }, + "dnsResolutionOnTransparentProxyIPv6UrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IPv6 URL categories to which DNS optimization on transparent proxy mode applies" + }, + "authBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from cookie authentication" + }, + "domainFrontingBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from domain fronting" + }, + "kerberosBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from Kerberos authentication" + }, + "basicBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from Basic authentication" + }, + "httpRangeHeaderRemoveUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories for which HTTP range headers must be removed" + }, + "digestAuthBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from Digest authentication" + }, + "sniDnsOptimizationBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are excluded from the preferSniOverConnHost setting (i.e., prefer SSL/TLS client hello SNI for DNS resolution instead of the CONNECT host for forward proxy connections)" + }, + "uiSessionTimeout": { + "type": "integer", + "description": "Specifies the login session timeout for admins accessing the ZIA Admin Portal" + }, + "apiSessionTimeout": { + "type": "integer", + "description": "API Session Timeout Duration (In Minutes)" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "authBypassUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs that are exempted from cookie authentication for users" + }, + "kerberosBypassUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs that are exempted from Kerberos authentication" + }, + "digestAuthBypassUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs that are exempted from Digest authentication" + }, + "dnsResolutionOnTransparentProxyExemptUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs to which DNS optimization on transparent proxy mode applies" + }, + "enableDnsResolutionOnTransparentProxy": { + "type": "boolean", + "description": "A Boolean value indicating whether DNS optimization is enabled or disabled for Z-Tunnel 2.0 and transparent proxy mode traffic (e.g., traffic via GRE or IPSec tunnels without a PAC file)." + }, + "enableIPv6DnsResolutionOnTransparentProxy": { + "type": "boolean", + "description": "A Boolean value indicating whether DNS optimization is enabled or disabled for IPv6 traffic sent via Z-Tunnel 2.0 and transparent proxy mode traffic (e.g., traffic via GRE or IPSec tunnels without a PAC file)." + }, + "enableIPv6DnsOptimizationOnAllTransparentProxy": { + "type": "boolean", + "description": "A Boolean value indicating whether DNS optimization is enabled or disabled for all IPv6 transparent proxy traffic" + }, + "enableEvaluatePolicyOnGlobalSSLBypass": { + "type": "boolean", + "description": "A Boolean value indicating whether policy evaluation for global SSL bypass traffic is enabled or not" + }, + "enableOffice365": { + "type": "boolean", + "description": "A Boolean value indicating whether Microsoft Office 365 One Click Configuration is enabled or not" + }, + "logInternalIp": { + "type": "boolean", + "description": "A Boolean value indicating whether to log internal IP address present in X-Forwarded-For (XFF) proxy header or not" + }, + "enforceSurrogateIpForWindowsApp": { + "type": "boolean", + "description": "Enforce Surrogate IP authentication for Windows app traffic" + }, + "trackHttpTunnelOnHttpPorts": { + "type": "boolean", + "description": "A Boolean value indicating whether to apply configured policies on tunneled HTTP traffic sent via a CONNECT method request on port 80" + }, + "blockHttpTunnelOnNonHttpPorts": { + "type": "boolean", + "description": "A Boolean value indicating whether HTTP CONNECT method requests to non-standard ports are allowed or not (i.e., requests directed to ports other than the standard HTTP and HTTPS ports, 80 and 443)" + }, + "blockDomainFrontingOnHostHeader": { + "type": "boolean", + "description": "A Boolean value indicating whether to block HTTP and HTTPS transactions that have an FQDN mismatch" + }, + "zscalerClientConnector1AndPacRoadWarriorInFirewall": { + "type": "boolean", + "description": "A Boolean value indicating whether to apply the Firewall rules configured without a specified location criteria (or with the Road Warrior location) to remote user traffic forwarded via Z-Tunnel 1.0 or PAC files" + }, + "cascadeUrlFiltering": { + "type": "boolean", + "description": "A Boolean value indicating whether to apply the URL Filtering policy even when the Cloud App Control policy already allows a transaction explicitly" + }, + "enablePolicyForUnauthenticatedTraffic": { + "type": "boolean", + "description": "A Boolean value indicating whether policies that include user and department criteria can be configured and applied for unauthenticated traffic" + }, + "blockNonCompliantHttpRequestOnHttpPorts": { + "type": "boolean", + "description": "A Boolean value indicating whether to allow or block traffic that is not compliant with RFC HTTP protocol standards" + }, + "enableAdminRankAccess": { + "type": "boolean", + "description": "A Boolean value indicating whether ranks are enabled for admins to allow admin ranks in policy configuration and management" + }, + "http2NonbrowserTrafficEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether or not HTTP/2 should be the default web protocol for accessing various applications at your organizational level" + }, + "ecsForAllEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether or not to include the ECS option in all DNS queries, originating from all locations and remote users." + }, + "dynamicUserRiskEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether to dynamically update user risk score by tracking risky user activities in real time" + }, + "blockConnectHostSniMismatch": { + "type": "boolean", + "description": "A Boolean value indicating whether CONNECT host and SNI mismatch (i.e., CONNECT host doesn't match the SSL/TLS client hello SNI) is blocked or not" + }, + "preferSniOverConnHost": { + "type": "boolean", + "description": "A Boolean value indicating whether or not to use the SSL/TLS client hello Server Name Indication (SNI) for DNS resolution instead of the CONNECT host for forward proxy connections" + }, + "sipaXffHeaderEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether or not to insert XFF header to all traffic forwarded from ZIA to ZPA, including source IP-anchored and ZIA-inspected ZPA application traffic." + }, + "blockNonHttpOnHttpPortEnabled": { + "type": "boolean", + "description": "A Boolean value indicating whether non-HTTP Traffic on HTTP and HTTPS ports are allowed or blocked" + }, + "ecsObject": { + "type": "object", + "description": "The ECS prefix that must be used in DNS queries when the ECS option is enabled" + }, + "authBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from cookie authenticatio" + }, + "kerberosBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from Kerberos authentication" + }, + "basicBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from Basic authentication" + }, + "digestAuthBypassApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are exempted from Digest authentication" + }, + "dnsResolutionOnTransparentProxyExemptApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyIPv6ExemptApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications that are excluded from DNS optimization for IPv6 addresses on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications to which DNS optimization on transparent proxy mode applies" + }, + "dnsResolutionOnTransparentProxyIPv6Apps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Cloud applications to which DNS optimization for IPv6 addresses on transparent proxy mode applies" + }, + "blockDomainFrontingApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Applications that are exempted from domain fronting" + }, + "preferSniOverConnHostApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Applications that are exempted from the preferSniOverConnHost setting" + }, + "dnsResolutionOnTransparentProxyExemptUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyIPv6ExemptUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IPv6 URL categories that are excluded from DNS optimization on transparent proxy mode" + }, + "dnsResolutionOnTransparentProxyUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories to which DNS optimization on transparent proxy mode applies" + }, + "dnsResolutionOnTransparentProxyIPv6UrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IPv6 URL categories to which DNS optimization on transparent proxy mode applies" + }, + "authBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from cookie authentication" + }, + "domainFrontingBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from domain fronting" + }, + "kerberosBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from Kerberos authentication" + }, + "basicBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from Basic authentication" + }, + "httpRangeHeaderRemoveUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories for which HTTP range headers must be removed" + }, + "digestAuthBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are exempted from Digest authentication" + }, + "sniDnsOptimizationBypassUrlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URL categories that are excluded from the preferSniOverConnHost setting (i.e., prefer SSL/TLS client hello SNI for DNS resolution instead of the CONNECT host for forward proxy connections)" + }, + "uiSessionTimeout": { + "type": "integer", + "description": "Specifies the login session timeout for admins accessing the ZIA Admin Portal" + }, + "apiSessionTimeout": { + "type": "integer", + "description": "API Session Timeout Duration (In Minutes)" + } + } + } + } + } + } + } + }, + "/zia/api/v1/advancedUrlFilterAndCloudAppSettings": { + "get": { + "operationId": "urlfilteringpolicies_GetUrlAndAppSettings", + "summary": "GetUrlAndAppSettings (Urlfilteringpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "urlfilteringpolicies_UpdateUrlAndAppSettings", + "summary": "UpdateUrlAndAppSettings (Urlfilteringpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + } + }, + "/zia/api/v1/alertDefinitions": { + "post": { + "operationId": "security_ueba_alerts__alert_definitions_Create", + "summary": "Create (Security Ueba Alerts / Alert Definitions)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "status": { + "type": "string" + }, + "alertName": { + "type": "string" + }, + "occurrence": { + "type": "string" + }, + "trafficChangePercent": { + "type": "integer" + }, + "interval": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "entity": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "severity": { + "type": "string" + }, + "comments": { + "type": "string" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "status": { + "type": "string" + }, + "alertName": { + "type": "string" + }, + "occurrence": { + "type": "string" + }, + "trafficChangePercent": { + "type": "integer" + }, + "interval": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "entity": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "severity": { + "type": "string" + }, + "comments": { + "type": "string" + } + } + } + } + } + } + }, + "get": { + "operationId": "security_ueba_alerts__alert_definitions_GetAll", + "summary": "GetAll (Security Ueba Alerts / Alert Definitions)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "status": { + "type": "string" + }, + "alertName": { + "type": "string" + }, + "occurrence": { + "type": "string" + }, + "trafficChangePercent": { + "type": "integer" + }, + "interval": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "entity": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "severity": { + "type": "string" + }, + "comments": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/alertDefinitions/{id}": { + "get": { + "operationId": "security_ueba_alerts__alert_definitions_Get", + "summary": "Get (Security Ueba Alerts / Alert Definitions)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "status": { + "type": "string" + }, + "alertName": { + "type": "string" + }, + "occurrence": { + "type": "string" + }, + "trafficChangePercent": { + "type": "integer" + }, + "interval": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "entity": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "severity": { + "type": "string" + }, + "comments": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "security_ueba_alerts__alert_definitions_Update", + "summary": "Update (Security Ueba Alerts / Alert Definitions)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "status": { + "type": "string" + }, + "alertName": { + "type": "string" + }, + "occurrence": { + "type": "string" + }, + "trafficChangePercent": { + "type": "integer" + }, + "interval": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "entity": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "severity": { + "type": "string" + }, + "comments": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "status": { + "type": "string" + }, + "alertName": { + "type": "string" + }, + "occurrence": { + "type": "string" + }, + "trafficChangePercent": { + "type": "integer" + }, + "interval": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "entity": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "severity": { + "type": "string" + }, + "comments": { + "type": "string" + } + } + } + } + } + } + }, + "delete": { + "operationId": "security_ueba_alerts__alert_definitions_Delete", + "summary": "Delete (Security Ueba Alerts / Alert Definitions)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "status": { + "type": "string" + }, + "alertName": { + "type": "string" + }, + "occurrence": { + "type": "string" + }, + "trafficChangePercent": { + "type": "integer" + }, + "interval": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "entity": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "severity": { + "type": "string" + }, + "comments": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/alertRuleConfiguration/rules": { + "post": { + "operationId": "security_ueba_alerts__alert_configurations_Create", + "summary": "Create (Security Ueba Alerts / Alert Configurations)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "get": { + "operationId": "security_ueba_alerts__alert_configurations_GetAll", + "summary": "GetAll (Security Ueba Alerts / Alert Configurations)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/alertRuleConfiguration/rules/{id}": { + "get": { + "operationId": "security_ueba_alerts__alert_configurations_Get", + "summary": "Get (Security Ueba Alerts / Alert Configurations)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "security_ueba_alerts__alert_configurations_Update", + "summary": "Update (Security Ueba Alerts / Alert Configurations)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "security_ueba_alerts__alert_configurations_Delete", + "summary": "Delete (Security Ueba Alerts / Alert Configurations)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/alertRuleConfiguration/uebaRules": { + "post": { + "operationId": "security_ueba_alerts__ueba_rules_Create", + "summary": "Create (Security Ueba Alerts / Ueba Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "get": { + "operationId": "security_ueba_alerts__ueba_rules_GetAll", + "summary": "GetAll (Security Ueba Alerts / Ueba Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/alertRuleConfiguration/uebaRules/{id}": { + "get": { + "operationId": "security_ueba_alerts__ueba_rules_Get", + "summary": "Get (Security Ueba Alerts / Ueba Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "security_ueba_alerts__ueba_rules_Update", + "summary": "Update (Security Ueba Alerts / Ueba Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "security_ueba_alerts__ueba_rules_Delete", + "summary": "Delete (Security Ueba Alerts / Ueba Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "alertName": { + "type": "string" + }, + "alertClass": { + "type": "string" + }, + "status": { + "type": "string" + }, + "eventTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "withinTime": { + "type": "integer" + }, + "minTimes": { + "type": "integer" + }, + "windowSize": { + "type": "integer" + }, + "enableUpdate": { + "type": "boolean" + }, + "updateWindowSize": { + "type": "integer" + }, + "numSystemImpacted": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "webhooks": { + "type": "array", + "items": { + "type": "integer" + } + }, + "emailIds": { + "type": "array", + "items": { + "type": "string" + } + }, + "channel": { + "type": "string" + }, + "alertType": { + "type": "string" + }, + "action": { + "type": "string" + }, + "actionThreshold": { + "type": "integer" + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "docTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionTimeInterval": { + "type": "integer" + }, + "activities": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "userGroupId": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/alertRuleConfiguration/webhooks": { + "post": { + "operationId": "security_ueba_alerts__webhooks_Create", + "summary": "Create (Security Ueba Alerts / Webhooks)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "userName": { + "type": "string" + }, + "password": { + "type": "string" + }, + "authToken": { + "type": "string" + }, + "urlText": { + "type": "string" + }, + "status": { + "type": "boolean" + }, + "lastTriggered": { + "type": "integer" + }, + "authenticationType": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "userName": { + "type": "string" + }, + "password": { + "type": "string" + }, + "authToken": { + "type": "string" + }, + "urlText": { + "type": "string" + }, + "status": { + "type": "boolean" + }, + "lastTriggered": { + "type": "integer" + }, + "authenticationType": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + }, + "get": { + "operationId": "security_ueba_alerts__webhooks_GetAll", + "summary": "GetAll (Security Ueba Alerts / Webhooks)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "userName": { + "type": "string" + }, + "password": { + "type": "string" + }, + "authToken": { + "type": "string" + }, + "urlText": { + "type": "string" + }, + "status": { + "type": "boolean" + }, + "lastTriggered": { + "type": "integer" + }, + "authenticationType": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/alertRuleConfiguration/webhooks/{id}": { + "put": { + "operationId": "security_ueba_alerts__webhooks_Update", + "summary": "Update (Security Ueba Alerts / Webhooks)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "userName": { + "type": "string" + }, + "password": { + "type": "string" + }, + "authToken": { + "type": "string" + }, + "urlText": { + "type": "string" + }, + "status": { + "type": "boolean" + }, + "lastTriggered": { + "type": "integer" + }, + "authenticationType": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "userName": { + "type": "string" + }, + "password": { + "type": "string" + }, + "authToken": { + "type": "string" + }, + "urlText": { + "type": "string" + }, + "status": { + "type": "boolean" + }, + "lastTriggered": { + "type": "integer" + }, + "authenticationType": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + }, + "delete": { + "operationId": "security_ueba_alerts__webhooks_Delete", + "summary": "Delete (Security Ueba Alerts / Webhooks)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "userName": { + "type": "string" + }, + "password": { + "type": "string" + }, + "authToken": { + "type": "string" + }, + "urlText": { + "type": "string" + }, + "status": { + "type": "boolean" + }, + "lastTriggered": { + "type": "integer" + }, + "authenticationType": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/alertSubscriptions": { + "post": { + "operationId": "alerts_Create", + "summary": "Create (Alerts)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "email": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "pt0Severities": { + "type": "array", + "items": { + "type": "string" + } + }, + "secureSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "manageSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "complySeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "systemSeverities": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "email": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "pt0Severities": { + "type": "array", + "items": { + "type": "string" + } + }, + "secureSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "manageSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "complySeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "systemSeverities": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "get": { + "operationId": "alerts_GetAll", + "summary": "GetAll (Alerts)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "email": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "pt0Severities": { + "type": "array", + "items": { + "type": "string" + } + }, + "secureSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "manageSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "complySeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "systemSeverities": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/alertSubscriptions/{id}": { + "get": { + "operationId": "alerts_Get", + "summary": "Get (Alerts)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "email": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "pt0Severities": { + "type": "array", + "items": { + "type": "string" + } + }, + "secureSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "manageSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "complySeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "systemSeverities": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "alerts_Update", + "summary": "Update (Alerts)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "email": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "pt0Severities": { + "type": "array", + "items": { + "type": "string" + } + }, + "secureSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "manageSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "complySeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "systemSeverities": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "email": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "pt0Severities": { + "type": "array", + "items": { + "type": "string" + } + }, + "secureSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "manageSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "complySeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "systemSeverities": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "alerts_Delete", + "summary": "Delete (Alerts)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "email": { + "type": "string" + }, + "deleted": { + "type": "boolean" + }, + "pt0Severities": { + "type": "array", + "items": { + "type": "string" + } + }, + "secureSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "manageSeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "complySeverities": { + "type": "array", + "items": { + "type": "string" + } + }, + "systemSeverities": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/appServiceGroups/lite": { + "get": { + "operationId": "firewallpolicies__appservicegroups_GetByName", + "summary": "GetByName (Firewallpolicies / Appservicegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "nameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/appServices/lite": { + "get": { + "operationId": "firewallpolicies__applicationservices_GetByName", + "summary": "GetByName (Firewallpolicies / Applicationservices)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "nameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/app_views/list": { + "get": { + "operationId": "apptotal_GetAppViewsResponse", + "summary": "GetAppViewsResponse (Apptotal)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "publisher": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "siteUrl": { + "type": "string" + }, + "logoUrl": { + "type": "string" + } + } + }, + "platform": { + "type": "string" + }, + "description": { + "type": "string" + }, + "redirectUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "websiteUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "categories": { + "type": "array", + "items": { + "type": "string" + } + }, + "tags": { + "type": "array", + "items": { + "type": "string" + } + }, + "permissionLevel": { + "type": "number" + }, + "riskScore": { + "type": "number" + }, + "risk": { + "type": "string" + }, + "externalIds": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "clientId": { + "type": "string" + }, + "permissions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scope": { + "type": "string" + }, + "service": { + "type": "string" + }, + "description": { + "type": "string" + }, + "accessType": { + "type": "string" + }, + "level": { + "type": "string" + } + } + } + }, + "compliance": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataRetention": { + "type": "string" + }, + "clientType": { + "type": "string" + }, + "logoUrl": { + "type": "string" + }, + "privacyPolicyUrl": { + "type": "string" + }, + "termsOfServiceUrl": { + "type": "string" + }, + "marketplaceUrl": { + "type": "string" + }, + "marketplaceData": { + "type": "object", + "properties": { + "stars": { + "type": "integer" + }, + "downloads": { + "type": "integer" + }, + "reviews": { + "type": "integer" + } + } + }, + "platformVerified": { + "type": "boolean" + }, + "canonicVerified": { + "type": "boolean" + }, + "developerEmail": { + "type": "string" + }, + "consentScreenshot": { + "type": "string" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "object", + "properties": { + "ispName": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "proxyType": { + "type": "string" + }, + "usageType": { + "type": "string" + }, + "domainName": { + "type": "string" + }, + "countryCode": { + "type": "string" + } + } + } + }, + "extractedUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "extractedApiCalls": { + "type": "array", + "items": { + "type": "string" + } + }, + "vulnerabilities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "version": { + "type": "string" + }, + "cveId": { + "type": "string" + }, + "summary": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "apiActivities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "operationType": { + "type": "string" + }, + "percentage": { + "type": "number" + } + } + } + }, + "risks": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "category": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "insights": { + "type": "array", + "items": { + "type": "object", + "properties": { + "description": { + "type": "string" + }, + "timestamp": { + "type": "integer" + }, + "urls": { + "type": "object" + } + } + } + }, + "instances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "integrationId": { + "type": "string" + }, + "status": { + "type": "string" + }, + "classification": { + "type": "string" + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/app_views/{id}": { + "get": { + "operationId": "apptotal_GetAppViewAppsResponse", + "summary": "GetAppViewAppsResponse (Apptotal)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "publisher": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "siteUrl": { + "type": "string" + }, + "logoUrl": { + "type": "string" + } + } + }, + "platform": { + "type": "string" + }, + "description": { + "type": "string" + }, + "redirectUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "websiteUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "categories": { + "type": "array", + "items": { + "type": "string" + } + }, + "tags": { + "type": "array", + "items": { + "type": "string" + } + }, + "permissionLevel": { + "type": "number" + }, + "riskScore": { + "type": "number" + }, + "risk": { + "type": "string" + }, + "externalIds": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "clientId": { + "type": "string" + }, + "permissions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scope": { + "type": "string" + }, + "service": { + "type": "string" + }, + "description": { + "type": "string" + }, + "accessType": { + "type": "string" + }, + "level": { + "type": "string" + } + } + } + }, + "compliance": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataRetention": { + "type": "string" + }, + "clientType": { + "type": "string" + }, + "logoUrl": { + "type": "string" + }, + "privacyPolicyUrl": { + "type": "string" + }, + "termsOfServiceUrl": { + "type": "string" + }, + "marketplaceUrl": { + "type": "string" + }, + "marketplaceData": { + "type": "object", + "properties": { + "stars": { + "type": "integer" + }, + "downloads": { + "type": "integer" + }, + "reviews": { + "type": "integer" + } + } + }, + "platformVerified": { + "type": "boolean" + }, + "canonicVerified": { + "type": "boolean" + }, + "developerEmail": { + "type": "string" + }, + "consentScreenshot": { + "type": "string" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "object", + "properties": { + "ispName": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "proxyType": { + "type": "string" + }, + "usageType": { + "type": "string" + }, + "domainName": { + "type": "string" + }, + "countryCode": { + "type": "string" + } + } + } + }, + "extractedUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "extractedApiCalls": { + "type": "array", + "items": { + "type": "string" + } + }, + "vulnerabilities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "version": { + "type": "string" + }, + "cveId": { + "type": "string" + }, + "summary": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "apiActivities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "operationType": { + "type": "string" + }, + "percentage": { + "type": "number" + } + } + } + }, + "risks": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "category": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "insights": { + "type": "array", + "items": { + "type": "object", + "properties": { + "description": { + "type": "string" + }, + "timestamp": { + "type": "integer" + }, + "urls": { + "type": "object" + } + } + } + }, + "instances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "integrationId": { + "type": "string" + }, + "status": { + "type": "string" + }, + "classification": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/apps/app": { + "get": { + "operationId": "apptotal_GetAllApps", + "summary": "GetAllApps (Apptotal)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "publisher": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "siteUrl": { + "type": "string" + }, + "logoUrl": { + "type": "string" + } + } + }, + "platform": { + "type": "string" + }, + "description": { + "type": "string" + }, + "redirectUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "websiteUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "categories": { + "type": "array", + "items": { + "type": "string" + } + }, + "tags": { + "type": "array", + "items": { + "type": "string" + } + }, + "permissionLevel": { + "type": "number" + }, + "riskScore": { + "type": "number" + }, + "risk": { + "type": "string" + }, + "externalIds": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "clientId": { + "type": "string" + }, + "permissions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scope": { + "type": "string" + }, + "service": { + "type": "string" + }, + "description": { + "type": "string" + }, + "accessType": { + "type": "string" + }, + "level": { + "type": "string" + } + } + } + }, + "compliance": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataRetention": { + "type": "string" + }, + "clientType": { + "type": "string" + }, + "logoUrl": { + "type": "string" + }, + "privacyPolicyUrl": { + "type": "string" + }, + "termsOfServiceUrl": { + "type": "string" + }, + "marketplaceUrl": { + "type": "string" + }, + "marketplaceData": { + "type": "object", + "properties": { + "stars": { + "type": "integer" + }, + "downloads": { + "type": "integer" + }, + "reviews": { + "type": "integer" + } + } + }, + "platformVerified": { + "type": "boolean" + }, + "canonicVerified": { + "type": "boolean" + }, + "developerEmail": { + "type": "string" + }, + "consentScreenshot": { + "type": "string" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "object", + "properties": { + "ispName": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "proxyType": { + "type": "string" + }, + "usageType": { + "type": "string" + }, + "domainName": { + "type": "string" + }, + "countryCode": { + "type": "string" + } + } + } + }, + "extractedUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "extractedApiCalls": { + "type": "array", + "items": { + "type": "string" + } + }, + "vulnerabilities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "version": { + "type": "string" + }, + "cveId": { + "type": "string" + }, + "summary": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "apiActivities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "operationType": { + "type": "string" + }, + "percentage": { + "type": "number" + } + } + } + }, + "risks": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "category": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "insights": { + "type": "array", + "items": { + "type": "object", + "properties": { + "description": { + "type": "string" + }, + "timestamp": { + "type": "integer" + }, + "urls": { + "type": "object" + } + } + } + }, + "instances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "integrationId": { + "type": "string" + }, + "status": { + "type": "string" + }, + "classification": { + "type": "string" + } + } + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "apptotal_CreateApp", + "summary": "CreateApp (Apptotal)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "publisher": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "siteUrl": { + "type": "string" + }, + "logoUrl": { + "type": "string" + } + } + }, + "platform": { + "type": "string" + }, + "description": { + "type": "string" + }, + "redirectUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "websiteUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "categories": { + "type": "array", + "items": { + "type": "string" + } + }, + "tags": { + "type": "array", + "items": { + "type": "string" + } + }, + "permissionLevel": { + "type": "number" + }, + "riskScore": { + "type": "number" + }, + "risk": { + "type": "string" + }, + "externalIds": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "clientId": { + "type": "string" + }, + "permissions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scope": { + "type": "string" + }, + "service": { + "type": "string" + }, + "description": { + "type": "string" + }, + "accessType": { + "type": "string" + }, + "level": { + "type": "string" + } + } + } + }, + "compliance": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataRetention": { + "type": "string" + }, + "clientType": { + "type": "string" + }, + "logoUrl": { + "type": "string" + }, + "privacyPolicyUrl": { + "type": "string" + }, + "termsOfServiceUrl": { + "type": "string" + }, + "marketplaceUrl": { + "type": "string" + }, + "marketplaceData": { + "type": "object", + "properties": { + "stars": { + "type": "integer" + }, + "downloads": { + "type": "integer" + }, + "reviews": { + "type": "integer" + } + } + }, + "platformVerified": { + "type": "boolean" + }, + "canonicVerified": { + "type": "boolean" + }, + "developerEmail": { + "type": "string" + }, + "consentScreenshot": { + "type": "string" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "object", + "properties": { + "ispName": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "proxyType": { + "type": "string" + }, + "usageType": { + "type": "string" + }, + "domainName": { + "type": "string" + }, + "countryCode": { + "type": "string" + } + } + } + }, + "extractedUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "extractedApiCalls": { + "type": "array", + "items": { + "type": "string" + } + }, + "vulnerabilities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "version": { + "type": "string" + }, + "cveId": { + "type": "string" + }, + "summary": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "apiActivities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "operationType": { + "type": "string" + }, + "percentage": { + "type": "number" + } + } + } + }, + "risks": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "category": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "insights": { + "type": "array", + "items": { + "type": "object", + "properties": { + "description": { + "type": "string" + }, + "timestamp": { + "type": "integer" + }, + "urls": { + "type": "object" + } + } + } + }, + "instances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "integrationId": { + "type": "string" + }, + "status": { + "type": "string" + }, + "classification": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "publisher": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "siteUrl": { + "type": "string" + }, + "logoUrl": { + "type": "string" + } + } + }, + "platform": { + "type": "string" + }, + "description": { + "type": "string" + }, + "redirectUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "websiteUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "categories": { + "type": "array", + "items": { + "type": "string" + } + }, + "tags": { + "type": "array", + "items": { + "type": "string" + } + }, + "permissionLevel": { + "type": "number" + }, + "riskScore": { + "type": "number" + }, + "risk": { + "type": "string" + }, + "externalIds": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "clientId": { + "type": "string" + }, + "permissions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scope": { + "type": "string" + }, + "service": { + "type": "string" + }, + "description": { + "type": "string" + }, + "accessType": { + "type": "string" + }, + "level": { + "type": "string" + } + } + } + }, + "compliance": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataRetention": { + "type": "string" + }, + "clientType": { + "type": "string" + }, + "logoUrl": { + "type": "string" + }, + "privacyPolicyUrl": { + "type": "string" + }, + "termsOfServiceUrl": { + "type": "string" + }, + "marketplaceUrl": { + "type": "string" + }, + "marketplaceData": { + "type": "object", + "properties": { + "stars": { + "type": "integer" + }, + "downloads": { + "type": "integer" + }, + "reviews": { + "type": "integer" + } + } + }, + "platformVerified": { + "type": "boolean" + }, + "canonicVerified": { + "type": "boolean" + }, + "developerEmail": { + "type": "string" + }, + "consentScreenshot": { + "type": "string" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "object", + "properties": { + "ispName": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "proxyType": { + "type": "string" + }, + "usageType": { + "type": "string" + }, + "domainName": { + "type": "string" + }, + "countryCode": { + "type": "string" + } + } + } + }, + "extractedUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "extractedApiCalls": { + "type": "array", + "items": { + "type": "string" + } + }, + "vulnerabilities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "version": { + "type": "string" + }, + "cveId": { + "type": "string" + }, + "summary": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "apiActivities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "operationType": { + "type": "string" + }, + "percentage": { + "type": "number" + } + } + } + }, + "risks": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "category": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "insights": { + "type": "array", + "items": { + "type": "object", + "properties": { + "description": { + "type": "string" + }, + "timestamp": { + "type": "integer" + }, + "urls": { + "type": "object" + } + } + } + }, + "instances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "integrationId": { + "type": "string" + }, + "status": { + "type": "string" + }, + "classification": { + "type": "string" + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/apps/search": { + "get": { + "operationId": "apptotal_AppsSearch", + "summary": "AppsSearch (Apptotal)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "publisher": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "siteUrl": { + "type": "string" + }, + "logoUrl": { + "type": "string" + } + } + }, + "platform": { + "type": "string" + }, + "description": { + "type": "string" + }, + "redirectUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "websiteUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "categories": { + "type": "array", + "items": { + "type": "string" + } + }, + "tags": { + "type": "array", + "items": { + "type": "string" + } + }, + "permissionLevel": { + "type": "number" + }, + "riskScore": { + "type": "number" + }, + "risk": { + "type": "string" + }, + "externalIds": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "clientId": { + "type": "string" + }, + "permissions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scope": { + "type": "string" + }, + "service": { + "type": "string" + }, + "description": { + "type": "string" + }, + "accessType": { + "type": "string" + }, + "level": { + "type": "string" + } + } + } + }, + "compliance": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataRetention": { + "type": "string" + }, + "clientType": { + "type": "string" + }, + "logoUrl": { + "type": "string" + }, + "privacyPolicyUrl": { + "type": "string" + }, + "termsOfServiceUrl": { + "type": "string" + }, + "marketplaceUrl": { + "type": "string" + }, + "marketplaceData": { + "type": "object", + "properties": { + "stars": { + "type": "integer" + }, + "downloads": { + "type": "integer" + }, + "reviews": { + "type": "integer" + } + } + }, + "platformVerified": { + "type": "boolean" + }, + "canonicVerified": { + "type": "boolean" + }, + "developerEmail": { + "type": "string" + }, + "consentScreenshot": { + "type": "string" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "object", + "properties": { + "ispName": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "proxyType": { + "type": "string" + }, + "usageType": { + "type": "string" + }, + "domainName": { + "type": "string" + }, + "countryCode": { + "type": "string" + } + } + } + }, + "extractedUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "extractedApiCalls": { + "type": "array", + "items": { + "type": "string" + } + }, + "vulnerabilities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "version": { + "type": "string" + }, + "cveId": { + "type": "string" + }, + "summary": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "apiActivities": { + "type": "array", + "items": { + "type": "object", + "properties": { + "operationType": { + "type": "string" + }, + "percentage": { + "type": "number" + } + } + } + }, + "risks": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "category": { + "type": "string" + }, + "severity": { + "type": "string" + } + } + } + }, + "insights": { + "type": "array", + "items": { + "type": "object", + "properties": { + "description": { + "type": "string" + }, + "timestamp": { + "type": "integer" + }, + "urls": { + "type": "object" + } + } + } + }, + "instances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "integrationId": { + "type": "string" + }, + "status": { + "type": "string" + }, + "classification": { + "type": "string" + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/auditlogEntryReport": { + "get": { + "operationId": "adminauditlogs_GetAll", + "summary": "GetAll (Adminauditlogs)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "status": { + "type": "string", + "description": "Status of running task" + }, + "progressItemsComplete": { + "type": "integer", + "description": "Number of items processed" + }, + "progressEndTime": { + "type": "integer", + "description": "End time" + }, + "errorMessage": { + "type": "string", + "description": "Error message" + }, + "errorCode": { + "type": "string" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "adminauditlogs_Delete", + "summary": "Delete (Adminauditlogs)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "status": { + "type": "string", + "description": "Status of running task" + }, + "progressItemsComplete": { + "type": "integer", + "description": "Number of items processed" + }, + "progressEndTime": { + "type": "integer", + "description": "End time" + }, + "errorMessage": { + "type": "string", + "description": "Error message" + }, + "errorCode": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/authSettings": { + "get": { + "operationId": "auth_settings_Get", + "summary": "Get (Auth Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "orgAuthType": { + "type": "string", + "description": "User authentication type. Setting it to an LDAP-based authentication requires a complete LdapProperties configuration." + }, + "oneTimeAuth": { + "type": "string", + "description": "When the orgAuthType is NONE, administrators must manually provide the password to new end users." + }, + "samlEnabled": { + "type": "boolean", + "description": "Whether or not to authenticate users using SAML Single Sign-On. Enabling SAML requires complete SamlSettings." + }, + "kerberosEnabled": { + "type": "boolean", + "description": "Whether or not to authenticate users using Kerberos" + }, + "kerberosPwd": { + "type": "string", + "description": "Read Only. Kerberos password can only be set through generateKerberosPassword api." + }, + "authFrequency": { + "type": "string", + "description": "How frequently the users are required to authenticate (i.e., cookie expiration duration after a user is first authenticated). This field is not applicable to the Lite API." + }, + "authCustomFrequency": { + "type": "integer", + "description": "How frequently the users are required to authenticate. This field is customized to set the value in days. Valid range is 1\u2013180." + }, + "passwordStrength": { + "type": "string", + "description": "Password strength required for form-based authentication of hosted DB users. Not applicable for other authentication types (e.g. SAML SSO or Directory)." + }, + "passwordExpiry": { + "type": "string", + "description": "Password expiration required for form-based authentication of hosted DB users. Not applicable for other authentication types (e.g. SAML SSO or Directory)." + }, + "lastSyncStartTime": { + "type": "integer", + "description": "Timestamp (epoch time in seconds) corresponding to the start of the last LDAP sync." + }, + "lastSyncEndTime": { + "type": "integer", + "description": "Timestamp (epoch time in seconds) corresponding to the end of the last LDAP sync." + }, + "mobileAdminSamlIdpEnabled": { + "type": "boolean", + "description": "Indicate the use of Mobile Admin as IdP" + }, + "autoProvision": { + "type": "boolean", + "description": "Enable SAML Auto-Provisioning" + }, + "directorySyncMigrateToScimEnabled": { + "type": "boolean", + "description": "Enable to disable directory synchronization for this user repository type so you can enable SCIM provisioning or SAML auto-provisioning." + } + } + } + } + } + } + } + }, + "put": { + "operationId": "auth_settings_UpdateAuthSettings", + "summary": "UpdateAuthSettings (Auth Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "orgAuthType": { + "type": "string", + "description": "User authentication type. Setting it to an LDAP-based authentication requires a complete LdapProperties configuration." + }, + "oneTimeAuth": { + "type": "string", + "description": "When the orgAuthType is NONE, administrators must manually provide the password to new end users." + }, + "samlEnabled": { + "type": "boolean", + "description": "Whether or not to authenticate users using SAML Single Sign-On. Enabling SAML requires complete SamlSettings." + }, + "kerberosEnabled": { + "type": "boolean", + "description": "Whether or not to authenticate users using Kerberos" + }, + "kerberosPwd": { + "type": "string", + "description": "Read Only. Kerberos password can only be set through generateKerberosPassword api." + }, + "authFrequency": { + "type": "string", + "description": "How frequently the users are required to authenticate (i.e., cookie expiration duration after a user is first authenticated). This field is not applicable to the Lite API." + }, + "authCustomFrequency": { + "type": "integer", + "description": "How frequently the users are required to authenticate. This field is customized to set the value in days. Valid range is 1\u2013180." + }, + "passwordStrength": { + "type": "string", + "description": "Password strength required for form-based authentication of hosted DB users. Not applicable for other authentication types (e.g. SAML SSO or Directory)." + }, + "passwordExpiry": { + "type": "string", + "description": "Password expiration required for form-based authentication of hosted DB users. Not applicable for other authentication types (e.g. SAML SSO or Directory)." + }, + "lastSyncStartTime": { + "type": "integer", + "description": "Timestamp (epoch time in seconds) corresponding to the start of the last LDAP sync." + }, + "lastSyncEndTime": { + "type": "integer", + "description": "Timestamp (epoch time in seconds) corresponding to the end of the last LDAP sync." + }, + "mobileAdminSamlIdpEnabled": { + "type": "boolean", + "description": "Indicate the use of Mobile Admin as IdP" + }, + "autoProvision": { + "type": "boolean", + "description": "Enable SAML Auto-Provisioning" + }, + "directorySyncMigrateToScimEnabled": { + "type": "boolean", + "description": "Enable to disable directory synchronization for this user repository type so you can enable SCIM provisioning or SAML auto-provisioning." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "orgAuthType": { + "type": "string", + "description": "User authentication type. Setting it to an LDAP-based authentication requires a complete LdapProperties configuration." + }, + "oneTimeAuth": { + "type": "string", + "description": "When the orgAuthType is NONE, administrators must manually provide the password to new end users." + }, + "samlEnabled": { + "type": "boolean", + "description": "Whether or not to authenticate users using SAML Single Sign-On. Enabling SAML requires complete SamlSettings." + }, + "kerberosEnabled": { + "type": "boolean", + "description": "Whether or not to authenticate users using Kerberos" + }, + "kerberosPwd": { + "type": "string", + "description": "Read Only. Kerberos password can only be set through generateKerberosPassword api." + }, + "authFrequency": { + "type": "string", + "description": "How frequently the users are required to authenticate (i.e., cookie expiration duration after a user is first authenticated). This field is not applicable to the Lite API." + }, + "authCustomFrequency": { + "type": "integer", + "description": "How frequently the users are required to authenticate. This field is customized to set the value in days. Valid range is 1\u2013180." + }, + "passwordStrength": { + "type": "string", + "description": "Password strength required for form-based authentication of hosted DB users. Not applicable for other authentication types (e.g. SAML SSO or Directory)." + }, + "passwordExpiry": { + "type": "string", + "description": "Password expiration required for form-based authentication of hosted DB users. Not applicable for other authentication types (e.g. SAML SSO or Directory)." + }, + "lastSyncStartTime": { + "type": "integer", + "description": "Timestamp (epoch time in seconds) corresponding to the start of the last LDAP sync." + }, + "lastSyncEndTime": { + "type": "integer", + "description": "Timestamp (epoch time in seconds) corresponding to the end of the last LDAP sync." + }, + "mobileAdminSamlIdpEnabled": { + "type": "boolean", + "description": "Indicate the use of Mobile Admin as IdP" + }, + "autoProvision": { + "type": "boolean", + "description": "Enable SAML Auto-Provisioning" + }, + "directorySyncMigrateToScimEnabled": { + "type": "boolean", + "description": "Enable to disable directory synchronization for this user repository type so you can enable SCIM provisioning or SAML auto-provisioning." + } + } + } + } + } + } + } + }, + "/zia/api/v1/authSettings/exemptedUrls": { + "get": { + "operationId": "user_authentication_settings_Get", + "summary": "Get (User Authentication Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Domains or URLs which are exempted from SSL Inspection" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/authSettings/lite": { + "get": { + "operationId": "auth_settings_GetLite", + "summary": "GetLite (Auth Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "orgAuthType": { + "type": "string", + "description": "User authentication type. Setting it to an LDAP-based authentication requires a complete LdapProperties configuration." + }, + "oneTimeAuth": { + "type": "string", + "description": "When the orgAuthType is NONE, administrators must manually provide the password to new end users." + }, + "samlEnabled": { + "type": "boolean", + "description": "Whether or not to authenticate users using SAML Single Sign-On. Enabling SAML requires complete SamlSettings." + }, + "kerberosEnabled": { + "type": "boolean", + "description": "Whether or not to authenticate users using Kerberos" + }, + "kerberosPwd": { + "type": "string", + "description": "Read Only. Kerberos password can only be set through generateKerberosPassword api." + }, + "authFrequency": { + "type": "string", + "description": "How frequently the users are required to authenticate (i.e., cookie expiration duration after a user is first authenticated). This field is not applicable to the Lite API." + }, + "authCustomFrequency": { + "type": "integer", + "description": "How frequently the users are required to authenticate. This field is customized to set the value in days. Valid range is 1\u2013180." + }, + "passwordStrength": { + "type": "string", + "description": "Password strength required for form-based authentication of hosted DB users. Not applicable for other authentication types (e.g. SAML SSO or Directory)." + }, + "passwordExpiry": { + "type": "string", + "description": "Password expiration required for form-based authentication of hosted DB users. Not applicable for other authentication types (e.g. SAML SSO or Directory)." + }, + "lastSyncStartTime": { + "type": "integer", + "description": "Timestamp (epoch time in seconds) corresponding to the start of the last LDAP sync." + }, + "lastSyncEndTime": { + "type": "integer", + "description": "Timestamp (epoch time in seconds) corresponding to the end of the last LDAP sync." + }, + "mobileAdminSamlIdpEnabled": { + "type": "boolean", + "description": "Indicate the use of Mobile Admin as IdP" + }, + "autoProvision": { + "type": "boolean", + "description": "Enable SAML Auto-Provisioning" + }, + "directorySyncMigrateToScimEnabled": { + "type": "boolean", + "description": "Enable to disable directory synchronization for this user repository type so you can enable SCIM provisioning or SAML auto-provisioning." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/bandwidthClasses": { + "get": { + "operationId": "bandwidth_control__bandwidth_classes_GetByName", + "summary": "GetByName (Bandwidth Control / Bandwidth Classes)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "name": { + "type": "string" + }, + "getfileSize": { + "type": "string" + }, + "fileSize": { + "type": "string" + }, + "type": { + "type": "string" + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "urls": { + "type": "array", + "items": { + "type": "string" + } + }, + "applicationServiceGroups": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkServices": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "bandwidth_control__bandwidth_classes_Create", + "summary": "Create (Bandwidth Control / Bandwidth Classes)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "name": { + "type": "string" + }, + "getfileSize": { + "type": "string" + }, + "fileSize": { + "type": "string" + }, + "type": { + "type": "string" + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "urls": { + "type": "array", + "items": { + "type": "string" + } + }, + "applicationServiceGroups": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkServices": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "name": { + "type": "string" + }, + "getfileSize": { + "type": "string" + }, + "fileSize": { + "type": "string" + }, + "type": { + "type": "string" + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "urls": { + "type": "array", + "items": { + "type": "string" + } + }, + "applicationServiceGroups": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkServices": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/bandwidthClasses/{id}": { + "get": { + "operationId": "bandwidth_control__bandwidth_classes_Get", + "summary": "Get (Bandwidth Control / Bandwidth Classes)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "name": { + "type": "string" + }, + "getfileSize": { + "type": "string" + }, + "fileSize": { + "type": "string" + }, + "type": { + "type": "string" + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "urls": { + "type": "array", + "items": { + "type": "string" + } + }, + "applicationServiceGroups": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkServices": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "bandwidth_control__bandwidth_classes_Update", + "summary": "Update (Bandwidth Control / Bandwidth Classes)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "name": { + "type": "string" + }, + "getfileSize": { + "type": "string" + }, + "fileSize": { + "type": "string" + }, + "type": { + "type": "string" + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "urls": { + "type": "array", + "items": { + "type": "string" + } + }, + "applicationServiceGroups": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkServices": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "name": { + "type": "string" + }, + "getfileSize": { + "type": "string" + }, + "fileSize": { + "type": "string" + }, + "type": { + "type": "string" + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "urls": { + "type": "array", + "items": { + "type": "string" + } + }, + "applicationServiceGroups": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkServices": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "bandwidth_control__bandwidth_classes_Delete", + "summary": "Delete (Bandwidth Control / Bandwidth Classes)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "name": { + "type": "string" + }, + "getfileSize": { + "type": "string" + }, + "fileSize": { + "type": "string" + }, + "type": { + "type": "string" + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "urls": { + "type": "array", + "items": { + "type": "string" + } + }, + "applicationServiceGroups": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "networkServices": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/bandwidthControlRules": { + "get": { + "operationId": "bandwidth_control__bandwidth_control_rules_GetByName", + "summary": "GetByName (Bandwidth Control / Bandwidth Control Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "state": { + "type": "string" + }, + "description": { + "type": "string" + }, + "maxBandwidth": { + "type": "integer" + }, + "minBandwidth": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "defaultRule": { + "type": "boolean" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "bandwidthClasses": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "bandwidth_control__bandwidth_control_rules_Create", + "summary": "Create (Bandwidth Control / Bandwidth Control Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "state": { + "type": "string" + }, + "description": { + "type": "string" + }, + "maxBandwidth": { + "type": "integer" + }, + "minBandwidth": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "defaultRule": { + "type": "boolean" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "bandwidthClasses": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "state": { + "type": "string" + }, + "description": { + "type": "string" + }, + "maxBandwidth": { + "type": "integer" + }, + "minBandwidth": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "defaultRule": { + "type": "boolean" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "bandwidthClasses": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/bandwidthControlRules/{id}": { + "get": { + "operationId": "bandwidth_control__bandwidth_control_rules_Get", + "summary": "Get (Bandwidth Control / Bandwidth Control Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "state": { + "type": "string" + }, + "description": { + "type": "string" + }, + "maxBandwidth": { + "type": "integer" + }, + "minBandwidth": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "defaultRule": { + "type": "boolean" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "bandwidthClasses": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "bandwidth_control__bandwidth_control_rules_Update", + "summary": "Update (Bandwidth Control / Bandwidth Control Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "state": { + "type": "string" + }, + "description": { + "type": "string" + }, + "maxBandwidth": { + "type": "integer" + }, + "minBandwidth": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "defaultRule": { + "type": "boolean" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "bandwidthClasses": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "state": { + "type": "string" + }, + "description": { + "type": "string" + }, + "maxBandwidth": { + "type": "integer" + }, + "minBandwidth": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "defaultRule": { + "type": "boolean" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "bandwidthClasses": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "bandwidth_control__bandwidth_control_rules_Delete", + "summary": "Delete (Bandwidth Control / Bandwidth Control Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "state": { + "type": "string" + }, + "description": { + "type": "string" + }, + "maxBandwidth": { + "type": "integer" + }, + "minBandwidth": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "defaultRule": { + "type": "boolean" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "bandwidthClasses": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/behavioralAnalysisAdvancedSettings": { + "get": { + "operationId": "sandbox__sandbox_settings_Get", + "summary": "Get (Sandbox / Sandbox Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "fileHashesToBeBlocked": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "put": { + "operationId": "sandbox__sandbox_settings_Updatev2", + "summary": "Updatev2 (Sandbox / Sandbox Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "fileHashesToBeBlocked": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "fileHashesToBeBlocked": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/browserControlSettings": { + "get": { + "operationId": "browser_control_settings_GetBrowserControlSettings", + "summary": "GetBrowserControlSettings (Browser Control Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "pluginCheckFrequency": { + "type": "string", + "description": "Specifies how frequently the service checks browsers and relevant applications to warn users regarding outdated or vulnerable browsers, plugins, and applications. If not set, the warnings are disabled\nSupported Values: DAILY, WEEKLY, MONTHLY, EVERY_2_HOURS, EVERY_4_HOURS, EVERY_6_HOURS, EVERY_8_HOURS, EVERY_12_HOURS" + }, + "bypassPlugins": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of plugins that need to be bypassed for warnings. This attribute has effect only if the 'enableWarnings' attribute is set to true. If not set, all vulnerable plugins are warned.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "bypassApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of applications that need to be bypassed for warnings. This attribute has effect only if the 'enableWarnings' attribute is set to true. If not set, all vulnerable applications are warned.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedInternetExplorerVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Microsoft browser that need to be blocked. If not set, all Microsoft browser versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedChromeVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Google Chrome browser that need to be blocked. If not set, all Google Chrome versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedFirefoxVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Mozilla Firefox browser that need to be blocked. If not set, all Mozilla Firefox versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedSafariVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Apple Safari browser that need to be blocked. If not set, all Apple Safari versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedOperaVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Opera browser that need to be blocked. If not set, all Opera versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "smartIsolationUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which the rule is applied" + }, + "smartIsolationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which the rule is applied" + }, + "smartIsolationProfile": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + } + }, + "description": "The isolation profile.\nSee https://help.zscaler.com/zia/creating-isolation-profiles-zia" + }, + "bypassAllBrowsers": { + "type": "boolean", + "description": "If set to true, all the browsers are bypassed for warnings.\nIf not set, all vulnerable browsers are warned. This attribute has effect only if the 'enableWarnings' is set to true." + }, + "allowAllBrowsers": { + "type": "boolean", + "description": "A Boolean value that specifies whether or not to allow all the browsers and their respective versions access to the internet" + }, + "enableWarnings": { + "type": "boolean", + "description": "A Boolean value that specifies if the warnings are enabled" + }, + "enableSmartBrowserIsolation": { + "type": "boolean", + "description": "A Boolean value that specifies if Smart Browser Isolation is enabled" + }, + "smartIsolationProfileId": { + "type": "integer", + "description": "The isolation profile ID" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "browser_control_settings_UpdateBrowserControlSettings", + "summary": "UpdateBrowserControlSettings (Browser Control Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "pluginCheckFrequency": { + "type": "string", + "description": "Specifies how frequently the service checks browsers and relevant applications to warn users regarding outdated or vulnerable browsers, plugins, and applications. If not set, the warnings are disabled\nSupported Values: DAILY, WEEKLY, MONTHLY, EVERY_2_HOURS, EVERY_4_HOURS, EVERY_6_HOURS, EVERY_8_HOURS, EVERY_12_HOURS" + }, + "bypassPlugins": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of plugins that need to be bypassed for warnings. This attribute has effect only if the 'enableWarnings' attribute is set to true. If not set, all vulnerable plugins are warned.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "bypassApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of applications that need to be bypassed for warnings. This attribute has effect only if the 'enableWarnings' attribute is set to true. If not set, all vulnerable applications are warned.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedInternetExplorerVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Microsoft browser that need to be blocked. If not set, all Microsoft browser versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedChromeVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Google Chrome browser that need to be blocked. If not set, all Google Chrome versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedFirefoxVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Mozilla Firefox browser that need to be blocked. If not set, all Mozilla Firefox versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedSafariVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Apple Safari browser that need to be blocked. If not set, all Apple Safari versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedOperaVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Opera browser that need to be blocked. If not set, all Opera versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "smartIsolationUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which the rule is applied" + }, + "smartIsolationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which the rule is applied" + }, + "smartIsolationProfile": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + } + }, + "description": "The isolation profile.\nSee https://help.zscaler.com/zia/creating-isolation-profiles-zia" + }, + "bypassAllBrowsers": { + "type": "boolean", + "description": "If set to true, all the browsers are bypassed for warnings.\nIf not set, all vulnerable browsers are warned. This attribute has effect only if the 'enableWarnings' is set to true." + }, + "allowAllBrowsers": { + "type": "boolean", + "description": "A Boolean value that specifies whether or not to allow all the browsers and their respective versions access to the internet" + }, + "enableWarnings": { + "type": "boolean", + "description": "A Boolean value that specifies if the warnings are enabled" + }, + "enableSmartBrowserIsolation": { + "type": "boolean", + "description": "A Boolean value that specifies if Smart Browser Isolation is enabled" + }, + "smartIsolationProfileId": { + "type": "integer", + "description": "The isolation profile ID" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "pluginCheckFrequency": { + "type": "string", + "description": "Specifies how frequently the service checks browsers and relevant applications to warn users regarding outdated or vulnerable browsers, plugins, and applications. If not set, the warnings are disabled\nSupported Values: DAILY, WEEKLY, MONTHLY, EVERY_2_HOURS, EVERY_4_HOURS, EVERY_6_HOURS, EVERY_8_HOURS, EVERY_12_HOURS" + }, + "bypassPlugins": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of plugins that need to be bypassed for warnings. This attribute has effect only if the 'enableWarnings' attribute is set to true. If not set, all vulnerable plugins are warned.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "bypassApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of applications that need to be bypassed for warnings. This attribute has effect only if the 'enableWarnings' attribute is set to true. If not set, all vulnerable applications are warned.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedInternetExplorerVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Microsoft browser that need to be blocked. If not set, all Microsoft browser versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedChromeVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Google Chrome browser that need to be blocked. If not set, all Google Chrome versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedFirefoxVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Mozilla Firefox browser that need to be blocked. If not set, all Mozilla Firefox versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedSafariVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Apple Safari browser that need to be blocked. If not set, all Apple Safari versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "blockedOperaVersions": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Versions of Opera browser that need to be blocked. If not set, all Opera versions are allowed.\nSee Browser Control API Reference for supported values: https://help.zscaler.com/zia/browser-control-policy#/browserControlSettings-get" + }, + "smartIsolationUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which the rule is applied" + }, + "smartIsolationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which the rule is applied" + }, + "smartIsolationProfile": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + } + }, + "description": "The isolation profile.\nSee https://help.zscaler.com/zia/creating-isolation-profiles-zia" + }, + "bypassAllBrowsers": { + "type": "boolean", + "description": "If set to true, all the browsers are bypassed for warnings.\nIf not set, all vulnerable browsers are warned. This attribute has effect only if the 'enableWarnings' is set to true." + }, + "allowAllBrowsers": { + "type": "boolean", + "description": "A Boolean value that specifies whether or not to allow all the browsers and their respective versions access to the internet" + }, + "enableWarnings": { + "type": "boolean", + "description": "A Boolean value that specifies if the warnings are enabled" + }, + "enableSmartBrowserIsolation": { + "type": "boolean", + "description": "A Boolean value that specifies if Smart Browser Isolation is enabled" + }, + "smartIsolationProfileId": { + "type": "integer", + "description": "The isolation profile ID" + } + } + } + } + } + } + } + }, + "/zia/api/v1/casbDlpRules": { + "get": { + "operationId": "saas_security_api__casb_dlp_rules_GetByRuleID", + "summary": "GetByRuleID (Saas Security Api / Casb Dlp Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "severity": { + "type": "string" + }, + "description": { + "type": "string" + }, + "bucketOwner": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "contentLocation": { + "type": "string" + }, + "numberOfInternalCollaborators": { + "type": "string" + }, + "numberOfExternalCollaborators": { + "type": "string" + }, + "recipient": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "accessControl": { + "type": "string" + }, + "watermarkDeleteOldVersion": { + "type": "boolean" + }, + "includeCriteriaDomainProfile": { + "type": "boolean" + }, + "includeEmailRecipientProfile": { + "type": "boolean" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "includeEntityGroups": { + "type": "boolean" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "collaborationScope": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "components": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "criteriaDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "entityGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDCustom object" + }, + "zscalerIncidentReceiver": { + "type": "object", + "description": "common.IDCustom object" + }, + "auditorNotification": { + "type": "object", + "description": "common.IDCustom object" + }, + "tag": { + "type": "object", + "description": "common.IDCustom object" + }, + "watermarkProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "redactionProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "saas_security_api__casb_dlp_rules_Create", + "summary": "Create (Saas Security Api / Casb Dlp Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "severity": { + "type": "string" + }, + "description": { + "type": "string" + }, + "bucketOwner": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "contentLocation": { + "type": "string" + }, + "numberOfInternalCollaborators": { + "type": "string" + }, + "numberOfExternalCollaborators": { + "type": "string" + }, + "recipient": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "accessControl": { + "type": "string" + }, + "watermarkDeleteOldVersion": { + "type": "boolean" + }, + "includeCriteriaDomainProfile": { + "type": "boolean" + }, + "includeEmailRecipientProfile": { + "type": "boolean" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "includeEntityGroups": { + "type": "boolean" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "collaborationScope": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "components": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "criteriaDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "entityGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDCustom object" + }, + "zscalerIncidentReceiver": { + "type": "object", + "description": "common.IDCustom object" + }, + "auditorNotification": { + "type": "object", + "description": "common.IDCustom object" + }, + "tag": { + "type": "object", + "description": "common.IDCustom object" + }, + "watermarkProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "redactionProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "severity": { + "type": "string" + }, + "description": { + "type": "string" + }, + "bucketOwner": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "contentLocation": { + "type": "string" + }, + "numberOfInternalCollaborators": { + "type": "string" + }, + "numberOfExternalCollaborators": { + "type": "string" + }, + "recipient": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "accessControl": { + "type": "string" + }, + "watermarkDeleteOldVersion": { + "type": "boolean" + }, + "includeCriteriaDomainProfile": { + "type": "boolean" + }, + "includeEmailRecipientProfile": { + "type": "boolean" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "includeEntityGroups": { + "type": "boolean" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "collaborationScope": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "components": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "criteriaDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "entityGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDCustom object" + }, + "zscalerIncidentReceiver": { + "type": "object", + "description": "common.IDCustom object" + }, + "auditorNotification": { + "type": "object", + "description": "common.IDCustom object" + }, + "tag": { + "type": "object", + "description": "common.IDCustom object" + }, + "watermarkProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "redactionProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "saas_security_api__casb_dlp_rules_Delete", + "summary": "Delete (Saas Security Api / Casb Dlp Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "severity": { + "type": "string" + }, + "description": { + "type": "string" + }, + "bucketOwner": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "contentLocation": { + "type": "string" + }, + "numberOfInternalCollaborators": { + "type": "string" + }, + "numberOfExternalCollaborators": { + "type": "string" + }, + "recipient": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "accessControl": { + "type": "string" + }, + "watermarkDeleteOldVersion": { + "type": "boolean" + }, + "includeCriteriaDomainProfile": { + "type": "boolean" + }, + "includeEmailRecipientProfile": { + "type": "boolean" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "includeEntityGroups": { + "type": "boolean" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "collaborationScope": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "components": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "criteriaDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "entityGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDCustom object" + }, + "zscalerIncidentReceiver": { + "type": "object", + "description": "common.IDCustom object" + }, + "auditorNotification": { + "type": "object", + "description": "common.IDCustom object" + }, + "tag": { + "type": "object", + "description": "common.IDCustom object" + }, + "watermarkProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "redactionProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/casbDlpRules/{id}": { + "put": { + "operationId": "saas_security_api__casb_dlp_rules_Update", + "summary": "Update (Saas Security Api / Casb Dlp Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "severity": { + "type": "string" + }, + "description": { + "type": "string" + }, + "bucketOwner": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "contentLocation": { + "type": "string" + }, + "numberOfInternalCollaborators": { + "type": "string" + }, + "numberOfExternalCollaborators": { + "type": "string" + }, + "recipient": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "accessControl": { + "type": "string" + }, + "watermarkDeleteOldVersion": { + "type": "boolean" + }, + "includeCriteriaDomainProfile": { + "type": "boolean" + }, + "includeEmailRecipientProfile": { + "type": "boolean" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "includeEntityGroups": { + "type": "boolean" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "collaborationScope": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "components": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "criteriaDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "entityGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDCustom object" + }, + "zscalerIncidentReceiver": { + "type": "object", + "description": "common.IDCustom object" + }, + "auditorNotification": { + "type": "object", + "description": "common.IDCustom object" + }, + "tag": { + "type": "object", + "description": "common.IDCustom object" + }, + "watermarkProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "redactionProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "severity": { + "type": "string" + }, + "description": { + "type": "string" + }, + "bucketOwner": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "contentLocation": { + "type": "string" + }, + "numberOfInternalCollaborators": { + "type": "string" + }, + "numberOfExternalCollaborators": { + "type": "string" + }, + "recipient": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "accessControl": { + "type": "string" + }, + "watermarkDeleteOldVersion": { + "type": "boolean" + }, + "includeCriteriaDomainProfile": { + "type": "boolean" + }, + "includeEmailRecipientProfile": { + "type": "boolean" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "includeEntityGroups": { + "type": "boolean" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "collaborationScope": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "components": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectTypes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "criteriaDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "entityGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDCustom object" + }, + "zscalerIncidentReceiver": { + "type": "object", + "description": "common.IDCustom object" + }, + "auditorNotification": { + "type": "object", + "description": "common.IDCustom object" + }, + "tag": { + "type": "object", + "description": "common.IDCustom object" + }, + "watermarkProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "redactionProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/casbEmailLabel/lite": { + "get": { + "operationId": "saas_security_api_GetCasbEmailLabelLite", + "summary": "GetCasbEmailLabelLite (Saas Security Api)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "profileId": { + "type": "integer", + "description": "Domain profile ID" + }, + "profileName": { + "type": "string", + "description": "Domain profile name" + }, + "includeCompanyDomains": { + "type": "boolean", + "description": "A Boolean flag to determine if the organizational domains have to be included in the domain profile" + }, + "includeSubdomains": { + "type": "boolean", + "description": "A Boolean flag to determine whether or not to include subdomains" + }, + "description": { + "type": "string", + "description": "Additional notes or information about the domain profile" + }, + "customDomains": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of custom domains for the domain profile. There can be one or more custom domains." + }, + "predefinedEmailDomains": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of predefined email service provider domains for the domain profile\nSee SaaS Security API for supported values: https://help.zscaler.com/zia/saas-security-api#/domainProfiles/lite-get" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/casbMalwareRules": { + "get": { + "operationId": "saas_security_api__casb_malware_rules_GetByRuleID", + "summary": "GetByRuleID (Saas Security Api / Casb Malware Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "scanInboundEmailLink": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenantIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudApplicationTenant": { + "type": "array", + "items": { + "type": "object", + "description": "saas_security_api.CasbTenants object" + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "saas_security_api__casb_malware_rules_Create", + "summary": "Create (Saas Security Api / Casb Malware Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "scanInboundEmailLink": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenantIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudApplicationTenant": { + "type": "array", + "items": { + "type": "object", + "description": "saas_security_api.CasbTenants object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "scanInboundEmailLink": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenantIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudApplicationTenant": { + "type": "array", + "items": { + "type": "object", + "description": "saas_security_api.CasbTenants object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "saas_security_api__casb_malware_rules_Delete", + "summary": "Delete (Saas Security Api / Casb Malware Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "scanInboundEmailLink": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenantIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudApplicationTenant": { + "type": "array", + "items": { + "type": "object", + "description": "saas_security_api.CasbTenants object" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/casbMalwareRules/{id}": { + "put": { + "operationId": "saas_security_api__casb_malware_rules_Update", + "summary": "Update (Saas Security Api / Casb Malware Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "scanInboundEmailLink": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenantIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudApplicationTenant": { + "type": "array", + "items": { + "type": "object", + "description": "saas_security_api.CasbTenants object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "type": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "quarantineLocation": { + "type": "string" + }, + "scanInboundEmailLink": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "accessControl": { + "type": "string" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "casbEmailLabel": { + "type": "object", + "description": "common.IDCustom object" + }, + "casbTombstoneTemplate": { + "type": "object", + "description": "common.IDCustom object" + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenantIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudAppTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "cloudApplicationTenant": { + "type": "array", + "items": { + "type": "object", + "description": "saas_security_api.CasbTenants object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/casbTenant": { + "get": { + "operationId": "saas_security_api_GetCasbTenantLite", + "summary": "GetCasbTenantLite (Saas Security Api)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "profileId": { + "type": "integer", + "description": "Domain profile ID" + }, + "profileName": { + "type": "string", + "description": "Domain profile name" + }, + "includeCompanyDomains": { + "type": "boolean", + "description": "A Boolean flag to determine if the organizational domains have to be included in the domain profile" + }, + "includeSubdomains": { + "type": "boolean", + "description": "A Boolean flag to determine whether or not to include subdomains" + }, + "description": { + "type": "string", + "description": "Additional notes or information about the domain profile" + }, + "customDomains": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of custom domains for the domain profile. There can be one or more custom domains." + }, + "predefinedEmailDomains": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of predefined email service provider domains for the domain profile\nSee SaaS Security API for supported values: https://help.zscaler.com/zia/saas-security-api#/domainProfiles/lite-get" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/casbTenant/{id}": { + "get": { + "operationId": "saas_security_api_GetCasbTenantTagPolicy", + "summary": "GetCasbTenantTagPolicy (Saas Security Api)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "profileId": { + "type": "integer", + "description": "Domain profile ID" + }, + "profileName": { + "type": "string", + "description": "Domain profile name" + }, + "includeCompanyDomains": { + "type": "boolean", + "description": "A Boolean flag to determine if the organizational domains have to be included in the domain profile" + }, + "includeSubdomains": { + "type": "boolean", + "description": "A Boolean flag to determine whether or not to include subdomains" + }, + "description": { + "type": "string", + "description": "Additional notes or information about the domain profile" + }, + "customDomains": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of custom domains for the domain profile. There can be one or more custom domains." + }, + "predefinedEmailDomains": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of predefined email service provider domains for the domain profile\nSee SaaS Security API for supported values: https://help.zscaler.com/zia/saas-security-api#/domainProfiles/lite-get" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/cloudApplicationInstances": { + "get": { + "operationId": "cloud_app_instances_GetInstanceByName", + "summary": "GetInstanceByName (Cloud App Instances)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceType": { + "type": "string" + }, + "instanceName": { + "type": "string" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "modifiedAt": { + "type": "integer" + }, + "instanceIdentifiers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceIdentifier": { + "type": "string" + }, + "instanceIdentifierName": { + "type": "string" + }, + "identifierType": { + "type": "string" + }, + "modifiedAt": { + "type": "integer" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "cloud_app_instances_Create", + "summary": "Create (Cloud App Instances)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceType": { + "type": "string" + }, + "instanceName": { + "type": "string" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "modifiedAt": { + "type": "integer" + }, + "instanceIdentifiers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceIdentifier": { + "type": "string" + }, + "instanceIdentifierName": { + "type": "string" + }, + "identifierType": { + "type": "string" + }, + "modifiedAt": { + "type": "integer" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceType": { + "type": "string" + }, + "instanceName": { + "type": "string" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "modifiedAt": { + "type": "integer" + }, + "instanceIdentifiers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceIdentifier": { + "type": "string" + }, + "instanceIdentifierName": { + "type": "string" + }, + "identifierType": { + "type": "string" + }, + "modifiedAt": { + "type": "integer" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/cloudApplicationInstances/{id}": { + "get": { + "operationId": "cloud_app_instances_Get", + "summary": "Get (Cloud App Instances)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceType": { + "type": "string" + }, + "instanceName": { + "type": "string" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "modifiedAt": { + "type": "integer" + }, + "instanceIdentifiers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceIdentifier": { + "type": "string" + }, + "instanceIdentifierName": { + "type": "string" + }, + "identifierType": { + "type": "string" + }, + "modifiedAt": { + "type": "integer" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "cloud_app_instances_Update", + "summary": "Update (Cloud App Instances)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceType": { + "type": "string" + }, + "instanceName": { + "type": "string" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "modifiedAt": { + "type": "integer" + }, + "instanceIdentifiers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceIdentifier": { + "type": "string" + }, + "instanceIdentifierName": { + "type": "string" + }, + "identifierType": { + "type": "string" + }, + "modifiedAt": { + "type": "integer" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceType": { + "type": "string" + }, + "instanceName": { + "type": "string" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "modifiedAt": { + "type": "integer" + }, + "instanceIdentifiers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceIdentifier": { + "type": "string" + }, + "instanceIdentifierName": { + "type": "string" + }, + "identifierType": { + "type": "string" + }, + "modifiedAt": { + "type": "integer" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "cloud_app_instances_Delete", + "summary": "Delete (Cloud App Instances)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceType": { + "type": "string" + }, + "instanceName": { + "type": "string" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "modifiedAt": { + "type": "integer" + }, + "instanceIdentifiers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "instanceId": { + "type": "integer" + }, + "instanceIdentifier": { + "type": "string" + }, + "instanceIdentifierName": { + "type": "string" + }, + "identifierType": { + "type": "string" + }, + "modifiedAt": { + "type": "integer" + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/cloudApplications/bulkUpdate": { + "put": { + "operationId": "shadowitreport_Update", + "summary": "Update (Shadowitreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "sanctionedState": { + "type": "string" + }, + "applicationIds": { + "type": "array", + "items": { + "type": "integer" + } + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the cloud application" + }, + "name": { + "type": "string", + "description": "The name of the cloud application" + } + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "sanctionedState": { + "type": "string" + }, + "applicationIds": { + "type": "array", + "items": { + "type": "integer" + } + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the cloud application" + }, + "name": { + "type": "string", + "description": "The name of the cloud application" + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/cloudApplications/lite": { + "get": { + "operationId": "shadowitreport_GetAllCloudAppsLite", + "summary": "GetAllCloudAppsLite (Shadowitreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "sanctionedState": { + "type": "string" + }, + "applicationIds": { + "type": "array", + "items": { + "type": "integer" + } + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the cloud application" + }, + "name": { + "type": "string", + "description": "The name of the cloud application" + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/cloudApplications/policy": { + "get": { + "operationId": "cloudapplications__cloudapplications_GetCloudApplicationPolicy", + "summary": "GetCloudApplicationPolicy (Cloudapplications / Cloudapplications)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "app": { + "type": "string", + "description": "Application enum constant" + }, + "appName": { + "type": "string", + "description": "Cloud application name" + }, + "parent": { + "type": "string", + "description": "Application category enum constant" + }, + "parentName": { + "type": "string", + "description": "Name of the cloud application category" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/cloudApplications/sslPolicy": { + "get": { + "operationId": "cloudapplications__cloudapplications_GetCloudApplicationSSLPolicy", + "summary": "GetCloudApplicationSSLPolicy (Cloudapplications / Cloudapplications)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "app": { + "type": "string", + "description": "Application enum constant" + }, + "appName": { + "type": "string", + "description": "Cloud application name" + }, + "parent": { + "type": "string", + "description": "Application category enum constant" + }, + "parentName": { + "type": "string", + "description": "Name of the cloud application category" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/cloudToCloudIR": { + "get": { + "operationId": "c2c_incident_receiver_GetC2CIRName", + "summary": "GetC2CIRName (C2C Incident Receiver)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "status": { + "type": "array", + "items": { + "type": "string" + } + }, + "modifiedTime": { + "type": "integer" + }, + "lastTenantValidationTime": { + "type": "integer" + }, + "lastValidationMsg": { + "type": "object", + "properties": { + "errorMsg": { + "type": "string" + }, + "errorCode": { + "type": "string" + } + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "onboardableEntity": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "enterpriseTenantId": { + "type": "string" + }, + "application": { + "type": "string" + }, + "lastValidationMsg": { + "type": "object", + "properties": { + "errorMsg": { + "type": "string" + }, + "errorCode": { + "type": "string" + } + } + }, + "tenantAuthorizationInfo": { + "type": "object", + "properties": { + "accessToken": { + "type": "string" + }, + "botToken": { + "type": "string" + }, + "redirectUrl": { + "type": "string" + }, + "type": { + "type": "string" + }, + "env": { + "type": "string" + }, + "tempAuthCode": { + "type": "string" + }, + "subdomain": { + "type": "string" + }, + "apicp": { + "type": "string" + }, + "clientId": { + "type": "string" + }, + "clientSecret": { + "type": "string" + }, + "secretToken": { + "type": "string" + }, + "userName": { + "type": "string" + }, + "userPwd": { + "type": "string" + }, + "instanceUrl": { + "type": "string" + }, + "roleArn": { + "type": "string" + }, + "quarantineBucketName": { + "type": "string" + }, + "cloudTrailBucketName": { + "type": "string" + }, + "botId": { + "type": "string" + }, + "orgApiKey": { + "type": "string" + }, + "externalId": { + "type": "string" + }, + "enterpriseId": { + "type": "string" + }, + "credJson": { + "type": "string" + }, + "role": { + "type": "string" + }, + "organizationId": { + "type": "string" + }, + "workspaceName": { + "type": "string" + }, + "workspaceId": { + "type": "string" + }, + "qtnChannelUrl": { + "type": "string" + }, + "featuresSupported": { + "type": "array", + "items": { + "type": "string" + } + }, + "malQtnLibName": { + "type": "string" + }, + "dlpQtnLibName": { + "type": "string" + }, + "credentials": { + "type": "string" + }, + "tokenEndpoint": { + "type": "string" + }, + "restApiEndpoint": { + "type": "string" + }, + "smirBucketConfig": { + "type": "array", + "items": { + "type": "object", + "description": "SmirBucketConfig object" + } + }, + "qtnInfo": { + "type": "array", + "items": { + "type": "object" + } + }, + "qtnInfoCleared": { + "type": "boolean" + } + } + }, + "zscalerAppTenantId": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/cloudToCloudIR/{id}": { + "get": { + "operationId": "c2c_incident_receiver_Get", + "summary": "Get (C2C Incident Receiver)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "status": { + "type": "array", + "items": { + "type": "string" + } + }, + "modifiedTime": { + "type": "integer" + }, + "lastTenantValidationTime": { + "type": "integer" + }, + "lastValidationMsg": { + "type": "object", + "properties": { + "errorMsg": { + "type": "string" + }, + "errorCode": { + "type": "string" + } + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "onboardableEntity": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "enterpriseTenantId": { + "type": "string" + }, + "application": { + "type": "string" + }, + "lastValidationMsg": { + "type": "object", + "properties": { + "errorMsg": { + "type": "string" + }, + "errorCode": { + "type": "string" + } + } + }, + "tenantAuthorizationInfo": { + "type": "object", + "properties": { + "accessToken": { + "type": "string" + }, + "botToken": { + "type": "string" + }, + "redirectUrl": { + "type": "string" + }, + "type": { + "type": "string" + }, + "env": { + "type": "string" + }, + "tempAuthCode": { + "type": "string" + }, + "subdomain": { + "type": "string" + }, + "apicp": { + "type": "string" + }, + "clientId": { + "type": "string" + }, + "clientSecret": { + "type": "string" + }, + "secretToken": { + "type": "string" + }, + "userName": { + "type": "string" + }, + "userPwd": { + "type": "string" + }, + "instanceUrl": { + "type": "string" + }, + "roleArn": { + "type": "string" + }, + "quarantineBucketName": { + "type": "string" + }, + "cloudTrailBucketName": { + "type": "string" + }, + "botId": { + "type": "string" + }, + "orgApiKey": { + "type": "string" + }, + "externalId": { + "type": "string" + }, + "enterpriseId": { + "type": "string" + }, + "credJson": { + "type": "string" + }, + "role": { + "type": "string" + }, + "organizationId": { + "type": "string" + }, + "workspaceName": { + "type": "string" + }, + "workspaceId": { + "type": "string" + }, + "qtnChannelUrl": { + "type": "string" + }, + "featuresSupported": { + "type": "array", + "items": { + "type": "string" + } + }, + "malQtnLibName": { + "type": "string" + }, + "dlpQtnLibName": { + "type": "string" + }, + "credentials": { + "type": "string" + }, + "tokenEndpoint": { + "type": "string" + }, + "restApiEndpoint": { + "type": "string" + }, + "smirBucketConfig": { + "type": "array", + "items": { + "type": "object", + "description": "SmirBucketConfig object" + } + }, + "qtnInfo": { + "type": "array", + "items": { + "type": "object" + } + }, + "qtnInfoCleared": { + "type": "boolean" + } + } + }, + "zscalerAppTenantId": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/customFileTypes": { + "get": { + "operationId": "filetypecontrol_GetCustomFileTypes", + "summary": "GetCustomFileTypes (Filetypecontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "filetypecontrol__custom_file_types_Create", + "summary": "Create (Filetypecontrol / Custom File Types)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the custom file type, if any." + }, + "extension": { + "type": "string", + "description": "Specifies the file type extension. The maximum extension length is 10 characters. Existing Zscaler extensions cannot be added to custom file types." + }, + "fileTypeId": { + "type": "integer", + "description": "File type ID. This ID is assigned and maintained for all file types including predefined and custom file types, and this value is different from the custom file type ID." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the custom file type, if any." + }, + "extension": { + "type": "string", + "description": "Specifies the file type extension. The maximum extension length is 10 characters. Existing Zscaler extensions cannot be added to custom file types." + }, + "fileTypeId": { + "type": "integer", + "description": "File type ID. This ID is assigned and maintained for all file types including predefined and custom file types, and this value is different from the custom file type ID." + } + } + } + } + } + } + } + }, + "/zia/api/v1/customFileTypes/count": { + "get": { + "operationId": "filetypecontrol__custom_file_types_GetCustomFileTypeCount", + "summary": "GetCustomFileTypeCount (Filetypecontrol / Custom File Types)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the custom file type, if any." + }, + "extension": { + "type": "string", + "description": "Specifies the file type extension. The maximum extension length is 10 characters. Existing Zscaler extensions cannot be added to custom file types." + }, + "fileTypeId": { + "type": "integer", + "description": "File type ID. This ID is assigned and maintained for all file types including predefined and custom file types, and this value is different from the custom file type ID." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/customFileTypes/{id}": { + "get": { + "operationId": "filetypecontrol__custom_file_types_Get", + "summary": "Get (Filetypecontrol / Custom File Types)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the custom file type, if any." + }, + "extension": { + "type": "string", + "description": "Specifies the file type extension. The maximum extension length is 10 characters. Existing Zscaler extensions cannot be added to custom file types." + }, + "fileTypeId": { + "type": "integer", + "description": "File type ID. This ID is assigned and maintained for all file types including predefined and custom file types, and this value is different from the custom file type ID." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "filetypecontrol__custom_file_types_Update", + "summary": "Update (Filetypecontrol / Custom File Types)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the custom file type, if any." + }, + "extension": { + "type": "string", + "description": "Specifies the file type extension. The maximum extension length is 10 characters. Existing Zscaler extensions cannot be added to custom file types." + }, + "fileTypeId": { + "type": "integer", + "description": "File type ID. This ID is assigned and maintained for all file types including predefined and custom file types, and this value is different from the custom file type ID." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the custom file type, if any." + }, + "extension": { + "type": "string", + "description": "Specifies the file type extension. The maximum extension length is 10 characters. Existing Zscaler extensions cannot be added to custom file types." + }, + "fileTypeId": { + "type": "integer", + "description": "File type ID. This ID is assigned and maintained for all file types including predefined and custom file types, and this value is different from the custom file type ID." + } + } + } + } + } + } + }, + "delete": { + "operationId": "filetypecontrol__custom_file_types_Delete", + "summary": "Delete (Filetypecontrol / Custom File Types)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the custom file type, if any." + }, + "extension": { + "type": "string", + "description": "Specifies the file type extension. The maximum extension length is 10 characters. Existing Zscaler extensions cannot be added to custom file types." + }, + "fileTypeId": { + "type": "integer", + "description": "File type ID. This ID is assigned and maintained for all file types including predefined and custom file types, and this value is different from the custom file type ID." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/customTags": { + "get": { + "operationId": "shadowitreport_GetAllCustomTags", + "summary": "GetAllCustomTags (Shadowitreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "sanctionedState": { + "type": "string" + }, + "applicationIds": { + "type": "array", + "items": { + "type": "integer" + } + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the cloud application" + }, + "name": { + "type": "string", + "description": "The name of the cloud application" + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/cyberThreatProtection/advancedThreatSettings": { + "get": { + "operationId": "advancedthreatsettings_GetAdvancedThreatSettings", + "summary": "GetAdvancedThreatSettings (Advancedthreatsettings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "riskTolerance": { + "type": "integer", + "description": "The Page Risk tolerance index set between 0 and 100 (100 being the highest risk).\nUsers are blocked from accessing web pages with higher Page Risk than the specified value." + }, + "riskToleranceCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspicious web pages" + }, + "cmdCtlServerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether connections to known Command & Control (C2) Servers are allowed or blocked" + }, + "cmdCtlServerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for connections to known C2 servers" + }, + "cmdCtlTrafficBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether botnets are allowed or blocked from sending or receiving commands to unknown servers" + }, + "cmdCtlTrafficCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for botnets" + }, + "malwareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known malicious sites and content are allowed or blocked" + }, + "malwareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious sites" + }, + "activeXBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether sites are allowed or blocked from accessing vulnerable ActiveX controls that are known to have been exploited." + }, + "activeXCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for ActiveX controls" + }, + "browserExploitsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known web browser vulnerabilities prone to exploitation are allowed or blocked." + }, + "browserExploitsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for browser exploits" + }, + "fileFormatVunerabilitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known file format vulnerabilities and suspicious or malicious content in Microsoft Office or PDF documents are allowed or blocked" + }, + "fileFormatVunerabilitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for file format vulnerabilities" + }, + "knownPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known phishing sites are allowed or blocked" + }, + "knownPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for known phishing sites" + }, + "suspectedPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block suspected phishing sites identified through heuristic detection.\nThe Zscaler service can inspect the content of a website for indications that it might be a phishing site." + }, + "suspectedPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected phishing sites" + }, + "suspectAdwareSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block any detections of communication and callback traffic associated with spyware agents and data transmission" + }, + "suspectAdwareSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected adware and spyware sites" + }, + "webspamBlocked": { + "type": "boolean", + "description": "Boolean value specifying whether to allow or block web pages that pretend to contain useful information, to get higher ranking in search engine results or drive traffic to phishing, adware, or spyware distribution sites." + }, + "webspamCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for web spam" + }, + "ircTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block IRC traffic being tunneled over HTTP/S" + }, + "ircTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for IRC tunnels" + }, + "anonymizerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block applications and methods used to obscure the destination and the content accessed by the user, therefore blocking traffic to anonymizing web proxies." + }, + "anonymizerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for anonymizers" + }, + "cookieStealingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block third-party websites that gather cookie information, which can be used to personally identify users, track internet activity, or steal a user's session or sensitive information." + }, + "cookieStealingPCAPEnabled": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cookie stealing" + }, + "potentialMaliciousRequestsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block this type of cross-site scripting (XSS)" + }, + "potentialMaliciousRequestsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for (XSS) attacks" + }, + "blockedCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A Boolean value specifying whether to allow or block requests to websites located in specific countries based on the ISO3166 mapping of countries to their IP address space" + }, + "blockCountriesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for blocked countries" + }, + "bitTorrentBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of BitTorrent, a popular P2P file sharing application that supports content download with encryption." + }, + "bitTorrentCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for BitTorrent" + }, + "torBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of Tor, a popular P2P anonymizer protocol with support for encryption." + }, + "torCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Tor" + }, + "googleTalkBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block access to Google Hangouts, a popular P2P VoIP application." + }, + "googleTalkCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Google Hangouts" + }, + "sshTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "sshTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "cryptoMiningBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block cryptocurrency mining network traffic and scripts\nwhich can negatively impact endpoint device performance and potentially lead to a misuse of company resources." + }, + "cryptoMiningCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cryptomining" + }, + "adSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block websites known to contain adware or\nspyware that displays malicious advertisements that can collect users' information without their knowledge" + }, + "adSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for adware and spyware sites" + }, + "dgaDomainsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block domains that are suspected to be generated using domain generation algorithms (DGA)" + }, + "alertForUnknownOrSuspiciousC2Traffic": { + "type": "boolean", + "description": "A Boolean value specifying whether to send alerts upon detecting unknown or suspicious C2 traffic" + }, + "dgaDomainsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for DGA domains" + }, + "maliciousUrlsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious URLs" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "advancedthreatsettings_UpdateAdvancedThreatSettings", + "summary": "UpdateAdvancedThreatSettings (Advancedthreatsettings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "riskTolerance": { + "type": "integer", + "description": "The Page Risk tolerance index set between 0 and 100 (100 being the highest risk).\nUsers are blocked from accessing web pages with higher Page Risk than the specified value." + }, + "riskToleranceCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspicious web pages" + }, + "cmdCtlServerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether connections to known Command & Control (C2) Servers are allowed or blocked" + }, + "cmdCtlServerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for connections to known C2 servers" + }, + "cmdCtlTrafficBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether botnets are allowed or blocked from sending or receiving commands to unknown servers" + }, + "cmdCtlTrafficCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for botnets" + }, + "malwareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known malicious sites and content are allowed or blocked" + }, + "malwareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious sites" + }, + "activeXBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether sites are allowed or blocked from accessing vulnerable ActiveX controls that are known to have been exploited." + }, + "activeXCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for ActiveX controls" + }, + "browserExploitsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known web browser vulnerabilities prone to exploitation are allowed or blocked." + }, + "browserExploitsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for browser exploits" + }, + "fileFormatVunerabilitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known file format vulnerabilities and suspicious or malicious content in Microsoft Office or PDF documents are allowed or blocked" + }, + "fileFormatVunerabilitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for file format vulnerabilities" + }, + "knownPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known phishing sites are allowed or blocked" + }, + "knownPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for known phishing sites" + }, + "suspectedPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block suspected phishing sites identified through heuristic detection.\nThe Zscaler service can inspect the content of a website for indications that it might be a phishing site." + }, + "suspectedPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected phishing sites" + }, + "suspectAdwareSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block any detections of communication and callback traffic associated with spyware agents and data transmission" + }, + "suspectAdwareSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected adware and spyware sites" + }, + "webspamBlocked": { + "type": "boolean", + "description": "Boolean value specifying whether to allow or block web pages that pretend to contain useful information, to get higher ranking in search engine results or drive traffic to phishing, adware, or spyware distribution sites." + }, + "webspamCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for web spam" + }, + "ircTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block IRC traffic being tunneled over HTTP/S" + }, + "ircTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for IRC tunnels" + }, + "anonymizerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block applications and methods used to obscure the destination and the content accessed by the user, therefore blocking traffic to anonymizing web proxies." + }, + "anonymizerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for anonymizers" + }, + "cookieStealingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block third-party websites that gather cookie information, which can be used to personally identify users, track internet activity, or steal a user's session or sensitive information." + }, + "cookieStealingPCAPEnabled": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cookie stealing" + }, + "potentialMaliciousRequestsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block this type of cross-site scripting (XSS)" + }, + "potentialMaliciousRequestsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for (XSS) attacks" + }, + "blockedCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A Boolean value specifying whether to allow or block requests to websites located in specific countries based on the ISO3166 mapping of countries to their IP address space" + }, + "blockCountriesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for blocked countries" + }, + "bitTorrentBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of BitTorrent, a popular P2P file sharing application that supports content download with encryption." + }, + "bitTorrentCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for BitTorrent" + }, + "torBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of Tor, a popular P2P anonymizer protocol with support for encryption." + }, + "torCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Tor" + }, + "googleTalkBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block access to Google Hangouts, a popular P2P VoIP application." + }, + "googleTalkCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Google Hangouts" + }, + "sshTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "sshTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "cryptoMiningBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block cryptocurrency mining network traffic and scripts\nwhich can negatively impact endpoint device performance and potentially lead to a misuse of company resources." + }, + "cryptoMiningCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cryptomining" + }, + "adSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block websites known to contain adware or\nspyware that displays malicious advertisements that can collect users' information without their knowledge" + }, + "adSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for adware and spyware sites" + }, + "dgaDomainsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block domains that are suspected to be generated using domain generation algorithms (DGA)" + }, + "alertForUnknownOrSuspiciousC2Traffic": { + "type": "boolean", + "description": "A Boolean value specifying whether to send alerts upon detecting unknown or suspicious C2 traffic" + }, + "dgaDomainsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for DGA domains" + }, + "maliciousUrlsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious URLs" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "riskTolerance": { + "type": "integer", + "description": "The Page Risk tolerance index set between 0 and 100 (100 being the highest risk).\nUsers are blocked from accessing web pages with higher Page Risk than the specified value." + }, + "riskToleranceCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspicious web pages" + }, + "cmdCtlServerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether connections to known Command & Control (C2) Servers are allowed or blocked" + }, + "cmdCtlServerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for connections to known C2 servers" + }, + "cmdCtlTrafficBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether botnets are allowed or blocked from sending or receiving commands to unknown servers" + }, + "cmdCtlTrafficCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for botnets" + }, + "malwareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known malicious sites and content are allowed or blocked" + }, + "malwareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious sites" + }, + "activeXBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether sites are allowed or blocked from accessing vulnerable ActiveX controls that are known to have been exploited." + }, + "activeXCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for ActiveX controls" + }, + "browserExploitsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known web browser vulnerabilities prone to exploitation are allowed or blocked." + }, + "browserExploitsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for browser exploits" + }, + "fileFormatVunerabilitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known file format vulnerabilities and suspicious or malicious content in Microsoft Office or PDF documents are allowed or blocked" + }, + "fileFormatVunerabilitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for file format vulnerabilities" + }, + "knownPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known phishing sites are allowed or blocked" + }, + "knownPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for known phishing sites" + }, + "suspectedPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block suspected phishing sites identified through heuristic detection.\nThe Zscaler service can inspect the content of a website for indications that it might be a phishing site." + }, + "suspectedPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected phishing sites" + }, + "suspectAdwareSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block any detections of communication and callback traffic associated with spyware agents and data transmission" + }, + "suspectAdwareSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected adware and spyware sites" + }, + "webspamBlocked": { + "type": "boolean", + "description": "Boolean value specifying whether to allow or block web pages that pretend to contain useful information, to get higher ranking in search engine results or drive traffic to phishing, adware, or spyware distribution sites." + }, + "webspamCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for web spam" + }, + "ircTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block IRC traffic being tunneled over HTTP/S" + }, + "ircTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for IRC tunnels" + }, + "anonymizerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block applications and methods used to obscure the destination and the content accessed by the user, therefore blocking traffic to anonymizing web proxies." + }, + "anonymizerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for anonymizers" + }, + "cookieStealingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block third-party websites that gather cookie information, which can be used to personally identify users, track internet activity, or steal a user's session or sensitive information." + }, + "cookieStealingPCAPEnabled": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cookie stealing" + }, + "potentialMaliciousRequestsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block this type of cross-site scripting (XSS)" + }, + "potentialMaliciousRequestsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for (XSS) attacks" + }, + "blockedCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A Boolean value specifying whether to allow or block requests to websites located in specific countries based on the ISO3166 mapping of countries to their IP address space" + }, + "blockCountriesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for blocked countries" + }, + "bitTorrentBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of BitTorrent, a popular P2P file sharing application that supports content download with encryption." + }, + "bitTorrentCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for BitTorrent" + }, + "torBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of Tor, a popular P2P anonymizer protocol with support for encryption." + }, + "torCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Tor" + }, + "googleTalkBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block access to Google Hangouts, a popular P2P VoIP application." + }, + "googleTalkCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Google Hangouts" + }, + "sshTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "sshTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "cryptoMiningBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block cryptocurrency mining network traffic and scripts\nwhich can negatively impact endpoint device performance and potentially lead to a misuse of company resources." + }, + "cryptoMiningCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cryptomining" + }, + "adSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block websites known to contain adware or\nspyware that displays malicious advertisements that can collect users' information without their knowledge" + }, + "adSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for adware and spyware sites" + }, + "dgaDomainsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block domains that are suspected to be generated using domain generation algorithms (DGA)" + }, + "alertForUnknownOrSuspiciousC2Traffic": { + "type": "boolean", + "description": "A Boolean value specifying whether to send alerts upon detecting unknown or suspicious C2 traffic" + }, + "dgaDomainsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for DGA domains" + }, + "maliciousUrlsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious URLs" + } + } + } + } + } + } + } + }, + "/zia/api/v1/cyberThreatProtection/atpMalwareInspection": { + "get": { + "operationId": "malware_protection_GetATPMalwareInspection", + "summary": "GetATPMalwareInspection (Malware Protection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "malware_protection_UpdateATPMalwareInspection", + "summary": "UpdateATPMalwareInspection (Malware Protection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + } + }, + "/zia/api/v1/cyberThreatProtection/atpMalwareProtocols": { + "get": { + "operationId": "malware_protection_GetATPMalwareProtocols", + "summary": "GetATPMalwareProtocols (Malware Protection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "malware_protection_UpdateATPMalwareProtocol", + "summary": "UpdateATPMalwareProtocol (Malware Protection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + } + }, + "/zia/api/v1/cyberThreatProtection/maliciousUrls": { + "get": { + "operationId": "advancedthreatsettings_GetMaliciousURLs", + "summary": "GetMaliciousURLs (Advancedthreatsettings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "riskTolerance": { + "type": "integer", + "description": "The Page Risk tolerance index set between 0 and 100 (100 being the highest risk).\nUsers are blocked from accessing web pages with higher Page Risk than the specified value." + }, + "riskToleranceCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspicious web pages" + }, + "cmdCtlServerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether connections to known Command & Control (C2) Servers are allowed or blocked" + }, + "cmdCtlServerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for connections to known C2 servers" + }, + "cmdCtlTrafficBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether botnets are allowed or blocked from sending or receiving commands to unknown servers" + }, + "cmdCtlTrafficCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for botnets" + }, + "malwareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known malicious sites and content are allowed or blocked" + }, + "malwareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious sites" + }, + "activeXBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether sites are allowed or blocked from accessing vulnerable ActiveX controls that are known to have been exploited." + }, + "activeXCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for ActiveX controls" + }, + "browserExploitsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known web browser vulnerabilities prone to exploitation are allowed or blocked." + }, + "browserExploitsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for browser exploits" + }, + "fileFormatVunerabilitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known file format vulnerabilities and suspicious or malicious content in Microsoft Office or PDF documents are allowed or blocked" + }, + "fileFormatVunerabilitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for file format vulnerabilities" + }, + "knownPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known phishing sites are allowed or blocked" + }, + "knownPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for known phishing sites" + }, + "suspectedPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block suspected phishing sites identified through heuristic detection.\nThe Zscaler service can inspect the content of a website for indications that it might be a phishing site." + }, + "suspectedPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected phishing sites" + }, + "suspectAdwareSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block any detections of communication and callback traffic associated with spyware agents and data transmission" + }, + "suspectAdwareSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected adware and spyware sites" + }, + "webspamBlocked": { + "type": "boolean", + "description": "Boolean value specifying whether to allow or block web pages that pretend to contain useful information, to get higher ranking in search engine results or drive traffic to phishing, adware, or spyware distribution sites." + }, + "webspamCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for web spam" + }, + "ircTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block IRC traffic being tunneled over HTTP/S" + }, + "ircTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for IRC tunnels" + }, + "anonymizerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block applications and methods used to obscure the destination and the content accessed by the user, therefore blocking traffic to anonymizing web proxies." + }, + "anonymizerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for anonymizers" + }, + "cookieStealingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block third-party websites that gather cookie information, which can be used to personally identify users, track internet activity, or steal a user's session or sensitive information." + }, + "cookieStealingPCAPEnabled": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cookie stealing" + }, + "potentialMaliciousRequestsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block this type of cross-site scripting (XSS)" + }, + "potentialMaliciousRequestsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for (XSS) attacks" + }, + "blockedCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A Boolean value specifying whether to allow or block requests to websites located in specific countries based on the ISO3166 mapping of countries to their IP address space" + }, + "blockCountriesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for blocked countries" + }, + "bitTorrentBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of BitTorrent, a popular P2P file sharing application that supports content download with encryption." + }, + "bitTorrentCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for BitTorrent" + }, + "torBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of Tor, a popular P2P anonymizer protocol with support for encryption." + }, + "torCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Tor" + }, + "googleTalkBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block access to Google Hangouts, a popular P2P VoIP application." + }, + "googleTalkCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Google Hangouts" + }, + "sshTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "sshTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "cryptoMiningBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block cryptocurrency mining network traffic and scripts\nwhich can negatively impact endpoint device performance and potentially lead to a misuse of company resources." + }, + "cryptoMiningCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cryptomining" + }, + "adSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block websites known to contain adware or\nspyware that displays malicious advertisements that can collect users' information without their knowledge" + }, + "adSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for adware and spyware sites" + }, + "dgaDomainsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block domains that are suspected to be generated using domain generation algorithms (DGA)" + }, + "alertForUnknownOrSuspiciousC2Traffic": { + "type": "boolean", + "description": "A Boolean value specifying whether to send alerts upon detecting unknown or suspicious C2 traffic" + }, + "dgaDomainsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for DGA domains" + }, + "maliciousUrlsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious URLs" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/cyberThreatProtection/malwarePolicy": { + "get": { + "operationId": "malware_protection_GetATPMalwarePolicy", + "summary": "GetATPMalwarePolicy (Malware Protection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "malware_protection_UpdateATPMalwarePolicy", + "summary": "UpdateATPMalwarePolicy (Malware Protection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + } + }, + "/zia/api/v1/cyberThreatProtection/malwareSettings": { + "get": { + "operationId": "malware_protection_GetATPMalwareSettings", + "summary": "GetATPMalwareSettings (Malware Protection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "malware_protection_UpdateATPMalwareSettings", + "summary": "UpdateATPMalwareSettings (Malware Protection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "inspectInbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of incoming internet traffic for malicious content" + }, + "inspectOutbound": { + "type": "boolean", + "description": "A Boolean value that enables or disables scanning of outgoing internet traffic for malicious content" + } + } + } + } + } + } + } + }, + "/zia/api/v1/cyberThreatProtection/securityExceptions": { + "get": { + "operationId": "advancedthreatsettings_GetSecurityExceptions", + "summary": "GetSecurityExceptions (Advancedthreatsettings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "riskTolerance": { + "type": "integer", + "description": "The Page Risk tolerance index set between 0 and 100 (100 being the highest risk).\nUsers are blocked from accessing web pages with higher Page Risk than the specified value." + }, + "riskToleranceCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspicious web pages" + }, + "cmdCtlServerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether connections to known Command & Control (C2) Servers are allowed or blocked" + }, + "cmdCtlServerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for connections to known C2 servers" + }, + "cmdCtlTrafficBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether botnets are allowed or blocked from sending or receiving commands to unknown servers" + }, + "cmdCtlTrafficCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for botnets" + }, + "malwareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known malicious sites and content are allowed or blocked" + }, + "malwareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious sites" + }, + "activeXBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether sites are allowed or blocked from accessing vulnerable ActiveX controls that are known to have been exploited." + }, + "activeXCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for ActiveX controls" + }, + "browserExploitsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known web browser vulnerabilities prone to exploitation are allowed or blocked." + }, + "browserExploitsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for browser exploits" + }, + "fileFormatVunerabilitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known file format vulnerabilities and suspicious or malicious content in Microsoft Office or PDF documents are allowed or blocked" + }, + "fileFormatVunerabilitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for file format vulnerabilities" + }, + "knownPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known phishing sites are allowed or blocked" + }, + "knownPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for known phishing sites" + }, + "suspectedPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block suspected phishing sites identified through heuristic detection.\nThe Zscaler service can inspect the content of a website for indications that it might be a phishing site." + }, + "suspectedPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected phishing sites" + }, + "suspectAdwareSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block any detections of communication and callback traffic associated with spyware agents and data transmission" + }, + "suspectAdwareSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected adware and spyware sites" + }, + "webspamBlocked": { + "type": "boolean", + "description": "Boolean value specifying whether to allow or block web pages that pretend to contain useful information, to get higher ranking in search engine results or drive traffic to phishing, adware, or spyware distribution sites." + }, + "webspamCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for web spam" + }, + "ircTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block IRC traffic being tunneled over HTTP/S" + }, + "ircTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for IRC tunnels" + }, + "anonymizerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block applications and methods used to obscure the destination and the content accessed by the user, therefore blocking traffic to anonymizing web proxies." + }, + "anonymizerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for anonymizers" + }, + "cookieStealingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block third-party websites that gather cookie information, which can be used to personally identify users, track internet activity, or steal a user's session or sensitive information." + }, + "cookieStealingPCAPEnabled": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cookie stealing" + }, + "potentialMaliciousRequestsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block this type of cross-site scripting (XSS)" + }, + "potentialMaliciousRequestsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for (XSS) attacks" + }, + "blockedCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A Boolean value specifying whether to allow or block requests to websites located in specific countries based on the ISO3166 mapping of countries to their IP address space" + }, + "blockCountriesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for blocked countries" + }, + "bitTorrentBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of BitTorrent, a popular P2P file sharing application that supports content download with encryption." + }, + "bitTorrentCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for BitTorrent" + }, + "torBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of Tor, a popular P2P anonymizer protocol with support for encryption." + }, + "torCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Tor" + }, + "googleTalkBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block access to Google Hangouts, a popular P2P VoIP application." + }, + "googleTalkCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Google Hangouts" + }, + "sshTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "sshTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "cryptoMiningBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block cryptocurrency mining network traffic and scripts\nwhich can negatively impact endpoint device performance and potentially lead to a misuse of company resources." + }, + "cryptoMiningCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cryptomining" + }, + "adSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block websites known to contain adware or\nspyware that displays malicious advertisements that can collect users' information without their knowledge" + }, + "adSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for adware and spyware sites" + }, + "dgaDomainsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block domains that are suspected to be generated using domain generation algorithms (DGA)" + }, + "alertForUnknownOrSuspiciousC2Traffic": { + "type": "boolean", + "description": "A Boolean value specifying whether to send alerts upon detecting unknown or suspicious C2 traffic" + }, + "dgaDomainsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for DGA domains" + }, + "maliciousUrlsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious URLs" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "advancedthreatsettings_UpdateSecurityExceptions", + "summary": "UpdateSecurityExceptions (Advancedthreatsettings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "riskTolerance": { + "type": "integer", + "description": "The Page Risk tolerance index set between 0 and 100 (100 being the highest risk).\nUsers are blocked from accessing web pages with higher Page Risk than the specified value." + }, + "riskToleranceCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspicious web pages" + }, + "cmdCtlServerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether connections to known Command & Control (C2) Servers are allowed or blocked" + }, + "cmdCtlServerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for connections to known C2 servers" + }, + "cmdCtlTrafficBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether botnets are allowed or blocked from sending or receiving commands to unknown servers" + }, + "cmdCtlTrafficCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for botnets" + }, + "malwareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known malicious sites and content are allowed or blocked" + }, + "malwareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious sites" + }, + "activeXBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether sites are allowed or blocked from accessing vulnerable ActiveX controls that are known to have been exploited." + }, + "activeXCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for ActiveX controls" + }, + "browserExploitsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known web browser vulnerabilities prone to exploitation are allowed or blocked." + }, + "browserExploitsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for browser exploits" + }, + "fileFormatVunerabilitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known file format vulnerabilities and suspicious or malicious content in Microsoft Office or PDF documents are allowed or blocked" + }, + "fileFormatVunerabilitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for file format vulnerabilities" + }, + "knownPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known phishing sites are allowed or blocked" + }, + "knownPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for known phishing sites" + }, + "suspectedPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block suspected phishing sites identified through heuristic detection.\nThe Zscaler service can inspect the content of a website for indications that it might be a phishing site." + }, + "suspectedPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected phishing sites" + }, + "suspectAdwareSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block any detections of communication and callback traffic associated with spyware agents and data transmission" + }, + "suspectAdwareSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected adware and spyware sites" + }, + "webspamBlocked": { + "type": "boolean", + "description": "Boolean value specifying whether to allow or block web pages that pretend to contain useful information, to get higher ranking in search engine results or drive traffic to phishing, adware, or spyware distribution sites." + }, + "webspamCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for web spam" + }, + "ircTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block IRC traffic being tunneled over HTTP/S" + }, + "ircTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for IRC tunnels" + }, + "anonymizerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block applications and methods used to obscure the destination and the content accessed by the user, therefore blocking traffic to anonymizing web proxies." + }, + "anonymizerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for anonymizers" + }, + "cookieStealingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block third-party websites that gather cookie information, which can be used to personally identify users, track internet activity, or steal a user's session or sensitive information." + }, + "cookieStealingPCAPEnabled": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cookie stealing" + }, + "potentialMaliciousRequestsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block this type of cross-site scripting (XSS)" + }, + "potentialMaliciousRequestsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for (XSS) attacks" + }, + "blockedCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A Boolean value specifying whether to allow or block requests to websites located in specific countries based on the ISO3166 mapping of countries to their IP address space" + }, + "blockCountriesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for blocked countries" + }, + "bitTorrentBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of BitTorrent, a popular P2P file sharing application that supports content download with encryption." + }, + "bitTorrentCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for BitTorrent" + }, + "torBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of Tor, a popular P2P anonymizer protocol with support for encryption." + }, + "torCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Tor" + }, + "googleTalkBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block access to Google Hangouts, a popular P2P VoIP application." + }, + "googleTalkCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Google Hangouts" + }, + "sshTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "sshTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "cryptoMiningBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block cryptocurrency mining network traffic and scripts\nwhich can negatively impact endpoint device performance and potentially lead to a misuse of company resources." + }, + "cryptoMiningCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cryptomining" + }, + "adSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block websites known to contain adware or\nspyware that displays malicious advertisements that can collect users' information without their knowledge" + }, + "adSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for adware and spyware sites" + }, + "dgaDomainsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block domains that are suspected to be generated using domain generation algorithms (DGA)" + }, + "alertForUnknownOrSuspiciousC2Traffic": { + "type": "boolean", + "description": "A Boolean value specifying whether to send alerts upon detecting unknown or suspicious C2 traffic" + }, + "dgaDomainsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for DGA domains" + }, + "maliciousUrlsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious URLs" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "riskTolerance": { + "type": "integer", + "description": "The Page Risk tolerance index set between 0 and 100 (100 being the highest risk).\nUsers are blocked from accessing web pages with higher Page Risk than the specified value." + }, + "riskToleranceCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspicious web pages" + }, + "cmdCtlServerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether connections to known Command & Control (C2) Servers are allowed or blocked" + }, + "cmdCtlServerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for connections to known C2 servers" + }, + "cmdCtlTrafficBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether botnets are allowed or blocked from sending or receiving commands to unknown servers" + }, + "cmdCtlTrafficCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for botnets" + }, + "malwareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known malicious sites and content are allowed or blocked" + }, + "malwareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious sites" + }, + "activeXBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether sites are allowed or blocked from accessing vulnerable ActiveX controls that are known to have been exploited." + }, + "activeXCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for ActiveX controls" + }, + "browserExploitsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known web browser vulnerabilities prone to exploitation are allowed or blocked." + }, + "browserExploitsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for browser exploits" + }, + "fileFormatVunerabilitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known file format vulnerabilities and suspicious or malicious content in Microsoft Office or PDF documents are allowed or blocked" + }, + "fileFormatVunerabilitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for file format vulnerabilities" + }, + "knownPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether known phishing sites are allowed or blocked" + }, + "knownPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for known phishing sites" + }, + "suspectedPhishingSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block suspected phishing sites identified through heuristic detection.\nThe Zscaler service can inspect the content of a website for indications that it might be a phishing site." + }, + "suspectedPhishingSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected phishing sites" + }, + "suspectAdwareSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block any detections of communication and callback traffic associated with spyware agents and data transmission" + }, + "suspectAdwareSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for suspected adware and spyware sites" + }, + "webspamBlocked": { + "type": "boolean", + "description": "Boolean value specifying whether to allow or block web pages that pretend to contain useful information, to get higher ranking in search engine results or drive traffic to phishing, adware, or spyware distribution sites." + }, + "webspamCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for web spam" + }, + "ircTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block IRC traffic being tunneled over HTTP/S" + }, + "ircTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for IRC tunnels" + }, + "anonymizerBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block applications and methods used to obscure the destination and the content accessed by the user, therefore blocking traffic to anonymizing web proxies." + }, + "anonymizerCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for anonymizers" + }, + "cookieStealingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block third-party websites that gather cookie information, which can be used to personally identify users, track internet activity, or steal a user's session or sensitive information." + }, + "cookieStealingPCAPEnabled": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cookie stealing" + }, + "potentialMaliciousRequestsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block this type of cross-site scripting (XSS)" + }, + "potentialMaliciousRequestsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for (XSS) attacks" + }, + "blockedCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "A Boolean value specifying whether to allow or block requests to websites located in specific countries based on the ISO3166 mapping of countries to their IP address space" + }, + "blockCountriesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for blocked countries" + }, + "bitTorrentBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of BitTorrent, a popular P2P file sharing application that supports content download with encryption." + }, + "bitTorrentCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for BitTorrent" + }, + "torBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block the usage of Tor, a popular P2P anonymizer protocol with support for encryption." + }, + "torCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Tor" + }, + "googleTalkBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block access to Google Hangouts, a popular P2P VoIP application." + }, + "googleTalkCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for Google Hangouts" + }, + "sshTunnellingBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "sshTunnellingCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for SSH tunnels" + }, + "cryptoMiningBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block cryptocurrency mining network traffic and scripts\nwhich can negatively impact endpoint device performance and potentially lead to a misuse of company resources." + }, + "cryptoMiningCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for cryptomining" + }, + "adSpywareSitesBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block websites known to contain adware or\nspyware that displays malicious advertisements that can collect users' information without their knowledge" + }, + "adSpywareSitesCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for adware and spyware sites" + }, + "dgaDomainsBlocked": { + "type": "boolean", + "description": "A Boolean value specifying whether to allow or block domains that are suspected to be generated using domain generation algorithms (DGA)" + }, + "alertForUnknownOrSuspiciousC2Traffic": { + "type": "boolean", + "description": "A Boolean value specifying whether to send alerts upon detecting unknown or suspicious C2 traffic" + }, + "dgaDomainsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for DGA domains" + }, + "maliciousUrlsCapture": { + "type": "boolean", + "description": "A Boolean value specifying whether packet capture (PCAP) is enabled or not for malicious URLs" + } + } + } + } + } + } + } + }, + "/zia/api/v1/datacenters": { + "get": { + "operationId": "trafficforwarding__dc_exclusions_GetDatacenters", + "summary": "GetDatacenters (Trafficforwarding / Dc Exclusions)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "dcid": { + "type": "integer" + }, + "expired": { + "type": "boolean" + }, + "startTime": { + "type": "integer" + }, + "endTime": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "dcName": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dcExclusions": { + "get": { + "operationId": "trafficforwarding__dc_exclusions_GetAll", + "summary": "GetAll (Trafficforwarding / Dc Exclusions)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "dcid": { + "type": "integer" + }, + "expired": { + "type": "boolean" + }, + "startTime": { + "type": "integer" + }, + "endTime": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "dcName": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dcExclusions/{id}": { + "delete": { + "operationId": "trafficforwarding__dc_exclusions_Delete", + "summary": "Delete (Trafficforwarding / Dc Exclusions)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "dcid": { + "type": "integer" + }, + "expired": { + "type": "boolean" + }, + "startTime": { + "type": "integer" + }, + "endTime": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "dcName": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dedicatedIPGateways/lite": { + "get": { + "operationId": "forwarding_control_policy__proxies_GetDedicatedIPGWLite", + "summary": "GetDedicatedIPGWLite (Forwarding Control Policy / Proxies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Proxy ID" + }, + "name": { + "type": "string", + "description": "Proxy name" + }, + "type": { + "type": "string", + "description": "Gateway type - Supported Values: PROXYCHAIN, ZIA, ECSELF" + }, + "address": { + "type": "string", + "description": "The IP address or the FQDN of the third-party proxy service" + }, + "port": { + "type": "integer", + "description": "The port number on which the third-party proxy service listens to the requests forwarded from Zscaler" + }, + "cert": { + "type": "object", + "description": "The root certificate used by the third-party proxy to perform SSL inspection.\nThis root certificate is used by Zscaler to validate the SSL leaf certificates signed by the upstream proxy.\nThe required root certificate appears in this drop-down menu only if it is uploaded from the Administration > Root Certificates page." + }, + "description": { + "type": "string", + "description": "Additional notes or information" + }, + "insertXauHeader": { + "type": "boolean", + "description": "Flag indicating whether X-Authenticated-User header is added by the proxy. Enable to automatically insert authenticated user ID to the HTTP header, X-Authenticated-User." + }, + "base64EncodeXauHeader": { + "type": "boolean", + "description": "Flag indicating whether the added X-Authenticated-User header is Base64 encoded. When enabled, the user ID is encoded using the Base64 encoding method." + }, + "lastModifiedBy": { + "type": "object", + "description": "Last user that modified the proxy" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp of when the proxy was last modified" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/departments": { + "post": { + "operationId": "usermanagement__departments_Create", + "summary": "Create (Usermanagement / Departments)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "get": { + "operationId": "usermanagement__departments_GetAll", + "summary": "GetAll (Usermanagement / Departments)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/departments/{id}": { + "get": { + "operationId": "usermanagement__departments_GetDepartments", + "summary": "GetDepartments (Usermanagement / Departments)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "usermanagement__departments_Update", + "summary": "Update (Usermanagement / Departments)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "delete": { + "operationId": "usermanagement__departments_Delete", + "summary": "Delete (Usermanagement / Departments)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/deviceGroups": { + "get": { + "operationId": "devicegroups_GetDeviceGroupByName", + "summary": "GetDeviceGroupByName (Devicegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifer for the device group" + }, + "name": { + "type": "string", + "description": "The device group name" + }, + "groupType": { + "type": "string", + "description": "The device group type" + }, + "description": { + "type": "string", + "description": "The device group's description" + }, + "osType": { + "type": "string", + "description": "The operating system (OS)" + }, + "predefined": { + "type": "boolean", + "description": "Indicates whether this is a predefined device group. If this value is set to true, the group is predefined" + }, + "deviceNames": { + "type": "string" + }, + "deviceCount": { + "type": "integer", + "description": "The number of devices within the group" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/deviceGroups/devices": { + "get": { + "operationId": "devicegroups_GetDevicesByName", + "summary": "GetDevicesByName (Devicegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifer for the device group" + }, + "name": { + "type": "string", + "description": "The device group name" + }, + "groupType": { + "type": "string", + "description": "The device group type" + }, + "description": { + "type": "string", + "description": "The device group's description" + }, + "osType": { + "type": "string", + "description": "The operating system (OS)" + }, + "predefined": { + "type": "boolean", + "description": "Indicates whether this is a predefined device group. If this value is set to true, the group is predefined" + }, + "deviceNames": { + "type": "string" + }, + "deviceCount": { + "type": "integer", + "description": "The number of devices within the group" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/devices": { + "get": { + "operationId": "devices_GetAll", + "summary": "GetAll (Devices)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "active": { + "type": "boolean" + }, + "version": { + "type": "string" + }, + "hostname": { + "type": "string" + }, + "vendor": { + "type": "string" + }, + "model": { + "type": "string" + }, + "locale": { + "type": "string" + }, + "os": { + "type": "string" + }, + "udid": { + "type": "string" + }, + "hardwareId": { + "type": "string" + }, + "macAddress": { + "type": "string" + }, + "user": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "firstRegistrationTimestamp": { + "type": "integer" + }, + "lastRegistrationTimestamp": { + "type": "integer" + }, + "unRegistrationTimestamp": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "rooted": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/devices/{id}": { + "get": { + "operationId": "devices_Get", + "summary": "Get (Devices)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "active": { + "type": "boolean" + }, + "version": { + "type": "string" + }, + "hostname": { + "type": "string" + }, + "vendor": { + "type": "string" + }, + "model": { + "type": "string" + }, + "locale": { + "type": "string" + }, + "os": { + "type": "string" + }, + "udid": { + "type": "string" + }, + "hardwareId": { + "type": "string" + }, + "macAddress": { + "type": "string" + }, + "user": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "firstRegistrationTimestamp": { + "type": "integer" + }, + "lastRegistrationTimestamp": { + "type": "integer" + }, + "unRegistrationTimestamp": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "rooted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dlpDictionaries": { + "get": { + "operationId": "dlp__dlpdictionaries_GetByName", + "summary": "GetByName (Dlp / Dlpdictionaries)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "dlp__dlpdictionaries_Create", + "summary": "Create (Dlp / Dlpdictionaries)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpDictionaries/{id}": { + "get": { + "operationId": "dlp__dlpdictionaries_Get", + "summary": "Get (Dlp / Dlpdictionaries)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "dlp__dlpdictionaries_Update", + "summary": "Update (Dlp / Dlpdictionaries)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + }, + "delete": { + "operationId": "dlp__dlpdictionaries_DeleteDlpDictionary", + "summary": "DeleteDlpDictionary (Dlp / Dlpdictionaries)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dlpEndpointResource": { + "post": { + "operationId": "endpoint_dlp__endpoint_resource_Create", + "summary": "Create (Endpoint Dlp / Endpoint Resource)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "channel": { + "type": "string" + }, + "isPredefined": { + "type": "boolean" + }, + "networkDriveType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "serverName": { + "type": "string" + }, + "appId": { + "type": "integer" + }, + "networkDrives": { + "type": "array", + "items": { + "type": "object", + "properties": { + "networkPath": { + "type": "string" + } + } + } + }, + "printer": { + "type": "object", + "properties": { + "unc": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "domain": { + "type": "string" + } + } + }, + "removableStorage": { + "type": "object", + "properties": { + "vendorId": { + "type": "string" + }, + "productId": { + "type": "string" + }, + "serialNumber": { + "type": "string" + } + } + }, + "application": { + "type": "object", + "properties": { + "osType": { + "type": "string" + }, + "fileName": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "channel": { + "type": "string" + }, + "isPredefined": { + "type": "boolean" + }, + "networkDriveType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "serverName": { + "type": "string" + }, + "appId": { + "type": "integer" + }, + "networkDrives": { + "type": "array", + "items": { + "type": "object", + "properties": { + "networkPath": { + "type": "string" + } + } + } + }, + "printer": { + "type": "object", + "properties": { + "unc": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "domain": { + "type": "string" + } + } + }, + "removableStorage": { + "type": "object", + "properties": { + "vendorId": { + "type": "string" + }, + "productId": { + "type": "string" + }, + "serialNumber": { + "type": "string" + } + } + }, + "application": { + "type": "object", + "properties": { + "osType": { + "type": "string" + }, + "fileName": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpEndpointResource/{id}": { + "put": { + "operationId": "endpoint_dlp__endpoint_resource_Update", + "summary": "Update (Endpoint Dlp / Endpoint Resource)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "channel": { + "type": "string" + }, + "isPredefined": { + "type": "boolean" + }, + "networkDriveType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "serverName": { + "type": "string" + }, + "appId": { + "type": "integer" + }, + "networkDrives": { + "type": "array", + "items": { + "type": "object", + "properties": { + "networkPath": { + "type": "string" + } + } + } + }, + "printer": { + "type": "object", + "properties": { + "unc": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "domain": { + "type": "string" + } + } + }, + "removableStorage": { + "type": "object", + "properties": { + "vendorId": { + "type": "string" + }, + "productId": { + "type": "string" + }, + "serialNumber": { + "type": "string" + } + } + }, + "application": { + "type": "object", + "properties": { + "osType": { + "type": "string" + }, + "fileName": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "channel": { + "type": "string" + }, + "isPredefined": { + "type": "boolean" + }, + "networkDriveType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "serverName": { + "type": "string" + }, + "appId": { + "type": "integer" + }, + "networkDrives": { + "type": "array", + "items": { + "type": "object", + "properties": { + "networkPath": { + "type": "string" + } + } + } + }, + "printer": { + "type": "object", + "properties": { + "unc": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "domain": { + "type": "string" + } + } + }, + "removableStorage": { + "type": "object", + "properties": { + "vendorId": { + "type": "string" + }, + "productId": { + "type": "string" + }, + "serialNumber": { + "type": "string" + } + } + }, + "application": { + "type": "object", + "properties": { + "osType": { + "type": "string" + }, + "fileName": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "endpoint_dlp__endpoint_resource_Delete", + "summary": "Delete (Endpoint Dlp / Endpoint Resource)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "channel": { + "type": "string" + }, + "isPredefined": { + "type": "boolean" + }, + "networkDriveType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "serverName": { + "type": "string" + }, + "appId": { + "type": "integer" + }, + "networkDrives": { + "type": "array", + "items": { + "type": "object", + "properties": { + "networkPath": { + "type": "string" + } + } + } + }, + "printer": { + "type": "object", + "properties": { + "unc": { + "type": "string" + }, + "ipAddress": { + "type": "string" + }, + "domain": { + "type": "string" + } + } + }, + "removableStorage": { + "type": "object", + "properties": { + "vendorId": { + "type": "string" + }, + "productId": { + "type": "string" + }, + "serialNumber": { + "type": "string" + } + } + }, + "application": { + "type": "object", + "properties": { + "osType": { + "type": "string" + }, + "fileName": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "get": { + "operationId": "endpoint_dlp__endpoint_resource_channel_GetChannelList", + "summary": "GetChannelList (Endpoint Dlp / Endpoint Resource Channel)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": {} + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dlpEndpointResource/{id}/{id2}": { + "get": { + "operationId": "endpoint_dlp__endpoint_resource_channel_GetChannel", + "summary": "GetChannel (Endpoint Dlp / Endpoint Resource Channel)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": {} + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dlpEngines": { + "post": { + "operationId": "dlp__dlp_engines_Create", + "summary": "Create (Dlp / Dlp Engines)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "get": { + "operationId": "dlp__dlp_engines_GetAll", + "summary": "GetAll (Dlp / Dlp Engines)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpEngines/lite": { + "get": { + "operationId": "dlp__dlp_engines_GetAllEngineLite", + "summary": "GetAllEngineLite (Dlp / Dlp Engines)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpEngines/{id}": { + "get": { + "operationId": "dlp__dlp_engines_Get", + "summary": "Get (Dlp / Dlp Engines)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "dlp__dlp_engines_Update", + "summary": "Update (Dlp / Dlp Engines)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "delete": { + "operationId": "dlp__dlp_engines_Delete", + "summary": "Delete (Dlp / Dlp Engines)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dlpExactDataMatchSchemas": { + "get": { + "operationId": "dlp__dlp_exact_data_match_GetDLPEDMByName", + "summary": "GetDLPEDMByName (Dlp / Dlp Exact Data Match)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "schemaId": { + "type": "integer", + "description": "The identifier (1-65519) for the EDM schema (i.e., EDM template) that is unique within the organization." + }, + "edmClient": { + "type": "object", + "description": "The unique identifer for the Index Tool that was used to create the EDM template. This attribute is ignored by PUT requests, but required for POST requests." + }, + "projectName": { + "type": "string", + "description": "The EDM schema (i.e., EDM template) name. This attribute is ignored by PUT requests, but required for POST requests." + }, + "revision": { + "type": "integer", + "description": "The revision number of the CSV file upload to the Index Tool. This attribute is required by PUT requests." + }, + "filename": { + "type": "string", + "description": "The generated filename, excluding the extention." + }, + "originalFileName": { + "type": "string", + "description": "The generated filename, excluding the extention." + }, + "fileUploadStatus": { + "type": "string", + "description": "The status of the EDM template's CSV file upload to the Index Tool. This attribute is required by PUT and POST requests." + }, + "schemaStatus": { + "type": "string", + "description": "The status of the EDM template's CSV file upload to the Index Tool. This attribute is required by PUT and POST requests." + }, + "origColCount": { + "type": "integer", + "description": "The total count of actual columns selected from the CSV file. This attribute is required by PUT and POST requests." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the EDM schema (i.e., EDM template) was last modified. Ignored if the request is PUT, POST, or DELETE." + }, + "modifiedBy": { + "type": "object", + "description": "The admin that modified the EDM template's schema last." + }, + "createdBy": { + "type": "object", + "description": "The login name (or userid) the admin who created the EDM schema (i.e., EDM template). Ignored if the request is PUT, POST, or DELETE." + }, + "cellsUsed": { + "type": "integer", + "description": "The total number of cells used by the EDM schema (i.e., EDM template)." + }, + "schemaActive": { + "type": "boolean", + "description": "Indicates the status of a specified EDM schema (i.e., EDM template). If this value is set to true, the schema is active and can be used by DLP dictionaries." + }, + "schedulePresent": { + "type": "boolean", + "description": "The total number of cells used by the EDM schema (i.e., EDM template)." + }, + "tokenList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string", + "description": "The token (i.e., criteria) name. This attribute is required by PUT and POST requests." + }, + "type": { + "type": "string", + "description": "The token (i.e., criteria) name. This attribute is required by PUT and POST requests." + }, + "primaryKey": { + "type": "boolean", + "description": "Indicates whether the token is a primary key." + }, + "originalColumn": { + "type": "integer", + "description": "The column position for the token in the original CSV file uploaded to the Index Tool, starting from 1. This attribue required by PUT and POST requests." + }, + "hashfileColumnOrder": { + "type": "integer", + "description": "The column position for the token in the hashed file, starting from 1." + }, + "colLengthBitmap": { + "type": "integer", + "description": "The length of the column bitmap in the hashed file." + } + } + }, + "description": "Indicates the status of a specified EDM schema (i.e., EDM template). If this value is set to true, the schema is active and can be used by DLP dictionaries." + }, + "schedule": { + "type": "object", + "properties": { + "scheduleType": { + "type": "string", + "description": "The schedule type for the EDM schema (i.e., EDM template), Monthly, Weekly, Daily, or None. This attribute is required by PUT and POST requests." + }, + "scheduleDayOfMonth": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The day of the month the EDM schema (i.e., EDM template) is scheduled for. This attribute is required by PUT and POST requests, and if the scheduleType is set to MONTHLY." + }, + "scheduleDayOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The day of the week the EDM schema (i.e., EDM template) is scheduled for. This attribute is required by PUT and POST requests, and if the scheduleType is set to WEEKLY." + }, + "scheduleTime": { + "type": "integer", + "description": "The time of the day (in minutes) that the EDM schema (i.e., EDM template) is scheduled for. For example: at 3am= 180 mins. This attribute is required by PUT and POST requests." + }, + "scheduleDisabled": { + "type": "boolean", + "description": "If set to true, the schedule for the EDM schema (i.e., EDM template) is temporarily in a disabled state. This attribute is required by PUT requests in order to disable or enable a schedule." + } + }, + "description": "The schedule details, if present for the EDM schema (i.e., EDM template). Ignored if the request is PUT, POST, or DELETE." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpExactDataMatchSchemas/lite": { + "get": { + "operationId": "dlp__dlp_exact_data_match_lite_GetBySchemaName", + "summary": "GetBySchemaName (Dlp / Dlp Exact Data Match Lite)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "schema": { + "type": "object", + "properties": { + "ID": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + }, + "description": "The identifier (1-65519) for the EDM schema (i.e., EDM template) that is unique within the organization." + }, + "tokenList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string", + "description": "The token (i.e., criteria) name. This attribute is required by PUT and POST requests." + }, + "type": { + "type": "string", + "description": "The token (i.e., criteria) name. This attribute is required by PUT and POST requests." + }, + "primaryKey": { + "type": "boolean", + "description": "Indicates whether the token is a primary key." + }, + "originalColumn": { + "type": "integer", + "description": "The column position for the token in the original CSV file uploaded to the Index Tool, starting from 1. This attribue required by PUT and POST requests." + }, + "hashfileColumnOrder": { + "type": "integer", + "description": "The column position for the token in the hashed file, starting from 1." + }, + "colLengthBitmap": { + "type": "integer", + "description": "The length of the column bitmap in the hashed file." + } + } + }, + "description": "Indicates the status of a specified EDM schema (i.e., EDM template). If this value is set to true, the schema is active and can be used by DLP dictionaries." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpExactDataMatchSchemas/{id}": { + "get": { + "operationId": "dlp__dlp_exact_data_match_GetDLPEDMSchemaID", + "summary": "GetDLPEDMSchemaID (Dlp / Dlp Exact Data Match)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "schemaId": { + "type": "integer", + "description": "The identifier (1-65519) for the EDM schema (i.e., EDM template) that is unique within the organization." + }, + "edmClient": { + "type": "object", + "description": "The unique identifer for the Index Tool that was used to create the EDM template. This attribute is ignored by PUT requests, but required for POST requests." + }, + "projectName": { + "type": "string", + "description": "The EDM schema (i.e., EDM template) name. This attribute is ignored by PUT requests, but required for POST requests." + }, + "revision": { + "type": "integer", + "description": "The revision number of the CSV file upload to the Index Tool. This attribute is required by PUT requests." + }, + "filename": { + "type": "string", + "description": "The generated filename, excluding the extention." + }, + "originalFileName": { + "type": "string", + "description": "The generated filename, excluding the extention." + }, + "fileUploadStatus": { + "type": "string", + "description": "The status of the EDM template's CSV file upload to the Index Tool. This attribute is required by PUT and POST requests." + }, + "schemaStatus": { + "type": "string", + "description": "The status of the EDM template's CSV file upload to the Index Tool. This attribute is required by PUT and POST requests." + }, + "origColCount": { + "type": "integer", + "description": "The total count of actual columns selected from the CSV file. This attribute is required by PUT and POST requests." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the EDM schema (i.e., EDM template) was last modified. Ignored if the request is PUT, POST, or DELETE." + }, + "modifiedBy": { + "type": "object", + "description": "The admin that modified the EDM template's schema last." + }, + "createdBy": { + "type": "object", + "description": "The login name (or userid) the admin who created the EDM schema (i.e., EDM template). Ignored if the request is PUT, POST, or DELETE." + }, + "cellsUsed": { + "type": "integer", + "description": "The total number of cells used by the EDM schema (i.e., EDM template)." + }, + "schemaActive": { + "type": "boolean", + "description": "Indicates the status of a specified EDM schema (i.e., EDM template). If this value is set to true, the schema is active and can be used by DLP dictionaries." + }, + "schedulePresent": { + "type": "boolean", + "description": "The total number of cells used by the EDM schema (i.e., EDM template)." + }, + "tokenList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { + "type": "string", + "description": "The token (i.e., criteria) name. This attribute is required by PUT and POST requests." + }, + "type": { + "type": "string", + "description": "The token (i.e., criteria) name. This attribute is required by PUT and POST requests." + }, + "primaryKey": { + "type": "boolean", + "description": "Indicates whether the token is a primary key." + }, + "originalColumn": { + "type": "integer", + "description": "The column position for the token in the original CSV file uploaded to the Index Tool, starting from 1. This attribue required by PUT and POST requests." + }, + "hashfileColumnOrder": { + "type": "integer", + "description": "The column position for the token in the hashed file, starting from 1." + }, + "colLengthBitmap": { + "type": "integer", + "description": "The length of the column bitmap in the hashed file." + } + } + }, + "description": "Indicates the status of a specified EDM schema (i.e., EDM template). If this value is set to true, the schema is active and can be used by DLP dictionaries." + }, + "schedule": { + "type": "object", + "properties": { + "scheduleType": { + "type": "string", + "description": "The schedule type for the EDM schema (i.e., EDM template), Monthly, Weekly, Daily, or None. This attribute is required by PUT and POST requests." + }, + "scheduleDayOfMonth": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The day of the month the EDM schema (i.e., EDM template) is scheduled for. This attribute is required by PUT and POST requests, and if the scheduleType is set to MONTHLY." + }, + "scheduleDayOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The day of the week the EDM schema (i.e., EDM template) is scheduled for. This attribute is required by PUT and POST requests, and if the scheduleType is set to WEEKLY." + }, + "scheduleTime": { + "type": "integer", + "description": "The time of the day (in minutes) that the EDM schema (i.e., EDM template) is scheduled for. For example: at 3am= 180 mins. This attribute is required by PUT and POST requests." + }, + "scheduleDisabled": { + "type": "boolean", + "description": "If set to true, the schedule for the EDM schema (i.e., EDM template) is temporarily in a disabled state. This attribute is required by PUT requests in order to disable or enable a schedule." + } + }, + "description": "The schedule details, if present for the EDM schema (i.e., EDM template). Ignored if the request is PUT, POST, or DELETE." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dlpNotificationTemplates": { + "get": { + "operationId": "dlp__dlp_notification_templates_GetByName", + "summary": "GetByName (Dlp / Dlp Notification Templates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "dlp__dlp_notification_templates_Create", + "summary": "Create (Dlp / Dlp Notification Templates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + } + }, + "/zia/api/v1/dlpNotificationTemplates/{id}": { + "get": { + "operationId": "dlp__dlp_notification_templates_Get", + "summary": "Get (Dlp / Dlp Notification Templates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "dlp__dlp_notification_templates_Update", + "summary": "Update (Dlp / Dlp Notification Templates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + }, + "delete": { + "operationId": "dlp__dlp_notification_templates_Delete", + "summary": "Delete (Dlp / Dlp Notification Templates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dnatRules": { + "get": { + "operationId": "nat_control_policies_GetByName", + "summary": "GetByName (Nat Control Policies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "accessControl": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "redirectFqdn": { + "type": "string" + }, + "redirectIp": { + "type": "string" + }, + "redirectPort": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "trustedResolverRule": { + "type": "boolean" + }, + "enableFullLogging": { + "type": "boolean" + }, + "predefined": { + "type": "boolean" + }, + "defaultRule": { + "type": "boolean" + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + } + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + } + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "nat_control_policies_Create", + "summary": "Create (Nat Control Policies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "accessControl": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "redirectFqdn": { + "type": "string" + }, + "redirectIp": { + "type": "string" + }, + "redirectPort": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "trustedResolverRule": { + "type": "boolean" + }, + "enableFullLogging": { + "type": "boolean" + }, + "predefined": { + "type": "boolean" + }, + "defaultRule": { + "type": "boolean" + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + } + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + } + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "accessControl": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "redirectFqdn": { + "type": "string" + }, + "redirectIp": { + "type": "string" + }, + "redirectPort": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "trustedResolverRule": { + "type": "boolean" + }, + "enableFullLogging": { + "type": "boolean" + }, + "predefined": { + "type": "boolean" + }, + "defaultRule": { + "type": "boolean" + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + } + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + } + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dnatRules/{id}": { + "get": { + "operationId": "nat_control_policies_Get", + "summary": "Get (Nat Control Policies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "accessControl": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "redirectFqdn": { + "type": "string" + }, + "redirectIp": { + "type": "string" + }, + "redirectPort": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "trustedResolverRule": { + "type": "boolean" + }, + "enableFullLogging": { + "type": "boolean" + }, + "predefined": { + "type": "boolean" + }, + "defaultRule": { + "type": "boolean" + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + } + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + } + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "nat_control_policies_Update", + "summary": "Update (Nat Control Policies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "accessControl": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "redirectFqdn": { + "type": "string" + }, + "redirectIp": { + "type": "string" + }, + "redirectPort": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "trustedResolverRule": { + "type": "boolean" + }, + "enableFullLogging": { + "type": "boolean" + }, + "predefined": { + "type": "boolean" + }, + "defaultRule": { + "type": "boolean" + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + } + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + } + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "accessControl": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "redirectFqdn": { + "type": "string" + }, + "redirectIp": { + "type": "string" + }, + "redirectPort": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "trustedResolverRule": { + "type": "boolean" + }, + "enableFullLogging": { + "type": "boolean" + }, + "predefined": { + "type": "boolean" + }, + "defaultRule": { + "type": "boolean" + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + } + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + } + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "nat_control_policies_Delete", + "summary": "Delete (Nat Control Policies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "accessControl": { + "type": "string" + }, + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "redirectFqdn": { + "type": "string" + }, + "redirectIp": { + "type": "string" + }, + "redirectPort": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "trustedResolverRule": { + "type": "boolean" + }, + "enableFullLogging": { + "type": "boolean" + }, + "predefined": { + "type": "boolean" + }, + "defaultRule": { + "type": "boolean" + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + } + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + } + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dnsApplicationGroups": { + "post": { + "operationId": "firewallpolicies__dns_application_groups_Create", + "summary": "Create (Firewallpolicies / Dns Application Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "get": { + "operationId": "firewallpolicies__dns_application_groups_GetAll", + "summary": "GetAll (Firewallpolicies / Dns Application Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dnsApplicationGroups/{id}": { + "get": { + "operationId": "firewallpolicies__dns_application_groups_Get", + "summary": "Get (Firewallpolicies / Dns Application Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "firewallpolicies__dns_application_groups_Update", + "summary": "Update (Firewallpolicies / Dns Application Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "delete": { + "operationId": "firewallpolicies__dns_application_groups_Delete", + "summary": "Delete (Firewallpolicies / Dns Application Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/dnsGateways": { + "get": { + "operationId": "firewallpolicies__dns_gateways_GetByName", + "summary": "GetByName (Firewallpolicies / Dns Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsGatewayType": { + "type": "string" + }, + "primaryIpOrFqdn": { + "type": "string" + }, + "primaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "secondaryIpOrFqdn": { + "type": "string" + }, + "secondaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "failureBehavior": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "autoCreated": { + "type": "boolean" + }, + "natZtrGateway": { + "type": "boolean" + }, + "dnsGatewayProtocols": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "firewallpolicies__dns_gateways_Create", + "summary": "Create (Firewallpolicies / Dns Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsGatewayType": { + "type": "string" + }, + "primaryIpOrFqdn": { + "type": "string" + }, + "primaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "secondaryIpOrFqdn": { + "type": "string" + }, + "secondaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "failureBehavior": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "autoCreated": { + "type": "boolean" + }, + "natZtrGateway": { + "type": "boolean" + }, + "dnsGatewayProtocols": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsGatewayType": { + "type": "string" + }, + "primaryIpOrFqdn": { + "type": "string" + }, + "primaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "secondaryIpOrFqdn": { + "type": "string" + }, + "secondaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "failureBehavior": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "autoCreated": { + "type": "boolean" + }, + "natZtrGateway": { + "type": "boolean" + }, + "dnsGatewayProtocols": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/dnsGateways/{id}": { + "get": { + "operationId": "firewallpolicies__dns_gateways_Get", + "summary": "Get (Firewallpolicies / Dns Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsGatewayType": { + "type": "string" + }, + "primaryIpOrFqdn": { + "type": "string" + }, + "primaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "secondaryIpOrFqdn": { + "type": "string" + }, + "secondaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "failureBehavior": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "autoCreated": { + "type": "boolean" + }, + "natZtrGateway": { + "type": "boolean" + }, + "dnsGatewayProtocols": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "firewallpolicies__dns_gateways_Update", + "summary": "Update (Firewallpolicies / Dns Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsGatewayType": { + "type": "string" + }, + "primaryIpOrFqdn": { + "type": "string" + }, + "primaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "secondaryIpOrFqdn": { + "type": "string" + }, + "secondaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "failureBehavior": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "autoCreated": { + "type": "boolean" + }, + "natZtrGateway": { + "type": "boolean" + }, + "dnsGatewayProtocols": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsGatewayType": { + "type": "string" + }, + "primaryIpOrFqdn": { + "type": "string" + }, + "primaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "secondaryIpOrFqdn": { + "type": "string" + }, + "secondaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "failureBehavior": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "autoCreated": { + "type": "boolean" + }, + "natZtrGateway": { + "type": "boolean" + }, + "dnsGatewayProtocols": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "firewallpolicies__dns_gateways_Delete", + "summary": "Delete (Firewallpolicies / Dns Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dnsGatewayType": { + "type": "string" + }, + "primaryIpOrFqdn": { + "type": "string" + }, + "primaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "secondaryIpOrFqdn": { + "type": "string" + }, + "secondaryPorts": { + "type": "array", + "items": { + "type": "integer" + } + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + } + }, + "failureBehavior": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "autoCreated": { + "type": "boolean" + }, + "natZtrGateway": { + "type": "boolean" + }, + "dnsGatewayProtocols": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/domainProfiles": { + "get": { + "operationId": "saas_security_api_GetDomainProfiles", + "summary": "GetDomainProfiles (Saas Security Api)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "profileId": { + "type": "integer", + "description": "Domain profile ID" + }, + "profileName": { + "type": "string", + "description": "Domain profile name" + }, + "includeCompanyDomains": { + "type": "boolean", + "description": "A Boolean flag to determine if the organizational domains have to be included in the domain profile" + }, + "includeSubdomains": { + "type": "boolean", + "description": "A Boolean flag to determine whether or not to include subdomains" + }, + "description": { + "type": "string", + "description": "Additional notes or information about the domain profile" + }, + "customDomains": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of custom domains for the domain profile. There can be one or more custom domains." + }, + "predefinedEmailDomains": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of predefined email service provider domains for the domain profile\nSee SaaS Security API for supported values: https://help.zscaler.com/zia/saas-security-api#/domainProfiles/lite-get" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/emailDlpRules": { + "get": { + "operationId": "endpoint_dlp__outbound_email_dlp_GetLite", + "summary": "GetLite (Endpoint Dlp / Outbound Email Dlp)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "OutboundEmailDlp object" + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "endpoint_dlp__outbound_email_dlp_Create", + "summary": "Create (Endpoint Dlp / Outbound Email Dlp)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "OutboundEmailDlp object" + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "OutboundEmailDlp object" + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/emailDlpRules/{id}": { + "get": { + "operationId": "endpoint_dlp__outbound_email_dlp_Get", + "summary": "Get (Endpoint Dlp / Outbound Email Dlp)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "OutboundEmailDlp object" + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "endpoint_dlp__outbound_email_dlp_Update", + "summary": "Update (Endpoint Dlp / Outbound Email Dlp)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "OutboundEmailDlp object" + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "OutboundEmailDlp object" + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "endpoint_dlp__outbound_email_dlp_Delete", + "summary": "Delete (Endpoint Dlp / Outbound Email Dlp)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "order": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "state": { + "type": "string" + }, + "action": { + "type": "string" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "minSize": { + "type": "integer" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "externalAuditorEmail": { + "type": "string" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailTenants": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "contentLocations": { + "type": "array", + "items": { + "type": "string" + } + }, + "parentRule": { + "type": "integer" + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "OutboundEmailDlp object" + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "customHeader": { + "type": "string" + }, + "emailRecipientProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/emailRecipientProfile": { + "post": { + "operationId": "email_profiles_Create", + "summary": "Create (Email Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "emails": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "emails": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "get": { + "operationId": "email_profiles_GetAllLite", + "summary": "GetAllLite (Email Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "emails": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/emailRecipientProfile/{id}": { + "get": { + "operationId": "email_profiles_Get", + "summary": "Get (Email Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "emails": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "email_profiles_Update", + "summary": "Update (Email Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "emails": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "emails": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "email_profiles_Delete", + "summary": "Delete (Email Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "emails": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/endPointApplicationGroups": { + "post": { + "operationId": "endpoint_dlp__endpoint_application_groups_Create", + "summary": "Create (Endpoint Dlp / Endpoint Application Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resourceCount": { + "type": "integer" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "properties": { + "appId": { + "type": "string" + }, + "name": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resourceCount": { + "type": "integer" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "properties": { + "appId": { + "type": "string" + }, + "name": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "get": { + "operationId": "endpoint_dlp__endpoint_application_groups_GetAll", + "summary": "GetAll (Endpoint Dlp / Endpoint Application Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resourceCount": { + "type": "integer" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "properties": { + "appId": { + "type": "string" + }, + "name": { + "type": "string" + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/endPointApplicationGroups/{id}": { + "put": { + "operationId": "endpoint_dlp__endpoint_application_groups_Update", + "summary": "Update (Endpoint Dlp / Endpoint Application Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resourceCount": { + "type": "integer" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "properties": { + "appId": { + "type": "string" + }, + "name": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resourceCount": { + "type": "integer" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "properties": { + "appId": { + "type": "string" + }, + "name": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "endpoint_dlp__endpoint_application_groups_Delete", + "summary": "Delete (Endpoint Dlp / Endpoint Application Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resourceCount": { + "type": "integer" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "properties": { + "appId": { + "type": "string" + }, + "name": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/endPointApplications": { + "get": { + "operationId": "endpoint_dlp__endpoint_applications_GetApplicationPolicies", + "summary": "GetApplicationPolicies (Endpoint Dlp / Endpoint Applications)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "ruleName": { + "type": "string" + }, + "ruleType": { + "type": "string" + }, + "id": { + "type": "string" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "endpoint_dlp__endpoint_custom_apps_Create", + "summary": "Create (Endpoint Dlp / Endpoint Custom Apps)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "resourceId": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "osType": { + "type": "string" + }, + "applicationName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "filename": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + }, + "modUId": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "applicationType": { + "type": "string" + }, + "version": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + }, + "versions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + } + }, + "zappId": { + "type": "string" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "resourceId": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "osType": { + "type": "string" + }, + "applicationName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "filename": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + }, + "modUId": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "applicationType": { + "type": "string" + }, + "version": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + }, + "versions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + } + }, + "zappId": { + "type": "string" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "/zia/api/v1/endPointApplications/{id}": { + "get": { + "operationId": "endpoint_dlp__endpoint_custom_apps_GetCustomApp", + "summary": "GetCustomApp (Endpoint Dlp / Endpoint Custom Apps)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "resourceId": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "osType": { + "type": "string" + }, + "applicationName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "filename": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + }, + "modUId": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "applicationType": { + "type": "string" + }, + "version": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + }, + "versions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + } + }, + "zappId": { + "type": "string" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "endpoint_dlp__endpoint_custom_apps_Update", + "summary": "Update (Endpoint Dlp / Endpoint Custom Apps)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "resourceId": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "osType": { + "type": "string" + }, + "applicationName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "filename": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + }, + "modUId": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "applicationType": { + "type": "string" + }, + "version": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + }, + "versions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + } + }, + "zappId": { + "type": "string" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "resourceId": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "osType": { + "type": "string" + }, + "applicationName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "filename": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + }, + "modUId": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "applicationType": { + "type": "string" + }, + "version": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + }, + "versions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + } + }, + "zappId": { + "type": "string" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "delete": { + "operationId": "endpoint_dlp__endpoint_custom_apps_Delete", + "summary": "Delete (Endpoint Dlp / Endpoint Custom Apps)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "resourceId": { + "type": "integer" + }, + "description": { + "type": "string" + }, + "osType": { + "type": "string" + }, + "applicationName": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "filename": { + "type": "string" + }, + "originalFileName": { + "type": "string" + }, + "digitallySigned": { + "type": "boolean" + }, + "modUId": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + }, + "applicationType": { + "type": "string" + }, + "version": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + }, + "versions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "version": { + "type": "string" + }, + "z_ver_id_md32": { + "type": "integer" + }, + "threat_type": { + "type": "integer" + }, + "threat_level": { + "type": "string" + }, + "bundleID": { + "type": "string" + }, + "code_signing_certificate_status": { + "type": "integer" + }, + "threatLevelUpdated": { + "type": "boolean" + } + } + } + }, + "zappId": { + "type": "string" + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/endPointDlpResourceGroups": { + "post": { + "operationId": "endpoint_dlp__endpoint_resource_group_Create", + "summary": "Create (Endpoint Dlp / Endpoint Resource Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "endpoint_resource.EndpointResource object" + } + }, + "resourceCount": { + "type": "integer" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "endpoint_resource.EndpointResource object" + } + }, + "resourceCount": { + "type": "integer" + } + } + } + } + } + } + } + }, + "/zia/api/v1/endPointDlpResourceGroups/{id}": { + "put": { + "operationId": "endpoint_dlp__endpoint_resource_group_Update", + "summary": "Update (Endpoint Dlp / Endpoint Resource Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "endpoint_resource.EndpointResource object" + } + }, + "resourceCount": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "endpoint_resource.EndpointResource object" + } + }, + "resourceCount": { + "type": "integer" + } + } + } + } + } + } + }, + "delete": { + "operationId": "endpoint_dlp__endpoint_resource_group_Delete", + "summary": "Delete (Endpoint Dlp / Endpoint Resource Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "endpoint_resource.EndpointResource object" + } + }, + "resourceCount": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "get": { + "operationId": "endpoint_dlp__endpoint_resource_group_GetResourceGroupTagsList", + "summary": "GetResourceGroupTagsList (Endpoint Dlp / Endpoint Resource Group)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "channel": { + "type": "string" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "endpoint_resource.EndpointResource object" + } + }, + "resourceCount": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/endPointDlpRules": { + "post": { + "operationId": "endpoint_dlp__endpoint_dlp_rules_Create", + "summary": "Create (Endpoint Dlp / Endpoint Dlp Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "EndpointDlpRules object" + } + } + } + } + } + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "EndpointDlpRules object" + } + } + } + } + } + } + } + } + } + } + } + } + } + }, + "get": { + "operationId": "endpoint_dlp__endpoint_dlp_rules_GetAll", + "summary": "GetAll (Endpoint Dlp / Endpoint Dlp Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "EndpointDlpRules object" + } + } + } + } + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/endPointDlpRules/{id}": { + "get": { + "operationId": "endpoint_dlp__endpoint_dlp_rules_Get", + "summary": "Get (Endpoint Dlp / Endpoint Dlp Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "EndpointDlpRules object" + } + } + } + } + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "endpoint_dlp__endpoint_dlp_rules_Update", + "summary": "Update (Endpoint Dlp / Endpoint Dlp Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "EndpointDlpRules object" + } + } + } + } + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "EndpointDlpRules object" + } + } + } + } + } + } + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "endpoint_dlp__endpoint_dlp_rules_Delete", + "summary": "Delete (Endpoint Dlp / Endpoint Dlp Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "EndpointDlpRules object" + } + } + } + } + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "post": { + "operationId": "endpoint_dlp__endpoint_dlp_sub_rules_Create", + "summary": "Create (Endpoint Dlp / Endpoint Dlp Sub Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/endPointDlpRules/{id}/{id2}": { + "put": { + "operationId": "endpoint_dlp__endpoint_dlp_sub_rules_Update", + "summary": "Update (Endpoint Dlp / Endpoint Dlp Sub Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "endpoint_dlp__endpoint_dlp_sub_rules_Delete", + "summary": "Delete (Endpoint Dlp / Endpoint Dlp Sub Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "state": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "rank": { + "type": "integer" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataTransferMethod": { + "type": "string" + }, + "description": { + "type": "string" + }, + "minSize": { + "type": "integer" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "action": { + "type": "string" + }, + "externalAuditorEmail": { + "type": "string" + }, + "lastModifiedTime": { + "type": "integer" + }, + "parentRule": { + "type": "integer" + }, + "severity": { + "type": "string" + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "ucTemplateId": { + "type": "integer" + }, + "networkType": { + "type": "string" + }, + "withoutContentInspection": { + "type": "boolean" + }, + "notificationTemplate": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "auditor": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "resources": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "resourceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "receiver": { + "type": "object", + "description": "dlp_web_rules.Receiver object" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/eun": { + "get": { + "operationId": "end_user_notification_GetUserNotificationSettings", + "summary": "GetUserNotificationSettings (End User Notification)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "aupFrequency": { + "type": "string" + }, + "aupCustomFrequency": { + "type": "integer" + }, + "aupDayOffset": { + "type": "integer" + }, + "aupMessage": { + "type": "string" + }, + "notificationType": { + "type": "string" + }, + "displayReason": { + "type": "boolean" + }, + "displayCompName": { + "type": "boolean" + }, + "displayCompLogo": { + "type": "boolean" + }, + "customText": { + "type": "string" + }, + "urlCatReviewEnabled": { + "type": "boolean" + }, + "urlCatReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "urlCatReviewCustomLocation": { + "type": "string" + }, + "urlCatReviewText": { + "type": "string" + }, + "securityReviewEnabled": { + "type": "boolean" + }, + "securityReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "securityReviewCustomLocation": { + "type": "string" + }, + "securityReviewText": { + "type": "string" + }, + "webDlpReviewEnabled": { + "type": "boolean" + }, + "webDlpReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "webDlpReviewCustomLocation": { + "type": "string" + }, + "webDlpReviewText": { + "type": "string" + }, + "redirectUrl": { + "type": "string" + }, + "supportEmail": { + "type": "string" + }, + "supportPhone": { + "type": "string" + }, + "orgPolicyLink": { + "type": "string" + }, + "cautionAgainAfter": { + "type": "integer" + }, + "cautionPerDomain": { + "type": "boolean" + }, + "cautionCustomText": { + "type": "string" + }, + "idpProxyNotificationText": { + "type": "string" + }, + "quarantineCustomNotificationText": { + "type": "string" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "end_user_notification_UpdateUserNotificationSettings", + "summary": "UpdateUserNotificationSettings (End User Notification)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "aupFrequency": { + "type": "string" + }, + "aupCustomFrequency": { + "type": "integer" + }, + "aupDayOffset": { + "type": "integer" + }, + "aupMessage": { + "type": "string" + }, + "notificationType": { + "type": "string" + }, + "displayReason": { + "type": "boolean" + }, + "displayCompName": { + "type": "boolean" + }, + "displayCompLogo": { + "type": "boolean" + }, + "customText": { + "type": "string" + }, + "urlCatReviewEnabled": { + "type": "boolean" + }, + "urlCatReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "urlCatReviewCustomLocation": { + "type": "string" + }, + "urlCatReviewText": { + "type": "string" + }, + "securityReviewEnabled": { + "type": "boolean" + }, + "securityReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "securityReviewCustomLocation": { + "type": "string" + }, + "securityReviewText": { + "type": "string" + }, + "webDlpReviewEnabled": { + "type": "boolean" + }, + "webDlpReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "webDlpReviewCustomLocation": { + "type": "string" + }, + "webDlpReviewText": { + "type": "string" + }, + "redirectUrl": { + "type": "string" + }, + "supportEmail": { + "type": "string" + }, + "supportPhone": { + "type": "string" + }, + "orgPolicyLink": { + "type": "string" + }, + "cautionAgainAfter": { + "type": "integer" + }, + "cautionPerDomain": { + "type": "boolean" + }, + "cautionCustomText": { + "type": "string" + }, + "idpProxyNotificationText": { + "type": "string" + }, + "quarantineCustomNotificationText": { + "type": "string" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "aupFrequency": { + "type": "string" + }, + "aupCustomFrequency": { + "type": "integer" + }, + "aupDayOffset": { + "type": "integer" + }, + "aupMessage": { + "type": "string" + }, + "notificationType": { + "type": "string" + }, + "displayReason": { + "type": "boolean" + }, + "displayCompName": { + "type": "boolean" + }, + "displayCompLogo": { + "type": "boolean" + }, + "customText": { + "type": "string" + }, + "urlCatReviewEnabled": { + "type": "boolean" + }, + "urlCatReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "urlCatReviewCustomLocation": { + "type": "string" + }, + "urlCatReviewText": { + "type": "string" + }, + "securityReviewEnabled": { + "type": "boolean" + }, + "securityReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "securityReviewCustomLocation": { + "type": "string" + }, + "securityReviewText": { + "type": "string" + }, + "webDlpReviewEnabled": { + "type": "boolean" + }, + "webDlpReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "webDlpReviewCustomLocation": { + "type": "string" + }, + "webDlpReviewText": { + "type": "string" + }, + "redirectUrl": { + "type": "string" + }, + "supportEmail": { + "type": "string" + }, + "supportPhone": { + "type": "string" + }, + "orgPolicyLink": { + "type": "string" + }, + "cautionAgainAfter": { + "type": "integer" + }, + "cautionPerDomain": { + "type": "boolean" + }, + "cautionCustomText": { + "type": "string" + }, + "idpProxyNotificationText": { + "type": "string" + }, + "quarantineCustomNotificationText": { + "type": "string" + } + } + } + } + } + } + } + }, + "/zia/api/v1/eunTemplate/{id}": { + "get": { + "operationId": "end_user_notification_GetEunEnablementStatus", + "summary": "GetEunEnablementStatus (End User Notification)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "aupFrequency": { + "type": "string" + }, + "aupCustomFrequency": { + "type": "integer" + }, + "aupDayOffset": { + "type": "integer" + }, + "aupMessage": { + "type": "string" + }, + "notificationType": { + "type": "string" + }, + "displayReason": { + "type": "boolean" + }, + "displayCompName": { + "type": "boolean" + }, + "displayCompLogo": { + "type": "boolean" + }, + "customText": { + "type": "string" + }, + "urlCatReviewEnabled": { + "type": "boolean" + }, + "urlCatReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "urlCatReviewCustomLocation": { + "type": "string" + }, + "urlCatReviewText": { + "type": "string" + }, + "securityReviewEnabled": { + "type": "boolean" + }, + "securityReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "securityReviewCustomLocation": { + "type": "string" + }, + "securityReviewText": { + "type": "string" + }, + "webDlpReviewEnabled": { + "type": "boolean" + }, + "webDlpReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "webDlpReviewCustomLocation": { + "type": "string" + }, + "webDlpReviewText": { + "type": "string" + }, + "redirectUrl": { + "type": "string" + }, + "supportEmail": { + "type": "string" + }, + "supportPhone": { + "type": "string" + }, + "orgPolicyLink": { + "type": "string" + }, + "cautionAgainAfter": { + "type": "integer" + }, + "cautionPerDomain": { + "type": "boolean" + }, + "cautionCustomText": { + "type": "string" + }, + "idpProxyNotificationText": { + "type": "string" + }, + "quarantineCustomNotificationText": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/eunTemplate/{id}/{id2}": { + "get": { + "operationId": "end_user_notification_GetEunTemplateBrowserBasedZCC", + "summary": "GetEunTemplateBrowserBasedZCC (End User Notification)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "aupFrequency": { + "type": "string" + }, + "aupCustomFrequency": { + "type": "integer" + }, + "aupDayOffset": { + "type": "integer" + }, + "aupMessage": { + "type": "string" + }, + "notificationType": { + "type": "string" + }, + "displayReason": { + "type": "boolean" + }, + "displayCompName": { + "type": "boolean" + }, + "displayCompLogo": { + "type": "boolean" + }, + "customText": { + "type": "string" + }, + "urlCatReviewEnabled": { + "type": "boolean" + }, + "urlCatReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "urlCatReviewCustomLocation": { + "type": "string" + }, + "urlCatReviewText": { + "type": "string" + }, + "securityReviewEnabled": { + "type": "boolean" + }, + "securityReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "securityReviewCustomLocation": { + "type": "string" + }, + "securityReviewText": { + "type": "string" + }, + "webDlpReviewEnabled": { + "type": "boolean" + }, + "webDlpReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "webDlpReviewCustomLocation": { + "type": "string" + }, + "webDlpReviewText": { + "type": "string" + }, + "redirectUrl": { + "type": "string" + }, + "supportEmail": { + "type": "string" + }, + "supportPhone": { + "type": "string" + }, + "orgPolicyLink": { + "type": "string" + }, + "cautionAgainAfter": { + "type": "integer" + }, + "cautionPerDomain": { + "type": "boolean" + }, + "cautionCustomText": { + "type": "string" + }, + "idpProxyNotificationText": { + "type": "string" + }, + "quarantineCustomNotificationText": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/eusaStatus": { + "get": { + "operationId": "activation_GetEusaStatus", + "summary": "GetEusaStatus (Activation)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "status": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/eusaStatus/{id}": { + "put": { + "operationId": "activation_UpdateEusaStatus", + "summary": "UpdateEusaStatus (Activation)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "status": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "status": { + "type": "string" + } + } + } + } + } + } + } + }, + "/zia/api/v1/eventlogEntryReport": { + "get": { + "operationId": "eventlogentryreport_GetAll", + "summary": "GetAll (Eventlogentryreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "startTime": { + "type": "integer", + "description": "The start time in the time range used to generate the event log report" + }, + "endTime": { + "type": "integer", + "description": "The end time in the time range used to generate the event log report" + }, + "page": { + "type": "integer" + }, + "pageSize": { + "type": "string" + }, + "category": { + "type": "string", + "description": "Filters the list based on the category for which the events were recorded." + }, + "subcategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Filters the list based on areas within a category where the events were recorded" + }, + "actionResult": { + "type": "string", + "description": "Filters the list based on the outcome (i.e., Failure or Success) of the events recorded" + }, + "message": { + "type": "string", + "description": "The search string used to match against the event log message" + }, + "errorCode": { + "type": "string", + "description": "The search string used to match against the error code in event log entries" + }, + "statusCode": { + "type": "string", + "description": "The search string used to match against the status code in event log entries" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "eventlogentryreport_Create", + "summary": "Create (Eventlogentryreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "startTime": { + "type": "integer", + "description": "The start time in the time range used to generate the event log report" + }, + "endTime": { + "type": "integer", + "description": "The end time in the time range used to generate the event log report" + }, + "page": { + "type": "integer" + }, + "pageSize": { + "type": "string" + }, + "category": { + "type": "string", + "description": "Filters the list based on the category for which the events were recorded." + }, + "subcategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Filters the list based on areas within a category where the events were recorded" + }, + "actionResult": { + "type": "string", + "description": "Filters the list based on the outcome (i.e., Failure or Success) of the events recorded" + }, + "message": { + "type": "string", + "description": "The search string used to match against the event log message" + }, + "errorCode": { + "type": "string", + "description": "The search string used to match against the error code in event log entries" + }, + "statusCode": { + "type": "string", + "description": "The search string used to match against the status code in event log entries" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "startTime": { + "type": "integer", + "description": "The start time in the time range used to generate the event log report" + }, + "endTime": { + "type": "integer", + "description": "The end time in the time range used to generate the event log report" + }, + "page": { + "type": "integer" + }, + "pageSize": { + "type": "string" + }, + "category": { + "type": "string", + "description": "Filters the list based on the category for which the events were recorded." + }, + "subcategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Filters the list based on areas within a category where the events were recorded" + }, + "actionResult": { + "type": "string", + "description": "Filters the list based on the outcome (i.e., Failure or Success) of the events recorded" + }, + "message": { + "type": "string", + "description": "The search string used to match against the event log message" + }, + "errorCode": { + "type": "string", + "description": "The search string used to match against the error code in event log entries" + }, + "statusCode": { + "type": "string", + "description": "The search string used to match against the status code in event log entries" + } + } + } + } + } + } + }, + "delete": { + "operationId": "eventlogentryreport_Delete", + "summary": "Delete (Eventlogentryreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "startTime": { + "type": "integer", + "description": "The start time in the time range used to generate the event log report" + }, + "endTime": { + "type": "integer", + "description": "The end time in the time range used to generate the event log report" + }, + "page": { + "type": "integer" + }, + "pageSize": { + "type": "string" + }, + "category": { + "type": "string", + "description": "Filters the list based on the category for which the events were recorded." + }, + "subcategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Filters the list based on areas within a category where the events were recorded" + }, + "actionResult": { + "type": "string", + "description": "Filters the list based on the outcome (i.e., Failure or Success) of the events recorded" + }, + "message": { + "type": "string", + "description": "The search string used to match against the event log message" + }, + "errorCode": { + "type": "string", + "description": "The search string used to match against the error code in event log entries" + }, + "statusCode": { + "type": "string", + "description": "The search string used to match against the status code in event log entries" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/extranet": { + "post": { + "operationId": "trafficforwarding__extranet_Create", + "summary": "Create (Trafficforwarding / Extranet)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the extranet" + }, + "name": { + "type": "string", + "description": "The name of the extranet" + }, + "description": { + "type": "string", + "description": "The description of the extranet" + }, + "extranetDNSList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "primaryDNSServer": { + "type": "string", + "description": "The IP address of the primary DNS server" + }, + "secondaryDNSServer": { + "type": "string", + "description": "The IP address of the secondary DNS server" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the DNS servers specified for the extranet" + }, + "extranetIpPoolList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "ipStart": { + "type": "string" + }, + "ipEnd": { + "type": "string" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the traffic selectors specified for the extranet (API returns an array)." + }, + "createdAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was created" + }, + "modifiedAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was last modified" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the extranet" + }, + "name": { + "type": "string", + "description": "The name of the extranet" + }, + "description": { + "type": "string", + "description": "The description of the extranet" + }, + "extranetDNSList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "primaryDNSServer": { + "type": "string", + "description": "The IP address of the primary DNS server" + }, + "secondaryDNSServer": { + "type": "string", + "description": "The IP address of the secondary DNS server" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the DNS servers specified for the extranet" + }, + "extranetIpPoolList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "ipStart": { + "type": "string" + }, + "ipEnd": { + "type": "string" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the traffic selectors specified for the extranet (API returns an array)." + }, + "createdAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was created" + }, + "modifiedAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was last modified" + } + } + } + } + } + } + }, + "put": { + "operationId": "trafficforwarding__extranet_Update", + "summary": "Update (Trafficforwarding / Extranet)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the extranet" + }, + "name": { + "type": "string", + "description": "The name of the extranet" + }, + "description": { + "type": "string", + "description": "The description of the extranet" + }, + "extranetDNSList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "primaryDNSServer": { + "type": "string", + "description": "The IP address of the primary DNS server" + }, + "secondaryDNSServer": { + "type": "string", + "description": "The IP address of the secondary DNS server" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the DNS servers specified for the extranet" + }, + "extranetIpPoolList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "ipStart": { + "type": "string" + }, + "ipEnd": { + "type": "string" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the traffic selectors specified for the extranet (API returns an array)." + }, + "createdAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was created" + }, + "modifiedAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was last modified" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the extranet" + }, + "name": { + "type": "string", + "description": "The name of the extranet" + }, + "description": { + "type": "string", + "description": "The description of the extranet" + }, + "extranetDNSList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "primaryDNSServer": { + "type": "string", + "description": "The IP address of the primary DNS server" + }, + "secondaryDNSServer": { + "type": "string", + "description": "The IP address of the secondary DNS server" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the DNS servers specified for the extranet" + }, + "extranetIpPoolList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "ipStart": { + "type": "string" + }, + "ipEnd": { + "type": "string" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the traffic selectors specified for the extranet (API returns an array)." + }, + "createdAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was created" + }, + "modifiedAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was last modified" + } + } + } + } + } + } + }, + "get": { + "operationId": "trafficforwarding__extranet_GetAll", + "summary": "GetAll (Trafficforwarding / Extranet)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the extranet" + }, + "name": { + "type": "string", + "description": "The name of the extranet" + }, + "description": { + "type": "string", + "description": "The description of the extranet" + }, + "extranetDNSList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "primaryDNSServer": { + "type": "string", + "description": "The IP address of the primary DNS server" + }, + "secondaryDNSServer": { + "type": "string", + "description": "The IP address of the secondary DNS server" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the DNS servers specified for the extranet" + }, + "extranetIpPoolList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "ipStart": { + "type": "string" + }, + "ipEnd": { + "type": "string" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the traffic selectors specified for the extranet (API returns an array)." + }, + "createdAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was created" + }, + "modifiedAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was last modified" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/extranet/{id}": { + "get": { + "operationId": "trafficforwarding__extranet_Get", + "summary": "Get (Trafficforwarding / Extranet)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the extranet" + }, + "name": { + "type": "string", + "description": "The name of the extranet" + }, + "description": { + "type": "string", + "description": "The description of the extranet" + }, + "extranetDNSList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "primaryDNSServer": { + "type": "string", + "description": "The IP address of the primary DNS server" + }, + "secondaryDNSServer": { + "type": "string", + "description": "The IP address of the secondary DNS server" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the DNS servers specified for the extranet" + }, + "extranetIpPoolList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "ipStart": { + "type": "string" + }, + "ipEnd": { + "type": "string" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the traffic selectors specified for the extranet (API returns an array)." + }, + "createdAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was created" + }, + "modifiedAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was last modified" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "delete": { + "operationId": "trafficforwarding__extranet_Delete", + "summary": "Delete (Trafficforwarding / Extranet)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the extranet" + }, + "name": { + "type": "string", + "description": "The name of the extranet" + }, + "description": { + "type": "string", + "description": "The description of the extranet" + }, + "extranetDNSList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "primaryDNSServer": { + "type": "string", + "description": "The IP address of the primary DNS server" + }, + "secondaryDNSServer": { + "type": "string", + "description": "The IP address of the secondary DNS server" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the DNS servers specified for the extranet" + }, + "extranetIpPoolList": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The ID generated for the DNS server configuration" + }, + "name": { + "type": "string", + "description": "The name of the DNS server" + }, + "ipStart": { + "type": "string" + }, + "ipEnd": { + "type": "string" + }, + "useAsDefault": { + "type": "boolean", + "description": "A Boolean value indicating that the DNS servers specified in the extranet are the designated default servers" + } + } + }, + "description": "Information about the traffic selectors specified for the extranet (API returns an array)." + }, + "createdAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was created" + }, + "modifiedAt": { + "type": "integer", + "description": "The Unix timestamp when the extranet was last modified" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/fileTypeCategories": { + "get": { + "operationId": "filetypecontrol_GetFileTypeCategories", + "summary": "GetFileTypeCategories (Filetypecontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/fileTypeRules": { + "get": { + "operationId": "filetypecontrol_GetByName", + "summary": "GetByName (Filetypecontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "filetypecontrol_Create", + "summary": "Create (Filetypecontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + } + }, + "/zia/api/v1/fileTypeRules/{id}": { + "get": { + "operationId": "filetypecontrol_Get", + "summary": "Get (Filetypecontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "filetypecontrol_Update", + "summary": "Update (Filetypecontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "delete": { + "operationId": "filetypecontrol_Delete", + "summary": "Delete (Filetypecontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/firewallDnsRules": { + "get": { + "operationId": "firewalldnscontrolpolicies_GetByName", + "summary": "GetByName (Firewalldnscontrolpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule\nSupported Values: \"ALLOW\", \"BLOCK\", \"REDIR_REQ\", \"REDIR_RES\", \"REDIR_ZPA\", \"REDIR_REQ_DOH\", \"REDIR_REQ_KEEP_SENDER\", \"REDIR_REQ_TCP\", \"REDIR_REQ_UDP\",\"BLOCK_WITH_RESPONSE\"" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "redirectIp": { + "type": "string", + "description": "The IP address to which the traffic will be redirected to when the DNAT rule is triggered. If not set, no redirection is done to specific IP addresses." + }, + "blockResponseCode": { + "type": "string", + "description": "Specifies the DNS response code to be sent to the client when the action is configured to block and send response code" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin who last modified the rule" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses or FQDNs to which the rule applies. If not set, the rule is not restricted to a\nspecific destination IP address. Each IP entry can be a single IP address, CIDR (e.g., 10.10.33.0/24), or an IP range (e.g., 10.10.33.1-10.10.33.10)." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "applications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS tunnels and network applications to which the rule applies" + }, + "dnsRuleRequestTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS request types to which the rule applies" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rules applies\nSupported Values: \"ANY_RULE\", \"SMRULEF_CASCADING_ALLOWED\", \"TCP_RULE\", \"UDP_RULE\", \"DOHTTPS_RULE\"" + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "defaultDnsRuleNameUsed": { + "type": "boolean", + "description": "If set to true, the default DNS rule name is used for the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "applicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "DNS application groups to which the rule applies" + }, + "dnsGateway": { + "type": "object", + "description": "The DNS gateway used to redirect traffic, specified when the rule action is to redirect DNS request to an external DNS service." + }, + "zpaIpGroup": { + "type": "object", + "description": "The ZPA IP pool specified when the rule action is to resolve domain names of ZPA applications to an ephemeral IP address from a preconfigured IP pool." + }, + "ednsEcsObject": { + "type": "object", + "description": "EDNS ECS object which resolves DNS request" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "isWebEUNEnabled": { + "type": "boolean", + "description": "If set to true, Web EUN is enabled for the rule" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "firewalldnscontrolpolicies_Create", + "summary": "Create (Firewalldnscontrolpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule\nSupported Values: \"ALLOW\", \"BLOCK\", \"REDIR_REQ\", \"REDIR_RES\", \"REDIR_ZPA\", \"REDIR_REQ_DOH\", \"REDIR_REQ_KEEP_SENDER\", \"REDIR_REQ_TCP\", \"REDIR_REQ_UDP\",\"BLOCK_WITH_RESPONSE\"" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "redirectIp": { + "type": "string", + "description": "The IP address to which the traffic will be redirected to when the DNAT rule is triggered. If not set, no redirection is done to specific IP addresses." + }, + "blockResponseCode": { + "type": "string", + "description": "Specifies the DNS response code to be sent to the client when the action is configured to block and send response code" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin who last modified the rule" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses or FQDNs to which the rule applies. If not set, the rule is not restricted to a\nspecific destination IP address. Each IP entry can be a single IP address, CIDR (e.g., 10.10.33.0/24), or an IP range (e.g., 10.10.33.1-10.10.33.10)." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "applications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS tunnels and network applications to which the rule applies" + }, + "dnsRuleRequestTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS request types to which the rule applies" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rules applies\nSupported Values: \"ANY_RULE\", \"SMRULEF_CASCADING_ALLOWED\", \"TCP_RULE\", \"UDP_RULE\", \"DOHTTPS_RULE\"" + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "defaultDnsRuleNameUsed": { + "type": "boolean", + "description": "If set to true, the default DNS rule name is used for the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "applicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "DNS application groups to which the rule applies" + }, + "dnsGateway": { + "type": "object", + "description": "The DNS gateway used to redirect traffic, specified when the rule action is to redirect DNS request to an external DNS service." + }, + "zpaIpGroup": { + "type": "object", + "description": "The ZPA IP pool specified when the rule action is to resolve domain names of ZPA applications to an ephemeral IP address from a preconfigured IP pool." + }, + "ednsEcsObject": { + "type": "object", + "description": "EDNS ECS object which resolves DNS request" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "isWebEUNEnabled": { + "type": "boolean", + "description": "If set to true, Web EUN is enabled for the rule" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule\nSupported Values: \"ALLOW\", \"BLOCK\", \"REDIR_REQ\", \"REDIR_RES\", \"REDIR_ZPA\", \"REDIR_REQ_DOH\", \"REDIR_REQ_KEEP_SENDER\", \"REDIR_REQ_TCP\", \"REDIR_REQ_UDP\",\"BLOCK_WITH_RESPONSE\"" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "redirectIp": { + "type": "string", + "description": "The IP address to which the traffic will be redirected to when the DNAT rule is triggered. If not set, no redirection is done to specific IP addresses." + }, + "blockResponseCode": { + "type": "string", + "description": "Specifies the DNS response code to be sent to the client when the action is configured to block and send response code" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin who last modified the rule" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses or FQDNs to which the rule applies. If not set, the rule is not restricted to a\nspecific destination IP address. Each IP entry can be a single IP address, CIDR (e.g., 10.10.33.0/24), or an IP range (e.g., 10.10.33.1-10.10.33.10)." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "applications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS tunnels and network applications to which the rule applies" + }, + "dnsRuleRequestTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS request types to which the rule applies" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rules applies\nSupported Values: \"ANY_RULE\", \"SMRULEF_CASCADING_ALLOWED\", \"TCP_RULE\", \"UDP_RULE\", \"DOHTTPS_RULE\"" + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "defaultDnsRuleNameUsed": { + "type": "boolean", + "description": "If set to true, the default DNS rule name is used for the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "applicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "DNS application groups to which the rule applies" + }, + "dnsGateway": { + "type": "object", + "description": "The DNS gateway used to redirect traffic, specified when the rule action is to redirect DNS request to an external DNS service." + }, + "zpaIpGroup": { + "type": "object", + "description": "The ZPA IP pool specified when the rule action is to resolve domain names of ZPA applications to an ephemeral IP address from a preconfigured IP pool." + }, + "ednsEcsObject": { + "type": "object", + "description": "EDNS ECS object which resolves DNS request" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "isWebEUNEnabled": { + "type": "boolean", + "description": "If set to true, Web EUN is enabled for the rule" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + } + } + } + } + } + } + } + }, + "/zia/api/v1/firewallDnsRules/{id}": { + "get": { + "operationId": "firewalldnscontrolpolicies_Get", + "summary": "Get (Firewalldnscontrolpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule\nSupported Values: \"ALLOW\", \"BLOCK\", \"REDIR_REQ\", \"REDIR_RES\", \"REDIR_ZPA\", \"REDIR_REQ_DOH\", \"REDIR_REQ_KEEP_SENDER\", \"REDIR_REQ_TCP\", \"REDIR_REQ_UDP\",\"BLOCK_WITH_RESPONSE\"" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "redirectIp": { + "type": "string", + "description": "The IP address to which the traffic will be redirected to when the DNAT rule is triggered. If not set, no redirection is done to specific IP addresses." + }, + "blockResponseCode": { + "type": "string", + "description": "Specifies the DNS response code to be sent to the client when the action is configured to block and send response code" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin who last modified the rule" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses or FQDNs to which the rule applies. If not set, the rule is not restricted to a\nspecific destination IP address. Each IP entry can be a single IP address, CIDR (e.g., 10.10.33.0/24), or an IP range (e.g., 10.10.33.1-10.10.33.10)." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "applications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS tunnels and network applications to which the rule applies" + }, + "dnsRuleRequestTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS request types to which the rule applies" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rules applies\nSupported Values: \"ANY_RULE\", \"SMRULEF_CASCADING_ALLOWED\", \"TCP_RULE\", \"UDP_RULE\", \"DOHTTPS_RULE\"" + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "defaultDnsRuleNameUsed": { + "type": "boolean", + "description": "If set to true, the default DNS rule name is used for the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "applicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "DNS application groups to which the rule applies" + }, + "dnsGateway": { + "type": "object", + "description": "The DNS gateway used to redirect traffic, specified when the rule action is to redirect DNS request to an external DNS service." + }, + "zpaIpGroup": { + "type": "object", + "description": "The ZPA IP pool specified when the rule action is to resolve domain names of ZPA applications to an ephemeral IP address from a preconfigured IP pool." + }, + "ednsEcsObject": { + "type": "object", + "description": "EDNS ECS object which resolves DNS request" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "isWebEUNEnabled": { + "type": "boolean", + "description": "If set to true, Web EUN is enabled for the rule" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "firewalldnscontrolpolicies_Update", + "summary": "Update (Firewalldnscontrolpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule\nSupported Values: \"ALLOW\", \"BLOCK\", \"REDIR_REQ\", \"REDIR_RES\", \"REDIR_ZPA\", \"REDIR_REQ_DOH\", \"REDIR_REQ_KEEP_SENDER\", \"REDIR_REQ_TCP\", \"REDIR_REQ_UDP\",\"BLOCK_WITH_RESPONSE\"" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "redirectIp": { + "type": "string", + "description": "The IP address to which the traffic will be redirected to when the DNAT rule is triggered. If not set, no redirection is done to specific IP addresses." + }, + "blockResponseCode": { + "type": "string", + "description": "Specifies the DNS response code to be sent to the client when the action is configured to block and send response code" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin who last modified the rule" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses or FQDNs to which the rule applies. If not set, the rule is not restricted to a\nspecific destination IP address. Each IP entry can be a single IP address, CIDR (e.g., 10.10.33.0/24), or an IP range (e.g., 10.10.33.1-10.10.33.10)." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "applications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS tunnels and network applications to which the rule applies" + }, + "dnsRuleRequestTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS request types to which the rule applies" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rules applies\nSupported Values: \"ANY_RULE\", \"SMRULEF_CASCADING_ALLOWED\", \"TCP_RULE\", \"UDP_RULE\", \"DOHTTPS_RULE\"" + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "defaultDnsRuleNameUsed": { + "type": "boolean", + "description": "If set to true, the default DNS rule name is used for the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "applicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "DNS application groups to which the rule applies" + }, + "dnsGateway": { + "type": "object", + "description": "The DNS gateway used to redirect traffic, specified when the rule action is to redirect DNS request to an external DNS service." + }, + "zpaIpGroup": { + "type": "object", + "description": "The ZPA IP pool specified when the rule action is to resolve domain names of ZPA applications to an ephemeral IP address from a preconfigured IP pool." + }, + "ednsEcsObject": { + "type": "object", + "description": "EDNS ECS object which resolves DNS request" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "isWebEUNEnabled": { + "type": "boolean", + "description": "If set to true, Web EUN is enabled for the rule" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule\nSupported Values: \"ALLOW\", \"BLOCK\", \"REDIR_REQ\", \"REDIR_RES\", \"REDIR_ZPA\", \"REDIR_REQ_DOH\", \"REDIR_REQ_KEEP_SENDER\", \"REDIR_REQ_TCP\", \"REDIR_REQ_UDP\",\"BLOCK_WITH_RESPONSE\"" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "redirectIp": { + "type": "string", + "description": "The IP address to which the traffic will be redirected to when the DNAT rule is triggered. If not set, no redirection is done to specific IP addresses." + }, + "blockResponseCode": { + "type": "string", + "description": "Specifies the DNS response code to be sent to the client when the action is configured to block and send response code" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin who last modified the rule" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses or FQDNs to which the rule applies. If not set, the rule is not restricted to a\nspecific destination IP address. Each IP entry can be a single IP address, CIDR (e.g., 10.10.33.0/24), or an IP range (e.g., 10.10.33.1-10.10.33.10)." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "applications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS tunnels and network applications to which the rule applies" + }, + "dnsRuleRequestTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS request types to which the rule applies" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rules applies\nSupported Values: \"ANY_RULE\", \"SMRULEF_CASCADING_ALLOWED\", \"TCP_RULE\", \"UDP_RULE\", \"DOHTTPS_RULE\"" + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "defaultDnsRuleNameUsed": { + "type": "boolean", + "description": "If set to true, the default DNS rule name is used for the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "applicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "DNS application groups to which the rule applies" + }, + "dnsGateway": { + "type": "object", + "description": "The DNS gateway used to redirect traffic, specified when the rule action is to redirect DNS request to an external DNS service." + }, + "zpaIpGroup": { + "type": "object", + "description": "The ZPA IP pool specified when the rule action is to resolve domain names of ZPA applications to an ephemeral IP address from a preconfigured IP pool." + }, + "ednsEcsObject": { + "type": "object", + "description": "EDNS ECS object which resolves DNS request" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "isWebEUNEnabled": { + "type": "boolean", + "description": "If set to true, Web EUN is enabled for the rule" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + } + } + } + } + } + } + }, + "delete": { + "operationId": "firewalldnscontrolpolicies_Delete", + "summary": "Delete (Firewalldnscontrolpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule\nSupported Values: \"ALLOW\", \"BLOCK\", \"REDIR_REQ\", \"REDIR_RES\", \"REDIR_ZPA\", \"REDIR_REQ_DOH\", \"REDIR_REQ_KEEP_SENDER\", \"REDIR_REQ_TCP\", \"REDIR_REQ_UDP\",\"BLOCK_WITH_RESPONSE\"" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "redirectIp": { + "type": "string", + "description": "The IP address to which the traffic will be redirected to when the DNAT rule is triggered. If not set, no redirection is done to specific IP addresses." + }, + "blockResponseCode": { + "type": "string", + "description": "Specifies the DNS response code to be sent to the client when the action is configured to block and send response code" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin who last modified the rule" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses or FQDNs to which the rule applies. If not set, the rule is not restricted to a\nspecific destination IP address. Each IP entry can be a single IP address, CIDR (e.g., 10.10.33.0/24), or an IP range (e.g., 10.10.33.1-10.10.33.10)." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "applications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS tunnels and network applications to which the rule applies" + }, + "dnsRuleRequestTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "DNS request types to which the rule applies" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rules applies\nSupported Values: \"ANY_RULE\", \"SMRULEF_CASCADING_ALLOWED\", \"TCP_RULE\", \"UDP_RULE\", \"DOHTTPS_RULE\"" + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "defaultDnsRuleNameUsed": { + "type": "boolean", + "description": "If set to true, the default DNS rule name is used for the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "applicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "DNS application groups to which the rule applies" + }, + "dnsGateway": { + "type": "object", + "description": "The DNS gateway used to redirect traffic, specified when the rule action is to redirect DNS request to an external DNS service." + }, + "zpaIpGroup": { + "type": "object", + "description": "The ZPA IP pool specified when the rule action is to resolve domain names of ZPA applications to an ephemeral IP address from a preconfigured IP pool." + }, + "ednsEcsObject": { + "type": "object", + "description": "EDNS ECS object which resolves DNS request" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + }, + "isWebEUNEnabled": { + "type": "boolean", + "description": "If set to true, Web EUN is enabled for the rule" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/firewallFilteringRules": { + "post": { + "operationId": "firewallpolicies__filteringrules_Create", + "summary": "Create (Firewallpolicies / Filteringrules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "get": { + "operationId": "firewallpolicies__filteringrules_GetAll", + "summary": "GetAll (Firewallpolicies / Filteringrules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/firewallFilteringRules/{id}": { + "get": { + "operationId": "firewallpolicies__filteringrules_Get", + "summary": "Get (Firewallpolicies / Filteringrules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "firewallpolicies__filteringrules_Update", + "summary": "Update (Firewallpolicies / Filteringrules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "firewallpolicies__filteringrules_Delete", + "summary": "Delete (Firewallpolicies / Filteringrules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/firewallIpsRules": { + "get": { + "operationId": "ips_control_policies__ips_policies_GetByName", + "summary": "GetByName (Ips Control Policies / Ips Policies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall IPS policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall IPS policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "threatCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Advanced threat categories to which the rule applies" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "ips_control_policies__ips_policies_Create", + "summary": "Create (Ips Control Policies / Ips Policies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall IPS policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall IPS policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "threatCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Advanced threat categories to which the rule applies" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall IPS policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall IPS policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "threatCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Advanced threat categories to which the rule applies" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + } + }, + "/zia/api/v1/firewallIpsRules/{id}": { + "get": { + "operationId": "ips_control_policies__ips_policies_Get", + "summary": "Get (Ips Control Policies / Ips Policies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall IPS policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall IPS policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "threatCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Advanced threat categories to which the rule applies" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "ips_control_policies__ips_policies_Update", + "summary": "Update (Ips Control Policies / Ips Policies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall IPS policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall IPS policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "threatCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Advanced threat categories to which the rule applies" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall IPS policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall IPS policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "threatCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Advanced threat categories to which the rule applies" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "delete": { + "operationId": "ips_control_policies__ips_policies_Delete", + "summary": "Delete (Ips Control Policies / Ips Policies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall IPS policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall IPS policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The countries of origin of traffic for which the rule is applicable. If not set, the rule is not restricted to specific source countries." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "predefined": { + "type": "boolean", + "description": "A Boolean field that indicates that the rule is predefined by using a true value" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IPv6 address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IPv6 address group." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "threatCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Advanced threat categories to which the rule applies" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/forwardingRules": { + "get": { + "operationId": "forwarding_control_policy__forwarding_rules_GetByName", + "summary": "GetByName (Forwarding Control Policy / Forwarding Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the forwarding rule" + }, + "name": { + "type": "string", + "description": "The name of the forwarding rule" + }, + "description": { + "type": "string", + "description": "Additional information about the forwarding rule" + }, + "type": { + "type": "string", + "description": "The rule type selected from the available options\nSupported Values: \"FIREWALL\", \"DNS\", \"DNAT\", \"SNAT\", \"FORWARDING\", \"INTRUSION_PREVENTION\", \"EC_DNS\", \"EC_RDR\", \"EC_SELF\", \"DNS_RESPONSE\"" + }, + "order": { + "type": "integer", + "description": "The order of execution for the forwarding rule order" + }, + "rank": { + "type": "integer", + "description": "Admin rank assigned to the forwarding rule" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the locations to which the forwarding rule applies. If not set, the rule is applied to all locations." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the forwarding rule applies" + }, + "ecGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the Zscaler Cloud Connector groups to which the forwarding rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the departments to which the forwarding rule applies. If not set, the rule applies to all departments." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the user groups to which the forwarding rule applies. If not set, the rule applies to all groups." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the users to which the forwarding rule applies. If not set, user criteria is ignored during policy enforcement." + }, + "forwardMethod": { + "type": "string", + "description": "The type of traffic forwarding method selected from the available options\nSupported Values: \"INVALID\", \"DIRECT\", \"PROXYCHAIN\", \"ZIA\", \"ZPA\", \"ECZPA\", \"ECSELF\", \"DROP\"" + }, + "state": { + "type": "string", + "description": "Indicates whether the forwarding rule is enabled or disabled\nSupported Values: DISABLED and ENABLED" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. This field is not applicable for POST or PUT request." + }, + "lastModifiedBy": { + "type": "object", + "description": "Admin user that last modified the rule. This field is not applicable for POST or PUT request." + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses or FQDNs for which the rule is applicable. CIDR notation can be used for destination IP addresses.\n If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups, or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups to which the rule is applied.\nIf not set, the rule is not restricted to a specific destination IP address group." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services to which the rule applies. If not set, the rule is not restricted to a specific network service.\nNote: When the forwarding method is Proxy Chaining, only TCP-based network services are considered for policy match ." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service group to which the rule applies.\nIf not set, the rule is not restricted to a specific network service group." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application groups to which the rule applied.\nIf not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "proxyGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "dedicatedIPGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "zpaGateway": { + "type": "object", + "description": "The ZPA Server Group for which this rule is applicable.\nOnly the Server Groups that are associated with the selected Application Segments are allowed.\nThis field is applicable only for the ZPA forwarding method." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "zpaApplicationSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "description": { + "type": "string", + "description": "Additional information about the Application Segment" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + } + } + }, + "description": "List of ZPA Application Segments for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaApplicationSegmentGroups": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment Group" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment Group" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + }, + "zpaAppSegmentsCount": { + "type": "integer", + "description": "The number of ZPA Application Segments in the group" + } + } + }, + "description": "List of ZPA Application Segment Groups for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaBrokerRule": { + "type": "boolean", + "description": "The predefined ZPA Broker Rule generated by Zscaler (readonly: true)" + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "forwarding_control_policy__forwarding_rules_Create", + "summary": "Create (Forwarding Control Policy / Forwarding Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the forwarding rule" + }, + "name": { + "type": "string", + "description": "The name of the forwarding rule" + }, + "description": { + "type": "string", + "description": "Additional information about the forwarding rule" + }, + "type": { + "type": "string", + "description": "The rule type selected from the available options\nSupported Values: \"FIREWALL\", \"DNS\", \"DNAT\", \"SNAT\", \"FORWARDING\", \"INTRUSION_PREVENTION\", \"EC_DNS\", \"EC_RDR\", \"EC_SELF\", \"DNS_RESPONSE\"" + }, + "order": { + "type": "integer", + "description": "The order of execution for the forwarding rule order" + }, + "rank": { + "type": "integer", + "description": "Admin rank assigned to the forwarding rule" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the locations to which the forwarding rule applies. If not set, the rule is applied to all locations." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the forwarding rule applies" + }, + "ecGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the Zscaler Cloud Connector groups to which the forwarding rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the departments to which the forwarding rule applies. If not set, the rule applies to all departments." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the user groups to which the forwarding rule applies. If not set, the rule applies to all groups." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the users to which the forwarding rule applies. If not set, user criteria is ignored during policy enforcement." + }, + "forwardMethod": { + "type": "string", + "description": "The type of traffic forwarding method selected from the available options\nSupported Values: \"INVALID\", \"DIRECT\", \"PROXYCHAIN\", \"ZIA\", \"ZPA\", \"ECZPA\", \"ECSELF\", \"DROP\"" + }, + "state": { + "type": "string", + "description": "Indicates whether the forwarding rule is enabled or disabled\nSupported Values: DISABLED and ENABLED" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. This field is not applicable for POST or PUT request." + }, + "lastModifiedBy": { + "type": "object", + "description": "Admin user that last modified the rule. This field is not applicable for POST or PUT request." + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses or FQDNs for which the rule is applicable. CIDR notation can be used for destination IP addresses.\n If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups, or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups to which the rule is applied.\nIf not set, the rule is not restricted to a specific destination IP address group." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services to which the rule applies. If not set, the rule is not restricted to a specific network service.\nNote: When the forwarding method is Proxy Chaining, only TCP-based network services are considered for policy match ." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service group to which the rule applies.\nIf not set, the rule is not restricted to a specific network service group." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application groups to which the rule applied.\nIf not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "proxyGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "dedicatedIPGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "zpaGateway": { + "type": "object", + "description": "The ZPA Server Group for which this rule is applicable.\nOnly the Server Groups that are associated with the selected Application Segments are allowed.\nThis field is applicable only for the ZPA forwarding method." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "zpaApplicationSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "description": { + "type": "string", + "description": "Additional information about the Application Segment" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + } + } + }, + "description": "List of ZPA Application Segments for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaApplicationSegmentGroups": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment Group" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment Group" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + }, + "zpaAppSegmentsCount": { + "type": "integer", + "description": "The number of ZPA Application Segments in the group" + } + } + }, + "description": "List of ZPA Application Segment Groups for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaBrokerRule": { + "type": "boolean", + "description": "The predefined ZPA Broker Rule generated by Zscaler (readonly: true)" + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the forwarding rule" + }, + "name": { + "type": "string", + "description": "The name of the forwarding rule" + }, + "description": { + "type": "string", + "description": "Additional information about the forwarding rule" + }, + "type": { + "type": "string", + "description": "The rule type selected from the available options\nSupported Values: \"FIREWALL\", \"DNS\", \"DNAT\", \"SNAT\", \"FORWARDING\", \"INTRUSION_PREVENTION\", \"EC_DNS\", \"EC_RDR\", \"EC_SELF\", \"DNS_RESPONSE\"" + }, + "order": { + "type": "integer", + "description": "The order of execution for the forwarding rule order" + }, + "rank": { + "type": "integer", + "description": "Admin rank assigned to the forwarding rule" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the locations to which the forwarding rule applies. If not set, the rule is applied to all locations." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the forwarding rule applies" + }, + "ecGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the Zscaler Cloud Connector groups to which the forwarding rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the departments to which the forwarding rule applies. If not set, the rule applies to all departments." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the user groups to which the forwarding rule applies. If not set, the rule applies to all groups." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the users to which the forwarding rule applies. If not set, user criteria is ignored during policy enforcement." + }, + "forwardMethod": { + "type": "string", + "description": "The type of traffic forwarding method selected from the available options\nSupported Values: \"INVALID\", \"DIRECT\", \"PROXYCHAIN\", \"ZIA\", \"ZPA\", \"ECZPA\", \"ECSELF\", \"DROP\"" + }, + "state": { + "type": "string", + "description": "Indicates whether the forwarding rule is enabled or disabled\nSupported Values: DISABLED and ENABLED" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. This field is not applicable for POST or PUT request." + }, + "lastModifiedBy": { + "type": "object", + "description": "Admin user that last modified the rule. This field is not applicable for POST or PUT request." + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses or FQDNs for which the rule is applicable. CIDR notation can be used for destination IP addresses.\n If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups, or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups to which the rule is applied.\nIf not set, the rule is not restricted to a specific destination IP address group." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services to which the rule applies. If not set, the rule is not restricted to a specific network service.\nNote: When the forwarding method is Proxy Chaining, only TCP-based network services are considered for policy match ." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service group to which the rule applies.\nIf not set, the rule is not restricted to a specific network service group." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application groups to which the rule applied.\nIf not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "proxyGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "dedicatedIPGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "zpaGateway": { + "type": "object", + "description": "The ZPA Server Group for which this rule is applicable.\nOnly the Server Groups that are associated with the selected Application Segments are allowed.\nThis field is applicable only for the ZPA forwarding method." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "zpaApplicationSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "description": { + "type": "string", + "description": "Additional information about the Application Segment" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + } + } + }, + "description": "List of ZPA Application Segments for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaApplicationSegmentGroups": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment Group" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment Group" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + }, + "zpaAppSegmentsCount": { + "type": "integer", + "description": "The number of ZPA Application Segments in the group" + } + } + }, + "description": "List of ZPA Application Segment Groups for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaBrokerRule": { + "type": "boolean", + "description": "The predefined ZPA Broker Rule generated by Zscaler (readonly: true)" + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + } + } + } + } + } + } + } + }, + "/zia/api/v1/forwardingRules/{id}": { + "get": { + "operationId": "forwarding_control_policy__forwarding_rules_Get", + "summary": "Get (Forwarding Control Policy / Forwarding Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the forwarding rule" + }, + "name": { + "type": "string", + "description": "The name of the forwarding rule" + }, + "description": { + "type": "string", + "description": "Additional information about the forwarding rule" + }, + "type": { + "type": "string", + "description": "The rule type selected from the available options\nSupported Values: \"FIREWALL\", \"DNS\", \"DNAT\", \"SNAT\", \"FORWARDING\", \"INTRUSION_PREVENTION\", \"EC_DNS\", \"EC_RDR\", \"EC_SELF\", \"DNS_RESPONSE\"" + }, + "order": { + "type": "integer", + "description": "The order of execution for the forwarding rule order" + }, + "rank": { + "type": "integer", + "description": "Admin rank assigned to the forwarding rule" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the locations to which the forwarding rule applies. If not set, the rule is applied to all locations." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the forwarding rule applies" + }, + "ecGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the Zscaler Cloud Connector groups to which the forwarding rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the departments to which the forwarding rule applies. If not set, the rule applies to all departments." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the user groups to which the forwarding rule applies. If not set, the rule applies to all groups." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the users to which the forwarding rule applies. If not set, user criteria is ignored during policy enforcement." + }, + "forwardMethod": { + "type": "string", + "description": "The type of traffic forwarding method selected from the available options\nSupported Values: \"INVALID\", \"DIRECT\", \"PROXYCHAIN\", \"ZIA\", \"ZPA\", \"ECZPA\", \"ECSELF\", \"DROP\"" + }, + "state": { + "type": "string", + "description": "Indicates whether the forwarding rule is enabled or disabled\nSupported Values: DISABLED and ENABLED" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. This field is not applicable for POST or PUT request." + }, + "lastModifiedBy": { + "type": "object", + "description": "Admin user that last modified the rule. This field is not applicable for POST or PUT request." + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses or FQDNs for which the rule is applicable. CIDR notation can be used for destination IP addresses.\n If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups, or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups to which the rule is applied.\nIf not set, the rule is not restricted to a specific destination IP address group." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services to which the rule applies. If not set, the rule is not restricted to a specific network service.\nNote: When the forwarding method is Proxy Chaining, only TCP-based network services are considered for policy match ." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service group to which the rule applies.\nIf not set, the rule is not restricted to a specific network service group." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application groups to which the rule applied.\nIf not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "proxyGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "dedicatedIPGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "zpaGateway": { + "type": "object", + "description": "The ZPA Server Group for which this rule is applicable.\nOnly the Server Groups that are associated with the selected Application Segments are allowed.\nThis field is applicable only for the ZPA forwarding method." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "zpaApplicationSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "description": { + "type": "string", + "description": "Additional information about the Application Segment" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + } + } + }, + "description": "List of ZPA Application Segments for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaApplicationSegmentGroups": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment Group" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment Group" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + }, + "zpaAppSegmentsCount": { + "type": "integer", + "description": "The number of ZPA Application Segments in the group" + } + } + }, + "description": "List of ZPA Application Segment Groups for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaBrokerRule": { + "type": "boolean", + "description": "The predefined ZPA Broker Rule generated by Zscaler (readonly: true)" + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "forwarding_control_policy__forwarding_rules_Update", + "summary": "Update (Forwarding Control Policy / Forwarding Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the forwarding rule" + }, + "name": { + "type": "string", + "description": "The name of the forwarding rule" + }, + "description": { + "type": "string", + "description": "Additional information about the forwarding rule" + }, + "type": { + "type": "string", + "description": "The rule type selected from the available options\nSupported Values: \"FIREWALL\", \"DNS\", \"DNAT\", \"SNAT\", \"FORWARDING\", \"INTRUSION_PREVENTION\", \"EC_DNS\", \"EC_RDR\", \"EC_SELF\", \"DNS_RESPONSE\"" + }, + "order": { + "type": "integer", + "description": "The order of execution for the forwarding rule order" + }, + "rank": { + "type": "integer", + "description": "Admin rank assigned to the forwarding rule" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the locations to which the forwarding rule applies. If not set, the rule is applied to all locations." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the forwarding rule applies" + }, + "ecGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the Zscaler Cloud Connector groups to which the forwarding rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the departments to which the forwarding rule applies. If not set, the rule applies to all departments." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the user groups to which the forwarding rule applies. If not set, the rule applies to all groups." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the users to which the forwarding rule applies. If not set, user criteria is ignored during policy enforcement." + }, + "forwardMethod": { + "type": "string", + "description": "The type of traffic forwarding method selected from the available options\nSupported Values: \"INVALID\", \"DIRECT\", \"PROXYCHAIN\", \"ZIA\", \"ZPA\", \"ECZPA\", \"ECSELF\", \"DROP\"" + }, + "state": { + "type": "string", + "description": "Indicates whether the forwarding rule is enabled or disabled\nSupported Values: DISABLED and ENABLED" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. This field is not applicable for POST or PUT request." + }, + "lastModifiedBy": { + "type": "object", + "description": "Admin user that last modified the rule. This field is not applicable for POST or PUT request." + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses or FQDNs for which the rule is applicable. CIDR notation can be used for destination IP addresses.\n If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups, or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups to which the rule is applied.\nIf not set, the rule is not restricted to a specific destination IP address group." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services to which the rule applies. If not set, the rule is not restricted to a specific network service.\nNote: When the forwarding method is Proxy Chaining, only TCP-based network services are considered for policy match ." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service group to which the rule applies.\nIf not set, the rule is not restricted to a specific network service group." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application groups to which the rule applied.\nIf not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "proxyGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "dedicatedIPGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "zpaGateway": { + "type": "object", + "description": "The ZPA Server Group for which this rule is applicable.\nOnly the Server Groups that are associated with the selected Application Segments are allowed.\nThis field is applicable only for the ZPA forwarding method." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "zpaApplicationSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "description": { + "type": "string", + "description": "Additional information about the Application Segment" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + } + } + }, + "description": "List of ZPA Application Segments for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaApplicationSegmentGroups": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment Group" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment Group" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + }, + "zpaAppSegmentsCount": { + "type": "integer", + "description": "The number of ZPA Application Segments in the group" + } + } + }, + "description": "List of ZPA Application Segment Groups for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaBrokerRule": { + "type": "boolean", + "description": "The predefined ZPA Broker Rule generated by Zscaler (readonly: true)" + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the forwarding rule" + }, + "name": { + "type": "string", + "description": "The name of the forwarding rule" + }, + "description": { + "type": "string", + "description": "Additional information about the forwarding rule" + }, + "type": { + "type": "string", + "description": "The rule type selected from the available options\nSupported Values: \"FIREWALL\", \"DNS\", \"DNAT\", \"SNAT\", \"FORWARDING\", \"INTRUSION_PREVENTION\", \"EC_DNS\", \"EC_RDR\", \"EC_SELF\", \"DNS_RESPONSE\"" + }, + "order": { + "type": "integer", + "description": "The order of execution for the forwarding rule order" + }, + "rank": { + "type": "integer", + "description": "Admin rank assigned to the forwarding rule" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the locations to which the forwarding rule applies. If not set, the rule is applied to all locations." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the forwarding rule applies" + }, + "ecGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the Zscaler Cloud Connector groups to which the forwarding rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the departments to which the forwarding rule applies. If not set, the rule applies to all departments." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the user groups to which the forwarding rule applies. If not set, the rule applies to all groups." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the users to which the forwarding rule applies. If not set, user criteria is ignored during policy enforcement." + }, + "forwardMethod": { + "type": "string", + "description": "The type of traffic forwarding method selected from the available options\nSupported Values: \"INVALID\", \"DIRECT\", \"PROXYCHAIN\", \"ZIA\", \"ZPA\", \"ECZPA\", \"ECSELF\", \"DROP\"" + }, + "state": { + "type": "string", + "description": "Indicates whether the forwarding rule is enabled or disabled\nSupported Values: DISABLED and ENABLED" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. This field is not applicable for POST or PUT request." + }, + "lastModifiedBy": { + "type": "object", + "description": "Admin user that last modified the rule. This field is not applicable for POST or PUT request." + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses or FQDNs for which the rule is applicable. CIDR notation can be used for destination IP addresses.\n If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups, or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups to which the rule is applied.\nIf not set, the rule is not restricted to a specific destination IP address group." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services to which the rule applies. If not set, the rule is not restricted to a specific network service.\nNote: When the forwarding method is Proxy Chaining, only TCP-based network services are considered for policy match ." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service group to which the rule applies.\nIf not set, the rule is not restricted to a specific network service group." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application groups to which the rule applied.\nIf not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "proxyGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "dedicatedIPGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "zpaGateway": { + "type": "object", + "description": "The ZPA Server Group for which this rule is applicable.\nOnly the Server Groups that are associated with the selected Application Segments are allowed.\nThis field is applicable only for the ZPA forwarding method." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "zpaApplicationSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "description": { + "type": "string", + "description": "Additional information about the Application Segment" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + } + } + }, + "description": "List of ZPA Application Segments for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaApplicationSegmentGroups": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment Group" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment Group" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + }, + "zpaAppSegmentsCount": { + "type": "integer", + "description": "The number of ZPA Application Segments in the group" + } + } + }, + "description": "List of ZPA Application Segment Groups for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaBrokerRule": { + "type": "boolean", + "description": "The predefined ZPA Broker Rule generated by Zscaler (readonly: true)" + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + } + } + } + } + } + } + }, + "delete": { + "operationId": "forwarding_control_policy__forwarding_rules_Delete", + "summary": "Delete (Forwarding Control Policy / Forwarding Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the forwarding rule" + }, + "name": { + "type": "string", + "description": "The name of the forwarding rule" + }, + "description": { + "type": "string", + "description": "Additional information about the forwarding rule" + }, + "type": { + "type": "string", + "description": "The rule type selected from the available options\nSupported Values: \"FIREWALL\", \"DNS\", \"DNAT\", \"SNAT\", \"FORWARDING\", \"INTRUSION_PREVENTION\", \"EC_DNS\", \"EC_RDR\", \"EC_SELF\", \"DNS_RESPONSE\"" + }, + "order": { + "type": "integer", + "description": "The order of execution for the forwarding rule order" + }, + "rank": { + "type": "integer", + "description": "Admin rank assigned to the forwarding rule" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the locations to which the forwarding rule applies. If not set, the rule is applied to all locations." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the forwarding rule applies" + }, + "ecGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the Zscaler Cloud Connector groups to which the forwarding rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the departments to which the forwarding rule applies. If not set, the rule applies to all departments." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the user groups to which the forwarding rule applies. If not set, the rule applies to all groups." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the users to which the forwarding rule applies. If not set, user criteria is ignored during policy enforcement." + }, + "forwardMethod": { + "type": "string", + "description": "The type of traffic forwarding method selected from the available options\nSupported Values: \"INVALID\", \"DIRECT\", \"PROXYCHAIN\", \"ZIA\", \"ZPA\", \"ECZPA\", \"ECSELF\", \"DROP\"" + }, + "state": { + "type": "string", + "description": "Indicates whether the forwarding rule is enabled or disabled\nSupported Values: DISABLED and ENABLED" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. This field is not applicable for POST or PUT request." + }, + "lastModifiedBy": { + "type": "object", + "description": "Admin user that last modified the rule. This field is not applicable for POST or PUT request." + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses or FQDNs for which the rule is applicable. CIDR notation can be used for destination IP addresses.\n If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups, or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "resCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP categories to which the rule applies. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups to which the rule is applied.\nIf not set, the rule is not restricted to a specific destination IP address group." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services to which the rule applies. If not set, the rule is not restricted to a specific network service.\nNote: When the forwarding method is Proxy Chaining, only TCP-based network services are considered for policy match ." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service group to which the rule applies.\nIf not set, the rule is not restricted to a specific network service group." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application groups to which the rule applied.\nIf not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "proxyGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "dedicatedIPGateway": { + "type": "object", + "description": "The proxy gateway for which the rule is applicable. This field is applicable only for the Proxy Chaining forwarding method." + }, + "zpaGateway": { + "type": "object", + "description": "The ZPA Server Group for which this rule is applicable.\nOnly the Server Groups that are associated with the selected Application Segments are allowed.\nThis field is applicable only for the ZPA forwarding method." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "zpaApplicationSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "description": { + "type": "string", + "description": "Additional information about the Application Segment" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + } + } + }, + "description": "List of ZPA Application Segments for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaApplicationSegmentGroups": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Application Segment Group" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment Group" + }, + "zpaId": { + "type": "integer", + "description": "ID of the ZPA tenant where the Application Segment is configured" + }, + "deleted": { + "type": "boolean", + "description": "Indicates whether the ZPA Application Segment has been deleted" + }, + "zpaAppSegmentsCount": { + "type": "integer", + "description": "The number of ZPA Application Segments in the group" + } + } + }, + "description": "List of ZPA Application Segment Groups for which this rule is applicable.\nThis field is applicable only for the ECZPA forwarding method (used for Zscaler Cloud Connector)." + }, + "zpaBrokerRule": { + "type": "boolean", + "description": "The predefined ZPA Broker Rule generated by Zscaler (readonly: true)" + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/ftpSettings": { + "get": { + "operationId": "ftp_control_policy_GetFTPControlPolicy", + "summary": "GetFTPControlPolicy (Ftp Control Policy)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "ftpOverHttpEnabled": { + "type": "boolean", + "description": "Indicates whether to enable FTP over HTTP." + }, + "ftpEnabled": { + "type": "boolean", + "description": "Indicates whether to enable native FTP. When enabled, users can connect to native FTP sites and download files." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of URL categories that allow FTP traffic" + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Domains or URLs included for the FTP Control settings" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "ftp_control_policy_UpdateFTPControlPolicy", + "summary": "UpdateFTPControlPolicy (Ftp Control Policy)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "ftpOverHttpEnabled": { + "type": "boolean", + "description": "Indicates whether to enable FTP over HTTP." + }, + "ftpEnabled": { + "type": "boolean", + "description": "Indicates whether to enable native FTP. When enabled, users can connect to native FTP sites and download files." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of URL categories that allow FTP traffic" + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Domains or URLs included for the FTP Control settings" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "ftpOverHttpEnabled": { + "type": "boolean", + "description": "Indicates whether to enable FTP over HTTP." + }, + "ftpEnabled": { + "type": "boolean", + "description": "Indicates whether to enable native FTP. When enabled, users can connect to native FTP sites and download files." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of URL categories that allow FTP traffic" + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Domains or URLs included for the FTP Control settings" + } + } + } + } + } + } + } + }, + "/zia/api/v1/greTunnels": { + "get": { + "operationId": "trafficforwarding__gretunnels_GetByIPAddress", + "summary": "GetByIPAddress (Trafficforwarding / Gretunnels)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the static IP address that is associated to a GRE tunnel" + }, + "sourceIp": { + "type": "string", + "description": "The source IP address of the GRE tunnel. This is typically a static IP address in the organization or SD-WAN. This IP address must be provisioned within the Zscaler service using the /staticIP endpoint." + }, + "internalIpRange": { + "type": "string", + "description": "The start of the internal IP address in /29 CIDR range" + }, + "lastModificationTime": { + "type": "integer", + "description": "When the GRE tunnel information was last modified" + }, + "withinCountry": { + "type": "boolean", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those within the same country as the source IP address" + }, + "comment": { + "type": "string", + "description": "Additional information about this GRE tunnel" + }, + "ipUnnumbered": { + "type": "boolean", + "description": "This is required to support the automated SD-WAN provisioning of GRE tunnels, when set to true gre_tun_ip and gre_tun_id are set to null" + }, + "subcloud": { + "type": "string", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those part of the subcloud" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the GRE tunnel information last" + }, + "primaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The primary destination data center and virtual IP address (VIP) of the GRE tunnel" + }, + "secondaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The secondary destination data center and virtual IP address (VIP) of the GRE tunnel" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "trafficforwarding__gretunnels_CreateGreTunnels", + "summary": "CreateGreTunnels (Trafficforwarding / Gretunnels)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the static IP address that is associated to a GRE tunnel" + }, + "sourceIp": { + "type": "string", + "description": "The source IP address of the GRE tunnel. This is typically a static IP address in the organization or SD-WAN. This IP address must be provisioned within the Zscaler service using the /staticIP endpoint." + }, + "internalIpRange": { + "type": "string", + "description": "The start of the internal IP address in /29 CIDR range" + }, + "lastModificationTime": { + "type": "integer", + "description": "When the GRE tunnel information was last modified" + }, + "withinCountry": { + "type": "boolean", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those within the same country as the source IP address" + }, + "comment": { + "type": "string", + "description": "Additional information about this GRE tunnel" + }, + "ipUnnumbered": { + "type": "boolean", + "description": "This is required to support the automated SD-WAN provisioning of GRE tunnels, when set to true gre_tun_ip and gre_tun_id are set to null" + }, + "subcloud": { + "type": "string", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those part of the subcloud" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the GRE tunnel information last" + }, + "primaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The primary destination data center and virtual IP address (VIP) of the GRE tunnel" + }, + "secondaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The secondary destination data center and virtual IP address (VIP) of the GRE tunnel" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the static IP address that is associated to a GRE tunnel" + }, + "sourceIp": { + "type": "string", + "description": "The source IP address of the GRE tunnel. This is typically a static IP address in the organization or SD-WAN. This IP address must be provisioned within the Zscaler service using the /staticIP endpoint." + }, + "internalIpRange": { + "type": "string", + "description": "The start of the internal IP address in /29 CIDR range" + }, + "lastModificationTime": { + "type": "integer", + "description": "When the GRE tunnel information was last modified" + }, + "withinCountry": { + "type": "boolean", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those within the same country as the source IP address" + }, + "comment": { + "type": "string", + "description": "Additional information about this GRE tunnel" + }, + "ipUnnumbered": { + "type": "boolean", + "description": "This is required to support the automated SD-WAN provisioning of GRE tunnels, when set to true gre_tun_ip and gre_tun_id are set to null" + }, + "subcloud": { + "type": "string", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those part of the subcloud" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the GRE tunnel information last" + }, + "primaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The primary destination data center and virtual IP address (VIP) of the GRE tunnel" + }, + "secondaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The secondary destination data center and virtual IP address (VIP) of the GRE tunnel" + } + } + } + } + } + } + } + }, + "/zia/api/v1/greTunnels/availableInternalIpRanges": { + "get": { + "operationId": "trafficforwarding__greinternalipranges_GetGREInternalIPRange", + "summary": "GetGREInternalIPRange (Trafficforwarding / Greinternalipranges)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "startIPAddress": { + "type": "string", + "description": "Starting IP address in the range" + }, + "endIPAddress": { + "type": "string", + "description": "Ending IP address in the range" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/greTunnels/{id}": { + "get": { + "operationId": "trafficforwarding__gretunnels_GetGreTunnels", + "summary": "GetGreTunnels (Trafficforwarding / Gretunnels)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the static IP address that is associated to a GRE tunnel" + }, + "sourceIp": { + "type": "string", + "description": "The source IP address of the GRE tunnel. This is typically a static IP address in the organization or SD-WAN. This IP address must be provisioned within the Zscaler service using the /staticIP endpoint." + }, + "internalIpRange": { + "type": "string", + "description": "The start of the internal IP address in /29 CIDR range" + }, + "lastModificationTime": { + "type": "integer", + "description": "When the GRE tunnel information was last modified" + }, + "withinCountry": { + "type": "boolean", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those within the same country as the source IP address" + }, + "comment": { + "type": "string", + "description": "Additional information about this GRE tunnel" + }, + "ipUnnumbered": { + "type": "boolean", + "description": "This is required to support the automated SD-WAN provisioning of GRE tunnels, when set to true gre_tun_ip and gre_tun_id are set to null" + }, + "subcloud": { + "type": "string", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those part of the subcloud" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the GRE tunnel information last" + }, + "primaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The primary destination data center and virtual IP address (VIP) of the GRE tunnel" + }, + "secondaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The secondary destination data center and virtual IP address (VIP) of the GRE tunnel" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "trafficforwarding__gretunnels_UpdateGreTunnels", + "summary": "UpdateGreTunnels (Trafficforwarding / Gretunnels)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the static IP address that is associated to a GRE tunnel" + }, + "sourceIp": { + "type": "string", + "description": "The source IP address of the GRE tunnel. This is typically a static IP address in the organization or SD-WAN. This IP address must be provisioned within the Zscaler service using the /staticIP endpoint." + }, + "internalIpRange": { + "type": "string", + "description": "The start of the internal IP address in /29 CIDR range" + }, + "lastModificationTime": { + "type": "integer", + "description": "When the GRE tunnel information was last modified" + }, + "withinCountry": { + "type": "boolean", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those within the same country as the source IP address" + }, + "comment": { + "type": "string", + "description": "Additional information about this GRE tunnel" + }, + "ipUnnumbered": { + "type": "boolean", + "description": "This is required to support the automated SD-WAN provisioning of GRE tunnels, when set to true gre_tun_ip and gre_tun_id are set to null" + }, + "subcloud": { + "type": "string", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those part of the subcloud" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the GRE tunnel information last" + }, + "primaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The primary destination data center and virtual IP address (VIP) of the GRE tunnel" + }, + "secondaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The secondary destination data center and virtual IP address (VIP) of the GRE tunnel" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the static IP address that is associated to a GRE tunnel" + }, + "sourceIp": { + "type": "string", + "description": "The source IP address of the GRE tunnel. This is typically a static IP address in the organization or SD-WAN. This IP address must be provisioned within the Zscaler service using the /staticIP endpoint." + }, + "internalIpRange": { + "type": "string", + "description": "The start of the internal IP address in /29 CIDR range" + }, + "lastModificationTime": { + "type": "integer", + "description": "When the GRE tunnel information was last modified" + }, + "withinCountry": { + "type": "boolean", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those within the same country as the source IP address" + }, + "comment": { + "type": "string", + "description": "Additional information about this GRE tunnel" + }, + "ipUnnumbered": { + "type": "boolean", + "description": "This is required to support the automated SD-WAN provisioning of GRE tunnels, when set to true gre_tun_ip and gre_tun_id are set to null" + }, + "subcloud": { + "type": "string", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those part of the subcloud" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the GRE tunnel information last" + }, + "primaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The primary destination data center and virtual IP address (VIP) of the GRE tunnel" + }, + "secondaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The secondary destination data center and virtual IP address (VIP) of the GRE tunnel" + } + } + } + } + } + } + }, + "delete": { + "operationId": "trafficforwarding__gretunnels_DeleteGreTunnels", + "summary": "DeleteGreTunnels (Trafficforwarding / Gretunnels)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the static IP address that is associated to a GRE tunnel" + }, + "sourceIp": { + "type": "string", + "description": "The source IP address of the GRE tunnel. This is typically a static IP address in the organization or SD-WAN. This IP address must be provisioned within the Zscaler service using the /staticIP endpoint." + }, + "internalIpRange": { + "type": "string", + "description": "The start of the internal IP address in /29 CIDR range" + }, + "lastModificationTime": { + "type": "integer", + "description": "When the GRE tunnel information was last modified" + }, + "withinCountry": { + "type": "boolean", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those within the same country as the source IP address" + }, + "comment": { + "type": "string", + "description": "Additional information about this GRE tunnel" + }, + "ipUnnumbered": { + "type": "boolean", + "description": "This is required to support the automated SD-WAN provisioning of GRE tunnels, when set to true gre_tun_ip and gre_tun_id are set to null" + }, + "subcloud": { + "type": "string", + "description": "Restrict the data center virtual IP addresses (VIPs) only to those part of the subcloud" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the GRE tunnel information last" + }, + "primaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The primary destination data center and virtual IP address (VIP) of the GRE tunnel" + }, + "secondaryDestVip": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer of the GRE virtual IP address (VIP)" + }, + "virtualIp": { + "type": "string", + "description": "GRE cluster virtual IP address (VIP)" + }, + "privateServiceEdge": { + "type": "boolean", + "description": "Set to true if the virtual IP address (VIP) is a ZIA Private Service Edge" + }, + "datacenter": { + "type": "string", + "description": "Data center information" + }, + "latitude": { + "type": "number", + "description": "Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "city": { + "type": "string", + "description": "City information" + }, + "countryCode": { + "type": "string", + "description": "Country Code information" + }, + "region": { + "type": "string", + "description": "Region information" + } + }, + "description": "The secondary destination data center and virtual IP address (VIP) of the GRE tunnel" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/groups": { + "post": { + "operationId": "usermanagement__groups_Create", + "summary": "Create (Usermanagement / Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "get": { + "operationId": "usermanagement__groups_GetAllGroups", + "summary": "GetAllGroups (Usermanagement / Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/groups/{id}": { + "get": { + "operationId": "usermanagement__groups_GetGroups", + "summary": "GetGroups (Usermanagement / Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "usermanagement__groups_Update", + "summary": "Update (Usermanagement / Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "delete": { + "operationId": "usermanagement__groups_Delete", + "summary": "Delete (Usermanagement / Groups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/httpHeaderActionProfile": { + "post": { + "operationId": "http_header_control__http_header_action_profile_Create", + "summary": "Create (Http Header Control / Http Header Action Profile)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "description": { + "type": "string" + }, + "httpHeaderActionProfileKeys": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "key": { + "type": "string" + }, + "value": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "description": { + "type": "string" + }, + "httpHeaderActionProfileKeys": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "key": { + "type": "string" + }, + "value": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "get": { + "operationId": "http_header_control__http_header_action_profile_GetAll", + "summary": "GetAll (Http Header Control / Http Header Action Profile)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "description": { + "type": "string" + }, + "httpHeaderActionProfileKeys": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "key": { + "type": "string" + }, + "value": { + "type": "string" + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/httpHeaderActionProfile/{id}": { + "put": { + "operationId": "http_header_control__http_header_action_profile_Update", + "summary": "Update (Http Header Control / Http Header Action Profile)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "description": { + "type": "string" + }, + "httpHeaderActionProfileKeys": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "key": { + "type": "string" + }, + "value": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "description": { + "type": "string" + }, + "httpHeaderActionProfileKeys": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "key": { + "type": "string" + }, + "value": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "http_header_control__http_header_action_profile_Delete", + "summary": "Delete (Http Header Control / Http Header Action Profile)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "description": { + "type": "string" + }, + "httpHeaderActionProfileKeys": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "key": { + "type": "string" + }, + "value": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/httpHeaderProfile": { + "post": { + "operationId": "http_header_control__http_header_profile_Create", + "summary": "Create (Http Header Control / Http Header Profile)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "httpHeaderProfileCriteria": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "header": { + "type": "string" + }, + "operator": { + "type": "string" + }, + "categoryBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "cloudAppBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgent": { + "type": "string" + }, + "userAgentBitmap": { + "type": "string" + }, + "userAgentVersion": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "httpHeaderProfileCriteria": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "header": { + "type": "string" + }, + "operator": { + "type": "string" + }, + "categoryBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "cloudAppBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgent": { + "type": "string" + }, + "userAgentBitmap": { + "type": "string" + }, + "userAgentVersion": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "get": { + "operationId": "http_header_control__http_header_profile_GetAll", + "summary": "GetAll (Http Header Control / Http Header Profile)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "httpHeaderProfileCriteria": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "header": { + "type": "string" + }, + "operator": { + "type": "string" + }, + "categoryBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "cloudAppBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgent": { + "type": "string" + }, + "userAgentBitmap": { + "type": "string" + }, + "userAgentVersion": { + "type": "string" + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/httpHeaderProfile/{id}": { + "put": { + "operationId": "http_header_control__http_header_profile_Update", + "summary": "Update (Http Header Control / Http Header Profile)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "httpHeaderProfileCriteria": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "header": { + "type": "string" + }, + "operator": { + "type": "string" + }, + "categoryBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "cloudAppBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgent": { + "type": "string" + }, + "userAgentBitmap": { + "type": "string" + }, + "userAgentVersion": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "httpHeaderProfileCriteria": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "header": { + "type": "string" + }, + "operator": { + "type": "string" + }, + "categoryBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "cloudAppBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgent": { + "type": "string" + }, + "userAgentBitmap": { + "type": "string" + }, + "userAgentVersion": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "http_header_control__http_header_profile_Delete", + "summary": "Delete (Http Header Control / Http Header Profile)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "slotId": { + "type": "integer" + }, + "deleted": { + "type": "boolean" + }, + "profileReadyForUse": { + "type": "boolean" + }, + "httpHeaderProfileCriteria": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "header": { + "type": "string" + }, + "operator": { + "type": "string" + }, + "categoryBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "cloudAppBitmap": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgent": { + "type": "string" + }, + "userAgentBitmap": { + "type": "string" + }, + "userAgentVersion": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/icapServers": { + "get": { + "operationId": "dlp__dlp_icap_servers_GetByName", + "summary": "GetByName (Dlp / Dlp Icap Servers)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP server." + }, + "name": { + "type": "string", + "description": "The DLP server name." + }, + "url": { + "type": "string", + "description": "The DLP server URL." + }, + "status": { + "type": "string", + "description": "The DLP server status" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/icapServers/{id}": { + "get": { + "operationId": "dlp__dlp_icap_servers_Get", + "summary": "Get (Dlp / Dlp Icap Servers)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP server." + }, + "name": { + "type": "string", + "description": "The DLP server name." + }, + "url": { + "type": "string", + "description": "The DLP server URL." + }, + "status": { + "type": "string", + "description": "The DLP server status" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/idmprofile": { + "get": { + "operationId": "dlp__dlp_idm_profiles_GetByName", + "summary": "GetByName (Dlp / Dlp Idm Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "profileId": { + "type": "integer", + "description": "The identifier (1-64) for the IDM template (i.e., IDM profile) that is unique within the organization." + }, + "profileName": { + "type": "string", + "description": "The IDM template name, which is unique per Index Tool." + }, + "profileDesc": { + "type": "string", + "description": "The IDM template's description." + }, + "profileType": { + "type": "string", + "description": "The IDM template's type. Supported values are: \"LOCAL\", \"REMOTECRON\", and \"REMOTE\"" + }, + "host": { + "type": "string", + "description": "The fully qualified domain name (FQDN) of the IDM template's host machine." + }, + "port": { + "type": "integer", + "description": "The port number of the IDM template's host machine." + }, + "profileDirPath": { + "type": "string", + "description": "The IDM template's directory file path, where all files are present." + }, + "scheduleType": { + "type": "string", + "description": "The schedule type for the IDM template's schedule (i.e., Monthly, Weekly, Daily, or None). This attribute is required by PUT and POST requests." + }, + "scheduleDay": { + "type": "integer", + "description": "The day the IDM template is scheduled for. This attribute is required by PUT and POST requests." + }, + "scheduleDayOfMonth": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The day of the month that the IDM template is scheduled for. This attribute is required by PUT and POST requests, and when scheduleType is set to MONTHLY." + }, + "scheduleDayOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The day of the week the IDM template is scheduled for. This attribute is required by PUT and POST requests, and when scheduleType is set to WEEKLY." + }, + "scheduleTime": { + "type": "integer", + "description": "The time of the day (in minutes) that the IDM template is scheduled for. For example: at 3am= 180 mins. This attribute is required by PUT and POST requests." + }, + "scheduleDisabled": { + "type": "boolean", + "description": "If set to true, the schedule for the IDM template is temporarily in a disabled state. This attribute is required by PUT requests in order to disable or enable a schedule." + }, + "uploadStatus": { + "type": "string", + "description": "The status of the file uploaded to the Index Tool for the IDM template." + }, + "userName": { + "type": "string", + "description": "The username to be used on the IDM template's host machine." + }, + "version": { + "type": "integer", + "description": "The version number for the IDM template." + }, + "idmClient": { + "type": "object", + "description": "The unique identifer for the Index Tool that was used to create the IDM template. This attribute is required by POST requests, but ignored if provided in PUT requests." + }, + "volumeOfDocuments": { + "type": "integer", + "description": "The total volume of all the documents associated to the IDM template." + }, + "numDocuments": { + "type": "integer", + "description": "The number of documents associated to the IDM template." + }, + "lastModifiedTime": { + "type": "integer", + "description": "The date and time the IDM template was last modified." + }, + "modifiedBy": { + "type": "object", + "description": "The admin that modified the IDM template last." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/idmprofile/lite": { + "get": { + "operationId": "dlp__dlp_idm_profile_lite_GetDLPProfileLiteID", + "summary": "GetDLPProfileLiteID (Dlp / Dlp Idm Profile Lite)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "profileId": { + "type": "integer", + "description": "The identifier (1-64) for the IDM template (i.e., IDM profile) that is unique within the organization." + }, + "templateName": { + "type": "string", + "description": "The IDM template name." + }, + "clientVm": { + "type": "object", + "description": "The name of the Index Tool virtual machine (VM) that the IDM template belongs to." + }, + "numDocuments": { + "type": "integer", + "description": "The name of the Index Tool virtual machine (VM) that the IDM template belongs to." + }, + "lastModifiedTime": { + "type": "integer", + "description": "The date and time the IDM template was last modified." + }, + "modifiedBy": { + "type": "object", + "description": "The admin that modified the IDM template last." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/idmprofile/{id}": { + "get": { + "operationId": "dlp__dlp_idm_profiles_Get", + "summary": "Get (Dlp / Dlp Idm Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "profileId": { + "type": "integer", + "description": "The identifier (1-64) for the IDM template (i.e., IDM profile) that is unique within the organization." + }, + "profileName": { + "type": "string", + "description": "The IDM template name, which is unique per Index Tool." + }, + "profileDesc": { + "type": "string", + "description": "The IDM template's description." + }, + "profileType": { + "type": "string", + "description": "The IDM template's type. Supported values are: \"LOCAL\", \"REMOTECRON\", and \"REMOTE\"" + }, + "host": { + "type": "string", + "description": "The fully qualified domain name (FQDN) of the IDM template's host machine." + }, + "port": { + "type": "integer", + "description": "The port number of the IDM template's host machine." + }, + "profileDirPath": { + "type": "string", + "description": "The IDM template's directory file path, where all files are present." + }, + "scheduleType": { + "type": "string", + "description": "The schedule type for the IDM template's schedule (i.e., Monthly, Weekly, Daily, or None). This attribute is required by PUT and POST requests." + }, + "scheduleDay": { + "type": "integer", + "description": "The day the IDM template is scheduled for. This attribute is required by PUT and POST requests." + }, + "scheduleDayOfMonth": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The day of the month that the IDM template is scheduled for. This attribute is required by PUT and POST requests, and when scheduleType is set to MONTHLY." + }, + "scheduleDayOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The day of the week the IDM template is scheduled for. This attribute is required by PUT and POST requests, and when scheduleType is set to WEEKLY." + }, + "scheduleTime": { + "type": "integer", + "description": "The time of the day (in minutes) that the IDM template is scheduled for. For example: at 3am= 180 mins. This attribute is required by PUT and POST requests." + }, + "scheduleDisabled": { + "type": "boolean", + "description": "If set to true, the schedule for the IDM template is temporarily in a disabled state. This attribute is required by PUT requests in order to disable or enable a schedule." + }, + "uploadStatus": { + "type": "string", + "description": "The status of the file uploaded to the Index Tool for the IDM template." + }, + "userName": { + "type": "string", + "description": "The username to be used on the IDM template's host machine." + }, + "version": { + "type": "integer", + "description": "The version number for the IDM template." + }, + "idmClient": { + "type": "object", + "description": "The unique identifer for the Index Tool that was used to create the IDM template. This attribute is required by POST requests, but ignored if provided in PUT requests." + }, + "volumeOfDocuments": { + "type": "integer", + "description": "The total volume of all the documents associated to the IDM template." + }, + "numDocuments": { + "type": "integer", + "description": "The number of documents associated to the IDM template." + }, + "lastModifiedTime": { + "type": "integer", + "description": "The date and time the IDM template was last modified." + }, + "modifiedBy": { + "type": "object", + "description": "The admin that modified the IDM template last." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/incidentReceiverServers": { + "get": { + "operationId": "dlp__dlp_incident_receiver_servers_GetByName", + "summary": "GetByName (Dlp / Dlp Incident Receiver Servers)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the Incident Receiver." + }, + "name": { + "type": "string", + "description": "The Incident Receiver server name." + }, + "url": { + "type": "string", + "description": "The Incident Receiver server URL." + }, + "status": { + "type": "string", + "description": "The status of the Incident Receiver." + }, + "flags": { + "type": "integer", + "description": "The Incident Receiver server flag." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/incidentReceiverServers/{id}": { + "get": { + "operationId": "dlp__dlp_incident_receiver_servers_Get", + "summary": "Get (Dlp / Dlp Incident Receiver Servers)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the Incident Receiver." + }, + "name": { + "type": "string", + "description": "The Incident Receiver server name." + }, + "url": { + "type": "string", + "description": "The Incident Receiver server URL." + }, + "status": { + "type": "string", + "description": "The status of the Incident Receiver." + }, + "flags": { + "type": "integer", + "description": "The Incident Receiver server flag." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/integrationPartners": { + "get": { + "operationId": "partner_integrations_GetPartnerIntegrations", + "summary": "GetPartnerIntegrations (Partner Integrations)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "disabled": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "partner_integrations_AcceptCrowdstrikeEndpointList", + "summary": "AcceptCrowdstrikeEndpointList (Partner Integrations)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "disabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "disabled": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "/zia/api/v1/integrationPartners/{id}": { + "get": { + "operationId": "partner_integrations_GetReportMD5Hash", + "summary": "GetReportMD5Hash (Partner Integrations)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "disabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/intermediateCaCertificate": { + "get": { + "operationId": "intermediatecacertificates_GetByName", + "summary": "GetByName (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "intermediatecacertificates_CreateIntCACertificate", + "summary": "CreateIntCACertificate (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + } + }, + "/zia/api/v1/intermediateCaCertificate/downloadAttestation/{id}": { + "get": { + "operationId": "intermediatecacertificates_GetDownloadAttestation", + "summary": "GetDownloadAttestation (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/intermediateCaCertificate/downloadCsr/{id}": { + "get": { + "operationId": "intermediatecacertificates_GetDownloadCSR", + "summary": "GetDownloadCSR (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/intermediateCaCertificate/downloadPublicKey/{id}": { + "get": { + "operationId": "intermediatecacertificates_GetDownloadPublicKey", + "summary": "GetDownloadPublicKey (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/intermediateCaCertificate/finalizeCert": { + "post": { + "operationId": "intermediatecacertificates_CreateIntCAFinalizeCert", + "summary": "CreateIntCAFinalizeCert (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + } + }, + "/zia/api/v1/intermediateCaCertificate/generateCsr": { + "post": { + "operationId": "intermediatecacertificates_CreateIntCAGenerateCSR", + "summary": "CreateIntCAGenerateCSR (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + } + }, + "/zia/api/v1/intermediateCaCertificate/keyPair": { + "post": { + "operationId": "intermediatecacertificates_CreateIntCAKeyPair", + "summary": "CreateIntCAKeyPair (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + } + }, + "/zia/api/v1/intermediateCaCertificate/makeDefault/{id}": { + "put": { + "operationId": "intermediatecacertificates_UpdateMakeDefault", + "summary": "UpdateMakeDefault (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + } + }, + "/zia/api/v1/intermediateCaCertificate/readyToUse": { + "get": { + "operationId": "intermediatecacertificates_GetIntCAReadyToUse", + "summary": "GetIntCAReadyToUse (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/intermediateCaCertificate/showCert/{id}": { + "get": { + "operationId": "intermediatecacertificates_GetShowCert", + "summary": "GetShowCert (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/intermediateCaCertificate/showCsr/{id}": { + "get": { + "operationId": "intermediatecacertificates_GetShowCSR", + "summary": "GetShowCSR (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/intermediateCaCertificate/uploadCert": { + "post": { + "operationId": "intermediatecacertificates_CreateUploadCert", + "summary": "CreateUploadCert (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + } + }, + "/zia/api/v1/intermediateCaCertificate/uploadCertChain": { + "post": { + "operationId": "intermediatecacertificates_CreateUploadCertChain", + "summary": "CreateUploadCertChain (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + } + }, + "/zia/api/v1/intermediateCaCertificate/verifyKeyAttestation": { + "post": { + "operationId": "intermediatecacertificates_CreateVerifyKeyAttestation", + "summary": "CreateVerifyKeyAttestation (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + } + }, + "/zia/api/v1/intermediateCaCertificate/{id}": { + "get": { + "operationId": "intermediatecacertificates_GetCertificate", + "summary": "GetCertificate (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "intermediatecacertificates_Update", + "summary": "Update (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "delete": { + "operationId": "intermediatecacertificates_Delete", + "summary": "Delete (Intermediatecacertificates)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the intermediate CA certificat" + }, + "name": { + "type": "string", + "description": "Name of the intermediate CA certificate" + }, + "description": { + "type": "string", + "description": "Description for the intermediate CA certificate" + }, + "type": { + "type": "string", + "description": "Type of the intermediate CA certificate. Available types: Zscaler\u2019s intermediate CA certificate (provided by Zscaler), custom intermediate certificate with software protection, and custom intermediate certificate with cloud HSM protection." + }, + "region": { + "type": "string", + "description": "Location of the HSM resources. Required for custom intermediate CA certificates with cloud HSM protection" + }, + "status": { + "type": "string", + "description": "Determines whether the intermediate CA certificate is enabled or disabled for SSL inspection. Subscription to cloud HSM protection allows a maximum of four active certificates for SSL inspection at a time, whereas software protection subscription allows only one active certificate" + }, + "defaultCertificate": { + "type": "boolean", + "description": "If set to true, the intermediate CA certificate is the default intermediate certificate. Only one certificate can be marked as the default intermediate certificate at a time" + }, + "certStartDate": { + "type": "integer", + "description": "Start date of the intermediate CA certificate\u2019s validity period" + }, + "certExpDate": { + "type": "integer", + "description": "Expiration date of the intermediate CA certificate\u2019s validity period" + }, + "currentState": { + "type": "string", + "description": "Tracks the progress of the intermediate CA certificate in the configuration workflow" + }, + "publicKey": { + "type": "string", + "description": "Public key in the HSM key pair generated for the intermediate CA certificate" + }, + "keyGenerationTime": { + "type": "integer", + "description": "Timestamp when the HSM key was generated" + }, + "hsmAttestationVerifiedTime": { + "type": "integer", + "description": "Timestamp when the attestation for the HSM key was verified" + }, + "csrFileName": { + "type": "string", + "description": "Certificate Signing Request (CSR) file name" + }, + "csrGenerationTime": { + "type": "integer", + "description": "Timestamp when the Certificate Signing Request (CSR) was generated" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/iotDiscovery/categories": { + "get": { + "operationId": "iotreport_GetIOTCategories", + "summary": "GetIOTCategories (Iotreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "uuid": { + "type": "string", + "description": "The universally unique identifier (UUID) of the item." + }, + "name": { + "type": "string", + "description": "The name of the item." + }, + "parent_uuid": { + "type": "string", + "description": "The parent UUID of the item. This field is not applicable for the device types endpoint." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/iotDiscovery/classifications": { + "get": { + "operationId": "iotreport_GetIOTClassifications", + "summary": "GetIOTClassifications (Iotreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "uuid": { + "type": "string", + "description": "The universally unique identifier (UUID) of the item." + }, + "name": { + "type": "string", + "description": "The name of the item." + }, + "parent_uuid": { + "type": "string", + "description": "The parent UUID of the item. This field is not applicable for the device types endpoint." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/iotDiscovery/deviceList": { + "get": { + "operationId": "iotreport_GetIOTDeviceList", + "summary": "GetIOTDeviceList (Iotreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "uuid": { + "type": "string", + "description": "The universally unique identifier (UUID) of the item." + }, + "name": { + "type": "string", + "description": "The name of the item." + }, + "parent_uuid": { + "type": "string", + "description": "The parent UUID of the item. This field is not applicable for the device types endpoint." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/iotDiscovery/deviceTypes": { + "get": { + "operationId": "iotreport_GetDeviceTypes", + "summary": "GetDeviceTypes (Iotreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "uuid": { + "type": "string", + "description": "The universally unique identifier (UUID) of the item." + }, + "name": { + "type": "string", + "description": "The name of the item." + }, + "parent_uuid": { + "type": "string", + "description": "The parent UUID of the item. This field is not applicable for the device types endpoint." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/ipDestinationGroups": { + "post": { + "operationId": "firewallpolicies__ipdestinationgroups_Create", + "summary": "Create (Firewallpolicies / Ipdestinationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "get": { + "operationId": "firewallpolicies__ipdestinationgroups_GetAll", + "summary": "GetAll (Firewallpolicies / Ipdestinationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/ipDestinationGroups/{id}": { + "get": { + "operationId": "firewallpolicies__ipdestinationgroups_Get", + "summary": "Get (Firewallpolicies / Ipdestinationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "firewallpolicies__ipdestinationgroups_Update", + "summary": "Update (Firewallpolicies / Ipdestinationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "delete": { + "operationId": "firewallpolicies__ipdestinationgroups_Delete", + "summary": "Delete (Firewallpolicies / Ipdestinationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/ipSourceGroups": { + "get": { + "operationId": "firewallpolicies__ipsourcegroups_GetByName", + "summary": "GetByName (Firewallpolicies / Ipsourcegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "firewallpolicies__ipsourcegroups_Create", + "summary": "Create (Firewallpolicies / Ipsourcegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + } + }, + "/zia/api/v1/ipSourceGroups/{id}": { + "get": { + "operationId": "firewallpolicies__ipsourcegroups_Get", + "summary": "Get (Firewallpolicies / Ipsourcegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "firewallpolicies__ipsourcegroups_Update", + "summary": "Update (Firewallpolicies / Ipsourcegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "delete": { + "operationId": "firewallpolicies__ipsourcegroups_Delete", + "summary": "Delete (Firewallpolicies / Ipsourcegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/ipsCategories": { + "get": { + "operationId": "ips_control_policies__ips_signature_rules_GetIPSCategories", + "summary": "GetIPSCategories (Ips Control Policies / Ips Signature Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the custom IPS signature rule" + }, + "name": { + "type": "string", + "description": "Custom IPS signature rule name" + }, + "ruleText": { + "type": "string", + "description": "The rule text in Suricata/Snort syntax that defines the custom IPS signature" + }, + "description": { + "type": "string", + "description": "Additional information about the custom signature rule" + }, + "category": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the threat category" + }, + "name": { + "type": "string", + "description": "Name of the threat category (e.g., ADVANCED_SECURITY)" + }, + "isNameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is a localization tag rather than a literal label" + } + }, + "description": "The threat category that is assigned to the custom signature rule" + }, + "enabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is enabled\nand is ready to be used in IPS Control rules via the assigned threat category" + }, + "deleted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is deleted" + }, + "promoteTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule was promoted; 0 if not yet promoted" + }, + "ruleTextModTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule text was last modified" + }, + "dynamicValidationSubmitted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was submitted for dynamic validation" + }, + "dynamicValidationRejected": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation rejected the rule" + }, + "dynamicValidationSucceeded": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation succeeded for the rule" + }, + "disabledFromZSCM": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was disabled from Zscaler Cloud Management" + }, + "dynamicValRejectCode": { + "type": "integer", + "description": "Reject code returned by dynamic validation" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/ipsSignatureRules": { + "post": { + "operationId": "ips_control_policies__ips_signature_rules_Create", + "summary": "Create (Ips Control Policies / Ips Signature Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the custom IPS signature rule" + }, + "name": { + "type": "string", + "description": "Custom IPS signature rule name" + }, + "ruleText": { + "type": "string", + "description": "The rule text in Suricata/Snort syntax that defines the custom IPS signature" + }, + "description": { + "type": "string", + "description": "Additional information about the custom signature rule" + }, + "category": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the threat category" + }, + "name": { + "type": "string", + "description": "Name of the threat category (e.g., ADVANCED_SECURITY)" + }, + "isNameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is a localization tag rather than a literal label" + } + }, + "description": "The threat category that is assigned to the custom signature rule" + }, + "enabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is enabled\nand is ready to be used in IPS Control rules via the assigned threat category" + }, + "deleted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is deleted" + }, + "promoteTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule was promoted; 0 if not yet promoted" + }, + "ruleTextModTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule text was last modified" + }, + "dynamicValidationSubmitted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was submitted for dynamic validation" + }, + "dynamicValidationRejected": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation rejected the rule" + }, + "dynamicValidationSucceeded": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation succeeded for the rule" + }, + "disabledFromZSCM": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was disabled from Zscaler Cloud Management" + }, + "dynamicValRejectCode": { + "type": "integer", + "description": "Reject code returned by dynamic validation" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the custom IPS signature rule" + }, + "name": { + "type": "string", + "description": "Custom IPS signature rule name" + }, + "ruleText": { + "type": "string", + "description": "The rule text in Suricata/Snort syntax that defines the custom IPS signature" + }, + "description": { + "type": "string", + "description": "Additional information about the custom signature rule" + }, + "category": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the threat category" + }, + "name": { + "type": "string", + "description": "Name of the threat category (e.g., ADVANCED_SECURITY)" + }, + "isNameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is a localization tag rather than a literal label" + } + }, + "description": "The threat category that is assigned to the custom signature rule" + }, + "enabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is enabled\nand is ready to be used in IPS Control rules via the assigned threat category" + }, + "deleted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is deleted" + }, + "promoteTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule was promoted; 0 if not yet promoted" + }, + "ruleTextModTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule text was last modified" + }, + "dynamicValidationSubmitted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was submitted for dynamic validation" + }, + "dynamicValidationRejected": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation rejected the rule" + }, + "dynamicValidationSucceeded": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation succeeded for the rule" + }, + "disabledFromZSCM": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was disabled from Zscaler Cloud Management" + }, + "dynamicValRejectCode": { + "type": "integer", + "description": "Reject code returned by dynamic validation" + } + } + } + } + } + } + }, + "get": { + "operationId": "ips_control_policies__ips_signature_rules_GetAll", + "summary": "GetAll (Ips Control Policies / Ips Signature Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the custom IPS signature rule" + }, + "name": { + "type": "string", + "description": "Custom IPS signature rule name" + }, + "ruleText": { + "type": "string", + "description": "The rule text in Suricata/Snort syntax that defines the custom IPS signature" + }, + "description": { + "type": "string", + "description": "Additional information about the custom signature rule" + }, + "category": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the threat category" + }, + "name": { + "type": "string", + "description": "Name of the threat category (e.g., ADVANCED_SECURITY)" + }, + "isNameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is a localization tag rather than a literal label" + } + }, + "description": "The threat category that is assigned to the custom signature rule" + }, + "enabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is enabled\nand is ready to be used in IPS Control rules via the assigned threat category" + }, + "deleted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is deleted" + }, + "promoteTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule was promoted; 0 if not yet promoted" + }, + "ruleTextModTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule text was last modified" + }, + "dynamicValidationSubmitted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was submitted for dynamic validation" + }, + "dynamicValidationRejected": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation rejected the rule" + }, + "dynamicValidationSucceeded": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation succeeded for the rule" + }, + "disabledFromZSCM": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was disabled from Zscaler Cloud Management" + }, + "dynamicValRejectCode": { + "type": "integer", + "description": "Reject code returned by dynamic validation" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/ipsSignatureRules/{id}": { + "get": { + "operationId": "ips_control_policies__ips_signature_rules_Get", + "summary": "Get (Ips Control Policies / Ips Signature Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the custom IPS signature rule" + }, + "name": { + "type": "string", + "description": "Custom IPS signature rule name" + }, + "ruleText": { + "type": "string", + "description": "The rule text in Suricata/Snort syntax that defines the custom IPS signature" + }, + "description": { + "type": "string", + "description": "Additional information about the custom signature rule" + }, + "category": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the threat category" + }, + "name": { + "type": "string", + "description": "Name of the threat category (e.g., ADVANCED_SECURITY)" + }, + "isNameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is a localization tag rather than a literal label" + } + }, + "description": "The threat category that is assigned to the custom signature rule" + }, + "enabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is enabled\nand is ready to be used in IPS Control rules via the assigned threat category" + }, + "deleted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is deleted" + }, + "promoteTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule was promoted; 0 if not yet promoted" + }, + "ruleTextModTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule text was last modified" + }, + "dynamicValidationSubmitted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was submitted for dynamic validation" + }, + "dynamicValidationRejected": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation rejected the rule" + }, + "dynamicValidationSucceeded": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation succeeded for the rule" + }, + "disabledFromZSCM": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was disabled from Zscaler Cloud Management" + }, + "dynamicValRejectCode": { + "type": "integer", + "description": "Reject code returned by dynamic validation" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "ips_control_policies__ips_signature_rules_Update", + "summary": "Update (Ips Control Policies / Ips Signature Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the custom IPS signature rule" + }, + "name": { + "type": "string", + "description": "Custom IPS signature rule name" + }, + "ruleText": { + "type": "string", + "description": "The rule text in Suricata/Snort syntax that defines the custom IPS signature" + }, + "description": { + "type": "string", + "description": "Additional information about the custom signature rule" + }, + "category": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the threat category" + }, + "name": { + "type": "string", + "description": "Name of the threat category (e.g., ADVANCED_SECURITY)" + }, + "isNameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is a localization tag rather than a literal label" + } + }, + "description": "The threat category that is assigned to the custom signature rule" + }, + "enabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is enabled\nand is ready to be used in IPS Control rules via the assigned threat category" + }, + "deleted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is deleted" + }, + "promoteTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule was promoted; 0 if not yet promoted" + }, + "ruleTextModTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule text was last modified" + }, + "dynamicValidationSubmitted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was submitted for dynamic validation" + }, + "dynamicValidationRejected": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation rejected the rule" + }, + "dynamicValidationSucceeded": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation succeeded for the rule" + }, + "disabledFromZSCM": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was disabled from Zscaler Cloud Management" + }, + "dynamicValRejectCode": { + "type": "integer", + "description": "Reject code returned by dynamic validation" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the custom IPS signature rule" + }, + "name": { + "type": "string", + "description": "Custom IPS signature rule name" + }, + "ruleText": { + "type": "string", + "description": "The rule text in Suricata/Snort syntax that defines the custom IPS signature" + }, + "description": { + "type": "string", + "description": "Additional information about the custom signature rule" + }, + "category": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the threat category" + }, + "name": { + "type": "string", + "description": "Name of the threat category (e.g., ADVANCED_SECURITY)" + }, + "isNameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is a localization tag rather than a literal label" + } + }, + "description": "The threat category that is assigned to the custom signature rule" + }, + "enabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is enabled\nand is ready to be used in IPS Control rules via the assigned threat category" + }, + "deleted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is deleted" + }, + "promoteTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule was promoted; 0 if not yet promoted" + }, + "ruleTextModTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule text was last modified" + }, + "dynamicValidationSubmitted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was submitted for dynamic validation" + }, + "dynamicValidationRejected": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation rejected the rule" + }, + "dynamicValidationSucceeded": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation succeeded for the rule" + }, + "disabledFromZSCM": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was disabled from Zscaler Cloud Management" + }, + "dynamicValRejectCode": { + "type": "integer", + "description": "Reject code returned by dynamic validation" + } + } + } + } + } + } + }, + "delete": { + "operationId": "ips_control_policies__ips_signature_rules_Delete", + "summary": "Delete (Ips Control Policies / Ips Signature Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the custom IPS signature rule" + }, + "name": { + "type": "string", + "description": "Custom IPS signature rule name" + }, + "ruleText": { + "type": "string", + "description": "The rule text in Suricata/Snort syntax that defines the custom IPS signature" + }, + "description": { + "type": "string", + "description": "Additional information about the custom signature rule" + }, + "category": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the threat category" + }, + "name": { + "type": "string", + "description": "Name of the threat category (e.g., ADVANCED_SECURITY)" + }, + "isNameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is a localization tag rather than a literal label" + } + }, + "description": "The threat category that is assigned to the custom signature rule" + }, + "enabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is enabled\nand is ready to be used in IPS Control rules via the assigned threat category" + }, + "deleted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the custom signature rule is deleted" + }, + "promoteTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule was promoted; 0 if not yet promoted" + }, + "ruleTextModTime": { + "type": "integer", + "description": "Unix timestamp (in seconds) when the rule text was last modified" + }, + "dynamicValidationSubmitted": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was submitted for dynamic validation" + }, + "dynamicValidationRejected": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation rejected the rule" + }, + "dynamicValidationSucceeded": { + "type": "boolean", + "description": "A Boolean value that indicates whether dynamic validation succeeded for the rule" + }, + "disabledFromZSCM": { + "type": "boolean", + "description": "A Boolean value that indicates whether the rule was disabled from Zscaler Cloud Management" + }, + "dynamicValRejectCode": { + "type": "integer", + "description": "Reject code returned by dynamic validation" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/ipv6config": { + "get": { + "operationId": "trafficforwarding__ipv6_config_GetIPv6Config", + "summary": "GetIPv6Config (Trafficforwarding / Ipv6 Config)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "ipV6Enabled": { + "type": "boolean" + }, + "natPrefixes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "prefixMask": { + "type": "string" + }, + "dnsPrefix": { + "type": "boolean" + }, + "nonEditable": { + "type": "boolean" + } + } + } + }, + "dnsPrefix": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/isolationVotiroCdr": { + "get": { + "operationId": "votiro_cdr_GetCDRPolicies", + "summary": "GetCDRPolicies (Votiro Cdr)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "integer" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/locations": { + "get": { + "operationId": "location__locationmanagement_GetLocationByName", + "summary": "GetLocationByName (Location / Locationmanagement)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "location__locationmanagement_Create", + "summary": "Create (Location / Locationmanagement)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/locations/groups": { + "get": { + "operationId": "location__locationgroups_GetGroupType", + "summary": "GetGroupType (Location / Locationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the location group" + }, + "name": { + "type": "string", + "description": "Location group name" + }, + "deleted": { + "type": "boolean", + "description": "Indicates the location group was deleted" + }, + "groupType": { + "type": "string", + "description": "The location group's type (i.e., Static or Dynamic)" + }, + "dynamicLocationGroupCriteria": { + "type": "object", + "properties": { + "name": { + "type": "object", + "properties": { + "matchString": { + "type": "string", + "description": "String value to be matched or partially matched" + }, + "matchType": { + "type": "string", + "description": "Operator that performs match action" + } + }, + "description": "A sub-string to match location name. Valid operators are contains, starts with, and ends with\"," + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "One or more countries from a predefined set" + }, + "city": { + "type": "object", + "properties": { + "matchString": { + "type": "string", + "description": "String value to be matched or partially matched" + }, + "matchType": { + "type": "string", + "description": "Operator that performs match action" + } + }, + "description": "A sub-string to match city. Valid operators are starts with, ends with, contains, and exact match operators." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "One or more values from a predefined set of SD-WAN partner list to display partner names." + }, + "enforceAuthentication": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "enforceAup": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location." + }, + "enforceFirewallControl": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "enableXffForwarding": { + "type": "boolean", + "description": "Enable XFF Forwarding. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header." + }, + "enableCaution": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location." + }, + "enableBandwidthControl": { + "type": "boolean", + "description": "Enable Bandwidth Control. When set to true, Bandwidth Control is enabled for the location." + }, + "profiles": { + "type": "array", + "items": { + "type": "string" + }, + "description": "One or more location profiles from a predefined set" + } + }, + "description": "A dynamic location group's criteria. This is ignored if the groupType is Static." + }, + "comments": { + "type": "string", + "description": "Additional information about the location group" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of the locations that are assigned to the static location group. This is ignored if the groupType is Dynamic." + }, + "lastModUser": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Automatically populated with the current ZIA admin user, after a successful POST or PUT request." + }, + "lastModTime": { + "type": "integer", + "description": "Automatically populated with the current time, after a successful POST or PUT request." + }, + "predefined": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/locations/groups/{id}": { + "get": { + "operationId": "location__locationgroups_GetLocationGroup", + "summary": "GetLocationGroup (Location / Locationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the location group" + }, + "name": { + "type": "string", + "description": "Location group name" + }, + "deleted": { + "type": "boolean", + "description": "Indicates the location group was deleted" + }, + "groupType": { + "type": "string", + "description": "The location group's type (i.e., Static or Dynamic)" + }, + "dynamicLocationGroupCriteria": { + "type": "object", + "properties": { + "name": { + "type": "object", + "properties": { + "matchString": { + "type": "string", + "description": "String value to be matched or partially matched" + }, + "matchType": { + "type": "string", + "description": "Operator that performs match action" + } + }, + "description": "A sub-string to match location name. Valid operators are contains, starts with, and ends with\"," + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "One or more countries from a predefined set" + }, + "city": { + "type": "object", + "properties": { + "matchString": { + "type": "string", + "description": "String value to be matched or partially matched" + }, + "matchType": { + "type": "string", + "description": "Operator that performs match action" + } + }, + "description": "A sub-string to match city. Valid operators are starts with, ends with, contains, and exact match operators." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "One or more values from a predefined set of SD-WAN partner list to display partner names." + }, + "enforceAuthentication": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "enforceAup": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location." + }, + "enforceFirewallControl": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "enableXffForwarding": { + "type": "boolean", + "description": "Enable XFF Forwarding. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header." + }, + "enableCaution": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location." + }, + "enableBandwidthControl": { + "type": "boolean", + "description": "Enable Bandwidth Control. When set to true, Bandwidth Control is enabled for the location." + }, + "profiles": { + "type": "array", + "items": { + "type": "string" + }, + "description": "One or more location profiles from a predefined set" + } + }, + "description": "A dynamic location group's criteria. This is ignored if the groupType is Static." + }, + "comments": { + "type": "string", + "description": "Additional information about the location group" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of the locations that are assigned to the static location group. This is ignored if the groupType is Dynamic." + }, + "lastModUser": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Automatically populated with the current ZIA admin user, after a successful POST or PUT request." + }, + "lastModTime": { + "type": "integer", + "description": "Automatically populated with the current time, after a successful POST or PUT request." + }, + "predefined": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/locations/lite": { + "get": { + "operationId": "location__locationlite_GetAll", + "summary": "GetAll (Location / Locationlite)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the location" + }, + "name": { + "type": "string", + "description": "Location name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location. To learn more, see About End User Notifications" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notification is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "zappSslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/locations/lite/{id}": { + "get": { + "operationId": "location__locationlite_GetLocationLiteID", + "summary": "GetLocationLiteID (Location / Locationlite)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the location" + }, + "name": { + "type": "string", + "description": "Location name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location. To learn more, see About End User Notifications" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notification is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "zappSslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/locations/{id}": { + "get": { + "operationId": "location__locationmanagement_GetLocation", + "summary": "GetLocation (Location / Locationmanagement)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "location__locationmanagement_Update", + "summary": "Update (Location / Locationmanagement)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "location__locationmanagement_Delete", + "summary": "Delete (Location / Locationmanagement)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/locations/{id}/{id2}": { + "get": { + "operationId": "location__locationmanagement_GetSublocations", + "summary": "GetSublocations (Location / Locationmanagement)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/mobileAdvanceThreatSettings": { + "get": { + "operationId": "mobile_threat_settings_GetMobileThreatSettings", + "summary": "GetMobileThreatSettings (Mobile Threat Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "blockAppsWithMaliciousActivity": { + "type": "boolean", + "description": "Blocks applications that are known to be malicious, compromised, or perform activities unknown to or hidden from the user" + }, + "blockAppsWithKnownVulnerabilities": { + "type": "boolean", + "description": "Blocks applications that contain vulnerabilities or that use insecure features, modules, or protocols" + }, + "blockAppsSendingUnencryptedUserCredentials": { + "type": "boolean", + "description": "Blocks an application from leaking a user's credentials in an unencrypted format" + }, + "blockAppsSendingLocationInfo": { + "type": "boolean", + "description": "Blocks an application from leaking device location details via communication in an unencrypted format or for an unknown purpose" + }, + "blockAppsSendingPersonallyIdentifiableInfo": { + "type": "boolean", + "description": "Blocks an application from leaking a user's personally identifiable information (PII) via communication in an unencrypted format or for an unknown purpose" + }, + "blockAppsSendingDeviceIdentifier": { + "type": "boolean", + "description": "Blocks an application from leaking device identifiers via communication in an unencrypted format or for an unknown purpose" + }, + "blockAppsCommunicatingWithAdWebsites": { + "type": "boolean", + "description": "Blocks an application from communicating with known advertisement websites" + }, + "blockAppsCommunicatingWithRemoteUnknownServers": { + "type": "boolean", + "description": "Blocks an application from communicating with unknown servers (i.e., servers not normally or historically associated with the application)" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "mobile_threat_settings_UpdateMobileThreatSettings", + "summary": "UpdateMobileThreatSettings (Mobile Threat Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "blockAppsWithMaliciousActivity": { + "type": "boolean", + "description": "Blocks applications that are known to be malicious, compromised, or perform activities unknown to or hidden from the user" + }, + "blockAppsWithKnownVulnerabilities": { + "type": "boolean", + "description": "Blocks applications that contain vulnerabilities or that use insecure features, modules, or protocols" + }, + "blockAppsSendingUnencryptedUserCredentials": { + "type": "boolean", + "description": "Blocks an application from leaking a user's credentials in an unencrypted format" + }, + "blockAppsSendingLocationInfo": { + "type": "boolean", + "description": "Blocks an application from leaking device location details via communication in an unencrypted format or for an unknown purpose" + }, + "blockAppsSendingPersonallyIdentifiableInfo": { + "type": "boolean", + "description": "Blocks an application from leaking a user's personally identifiable information (PII) via communication in an unencrypted format or for an unknown purpose" + }, + "blockAppsSendingDeviceIdentifier": { + "type": "boolean", + "description": "Blocks an application from leaking device identifiers via communication in an unencrypted format or for an unknown purpose" + }, + "blockAppsCommunicatingWithAdWebsites": { + "type": "boolean", + "description": "Blocks an application from communicating with known advertisement websites" + }, + "blockAppsCommunicatingWithRemoteUnknownServers": { + "type": "boolean", + "description": "Blocks an application from communicating with unknown servers (i.e., servers not normally or historically associated with the application)" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "blockAppsWithMaliciousActivity": { + "type": "boolean", + "description": "Blocks applications that are known to be malicious, compromised, or perform activities unknown to or hidden from the user" + }, + "blockAppsWithKnownVulnerabilities": { + "type": "boolean", + "description": "Blocks applications that contain vulnerabilities or that use insecure features, modules, or protocols" + }, + "blockAppsSendingUnencryptedUserCredentials": { + "type": "boolean", + "description": "Blocks an application from leaking a user's credentials in an unencrypted format" + }, + "blockAppsSendingLocationInfo": { + "type": "boolean", + "description": "Blocks an application from leaking device location details via communication in an unencrypted format or for an unknown purpose" + }, + "blockAppsSendingPersonallyIdentifiableInfo": { + "type": "boolean", + "description": "Blocks an application from leaking a user's personally identifiable information (PII) via communication in an unencrypted format or for an unknown purpose" + }, + "blockAppsSendingDeviceIdentifier": { + "type": "boolean", + "description": "Blocks an application from leaking device identifiers via communication in an unencrypted format or for an unknown purpose" + }, + "blockAppsCommunicatingWithAdWebsites": { + "type": "boolean", + "description": "Blocks an application from communicating with known advertisement websites" + }, + "blockAppsCommunicatingWithRemoteUnknownServers": { + "type": "boolean", + "description": "Blocks an application from communicating with unknown servers (i.e., servers not normally or historically associated with the application)" + } + } + } + } + } + } + } + }, + "/zia/api/v1/networkApplicationGroups": { + "get": { + "operationId": "firewallpolicies__networkapplicationgroups_GetNetworkApplicationGroupsByName", + "summary": "GetNetworkApplicationGroupsByName (Firewallpolicies / Networkapplicationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "firewallpolicies__networkapplicationgroups_Create", + "summary": "Create (Firewallpolicies / Networkapplicationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + } + }, + "/zia/api/v1/networkApplicationGroups/{id}": { + "get": { + "operationId": "firewallpolicies__networkapplicationgroups_GetNetworkApplicationGroups", + "summary": "GetNetworkApplicationGroups (Firewallpolicies / Networkapplicationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "firewallpolicies__networkapplicationgroups_Update", + "summary": "Update (Firewallpolicies / Networkapplicationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "delete": { + "operationId": "firewallpolicies__networkapplicationgroups_Delete", + "summary": "Delete (Firewallpolicies / Networkapplicationgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/networkApplications": { + "get": { + "operationId": "firewallpolicies__networkapplications_GetByName", + "summary": "GetByName (Firewallpolicies / Networkapplications)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "parentCategory": { + "type": "string" + }, + "description": { + "type": "string" + }, + "deprecated": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/networkApplications/{id}": { + "get": { + "operationId": "firewallpolicies__networkapplications_GetNetworkApplication", + "summary": "GetNetworkApplication (Firewallpolicies / Networkapplications)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "parentCategory": { + "type": "string" + }, + "description": { + "type": "string" + }, + "deprecated": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/networkServiceGroups": { + "get": { + "operationId": "firewallpolicies__networkservicegroups_GetNetworkServiceGroupsByName", + "summary": "GetNetworkServiceGroupsByName (Firewallpolicies / Networkservicegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "firewallpolicies__networkservicegroups_CreateNetworkServiceGroups", + "summary": "CreateNetworkServiceGroups (Firewallpolicies / Networkservicegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + } + }, + "/zia/api/v1/networkServiceGroups/{id}": { + "get": { + "operationId": "firewallpolicies__networkservicegroups_GetNetworkServiceGroups", + "summary": "GetNetworkServiceGroups (Firewallpolicies / Networkservicegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "firewallpolicies__networkservicegroups_UpdateNetworkServiceGroups", + "summary": "UpdateNetworkServiceGroups (Firewallpolicies / Networkservicegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "delete": { + "operationId": "firewallpolicies__networkservicegroups_DeleteNetworkServiceGroups", + "summary": "DeleteNetworkServiceGroups (Firewallpolicies / Networkservicegroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/networkServices": { + "get": { + "operationId": "firewallpolicies__networkservices_GetByName", + "summary": "GetByName (Firewallpolicies / Networkservices)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "firewallpolicies__networkservices_Create", + "summary": "Create (Firewallpolicies / Networkservices)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "/zia/api/v1/networkServices/{id}": { + "get": { + "operationId": "firewallpolicies__networkservices_Get", + "summary": "Get (Firewallpolicies / Networkservices)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "firewallpolicies__networkservices_Update", + "summary": "Update (Firewallpolicies / Networkservices)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + }, + "delete": { + "operationId": "firewallpolicies__networkservices_Delete", + "summary": "Delete (Firewallpolicies / Networkservices)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/nssFeeds": { + "get": { + "operationId": "cloudnss__cloudnss_GetByName", + "summary": "GetByName (Cloudnss / Cloudnss)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "feedStatus": { + "type": "string" + }, + "nssLogType": { + "type": "string" + }, + "nssFeedType": { + "type": "string" + }, + "feedOutputFormat": { + "type": "string" + }, + "userObfuscation": { + "type": "string" + }, + "timeZone": { + "type": "string" + }, + "customEscapedCharacter": { + "type": "array", + "items": { + "type": "string" + } + }, + "epsRateLimit": { + "type": "integer" + }, + "jsonArrayToggle": { + "type": "boolean" + }, + "siemType": { + "type": "string" + }, + "maxBatchSize": { + "type": "integer" + }, + "connectionURL": { + "type": "string" + }, + "authenticationToken": { + "type": "string" + }, + "connectionHeaders": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastSuccessFullTest": { + "type": "integer" + }, + "testConnectivityCode": { + "type": "integer" + }, + "base64EncodedCertificate": { + "type": "string" + }, + "nssType": { + "type": "string" + }, + "clientId": { + "type": "string" + }, + "clientSecret": { + "type": "string" + }, + "authenticationUrl": { + "type": "string" + }, + "grantType": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "cloudNss": { + "type": "boolean" + }, + "oauthAuthentication": { + "type": "boolean" + }, + "serverIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsRequestTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponseTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponses": { + "type": "array", + "items": { + "type": "string" + } + }, + "durations": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallLoggingMode": { + "type": "string" + }, + "clientSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionFilter": { + "type": "string" + }, + "emailDlpPolicyAction": { + "type": "string" + }, + "direction": { + "type": "string" + }, + "event": { + "type": "string" + }, + "policyReasons": { + "type": "array", + "items": { + "type": "string" + } + }, + "protocolTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestMethods": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbSeverity": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbPolicyTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbAction": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplicationClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "advancedThreats": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseCodes": { + "type": "array", + "items": { + "type": "string" + } + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "natActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "trafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "webTrafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "alerts": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType": { + "type": "array", + "items": { + "type": "string" + } + }, + "activity": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType1": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType2": { + "type": "array", + "items": { + "type": "string" + } + }, + "endPointDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileType": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "messageSize": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "transactionSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "inBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "outBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "downloadTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "scanTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "internalIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelDestIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "auditLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "projectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "repoName": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "channelName": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSource": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileName": { + "type": "array", + "items": { + "type": "string" + } + }, + "sessionCounts": { + "type": "array", + "items": { + "type": "string" + } + }, + "advUserAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "refererUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "hostNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "fullUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "threatNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "pageRiskIndexes": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationPorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourcePort": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbTenant": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "senderName": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "externalOwners": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "externalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "internalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "itsmObjectType": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpDictionaries": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "rules": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "cloudnss__cloudnss_Create", + "summary": "Create (Cloudnss / Cloudnss)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "feedStatus": { + "type": "string" + }, + "nssLogType": { + "type": "string" + }, + "nssFeedType": { + "type": "string" + }, + "feedOutputFormat": { + "type": "string" + }, + "userObfuscation": { + "type": "string" + }, + "timeZone": { + "type": "string" + }, + "customEscapedCharacter": { + "type": "array", + "items": { + "type": "string" + } + }, + "epsRateLimit": { + "type": "integer" + }, + "jsonArrayToggle": { + "type": "boolean" + }, + "siemType": { + "type": "string" + }, + "maxBatchSize": { + "type": "integer" + }, + "connectionURL": { + "type": "string" + }, + "authenticationToken": { + "type": "string" + }, + "connectionHeaders": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastSuccessFullTest": { + "type": "integer" + }, + "testConnectivityCode": { + "type": "integer" + }, + "base64EncodedCertificate": { + "type": "string" + }, + "nssType": { + "type": "string" + }, + "clientId": { + "type": "string" + }, + "clientSecret": { + "type": "string" + }, + "authenticationUrl": { + "type": "string" + }, + "grantType": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "cloudNss": { + "type": "boolean" + }, + "oauthAuthentication": { + "type": "boolean" + }, + "serverIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsRequestTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponseTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponses": { + "type": "array", + "items": { + "type": "string" + } + }, + "durations": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallLoggingMode": { + "type": "string" + }, + "clientSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionFilter": { + "type": "string" + }, + "emailDlpPolicyAction": { + "type": "string" + }, + "direction": { + "type": "string" + }, + "event": { + "type": "string" + }, + "policyReasons": { + "type": "array", + "items": { + "type": "string" + } + }, + "protocolTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestMethods": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbSeverity": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbPolicyTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbAction": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplicationClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "advancedThreats": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseCodes": { + "type": "array", + "items": { + "type": "string" + } + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "natActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "trafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "webTrafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "alerts": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType": { + "type": "array", + "items": { + "type": "string" + } + }, + "activity": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType1": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType2": { + "type": "array", + "items": { + "type": "string" + } + }, + "endPointDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileType": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "messageSize": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "transactionSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "inBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "outBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "downloadTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "scanTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "internalIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelDestIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "auditLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "projectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "repoName": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "channelName": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSource": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileName": { + "type": "array", + "items": { + "type": "string" + } + }, + "sessionCounts": { + "type": "array", + "items": { + "type": "string" + } + }, + "advUserAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "refererUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "hostNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "fullUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "threatNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "pageRiskIndexes": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationPorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourcePort": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbTenant": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "senderName": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "externalOwners": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "externalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "internalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "itsmObjectType": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpDictionaries": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "rules": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "feedStatus": { + "type": "string" + }, + "nssLogType": { + "type": "string" + }, + "nssFeedType": { + "type": "string" + }, + "feedOutputFormat": { + "type": "string" + }, + "userObfuscation": { + "type": "string" + }, + "timeZone": { + "type": "string" + }, + "customEscapedCharacter": { + "type": "array", + "items": { + "type": "string" + } + }, + "epsRateLimit": { + "type": "integer" + }, + "jsonArrayToggle": { + "type": "boolean" + }, + "siemType": { + "type": "string" + }, + "maxBatchSize": { + "type": "integer" + }, + "connectionURL": { + "type": "string" + }, + "authenticationToken": { + "type": "string" + }, + "connectionHeaders": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastSuccessFullTest": { + "type": "integer" + }, + "testConnectivityCode": { + "type": "integer" + }, + "base64EncodedCertificate": { + "type": "string" + }, + "nssType": { + "type": "string" + }, + "clientId": { + "type": "string" + }, + "clientSecret": { + "type": "string" + }, + "authenticationUrl": { + "type": "string" + }, + "grantType": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "cloudNss": { + "type": "boolean" + }, + "oauthAuthentication": { + "type": "boolean" + }, + "serverIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsRequestTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponseTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponses": { + "type": "array", + "items": { + "type": "string" + } + }, + "durations": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallLoggingMode": { + "type": "string" + }, + "clientSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionFilter": { + "type": "string" + }, + "emailDlpPolicyAction": { + "type": "string" + }, + "direction": { + "type": "string" + }, + "event": { + "type": "string" + }, + "policyReasons": { + "type": "array", + "items": { + "type": "string" + } + }, + "protocolTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestMethods": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbSeverity": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbPolicyTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbAction": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplicationClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "advancedThreats": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseCodes": { + "type": "array", + "items": { + "type": "string" + } + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "natActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "trafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "webTrafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "alerts": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType": { + "type": "array", + "items": { + "type": "string" + } + }, + "activity": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType1": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType2": { + "type": "array", + "items": { + "type": "string" + } + }, + "endPointDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileType": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "messageSize": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "transactionSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "inBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "outBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "downloadTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "scanTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "internalIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelDestIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "auditLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "projectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "repoName": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "channelName": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSource": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileName": { + "type": "array", + "items": { + "type": "string" + } + }, + "sessionCounts": { + "type": "array", + "items": { + "type": "string" + } + }, + "advUserAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "refererUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "hostNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "fullUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "threatNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "pageRiskIndexes": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationPorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourcePort": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbTenant": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "senderName": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "externalOwners": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "externalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "internalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "itsmObjectType": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpDictionaries": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "rules": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/nssFeeds/testConnectivity/{id}": { + "get": { + "operationId": "cloudnss__cloudnss_GetTestConnectivity", + "summary": "GetTestConnectivity (Cloudnss / Cloudnss)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "feedStatus": { + "type": "string" + }, + "nssLogType": { + "type": "string" + }, + "nssFeedType": { + "type": "string" + }, + "feedOutputFormat": { + "type": "string" + }, + "userObfuscation": { + "type": "string" + }, + "timeZone": { + "type": "string" + }, + "customEscapedCharacter": { + "type": "array", + "items": { + "type": "string" + } + }, + "epsRateLimit": { + "type": "integer" + }, + "jsonArrayToggle": { + "type": "boolean" + }, + "siemType": { + "type": "string" + }, + "maxBatchSize": { + "type": "integer" + }, + "connectionURL": { + "type": "string" + }, + "authenticationToken": { + "type": "string" + }, + "connectionHeaders": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastSuccessFullTest": { + "type": "integer" + }, + "testConnectivityCode": { + "type": "integer" + }, + "base64EncodedCertificate": { + "type": "string" + }, + "nssType": { + "type": "string" + }, + "clientId": { + "type": "string" + }, + "clientSecret": { + "type": "string" + }, + "authenticationUrl": { + "type": "string" + }, + "grantType": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "cloudNss": { + "type": "boolean" + }, + "oauthAuthentication": { + "type": "boolean" + }, + "serverIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsRequestTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponseTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponses": { + "type": "array", + "items": { + "type": "string" + } + }, + "durations": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallLoggingMode": { + "type": "string" + }, + "clientSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionFilter": { + "type": "string" + }, + "emailDlpPolicyAction": { + "type": "string" + }, + "direction": { + "type": "string" + }, + "event": { + "type": "string" + }, + "policyReasons": { + "type": "array", + "items": { + "type": "string" + } + }, + "protocolTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestMethods": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbSeverity": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbPolicyTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbAction": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplicationClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "advancedThreats": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseCodes": { + "type": "array", + "items": { + "type": "string" + } + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "natActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "trafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "webTrafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "alerts": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType": { + "type": "array", + "items": { + "type": "string" + } + }, + "activity": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType1": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType2": { + "type": "array", + "items": { + "type": "string" + } + }, + "endPointDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileType": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "messageSize": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "transactionSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "inBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "outBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "downloadTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "scanTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "internalIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelDestIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "auditLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "projectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "repoName": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "channelName": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSource": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileName": { + "type": "array", + "items": { + "type": "string" + } + }, + "sessionCounts": { + "type": "array", + "items": { + "type": "string" + } + }, + "advUserAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "refererUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "hostNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "fullUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "threatNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "pageRiskIndexes": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationPorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourcePort": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbTenant": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "senderName": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "externalOwners": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "externalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "internalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "itsmObjectType": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpDictionaries": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "rules": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/nssFeeds/{id}": { + "get": { + "operationId": "cloudnss__cloudnss_Get", + "summary": "Get (Cloudnss / Cloudnss)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "feedStatus": { + "type": "string" + }, + "nssLogType": { + "type": "string" + }, + "nssFeedType": { + "type": "string" + }, + "feedOutputFormat": { + "type": "string" + }, + "userObfuscation": { + "type": "string" + }, + "timeZone": { + "type": "string" + }, + "customEscapedCharacter": { + "type": "array", + "items": { + "type": "string" + } + }, + "epsRateLimit": { + "type": "integer" + }, + "jsonArrayToggle": { + "type": "boolean" + }, + "siemType": { + "type": "string" + }, + "maxBatchSize": { + "type": "integer" + }, + "connectionURL": { + "type": "string" + }, + "authenticationToken": { + "type": "string" + }, + "connectionHeaders": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastSuccessFullTest": { + "type": "integer" + }, + "testConnectivityCode": { + "type": "integer" + }, + "base64EncodedCertificate": { + "type": "string" + }, + "nssType": { + "type": "string" + }, + "clientId": { + "type": "string" + }, + "clientSecret": { + "type": "string" + }, + "authenticationUrl": { + "type": "string" + }, + "grantType": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "cloudNss": { + "type": "boolean" + }, + "oauthAuthentication": { + "type": "boolean" + }, + "serverIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsRequestTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponseTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponses": { + "type": "array", + "items": { + "type": "string" + } + }, + "durations": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallLoggingMode": { + "type": "string" + }, + "clientSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionFilter": { + "type": "string" + }, + "emailDlpPolicyAction": { + "type": "string" + }, + "direction": { + "type": "string" + }, + "event": { + "type": "string" + }, + "policyReasons": { + "type": "array", + "items": { + "type": "string" + } + }, + "protocolTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestMethods": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbSeverity": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbPolicyTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbAction": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplicationClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "advancedThreats": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseCodes": { + "type": "array", + "items": { + "type": "string" + } + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "natActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "trafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "webTrafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "alerts": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType": { + "type": "array", + "items": { + "type": "string" + } + }, + "activity": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType1": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType2": { + "type": "array", + "items": { + "type": "string" + } + }, + "endPointDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileType": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "messageSize": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "transactionSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "inBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "outBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "downloadTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "scanTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "internalIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelDestIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "auditLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "projectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "repoName": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "channelName": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSource": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileName": { + "type": "array", + "items": { + "type": "string" + } + }, + "sessionCounts": { + "type": "array", + "items": { + "type": "string" + } + }, + "advUserAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "refererUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "hostNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "fullUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "threatNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "pageRiskIndexes": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationPorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourcePort": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbTenant": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "senderName": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "externalOwners": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "externalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "internalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "itsmObjectType": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpDictionaries": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "rules": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "cloudnss__cloudnss_Update", + "summary": "Update (Cloudnss / Cloudnss)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "feedStatus": { + "type": "string" + }, + "nssLogType": { + "type": "string" + }, + "nssFeedType": { + "type": "string" + }, + "feedOutputFormat": { + "type": "string" + }, + "userObfuscation": { + "type": "string" + }, + "timeZone": { + "type": "string" + }, + "customEscapedCharacter": { + "type": "array", + "items": { + "type": "string" + } + }, + "epsRateLimit": { + "type": "integer" + }, + "jsonArrayToggle": { + "type": "boolean" + }, + "siemType": { + "type": "string" + }, + "maxBatchSize": { + "type": "integer" + }, + "connectionURL": { + "type": "string" + }, + "authenticationToken": { + "type": "string" + }, + "connectionHeaders": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastSuccessFullTest": { + "type": "integer" + }, + "testConnectivityCode": { + "type": "integer" + }, + "base64EncodedCertificate": { + "type": "string" + }, + "nssType": { + "type": "string" + }, + "clientId": { + "type": "string" + }, + "clientSecret": { + "type": "string" + }, + "authenticationUrl": { + "type": "string" + }, + "grantType": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "cloudNss": { + "type": "boolean" + }, + "oauthAuthentication": { + "type": "boolean" + }, + "serverIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsRequestTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponseTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponses": { + "type": "array", + "items": { + "type": "string" + } + }, + "durations": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallLoggingMode": { + "type": "string" + }, + "clientSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionFilter": { + "type": "string" + }, + "emailDlpPolicyAction": { + "type": "string" + }, + "direction": { + "type": "string" + }, + "event": { + "type": "string" + }, + "policyReasons": { + "type": "array", + "items": { + "type": "string" + } + }, + "protocolTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestMethods": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbSeverity": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbPolicyTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbAction": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplicationClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "advancedThreats": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseCodes": { + "type": "array", + "items": { + "type": "string" + } + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "natActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "trafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "webTrafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "alerts": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType": { + "type": "array", + "items": { + "type": "string" + } + }, + "activity": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType1": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType2": { + "type": "array", + "items": { + "type": "string" + } + }, + "endPointDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileType": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "messageSize": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "transactionSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "inBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "outBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "downloadTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "scanTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "internalIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelDestIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "auditLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "projectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "repoName": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "channelName": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSource": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileName": { + "type": "array", + "items": { + "type": "string" + } + }, + "sessionCounts": { + "type": "array", + "items": { + "type": "string" + } + }, + "advUserAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "refererUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "hostNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "fullUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "threatNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "pageRiskIndexes": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationPorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourcePort": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbTenant": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "senderName": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "externalOwners": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "externalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "internalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "itsmObjectType": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpDictionaries": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "rules": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "feedStatus": { + "type": "string" + }, + "nssLogType": { + "type": "string" + }, + "nssFeedType": { + "type": "string" + }, + "feedOutputFormat": { + "type": "string" + }, + "userObfuscation": { + "type": "string" + }, + "timeZone": { + "type": "string" + }, + "customEscapedCharacter": { + "type": "array", + "items": { + "type": "string" + } + }, + "epsRateLimit": { + "type": "integer" + }, + "jsonArrayToggle": { + "type": "boolean" + }, + "siemType": { + "type": "string" + }, + "maxBatchSize": { + "type": "integer" + }, + "connectionURL": { + "type": "string" + }, + "authenticationToken": { + "type": "string" + }, + "connectionHeaders": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastSuccessFullTest": { + "type": "integer" + }, + "testConnectivityCode": { + "type": "integer" + }, + "base64EncodedCertificate": { + "type": "string" + }, + "nssType": { + "type": "string" + }, + "clientId": { + "type": "string" + }, + "clientSecret": { + "type": "string" + }, + "authenticationUrl": { + "type": "string" + }, + "grantType": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "cloudNss": { + "type": "boolean" + }, + "oauthAuthentication": { + "type": "boolean" + }, + "serverIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsRequestTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponseTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponses": { + "type": "array", + "items": { + "type": "string" + } + }, + "durations": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallLoggingMode": { + "type": "string" + }, + "clientSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionFilter": { + "type": "string" + }, + "emailDlpPolicyAction": { + "type": "string" + }, + "direction": { + "type": "string" + }, + "event": { + "type": "string" + }, + "policyReasons": { + "type": "array", + "items": { + "type": "string" + } + }, + "protocolTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestMethods": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbSeverity": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbPolicyTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbAction": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplicationClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "advancedThreats": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseCodes": { + "type": "array", + "items": { + "type": "string" + } + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "natActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "trafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "webTrafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "alerts": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType": { + "type": "array", + "items": { + "type": "string" + } + }, + "activity": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType1": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType2": { + "type": "array", + "items": { + "type": "string" + } + }, + "endPointDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileType": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "messageSize": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "transactionSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "inBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "outBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "downloadTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "scanTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "internalIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelDestIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "auditLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "projectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "repoName": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "channelName": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSource": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileName": { + "type": "array", + "items": { + "type": "string" + } + }, + "sessionCounts": { + "type": "array", + "items": { + "type": "string" + } + }, + "advUserAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "refererUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "hostNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "fullUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "threatNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "pageRiskIndexes": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationPorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourcePort": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbTenant": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "senderName": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "externalOwners": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "externalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "internalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "itsmObjectType": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpDictionaries": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "rules": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "cloudnss__cloudnss_Delete", + "summary": "Delete (Cloudnss / Cloudnss)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "feedStatus": { + "type": "string" + }, + "nssLogType": { + "type": "string" + }, + "nssFeedType": { + "type": "string" + }, + "feedOutputFormat": { + "type": "string" + }, + "userObfuscation": { + "type": "string" + }, + "timeZone": { + "type": "string" + }, + "customEscapedCharacter": { + "type": "array", + "items": { + "type": "string" + } + }, + "epsRateLimit": { + "type": "integer" + }, + "jsonArrayToggle": { + "type": "boolean" + }, + "siemType": { + "type": "string" + }, + "maxBatchSize": { + "type": "integer" + }, + "connectionURL": { + "type": "string" + }, + "authenticationToken": { + "type": "string" + }, + "connectionHeaders": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastSuccessFullTest": { + "type": "integer" + }, + "testConnectivityCode": { + "type": "integer" + }, + "base64EncodedCertificate": { + "type": "string" + }, + "nssType": { + "type": "string" + }, + "clientId": { + "type": "string" + }, + "clientSecret": { + "type": "string" + }, + "authenticationUrl": { + "type": "string" + }, + "grantType": { + "type": "string" + }, + "scope": { + "type": "string" + }, + "cloudNss": { + "type": "boolean" + }, + "oauthAuthentication": { + "type": "boolean" + }, + "serverIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "domains": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsRequestTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponseTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsResponses": { + "type": "array", + "items": { + "type": "string" + } + }, + "durations": { + "type": "array", + "items": { + "type": "string" + } + }, + "dnsActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallLoggingMode": { + "type": "string" + }, + "clientSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "firewallActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "countries": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientSourcePorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "actionFilter": { + "type": "string" + }, + "emailDlpPolicyAction": { + "type": "string" + }, + "direction": { + "type": "string" + }, + "event": { + "type": "string" + }, + "policyReasons": { + "type": "array", + "items": { + "type": "string" + } + }, + "protocolTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "userAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestMethods": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbSeverity": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbPolicyTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbAction": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "webApplicationClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "malwareClasses": { + "type": "array", + "items": { + "type": "string" + } + }, + "advancedThreats": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseCodes": { + "type": "array", + "items": { + "type": "string" + } + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "natActions": { + "type": "array", + "items": { + "type": "string" + } + }, + "trafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "webTrafficForwards": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "alerts": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType": { + "type": "array", + "items": { + "type": "string" + } + }, + "activity": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType1": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectType2": { + "type": "array", + "items": { + "type": "string" + } + }, + "endPointDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "emailDLPLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileType": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbFileTypeSuperCategories": { + "type": "array", + "items": { + "type": "string" + } + }, + "messageSize": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "requestSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "responseSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "transactionSizes": { + "type": "array", + "items": { + "type": "string" + } + }, + "inBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "outBoundBytes": { + "type": "array", + "items": { + "type": "string" + } + }, + "downloadTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "scanTime": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "serverDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "internalIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourceIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelDestIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "auditLogType": { + "type": "array", + "items": { + "type": "string" + } + }, + "projectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "repoName": { + "type": "array", + "items": { + "type": "string" + } + }, + "objectName": { + "type": "array", + "items": { + "type": "string" + } + }, + "channelName": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileSource": { + "type": "array", + "items": { + "type": "string" + } + }, + "fileName": { + "type": "array", + "items": { + "type": "string" + } + }, + "sessionCounts": { + "type": "array", + "items": { + "type": "string" + } + }, + "advUserAgents": { + "type": "array", + "items": { + "type": "string" + } + }, + "refererUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "hostNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "fullUrls": { + "type": "array", + "items": { + "type": "string" + } + }, + "threatNames": { + "type": "array", + "items": { + "type": "string" + } + }, + "pageRiskIndexes": { + "type": "array", + "items": { + "type": "string" + } + }, + "clientDestinationPorts": { + "type": "array", + "items": { + "type": "string" + } + }, + "tunnelSourcePort": { + "type": "array", + "items": { + "type": "string" + } + }, + "casbTenant": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "senderName": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "buckets": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "description": "common.CommonNSS object" + } + }, + "externalOwners": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "externalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "internalCollaborators": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "itsmObjectType": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "dlpDictionaries": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "rules": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/nssServers": { + "get": { + "operationId": "cloudnss__nss_servers_GetByName", + "summary": "GetByName (Cloudnss / Nss Servers)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "status": { + "type": "string" + }, + "state": { + "type": "string" + }, + "type": { + "type": "string" + }, + "icapSvrId": { + "type": "integer" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "cloudnss__nss_servers_Create", + "summary": "Create (Cloudnss / Nss Servers)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "status": { + "type": "string" + }, + "state": { + "type": "string" + }, + "type": { + "type": "string" + }, + "icapSvrId": { + "type": "integer" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "status": { + "type": "string" + }, + "state": { + "type": "string" + }, + "type": { + "type": "string" + }, + "icapSvrId": { + "type": "integer" + } + } + } + } + } + } + } + }, + "/zia/api/v1/nssServers/{id}": { + "get": { + "operationId": "cloudnss__nss_servers_Get", + "summary": "Get (Cloudnss / Nss Servers)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "status": { + "type": "string" + }, + "state": { + "type": "string" + }, + "type": { + "type": "string" + }, + "icapSvrId": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "cloudnss__nss_servers_Update", + "summary": "Update (Cloudnss / Nss Servers)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "status": { + "type": "string" + }, + "state": { + "type": "string" + }, + "type": { + "type": "string" + }, + "icapSvrId": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "status": { + "type": "string" + }, + "state": { + "type": "string" + }, + "type": { + "type": "string" + }, + "icapSvrId": { + "type": "integer" + } + } + } + } + } + } + }, + "delete": { + "operationId": "cloudnss__nss_servers_Delete", + "summary": "Delete (Cloudnss / Nss Servers)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "status": { + "type": "string" + }, + "state": { + "type": "string" + }, + "type": { + "type": "string" + }, + "icapSvrId": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/orgInformation": { + "get": { + "operationId": "organization_details_GetOrgInformation", + "summary": "GetOrgInformation (Organization Details)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "The unique identifier of the subscription" + }, + "status": { + "type": "string", + "description": "The status of the subscription indicating whether it is on trial, expired and disabled, not subscribed, subscribed, or temporarily extended" + }, + "state": { + "type": "string", + "description": "The current state of the subscription indicating whether it is active, expired, disabled, or not started." + }, + "licenses": { + "type": "integer", + "description": "The number of licenses owned by the tenant under the subscription. The license could be for users, Virtual Service Edges, proxy ports, NSS feeds, etc." + }, + "startDate": { + "type": "integer", + "description": "The subscription start time in Unix time format" + }, + "strStartDate": { + "type": "string", + "description": "The subscription start date in MM/DD/YYYY format" + }, + "strEndDate": { + "type": "string", + "description": "The subscription end date in MM/DD/YYYY format" + }, + "endDate": { + "type": "integer", + "description": "The subscription end time in Unix time format" + }, + "sku": { + "type": "string", + "description": "The ID of the service enabled through the subscription" + }, + "cellCount": { + "type": "string" + }, + "updatedAtTimestamp": { + "type": "integer", + "description": "The timestamp in Unix time format when the subscription was last updated" + }, + "subscribed": { + "type": "boolean", + "description": "A Boolean value indicating that the subscription is active or is not started" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/orgInformation/lite": { + "get": { + "operationId": "organization_details_GetOrgInformationLite", + "summary": "GetOrgInformationLite (Organization Details)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "The unique identifier of the subscription" + }, + "status": { + "type": "string", + "description": "The status of the subscription indicating whether it is on trial, expired and disabled, not subscribed, subscribed, or temporarily extended" + }, + "state": { + "type": "string", + "description": "The current state of the subscription indicating whether it is active, expired, disabled, or not started." + }, + "licenses": { + "type": "integer", + "description": "The number of licenses owned by the tenant under the subscription. The license could be for users, Virtual Service Edges, proxy ports, NSS feeds, etc." + }, + "startDate": { + "type": "integer", + "description": "The subscription start time in Unix time format" + }, + "strStartDate": { + "type": "string", + "description": "The subscription start date in MM/DD/YYYY format" + }, + "strEndDate": { + "type": "string", + "description": "The subscription end date in MM/DD/YYYY format" + }, + "endDate": { + "type": "integer", + "description": "The subscription end time in Unix time format" + }, + "sku": { + "type": "string", + "description": "The ID of the service enabled through the subscription" + }, + "cellCount": { + "type": "string" + }, + "updatedAtTimestamp": { + "type": "integer", + "description": "The timestamp in Unix time format when the subscription was last updated" + }, + "subscribed": { + "type": "boolean", + "description": "A Boolean value indicating that the subscription is active or is not started" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/orgProvisioning/ipGreTunnelInfo": { + "get": { + "operationId": "trafficforwarding__gretunnelinfo_GetGRETunnelInfo", + "summary": "GetGRETunnelInfo (Trafficforwarding / Gretunnelinfo)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "tunID": { + "type": "integer" + }, + "ipAddress": { + "type": "string" + }, + "greEnabled": { + "type": "boolean" + }, + "greTunnelIP": { + "type": "string" + }, + "primaryGW": { + "type": "string" + }, + "secondaryGW": { + "type": "string" + }, + "greRangePrimary": { + "type": "string" + }, + "greRangeSecondary": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/pacFiles": { + "get": { + "operationId": "pacfiles_GetPacFileByName", + "summary": "GetPacFileByName (Pacfiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the PAC file" + }, + "name": { + "type": "string", + "description": "The name of the PAC file" + }, + "description": { + "type": "string", + "description": "The description of the PAC file" + }, + "domain": { + "type": "string", + "description": "The domain of your organization to which the PAC file applies" + }, + "pacUrl": { + "type": "string", + "description": "The URL location of the PAC file that is auto-generated when the PAC file is added for the first time.\nNote: This value is not required in POST and PUT requests and the value is ignored if present." + }, + "pacContent": { + "type": "string", + "description": "The content of the PAC file.\nTo learn more, see Writing a PAC File. https://help.zscaler.com/zia/writing-pac-file" + }, + "editable": { + "type": "boolean", + "description": "Indicates whether the PAC file is editable" + }, + "pacSubURL": { + "type": "string", + "description": "Obfuscated domain name of the organization to which this PAC file applies" + }, + "pacUrlObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the PAC file URL is obfuscated.\nIf this value is true, the obfuscated URL is returned in the pacSubURL field." + }, + "pacVerificationStatus": { + "type": "string", + "description": "Indicates the verification status of the PAC file and if any errors are identified in the syntax\nSupported values are: VERIFY_NOERR, VERIFY_ERR, NOVERIFY" + }, + "pacVersionStatus": { + "type": "string", + "description": "Indicates the status of a specific version of a PAC file\nas whether it is deployed, staged for deployment, or is marked as the last known good version.\nSupported values are: DEPLOYED, STAGE, LKG" + }, + "pacVersion": { + "type": "integer", + "description": "The version number of the PAC file" + }, + "pacCommitMessage": { + "type": "string", + "description": "The commit message entered while saving the PAC file version as indicated by the pacVersion field" + }, + "totalHits": { + "type": "integer", + "description": "The number of times the PAC file was used during the last 30 days" + }, + "lastModificationTime": { + "type": "integer", + "description": "The timestamp when the PAC file was last modified. This value is represented in Unix time." + }, + "lastModifiedBy": { + "type": "object", + "description": "The username of the admin who last modified the PAC file" + }, + "createTime": { + "type": "integer", + "description": "The timestamp when the PAC file was created. This value is represented in Unix time." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "pacfiles_CreatePacFile", + "summary": "CreatePacFile (Pacfiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the PAC file" + }, + "name": { + "type": "string", + "description": "The name of the PAC file" + }, + "description": { + "type": "string", + "description": "The description of the PAC file" + }, + "domain": { + "type": "string", + "description": "The domain of your organization to which the PAC file applies" + }, + "pacUrl": { + "type": "string", + "description": "The URL location of the PAC file that is auto-generated when the PAC file is added for the first time.\nNote: This value is not required in POST and PUT requests and the value is ignored if present." + }, + "pacContent": { + "type": "string", + "description": "The content of the PAC file.\nTo learn more, see Writing a PAC File. https://help.zscaler.com/zia/writing-pac-file" + }, + "editable": { + "type": "boolean", + "description": "Indicates whether the PAC file is editable" + }, + "pacSubURL": { + "type": "string", + "description": "Obfuscated domain name of the organization to which this PAC file applies" + }, + "pacUrlObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the PAC file URL is obfuscated.\nIf this value is true, the obfuscated URL is returned in the pacSubURL field." + }, + "pacVerificationStatus": { + "type": "string", + "description": "Indicates the verification status of the PAC file and if any errors are identified in the syntax\nSupported values are: VERIFY_NOERR, VERIFY_ERR, NOVERIFY" + }, + "pacVersionStatus": { + "type": "string", + "description": "Indicates the status of a specific version of a PAC file\nas whether it is deployed, staged for deployment, or is marked as the last known good version.\nSupported values are: DEPLOYED, STAGE, LKG" + }, + "pacVersion": { + "type": "integer", + "description": "The version number of the PAC file" + }, + "pacCommitMessage": { + "type": "string", + "description": "The commit message entered while saving the PAC file version as indicated by the pacVersion field" + }, + "totalHits": { + "type": "integer", + "description": "The number of times the PAC file was used during the last 30 days" + }, + "lastModificationTime": { + "type": "integer", + "description": "The timestamp when the PAC file was last modified. This value is represented in Unix time." + }, + "lastModifiedBy": { + "type": "object", + "description": "The username of the admin who last modified the PAC file" + }, + "createTime": { + "type": "integer", + "description": "The timestamp when the PAC file was created. This value is represented in Unix time." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the PAC file" + }, + "name": { + "type": "string", + "description": "The name of the PAC file" + }, + "description": { + "type": "string", + "description": "The description of the PAC file" + }, + "domain": { + "type": "string", + "description": "The domain of your organization to which the PAC file applies" + }, + "pacUrl": { + "type": "string", + "description": "The URL location of the PAC file that is auto-generated when the PAC file is added for the first time.\nNote: This value is not required in POST and PUT requests and the value is ignored if present." + }, + "pacContent": { + "type": "string", + "description": "The content of the PAC file.\nTo learn more, see Writing a PAC File. https://help.zscaler.com/zia/writing-pac-file" + }, + "editable": { + "type": "boolean", + "description": "Indicates whether the PAC file is editable" + }, + "pacSubURL": { + "type": "string", + "description": "Obfuscated domain name of the organization to which this PAC file applies" + }, + "pacUrlObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the PAC file URL is obfuscated.\nIf this value is true, the obfuscated URL is returned in the pacSubURL field." + }, + "pacVerificationStatus": { + "type": "string", + "description": "Indicates the verification status of the PAC file and if any errors are identified in the syntax\nSupported values are: VERIFY_NOERR, VERIFY_ERR, NOVERIFY" + }, + "pacVersionStatus": { + "type": "string", + "description": "Indicates the status of a specific version of a PAC file\nas whether it is deployed, staged for deployment, or is marked as the last known good version.\nSupported values are: DEPLOYED, STAGE, LKG" + }, + "pacVersion": { + "type": "integer", + "description": "The version number of the PAC file" + }, + "pacCommitMessage": { + "type": "string", + "description": "The commit message entered while saving the PAC file version as indicated by the pacVersion field" + }, + "totalHits": { + "type": "integer", + "description": "The number of times the PAC file was used during the last 30 days" + }, + "lastModificationTime": { + "type": "integer", + "description": "The timestamp when the PAC file was last modified. This value is represented in Unix time." + }, + "lastModifiedBy": { + "type": "object", + "description": "The username of the admin who last modified the PAC file" + }, + "createTime": { + "type": "integer", + "description": "The timestamp when the PAC file was created. This value is represented in Unix time." + } + } + } + } + } + } + } + }, + "/zia/api/v1/pacFiles/{id}": { + "get": { + "operationId": "pacfiles_GetPacFileVersion", + "summary": "GetPacFileVersion (Pacfiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the PAC file" + }, + "name": { + "type": "string", + "description": "The name of the PAC file" + }, + "description": { + "type": "string", + "description": "The description of the PAC file" + }, + "domain": { + "type": "string", + "description": "The domain of your organization to which the PAC file applies" + }, + "pacUrl": { + "type": "string", + "description": "The URL location of the PAC file that is auto-generated when the PAC file is added for the first time.\nNote: This value is not required in POST and PUT requests and the value is ignored if present." + }, + "pacContent": { + "type": "string", + "description": "The content of the PAC file.\nTo learn more, see Writing a PAC File. https://help.zscaler.com/zia/writing-pac-file" + }, + "editable": { + "type": "boolean", + "description": "Indicates whether the PAC file is editable" + }, + "pacSubURL": { + "type": "string", + "description": "Obfuscated domain name of the organization to which this PAC file applies" + }, + "pacUrlObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the PAC file URL is obfuscated.\nIf this value is true, the obfuscated URL is returned in the pacSubURL field." + }, + "pacVerificationStatus": { + "type": "string", + "description": "Indicates the verification status of the PAC file and if any errors are identified in the syntax\nSupported values are: VERIFY_NOERR, VERIFY_ERR, NOVERIFY" + }, + "pacVersionStatus": { + "type": "string", + "description": "Indicates the status of a specific version of a PAC file\nas whether it is deployed, staged for deployment, or is marked as the last known good version.\nSupported values are: DEPLOYED, STAGE, LKG" + }, + "pacVersion": { + "type": "integer", + "description": "The version number of the PAC file" + }, + "pacCommitMessage": { + "type": "string", + "description": "The commit message entered while saving the PAC file version as indicated by the pacVersion field" + }, + "totalHits": { + "type": "integer", + "description": "The number of times the PAC file was used during the last 30 days" + }, + "lastModificationTime": { + "type": "integer", + "description": "The timestamp when the PAC file was last modified. This value is represented in Unix time." + }, + "lastModifiedBy": { + "type": "object", + "description": "The username of the admin who last modified the PAC file" + }, + "createTime": { + "type": "integer", + "description": "The timestamp when the PAC file was created. This value is represented in Unix time." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "delete": { + "operationId": "pacfiles_DeletePacFile", + "summary": "DeletePacFile (Pacfiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the PAC file" + }, + "name": { + "type": "string", + "description": "The name of the PAC file" + }, + "description": { + "type": "string", + "description": "The description of the PAC file" + }, + "domain": { + "type": "string", + "description": "The domain of your organization to which the PAC file applies" + }, + "pacUrl": { + "type": "string", + "description": "The URL location of the PAC file that is auto-generated when the PAC file is added for the first time.\nNote: This value is not required in POST and PUT requests and the value is ignored if present." + }, + "pacContent": { + "type": "string", + "description": "The content of the PAC file.\nTo learn more, see Writing a PAC File. https://help.zscaler.com/zia/writing-pac-file" + }, + "editable": { + "type": "boolean", + "description": "Indicates whether the PAC file is editable" + }, + "pacSubURL": { + "type": "string", + "description": "Obfuscated domain name of the organization to which this PAC file applies" + }, + "pacUrlObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the PAC file URL is obfuscated.\nIf this value is true, the obfuscated URL is returned in the pacSubURL field." + }, + "pacVerificationStatus": { + "type": "string", + "description": "Indicates the verification status of the PAC file and if any errors are identified in the syntax\nSupported values are: VERIFY_NOERR, VERIFY_ERR, NOVERIFY" + }, + "pacVersionStatus": { + "type": "string", + "description": "Indicates the status of a specific version of a PAC file\nas whether it is deployed, staged for deployment, or is marked as the last known good version.\nSupported values are: DEPLOYED, STAGE, LKG" + }, + "pacVersion": { + "type": "integer", + "description": "The version number of the PAC file" + }, + "pacCommitMessage": { + "type": "string", + "description": "The commit message entered while saving the PAC file version as indicated by the pacVersion field" + }, + "totalHits": { + "type": "integer", + "description": "The number of times the PAC file was used during the last 30 days" + }, + "lastModificationTime": { + "type": "integer", + "description": "The timestamp when the PAC file was last modified. This value is represented in Unix time." + }, + "lastModifiedBy": { + "type": "object", + "description": "The username of the admin who last modified the PAC file" + }, + "createTime": { + "type": "integer", + "description": "The timestamp when the PAC file was created. This value is represented in Unix time." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/pacFiles/{id}/{id2}": { + "get": { + "operationId": "pacfiles_GetPacVersionID", + "summary": "GetPacVersionID (Pacfiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the PAC file" + }, + "name": { + "type": "string", + "description": "The name of the PAC file" + }, + "description": { + "type": "string", + "description": "The description of the PAC file" + }, + "domain": { + "type": "string", + "description": "The domain of your organization to which the PAC file applies" + }, + "pacUrl": { + "type": "string", + "description": "The URL location of the PAC file that is auto-generated when the PAC file is added for the first time.\nNote: This value is not required in POST and PUT requests and the value is ignored if present." + }, + "pacContent": { + "type": "string", + "description": "The content of the PAC file.\nTo learn more, see Writing a PAC File. https://help.zscaler.com/zia/writing-pac-file" + }, + "editable": { + "type": "boolean", + "description": "Indicates whether the PAC file is editable" + }, + "pacSubURL": { + "type": "string", + "description": "Obfuscated domain name of the organization to which this PAC file applies" + }, + "pacUrlObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the PAC file URL is obfuscated.\nIf this value is true, the obfuscated URL is returned in the pacSubURL field." + }, + "pacVerificationStatus": { + "type": "string", + "description": "Indicates the verification status of the PAC file and if any errors are identified in the syntax\nSupported values are: VERIFY_NOERR, VERIFY_ERR, NOVERIFY" + }, + "pacVersionStatus": { + "type": "string", + "description": "Indicates the status of a specific version of a PAC file\nas whether it is deployed, staged for deployment, or is marked as the last known good version.\nSupported values are: DEPLOYED, STAGE, LKG" + }, + "pacVersion": { + "type": "integer", + "description": "The version number of the PAC file" + }, + "pacCommitMessage": { + "type": "string", + "description": "The commit message entered while saving the PAC file version as indicated by the pacVersion field" + }, + "totalHits": { + "type": "integer", + "description": "The number of times the PAC file was used during the last 30 days" + }, + "lastModificationTime": { + "type": "integer", + "description": "The timestamp when the PAC file was last modified. This value is represented in Unix time." + }, + "lastModifiedBy": { + "type": "object", + "description": "The username of the admin who last modified the PAC file" + }, + "createTime": { + "type": "integer", + "description": "The timestamp when the PAC file was created. This value is represented in Unix time." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "post": { + "operationId": "pacfiles_CreateClonedPacFileVersion", + "summary": "CreateClonedPacFileVersion (Pacfiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the PAC file" + }, + "name": { + "type": "string", + "description": "The name of the PAC file" + }, + "description": { + "type": "string", + "description": "The description of the PAC file" + }, + "domain": { + "type": "string", + "description": "The domain of your organization to which the PAC file applies" + }, + "pacUrl": { + "type": "string", + "description": "The URL location of the PAC file that is auto-generated when the PAC file is added for the first time.\nNote: This value is not required in POST and PUT requests and the value is ignored if present." + }, + "pacContent": { + "type": "string", + "description": "The content of the PAC file.\nTo learn more, see Writing a PAC File. https://help.zscaler.com/zia/writing-pac-file" + }, + "editable": { + "type": "boolean", + "description": "Indicates whether the PAC file is editable" + }, + "pacSubURL": { + "type": "string", + "description": "Obfuscated domain name of the organization to which this PAC file applies" + }, + "pacUrlObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the PAC file URL is obfuscated.\nIf this value is true, the obfuscated URL is returned in the pacSubURL field." + }, + "pacVerificationStatus": { + "type": "string", + "description": "Indicates the verification status of the PAC file and if any errors are identified in the syntax\nSupported values are: VERIFY_NOERR, VERIFY_ERR, NOVERIFY" + }, + "pacVersionStatus": { + "type": "string", + "description": "Indicates the status of a specific version of a PAC file\nas whether it is deployed, staged for deployment, or is marked as the last known good version.\nSupported values are: DEPLOYED, STAGE, LKG" + }, + "pacVersion": { + "type": "integer", + "description": "The version number of the PAC file" + }, + "pacCommitMessage": { + "type": "string", + "description": "The commit message entered while saving the PAC file version as indicated by the pacVersion field" + }, + "totalHits": { + "type": "integer", + "description": "The number of times the PAC file was used during the last 30 days" + }, + "lastModificationTime": { + "type": "integer", + "description": "The timestamp when the PAC file was last modified. This value is represented in Unix time." + }, + "lastModifiedBy": { + "type": "object", + "description": "The username of the admin who last modified the PAC file" + }, + "createTime": { + "type": "integer", + "description": "The timestamp when the PAC file was created. This value is represented in Unix time." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the PAC file" + }, + "name": { + "type": "string", + "description": "The name of the PAC file" + }, + "description": { + "type": "string", + "description": "The description of the PAC file" + }, + "domain": { + "type": "string", + "description": "The domain of your organization to which the PAC file applies" + }, + "pacUrl": { + "type": "string", + "description": "The URL location of the PAC file that is auto-generated when the PAC file is added for the first time.\nNote: This value is not required in POST and PUT requests and the value is ignored if present." + }, + "pacContent": { + "type": "string", + "description": "The content of the PAC file.\nTo learn more, see Writing a PAC File. https://help.zscaler.com/zia/writing-pac-file" + }, + "editable": { + "type": "boolean", + "description": "Indicates whether the PAC file is editable" + }, + "pacSubURL": { + "type": "string", + "description": "Obfuscated domain name of the organization to which this PAC file applies" + }, + "pacUrlObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the PAC file URL is obfuscated.\nIf this value is true, the obfuscated URL is returned in the pacSubURL field." + }, + "pacVerificationStatus": { + "type": "string", + "description": "Indicates the verification status of the PAC file and if any errors are identified in the syntax\nSupported values are: VERIFY_NOERR, VERIFY_ERR, NOVERIFY" + }, + "pacVersionStatus": { + "type": "string", + "description": "Indicates the status of a specific version of a PAC file\nas whether it is deployed, staged for deployment, or is marked as the last known good version.\nSupported values are: DEPLOYED, STAGE, LKG" + }, + "pacVersion": { + "type": "integer", + "description": "The version number of the PAC file" + }, + "pacCommitMessage": { + "type": "string", + "description": "The commit message entered while saving the PAC file version as indicated by the pacVersion field" + }, + "totalHits": { + "type": "integer", + "description": "The number of times the PAC file was used during the last 30 days" + }, + "lastModificationTime": { + "type": "integer", + "description": "The timestamp when the PAC file was last modified. This value is represented in Unix time." + }, + "lastModifiedBy": { + "type": "object", + "description": "The username of the admin who last modified the PAC file" + }, + "createTime": { + "type": "integer", + "description": "The timestamp when the PAC file was created. This value is represented in Unix time." + } + } + } + } + } + } + } + }, + "/zia/api/v1/passwordExpiry/settings": { + "get": { + "operationId": "adminuserrolemgmt__admins_GetPasswordExpirySettings", + "summary": "GetPasswordExpirySettings (Adminuserrolemgmt / Admins)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin or auditor's user ID" + }, + "loginName": { + "type": "string", + "description": "Admin or auditor's login name. loginName is in email format and uses the domain name associated to the Zscaler account" + }, + "userName": { + "type": "string", + "description": "Admin or auditor's username" + }, + "email": { + "type": "string", + "description": "Admin or auditor's email address" + }, + "comments": { + "type": "string", + "description": "Additional information about the admin or auditor" + }, + "disabled": { + "type": "boolean", + "description": "Indicates whether or not the admin account is disabled" + }, + "password": { + "type": "string", + "description": "The admin's password. If admin single sign-on (SSO) is disabled, then this field is mandatory for POST requests. This information is not provided in a GET response.\"" + }, + "pwdLastModifiedTime": { + "type": "integer" + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not the admin can be edited or deleted" + }, + "isPasswordLoginAllowed": { + "type": "boolean", + "description": "The default is true when SAML Authentication is disabled. When SAML Authentication is enabled, this can be set to false in order to force the admin to login via SSO only." + }, + "isPasswordExpired": { + "type": "boolean", + "description": "Indicates whether or not an admin's password has expired" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether the user is an auditor. This attribute is subject to change." + }, + "isSecurityReportCommEnabled": { + "type": "boolean", + "description": "Communication for Security Report is enabled." + }, + "isServiceUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Service Update" + }, + "isProductUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Product Update" + }, + "isExecMobileAppEnabled": { + "type": "boolean", + "description": "Indicates whether or not Executive Insights App access is enabled for the admin" + }, + "adminScopescopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change" + }, + "adminScopeScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change" + }, + "adminScopeType": { + "type": "string", + "description": "The admin's scope. A scope is required for admins, but not applicable to auditors. This attribute is subject to change" + }, + "role": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "extensions": { + "type": "object" + } + }, + "description": "Role of the admin. This is not required for an auditor" + }, + "execMobileAppTokens": { + "type": "array", + "items": { + "type": "object", + "properties": { + "cloud": { + "type": "string" + }, + "orgId": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tokenId": { + "type": "string" + }, + "token": { + "type": "string" + }, + "tokenExpiry": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "deviceId": { + "type": "string" + }, + "deviceName": { + "type": "string" + } + } + }, + "description": "Read-only information about a Executive Insights App token, if it exists" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "adminuserrolemgmt__admins_UpdatePasswordExpirySettings", + "summary": "UpdatePasswordExpirySettings (Adminuserrolemgmt / Admins)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin or auditor's user ID" + }, + "loginName": { + "type": "string", + "description": "Admin or auditor's login name. loginName is in email format and uses the domain name associated to the Zscaler account" + }, + "userName": { + "type": "string", + "description": "Admin or auditor's username" + }, + "email": { + "type": "string", + "description": "Admin or auditor's email address" + }, + "comments": { + "type": "string", + "description": "Additional information about the admin or auditor" + }, + "disabled": { + "type": "boolean", + "description": "Indicates whether or not the admin account is disabled" + }, + "password": { + "type": "string", + "description": "The admin's password. If admin single sign-on (SSO) is disabled, then this field is mandatory for POST requests. This information is not provided in a GET response.\"" + }, + "pwdLastModifiedTime": { + "type": "integer" + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not the admin can be edited or deleted" + }, + "isPasswordLoginAllowed": { + "type": "boolean", + "description": "The default is true when SAML Authentication is disabled. When SAML Authentication is enabled, this can be set to false in order to force the admin to login via SSO only." + }, + "isPasswordExpired": { + "type": "boolean", + "description": "Indicates whether or not an admin's password has expired" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether the user is an auditor. This attribute is subject to change." + }, + "isSecurityReportCommEnabled": { + "type": "boolean", + "description": "Communication for Security Report is enabled." + }, + "isServiceUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Service Update" + }, + "isProductUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Product Update" + }, + "isExecMobileAppEnabled": { + "type": "boolean", + "description": "Indicates whether or not Executive Insights App access is enabled for the admin" + }, + "adminScopescopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change" + }, + "adminScopeScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change" + }, + "adminScopeType": { + "type": "string", + "description": "The admin's scope. A scope is required for admins, but not applicable to auditors. This attribute is subject to change" + }, + "role": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "extensions": { + "type": "object" + } + }, + "description": "Role of the admin. This is not required for an auditor" + }, + "execMobileAppTokens": { + "type": "array", + "items": { + "type": "object", + "properties": { + "cloud": { + "type": "string" + }, + "orgId": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tokenId": { + "type": "string" + }, + "token": { + "type": "string" + }, + "tokenExpiry": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "deviceId": { + "type": "string" + }, + "deviceName": { + "type": "string" + } + } + }, + "description": "Read-only information about a Executive Insights App token, if it exists" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Admin or auditor's user ID" + }, + "loginName": { + "type": "string", + "description": "Admin or auditor's login name. loginName is in email format and uses the domain name associated to the Zscaler account" + }, + "userName": { + "type": "string", + "description": "Admin or auditor's username" + }, + "email": { + "type": "string", + "description": "Admin or auditor's email address" + }, + "comments": { + "type": "string", + "description": "Additional information about the admin or auditor" + }, + "disabled": { + "type": "boolean", + "description": "Indicates whether or not the admin account is disabled" + }, + "password": { + "type": "string", + "description": "The admin's password. If admin single sign-on (SSO) is disabled, then this field is mandatory for POST requests. This information is not provided in a GET response.\"" + }, + "pwdLastModifiedTime": { + "type": "integer" + }, + "isNonEditable": { + "type": "boolean", + "description": "Indicates whether or not the admin can be edited or deleted" + }, + "isPasswordLoginAllowed": { + "type": "boolean", + "description": "The default is true when SAML Authentication is disabled. When SAML Authentication is enabled, this can be set to false in order to force the admin to login via SSO only." + }, + "isPasswordExpired": { + "type": "boolean", + "description": "Indicates whether or not an admin's password has expired" + }, + "isAuditor": { + "type": "boolean", + "description": "Indicates whether the user is an auditor. This attribute is subject to change." + }, + "isSecurityReportCommEnabled": { + "type": "boolean", + "description": "Communication for Security Report is enabled." + }, + "isServiceUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Service Update" + }, + "isProductUpdateCommEnabled": { + "type": "boolean", + "description": "Communication setting for Product Update" + }, + "isExecMobileAppEnabled": { + "type": "boolean", + "description": "Indicates whether or not Executive Insights App access is enabled for the admin" + }, + "adminScopescopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change" + }, + "adminScopeScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change" + }, + "adminScopeType": { + "type": "string", + "description": "The admin's scope. A scope is required for admins, but not applicable to auditors. This attribute is subject to change" + }, + "role": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "isNameL10nTag": { + "type": "boolean" + }, + "extensions": { + "type": "object" + } + }, + "description": "Role of the admin. This is not required for an auditor" + }, + "execMobileAppTokens": { + "type": "array", + "items": { + "type": "object", + "properties": { + "cloud": { + "type": "string" + }, + "orgId": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tokenId": { + "type": "string" + }, + "token": { + "type": "string" + }, + "tokenExpiry": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "deviceId": { + "type": "string" + }, + "deviceName": { + "type": "string" + } + } + }, + "description": "Read-only information about a Executive Insights App token, if it exists" + } + } + } + } + } + } + } + }, + "/zia/api/v1/proxies": { + "get": { + "operationId": "forwarding_control_policy__proxies_GetByName", + "summary": "GetByName (Forwarding Control Policy / Proxies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Proxy ID" + }, + "name": { + "type": "string", + "description": "Proxy name" + }, + "type": { + "type": "string", + "description": "Gateway type - Supported Values: PROXYCHAIN, ZIA, ECSELF" + }, + "address": { + "type": "string", + "description": "The IP address or the FQDN of the third-party proxy service" + }, + "port": { + "type": "integer", + "description": "The port number on which the third-party proxy service listens to the requests forwarded from Zscaler" + }, + "cert": { + "type": "object", + "description": "The root certificate used by the third-party proxy to perform SSL inspection.\nThis root certificate is used by Zscaler to validate the SSL leaf certificates signed by the upstream proxy.\nThe required root certificate appears in this drop-down menu only if it is uploaded from the Administration > Root Certificates page." + }, + "description": { + "type": "string", + "description": "Additional notes or information" + }, + "insertXauHeader": { + "type": "boolean", + "description": "Flag indicating whether X-Authenticated-User header is added by the proxy. Enable to automatically insert authenticated user ID to the HTTP header, X-Authenticated-User." + }, + "base64EncodeXauHeader": { + "type": "boolean", + "description": "Flag indicating whether the added X-Authenticated-User header is Base64 encoded. When enabled, the user ID is encoded using the Base64 encoding method." + }, + "lastModifiedBy": { + "type": "object", + "description": "Last user that modified the proxy" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp of when the proxy was last modified" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "forwarding_control_policy__proxies_Create", + "summary": "Create (Forwarding Control Policy / Proxies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Proxy ID" + }, + "name": { + "type": "string", + "description": "Proxy name" + }, + "type": { + "type": "string", + "description": "Gateway type - Supported Values: PROXYCHAIN, ZIA, ECSELF" + }, + "address": { + "type": "string", + "description": "The IP address or the FQDN of the third-party proxy service" + }, + "port": { + "type": "integer", + "description": "The port number on which the third-party proxy service listens to the requests forwarded from Zscaler" + }, + "cert": { + "type": "object", + "description": "The root certificate used by the third-party proxy to perform SSL inspection.\nThis root certificate is used by Zscaler to validate the SSL leaf certificates signed by the upstream proxy.\nThe required root certificate appears in this drop-down menu only if it is uploaded from the Administration > Root Certificates page." + }, + "description": { + "type": "string", + "description": "Additional notes or information" + }, + "insertXauHeader": { + "type": "boolean", + "description": "Flag indicating whether X-Authenticated-User header is added by the proxy. Enable to automatically insert authenticated user ID to the HTTP header, X-Authenticated-User." + }, + "base64EncodeXauHeader": { + "type": "boolean", + "description": "Flag indicating whether the added X-Authenticated-User header is Base64 encoded. When enabled, the user ID is encoded using the Base64 encoding method." + }, + "lastModifiedBy": { + "type": "object", + "description": "Last user that modified the proxy" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp of when the proxy was last modified" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Proxy ID" + }, + "name": { + "type": "string", + "description": "Proxy name" + }, + "type": { + "type": "string", + "description": "Gateway type - Supported Values: PROXYCHAIN, ZIA, ECSELF" + }, + "address": { + "type": "string", + "description": "The IP address or the FQDN of the third-party proxy service" + }, + "port": { + "type": "integer", + "description": "The port number on which the third-party proxy service listens to the requests forwarded from Zscaler" + }, + "cert": { + "type": "object", + "description": "The root certificate used by the third-party proxy to perform SSL inspection.\nThis root certificate is used by Zscaler to validate the SSL leaf certificates signed by the upstream proxy.\nThe required root certificate appears in this drop-down menu only if it is uploaded from the Administration > Root Certificates page." + }, + "description": { + "type": "string", + "description": "Additional notes or information" + }, + "insertXauHeader": { + "type": "boolean", + "description": "Flag indicating whether X-Authenticated-User header is added by the proxy. Enable to automatically insert authenticated user ID to the HTTP header, X-Authenticated-User." + }, + "base64EncodeXauHeader": { + "type": "boolean", + "description": "Flag indicating whether the added X-Authenticated-User header is Base64 encoded. When enabled, the user ID is encoded using the Base64 encoding method." + }, + "lastModifiedBy": { + "type": "object", + "description": "Last user that modified the proxy" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp of when the proxy was last modified" + } + } + } + } + } + } + } + }, + "/zia/api/v1/proxies/{id}": { + "get": { + "operationId": "forwarding_control_policy__proxies_Get", + "summary": "Get (Forwarding Control Policy / Proxies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Proxy ID" + }, + "name": { + "type": "string", + "description": "Proxy name" + }, + "type": { + "type": "string", + "description": "Gateway type - Supported Values: PROXYCHAIN, ZIA, ECSELF" + }, + "address": { + "type": "string", + "description": "The IP address or the FQDN of the third-party proxy service" + }, + "port": { + "type": "integer", + "description": "The port number on which the third-party proxy service listens to the requests forwarded from Zscaler" + }, + "cert": { + "type": "object", + "description": "The root certificate used by the third-party proxy to perform SSL inspection.\nThis root certificate is used by Zscaler to validate the SSL leaf certificates signed by the upstream proxy.\nThe required root certificate appears in this drop-down menu only if it is uploaded from the Administration > Root Certificates page." + }, + "description": { + "type": "string", + "description": "Additional notes or information" + }, + "insertXauHeader": { + "type": "boolean", + "description": "Flag indicating whether X-Authenticated-User header is added by the proxy. Enable to automatically insert authenticated user ID to the HTTP header, X-Authenticated-User." + }, + "base64EncodeXauHeader": { + "type": "boolean", + "description": "Flag indicating whether the added X-Authenticated-User header is Base64 encoded. When enabled, the user ID is encoded using the Base64 encoding method." + }, + "lastModifiedBy": { + "type": "object", + "description": "Last user that modified the proxy" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp of when the proxy was last modified" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "forwarding_control_policy__proxies_Update", + "summary": "Update (Forwarding Control Policy / Proxies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Proxy ID" + }, + "name": { + "type": "string", + "description": "Proxy name" + }, + "type": { + "type": "string", + "description": "Gateway type - Supported Values: PROXYCHAIN, ZIA, ECSELF" + }, + "address": { + "type": "string", + "description": "The IP address or the FQDN of the third-party proxy service" + }, + "port": { + "type": "integer", + "description": "The port number on which the third-party proxy service listens to the requests forwarded from Zscaler" + }, + "cert": { + "type": "object", + "description": "The root certificate used by the third-party proxy to perform SSL inspection.\nThis root certificate is used by Zscaler to validate the SSL leaf certificates signed by the upstream proxy.\nThe required root certificate appears in this drop-down menu only if it is uploaded from the Administration > Root Certificates page." + }, + "description": { + "type": "string", + "description": "Additional notes or information" + }, + "insertXauHeader": { + "type": "boolean", + "description": "Flag indicating whether X-Authenticated-User header is added by the proxy. Enable to automatically insert authenticated user ID to the HTTP header, X-Authenticated-User." + }, + "base64EncodeXauHeader": { + "type": "boolean", + "description": "Flag indicating whether the added X-Authenticated-User header is Base64 encoded. When enabled, the user ID is encoded using the Base64 encoding method." + }, + "lastModifiedBy": { + "type": "object", + "description": "Last user that modified the proxy" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp of when the proxy was last modified" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Proxy ID" + }, + "name": { + "type": "string", + "description": "Proxy name" + }, + "type": { + "type": "string", + "description": "Gateway type - Supported Values: PROXYCHAIN, ZIA, ECSELF" + }, + "address": { + "type": "string", + "description": "The IP address or the FQDN of the third-party proxy service" + }, + "port": { + "type": "integer", + "description": "The port number on which the third-party proxy service listens to the requests forwarded from Zscaler" + }, + "cert": { + "type": "object", + "description": "The root certificate used by the third-party proxy to perform SSL inspection.\nThis root certificate is used by Zscaler to validate the SSL leaf certificates signed by the upstream proxy.\nThe required root certificate appears in this drop-down menu only if it is uploaded from the Administration > Root Certificates page." + }, + "description": { + "type": "string", + "description": "Additional notes or information" + }, + "insertXauHeader": { + "type": "boolean", + "description": "Flag indicating whether X-Authenticated-User header is added by the proxy. Enable to automatically insert authenticated user ID to the HTTP header, X-Authenticated-User." + }, + "base64EncodeXauHeader": { + "type": "boolean", + "description": "Flag indicating whether the added X-Authenticated-User header is Base64 encoded. When enabled, the user ID is encoded using the Base64 encoding method." + }, + "lastModifiedBy": { + "type": "object", + "description": "Last user that modified the proxy" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp of when the proxy was last modified" + } + } + } + } + } + } + }, + "delete": { + "operationId": "forwarding_control_policy__proxies_Delete", + "summary": "Delete (Forwarding Control Policy / Proxies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Proxy ID" + }, + "name": { + "type": "string", + "description": "Proxy name" + }, + "type": { + "type": "string", + "description": "Gateway type - Supported Values: PROXYCHAIN, ZIA, ECSELF" + }, + "address": { + "type": "string", + "description": "The IP address or the FQDN of the third-party proxy service" + }, + "port": { + "type": "integer", + "description": "The port number on which the third-party proxy service listens to the requests forwarded from Zscaler" + }, + "cert": { + "type": "object", + "description": "The root certificate used by the third-party proxy to perform SSL inspection.\nThis root certificate is used by Zscaler to validate the SSL leaf certificates signed by the upstream proxy.\nThe required root certificate appears in this drop-down menu only if it is uploaded from the Administration > Root Certificates page." + }, + "description": { + "type": "string", + "description": "Additional notes or information" + }, + "insertXauHeader": { + "type": "boolean", + "description": "Flag indicating whether X-Authenticated-User header is added by the proxy. Enable to automatically insert authenticated user ID to the HTTP header, X-Authenticated-User." + }, + "base64EncodeXauHeader": { + "type": "boolean", + "description": "Flag indicating whether the added X-Authenticated-User header is Base64 encoded. When enabled, the user ID is encoded using the Base64 encoding method." + }, + "lastModifiedBy": { + "type": "object", + "description": "Last user that modified the proxy" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp of when the proxy was last modified" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/proxyGateways": { + "get": { + "operationId": "forwarding_control_policy__proxy_gateways_GetByName", + "summary": "GetByName (Forwarding Control Policy / Proxy Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Proxy gateway" + }, + "name": { + "type": "string", + "description": "The name of the Proxy gateway" + }, + "description": { + "type": "string", + "description": "Additional details about the Proxy gateway" + }, + "primaryProxy": { + "type": "object", + "description": "The primary proxy for the gateway. This field is not applicable to the Lite API." + }, + "secondaryProxy": { + "type": "object", + "description": "The seconday proxy for the gateway. This field is not applicable to the Lite API." + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin user that last modified the ZPA gateway" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the ZPA gateway was last modified" + }, + "failClosed": { + "type": "boolean", + "description": "Indicates whether fail close is enabled to drop the traffic or disabled to allow the traffic when both primary and secondary proxies defined in this gateway are unreachable." + }, + "type": { + "type": "string", + "description": "Proxy type: Supported Values: \"PROXYCHAIN\", \"ZIA\", \"ECSELF\"" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/proxyGateways/lite": { + "get": { + "operationId": "forwarding_control_policy__proxy_gateways_GetLite", + "summary": "GetLite (Forwarding Control Policy / Proxy Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the Proxy gateway" + }, + "name": { + "type": "string", + "description": "The name of the Proxy gateway" + }, + "description": { + "type": "string", + "description": "Additional details about the Proxy gateway" + }, + "primaryProxy": { + "type": "object", + "description": "The primary proxy for the gateway. This field is not applicable to the Lite API." + }, + "secondaryProxy": { + "type": "object", + "description": "The seconday proxy for the gateway. This field is not applicable to the Lite API." + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin user that last modified the ZPA gateway" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the ZPA gateway was last modified" + }, + "failClosed": { + "type": "boolean", + "description": "Indicates whether fail close is enabled to drop the traffic or disabled to allow the traffic when both primary and secondary proxies defined in this gateway are unreachable." + }, + "type": { + "type": "string", + "description": "Proxy type: Supported Values: \"PROXYCHAIN\", \"ZIA\", \"ECSELF\"" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/quarantineTombstoneTemplate/lite": { + "get": { + "operationId": "saas_security_api_GetQuarantineTombstoneLite", + "summary": "GetQuarantineTombstoneLite (Saas Security Api)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "profileId": { + "type": "integer", + "description": "Domain profile ID" + }, + "profileName": { + "type": "string", + "description": "Domain profile name" + }, + "includeCompanyDomains": { + "type": "boolean", + "description": "A Boolean flag to determine if the organizational domains have to be included in the domain profile" + }, + "includeSubdomains": { + "type": "boolean", + "description": "A Boolean flag to determine whether or not to include subdomains" + }, + "description": { + "type": "string", + "description": "Additional notes or information about the domain profile" + }, + "customDomains": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of custom domains for the domain profile. There can be one or more custom domains." + }, + "predefinedEmailDomains": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of predefined email service provider domains for the domain profile\nSee SaaS Security API for supported values: https://help.zscaler.com/zia/saas-security-api#/domainProfiles/lite-get" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/region/byIPAddress/{id}": { + "get": { + "operationId": "trafficforwarding__region__ip_address_GetByIPAddress", + "summary": "GetByIPAddress (Trafficforwarding / Region / Ip Address)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "cityGeoId": { + "type": "integer", + "description": "The geographical ID of the city" + }, + "stateGeoId": { + "type": "integer", + "description": "The geographical ID of the state" + }, + "latitude": { + "type": "number", + "description": "The latitude coordinate of the city" + }, + "longitude": { + "type": "number", + "description": "The longitude coordinate of the city" + }, + "cityName": { + "type": "string", + "description": "The name of the city" + }, + "stateName": { + "type": "string", + "description": "The name of the state, province, or territory of a country" + }, + "countryName": { + "type": "string", + "description": "The name of the country" + }, + "countryCode": { + "type": "string", + "description": "The ISO standard two-letter country code" + }, + "postalCode": { + "type": "string", + "description": "The postal code" + }, + "continentCode": { + "type": "string", + "description": "The ISO standard two-letter continent code" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/region/search": { + "get": { + "operationId": "trafficforwarding__region__search_GetDatacenterRegion", + "summary": "GetDatacenterRegion (Trafficforwarding / Region / Search)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "cityGeoId": { + "type": "integer", + "description": "The geographical ID of the city" + }, + "stateGeoId": { + "type": "integer", + "description": "The geographical ID of the state" + }, + "latitude": { + "type": "number", + "description": "The latitude coordinate of the city" + }, + "longitude": { + "type": "number", + "description": "The longitude coordinate of the city" + }, + "cityName": { + "type": "string", + "description": "The name of the city" + }, + "stateName": { + "type": "string", + "description": "The name of the state, province, or territory of a country" + }, + "countryName": { + "type": "string", + "description": "The name of the country" + }, + "countryCode": { + "type": "string", + "description": "The ISO standard two-letter country code" + }, + "postalCode": { + "type": "string", + "description": "The postal code" + }, + "continentCode": { + "type": "string", + "description": "The ISO standard two-letter continent code" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/remoteAssistance": { + "get": { + "operationId": "remote_assistance_GetRemoteAssistance", + "summary": "GetRemoteAssistance (Remote Assistance)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "viewOnlyUntil": { + "type": "integer", + "description": "The time until when view-only access is granted. Unix time is used." + }, + "fullAccessUntil": { + "type": "integer", + "description": "A Boolean value that indicates whether the user names for single sign-on users should be obfuscated or visible\nNOTE: This is incorrect: The API swagger description indicates Boolean but the value is int." + }, + "usernameObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the user names for single sign-on users should be obfuscated or visible" + }, + "deviceInfoObfuscate": { + "type": "boolean", + "description": "A Boolean value that indicates whether the device information (Device Hostname, Device Name, and Device Owner) should be obfuscated or visible on the Dashboard and Analytics pages" + } + } + } + } + } + } + } + }, + "put": { + "operationId": "remote_assistance_UpdateRemoteAssistance", + "summary": "UpdateRemoteAssistance (Remote Assistance)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "viewOnlyUntil": { + "type": "integer", + "description": "The time until when view-only access is granted. Unix time is used." + }, + "fullAccessUntil": { + "type": "integer", + "description": "A Boolean value that indicates whether the user names for single sign-on users should be obfuscated or visible\nNOTE: This is incorrect: The API swagger description indicates Boolean but the value is int." + }, + "usernameObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the user names for single sign-on users should be obfuscated or visible" + }, + "deviceInfoObfuscate": { + "type": "boolean", + "description": "A Boolean value that indicates whether the device information (Device Hostname, Device Name, and Device Owner) should be obfuscated or visible on the Dashboard and Analytics pages" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "viewOnlyUntil": { + "type": "integer", + "description": "The time until when view-only access is granted. Unix time is used." + }, + "fullAccessUntil": { + "type": "integer", + "description": "A Boolean value that indicates whether the user names for single sign-on users should be obfuscated or visible\nNOTE: This is incorrect: The API swagger description indicates Boolean but the value is int." + }, + "usernameObfuscated": { + "type": "boolean", + "description": "A Boolean value that indicates whether the user names for single sign-on users should be obfuscated or visible" + }, + "deviceInfoObfuscate": { + "type": "boolean", + "description": "A Boolean value that indicates whether the device information (Device Hostname, Device Name, and Device Owner) should be obfuscated or visible on the Dashboard and Analytics pages" + } + } + } + } + } + } + } + }, + "/zia/api/v1/riskProfiles": { + "get": { + "operationId": "cloudapplications__risk_profiles_GetByName", + "summary": "GetByName (Cloudapplications / Risk Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "profileName": { + "type": "string" + }, + "profileType": { + "type": "string" + }, + "status": { + "type": "string" + }, + "excludeCertificates": { + "type": "integer" + }, + "poorItemsOfService": { + "type": "string" + }, + "adminAuditLogs": { + "type": "string" + }, + "dataBreach": { + "type": "string" + }, + "sourceIpRestrictions": { + "type": "string" + }, + "mfaSupport": { + "type": "string" + }, + "sslPinned": { + "type": "string" + }, + "httpSecurityHeaders": { + "type": "string" + }, + "evasive": { + "type": "string" + }, + "dnsCaaPolicy": { + "type": "string" + }, + "weakCipherSupport": { + "type": "string" + }, + "passwordStrength": { + "type": "string" + }, + "sslCertValidity": { + "type": "string" + }, + "vulnerability": { + "type": "string" + }, + "malwareScanningForContent": { + "type": "string" + }, + "fileSharing": { + "type": "string" + }, + "sslCertKeySize": { + "type": "string" + }, + "vulnerableToHeartBleed": { + "type": "string" + }, + "vulnerableToLogJam": { + "type": "string" + }, + "vulnerableToPoodle": { + "type": "string" + }, + "vulnerabilityDisclosure": { + "type": "string" + }, + "supportForWaf": { + "type": "string" + }, + "remoteScreenSharing": { + "type": "string" + }, + "senderPolicyFramework": { + "type": "string" + }, + "domainKeysIdentifiedMail": { + "type": "string" + }, + "domainBasedMessageAuth": { + "type": "string" + }, + "lastModTime": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "certifications": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataEncryptionInTransit": { + "type": "array", + "items": { + "type": "string" + } + }, + "riskIndex": { + "type": "array", + "items": { + "type": "integer" + } + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "cloudapplications__risk_profiles_Create", + "summary": "Create (Cloudapplications / Risk Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "profileName": { + "type": "string" + }, + "profileType": { + "type": "string" + }, + "status": { + "type": "string" + }, + "excludeCertificates": { + "type": "integer" + }, + "poorItemsOfService": { + "type": "string" + }, + "adminAuditLogs": { + "type": "string" + }, + "dataBreach": { + "type": "string" + }, + "sourceIpRestrictions": { + "type": "string" + }, + "mfaSupport": { + "type": "string" + }, + "sslPinned": { + "type": "string" + }, + "httpSecurityHeaders": { + "type": "string" + }, + "evasive": { + "type": "string" + }, + "dnsCaaPolicy": { + "type": "string" + }, + "weakCipherSupport": { + "type": "string" + }, + "passwordStrength": { + "type": "string" + }, + "sslCertValidity": { + "type": "string" + }, + "vulnerability": { + "type": "string" + }, + "malwareScanningForContent": { + "type": "string" + }, + "fileSharing": { + "type": "string" + }, + "sslCertKeySize": { + "type": "string" + }, + "vulnerableToHeartBleed": { + "type": "string" + }, + "vulnerableToLogJam": { + "type": "string" + }, + "vulnerableToPoodle": { + "type": "string" + }, + "vulnerabilityDisclosure": { + "type": "string" + }, + "supportForWaf": { + "type": "string" + }, + "remoteScreenSharing": { + "type": "string" + }, + "senderPolicyFramework": { + "type": "string" + }, + "domainKeysIdentifiedMail": { + "type": "string" + }, + "domainBasedMessageAuth": { + "type": "string" + }, + "lastModTime": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "certifications": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataEncryptionInTransit": { + "type": "array", + "items": { + "type": "string" + } + }, + "riskIndex": { + "type": "array", + "items": { + "type": "integer" + } + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "profileName": { + "type": "string" + }, + "profileType": { + "type": "string" + }, + "status": { + "type": "string" + }, + "excludeCertificates": { + "type": "integer" + }, + "poorItemsOfService": { + "type": "string" + }, + "adminAuditLogs": { + "type": "string" + }, + "dataBreach": { + "type": "string" + }, + "sourceIpRestrictions": { + "type": "string" + }, + "mfaSupport": { + "type": "string" + }, + "sslPinned": { + "type": "string" + }, + "httpSecurityHeaders": { + "type": "string" + }, + "evasive": { + "type": "string" + }, + "dnsCaaPolicy": { + "type": "string" + }, + "weakCipherSupport": { + "type": "string" + }, + "passwordStrength": { + "type": "string" + }, + "sslCertValidity": { + "type": "string" + }, + "vulnerability": { + "type": "string" + }, + "malwareScanningForContent": { + "type": "string" + }, + "fileSharing": { + "type": "string" + }, + "sslCertKeySize": { + "type": "string" + }, + "vulnerableToHeartBleed": { + "type": "string" + }, + "vulnerableToLogJam": { + "type": "string" + }, + "vulnerableToPoodle": { + "type": "string" + }, + "vulnerabilityDisclosure": { + "type": "string" + }, + "supportForWaf": { + "type": "string" + }, + "remoteScreenSharing": { + "type": "string" + }, + "senderPolicyFramework": { + "type": "string" + }, + "domainKeysIdentifiedMail": { + "type": "string" + }, + "domainBasedMessageAuth": { + "type": "string" + }, + "lastModTime": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "certifications": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataEncryptionInTransit": { + "type": "array", + "items": { + "type": "string" + } + }, + "riskIndex": { + "type": "array", + "items": { + "type": "integer" + } + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/riskProfiles/{id}": { + "get": { + "operationId": "cloudapplications__risk_profiles_Get", + "summary": "Get (Cloudapplications / Risk Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "profileName": { + "type": "string" + }, + "profileType": { + "type": "string" + }, + "status": { + "type": "string" + }, + "excludeCertificates": { + "type": "integer" + }, + "poorItemsOfService": { + "type": "string" + }, + "adminAuditLogs": { + "type": "string" + }, + "dataBreach": { + "type": "string" + }, + "sourceIpRestrictions": { + "type": "string" + }, + "mfaSupport": { + "type": "string" + }, + "sslPinned": { + "type": "string" + }, + "httpSecurityHeaders": { + "type": "string" + }, + "evasive": { + "type": "string" + }, + "dnsCaaPolicy": { + "type": "string" + }, + "weakCipherSupport": { + "type": "string" + }, + "passwordStrength": { + "type": "string" + }, + "sslCertValidity": { + "type": "string" + }, + "vulnerability": { + "type": "string" + }, + "malwareScanningForContent": { + "type": "string" + }, + "fileSharing": { + "type": "string" + }, + "sslCertKeySize": { + "type": "string" + }, + "vulnerableToHeartBleed": { + "type": "string" + }, + "vulnerableToLogJam": { + "type": "string" + }, + "vulnerableToPoodle": { + "type": "string" + }, + "vulnerabilityDisclosure": { + "type": "string" + }, + "supportForWaf": { + "type": "string" + }, + "remoteScreenSharing": { + "type": "string" + }, + "senderPolicyFramework": { + "type": "string" + }, + "domainKeysIdentifiedMail": { + "type": "string" + }, + "domainBasedMessageAuth": { + "type": "string" + }, + "lastModTime": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "certifications": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataEncryptionInTransit": { + "type": "array", + "items": { + "type": "string" + } + }, + "riskIndex": { + "type": "array", + "items": { + "type": "integer" + } + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "cloudapplications__risk_profiles_Update", + "summary": "Update (Cloudapplications / Risk Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "profileName": { + "type": "string" + }, + "profileType": { + "type": "string" + }, + "status": { + "type": "string" + }, + "excludeCertificates": { + "type": "integer" + }, + "poorItemsOfService": { + "type": "string" + }, + "adminAuditLogs": { + "type": "string" + }, + "dataBreach": { + "type": "string" + }, + "sourceIpRestrictions": { + "type": "string" + }, + "mfaSupport": { + "type": "string" + }, + "sslPinned": { + "type": "string" + }, + "httpSecurityHeaders": { + "type": "string" + }, + "evasive": { + "type": "string" + }, + "dnsCaaPolicy": { + "type": "string" + }, + "weakCipherSupport": { + "type": "string" + }, + "passwordStrength": { + "type": "string" + }, + "sslCertValidity": { + "type": "string" + }, + "vulnerability": { + "type": "string" + }, + "malwareScanningForContent": { + "type": "string" + }, + "fileSharing": { + "type": "string" + }, + "sslCertKeySize": { + "type": "string" + }, + "vulnerableToHeartBleed": { + "type": "string" + }, + "vulnerableToLogJam": { + "type": "string" + }, + "vulnerableToPoodle": { + "type": "string" + }, + "vulnerabilityDisclosure": { + "type": "string" + }, + "supportForWaf": { + "type": "string" + }, + "remoteScreenSharing": { + "type": "string" + }, + "senderPolicyFramework": { + "type": "string" + }, + "domainKeysIdentifiedMail": { + "type": "string" + }, + "domainBasedMessageAuth": { + "type": "string" + }, + "lastModTime": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "certifications": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataEncryptionInTransit": { + "type": "array", + "items": { + "type": "string" + } + }, + "riskIndex": { + "type": "array", + "items": { + "type": "integer" + } + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "profileName": { + "type": "string" + }, + "profileType": { + "type": "string" + }, + "status": { + "type": "string" + }, + "excludeCertificates": { + "type": "integer" + }, + "poorItemsOfService": { + "type": "string" + }, + "adminAuditLogs": { + "type": "string" + }, + "dataBreach": { + "type": "string" + }, + "sourceIpRestrictions": { + "type": "string" + }, + "mfaSupport": { + "type": "string" + }, + "sslPinned": { + "type": "string" + }, + "httpSecurityHeaders": { + "type": "string" + }, + "evasive": { + "type": "string" + }, + "dnsCaaPolicy": { + "type": "string" + }, + "weakCipherSupport": { + "type": "string" + }, + "passwordStrength": { + "type": "string" + }, + "sslCertValidity": { + "type": "string" + }, + "vulnerability": { + "type": "string" + }, + "malwareScanningForContent": { + "type": "string" + }, + "fileSharing": { + "type": "string" + }, + "sslCertKeySize": { + "type": "string" + }, + "vulnerableToHeartBleed": { + "type": "string" + }, + "vulnerableToLogJam": { + "type": "string" + }, + "vulnerableToPoodle": { + "type": "string" + }, + "vulnerabilityDisclosure": { + "type": "string" + }, + "supportForWaf": { + "type": "string" + }, + "remoteScreenSharing": { + "type": "string" + }, + "senderPolicyFramework": { + "type": "string" + }, + "domainKeysIdentifiedMail": { + "type": "string" + }, + "domainBasedMessageAuth": { + "type": "string" + }, + "lastModTime": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "certifications": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataEncryptionInTransit": { + "type": "array", + "items": { + "type": "string" + } + }, + "riskIndex": { + "type": "array", + "items": { + "type": "integer" + } + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "cloudapplications__risk_profiles_Delete", + "summary": "Delete (Cloudapplications / Risk Profiles)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "profileName": { + "type": "string" + }, + "profileType": { + "type": "string" + }, + "status": { + "type": "string" + }, + "excludeCertificates": { + "type": "integer" + }, + "poorItemsOfService": { + "type": "string" + }, + "adminAuditLogs": { + "type": "string" + }, + "dataBreach": { + "type": "string" + }, + "sourceIpRestrictions": { + "type": "string" + }, + "mfaSupport": { + "type": "string" + }, + "sslPinned": { + "type": "string" + }, + "httpSecurityHeaders": { + "type": "string" + }, + "evasive": { + "type": "string" + }, + "dnsCaaPolicy": { + "type": "string" + }, + "weakCipherSupport": { + "type": "string" + }, + "passwordStrength": { + "type": "string" + }, + "sslCertValidity": { + "type": "string" + }, + "vulnerability": { + "type": "string" + }, + "malwareScanningForContent": { + "type": "string" + }, + "fileSharing": { + "type": "string" + }, + "sslCertKeySize": { + "type": "string" + }, + "vulnerableToHeartBleed": { + "type": "string" + }, + "vulnerableToLogJam": { + "type": "string" + }, + "vulnerableToPoodle": { + "type": "string" + }, + "vulnerabilityDisclosure": { + "type": "string" + }, + "supportForWaf": { + "type": "string" + }, + "remoteScreenSharing": { + "type": "string" + }, + "senderPolicyFramework": { + "type": "string" + }, + "domainKeysIdentifiedMail": { + "type": "string" + }, + "domainBasedMessageAuth": { + "type": "string" + }, + "lastModTime": { + "type": "integer" + }, + "createTime": { + "type": "integer" + }, + "certifications": { + "type": "array", + "items": { + "type": "string" + } + }, + "dataEncryptionInTransit": { + "type": "array", + "items": { + "type": "string" + } + }, + "riskIndex": { + "type": "array", + "items": { + "type": "integer" + } + }, + "modifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/ruleLabels": { + "post": { + "operationId": "rule_labels_Create", + "summary": "Create (Rule Labels)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "get": { + "operationId": "rule_labels_GetAll", + "summary": "GetAll (Rule Labels)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/ruleLabels/{id}": { + "get": { + "operationId": "rule_labels_Get", + "summary": "Get (Rule Labels)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "rule_labels_Update", + "summary": "Update (Rule Labels)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "delete": { + "operationId": "rule_labels_Delete", + "summary": "Delete (Rule Labels)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/sandbox/report/": { + "get": { + "operationId": "sandbox__sandbox_report_GetReportMD5Hash", + "summary": "GetReportMD5Hash (Sandbox / Sandbox Report)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "startTime": { + "type": "integer" + }, + "used": { + "type": "integer" + }, + "allowed": { + "type": "integer" + }, + "scale": { + "type": "string" + }, + "unused": { + "type": "integer" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/sandbox/report/quota": { + "get": { + "operationId": "sandbox__sandbox_report_GetRatingQuota", + "summary": "GetRatingQuota (Sandbox / Sandbox Report)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "startTime": { + "type": "integer" + }, + "used": { + "type": "integer" + }, + "allowed": { + "type": "integer" + }, + "scale": { + "type": "string" + }, + "unused": { + "type": "integer" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/sandboxRules": { + "get": { + "operationId": "sandbox__sandbox_rules_GetByName", + "summary": "GetByName (Sandbox / Sandbox Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier generated for the rule" + }, + "name": { + "type": "string", + "description": "The name of the Sandbox rule" + }, + "description": { + "type": "string", + "description": "Additional information about the Sandbox rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Policy rules are evaluated in ascending numerical order (Rule 1 before Rule 2, and so on), and this field specifies the order of execution for the rule." + }, + "baRuleAction": { + "type": "string", + "description": "The action configured for the rule that must take place if the traffic matches the rule criteria. Supported values: \"ALLOW\" and \"BLOCK\"" + }, + "firstTimeEnable": { + "type": "boolean", + "description": "A Boolean value indicating whether a First-Time Action is specifically configured for the rule." + }, + "firstTimeOperation": { + "type": "string", + "description": "The action that must take place when users download unknown files for the first time\nSupported values: \"ALLOW_SCAN\", \"QUARANTINE\", \"ALLOW_NOSCAN\", \"QUARANTINE_ISOLATE\"" + }, + "mlActionEnabled": { + "type": "boolean", + "description": "When set to true, this indicates that 'Machine Learning Intelligence Action' checkbox has been checked on" + }, + "byThreatScore": { + "type": "integer" + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rule applies" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "baPolicyCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The threat categories to which the rule applies" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "sandbox__sandbox_rules_Create", + "summary": "Create (Sandbox / Sandbox Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier generated for the rule" + }, + "name": { + "type": "string", + "description": "The name of the Sandbox rule" + }, + "description": { + "type": "string", + "description": "Additional information about the Sandbox rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Policy rules are evaluated in ascending numerical order (Rule 1 before Rule 2, and so on), and this field specifies the order of execution for the rule." + }, + "baRuleAction": { + "type": "string", + "description": "The action configured for the rule that must take place if the traffic matches the rule criteria. Supported values: \"ALLOW\" and \"BLOCK\"" + }, + "firstTimeEnable": { + "type": "boolean", + "description": "A Boolean value indicating whether a First-Time Action is specifically configured for the rule." + }, + "firstTimeOperation": { + "type": "string", + "description": "The action that must take place when users download unknown files for the first time\nSupported values: \"ALLOW_SCAN\", \"QUARANTINE\", \"ALLOW_NOSCAN\", \"QUARANTINE_ISOLATE\"" + }, + "mlActionEnabled": { + "type": "boolean", + "description": "When set to true, this indicates that 'Machine Learning Intelligence Action' checkbox has been checked on" + }, + "byThreatScore": { + "type": "integer" + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rule applies" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "baPolicyCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The threat categories to which the rule applies" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier generated for the rule" + }, + "name": { + "type": "string", + "description": "The name of the Sandbox rule" + }, + "description": { + "type": "string", + "description": "Additional information about the Sandbox rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Policy rules are evaluated in ascending numerical order (Rule 1 before Rule 2, and so on), and this field specifies the order of execution for the rule." + }, + "baRuleAction": { + "type": "string", + "description": "The action configured for the rule that must take place if the traffic matches the rule criteria. Supported values: \"ALLOW\" and \"BLOCK\"" + }, + "firstTimeEnable": { + "type": "boolean", + "description": "A Boolean value indicating whether a First-Time Action is specifically configured for the rule." + }, + "firstTimeOperation": { + "type": "string", + "description": "The action that must take place when users download unknown files for the first time\nSupported values: \"ALLOW_SCAN\", \"QUARANTINE\", \"ALLOW_NOSCAN\", \"QUARANTINE_ISOLATE\"" + }, + "mlActionEnabled": { + "type": "boolean", + "description": "When set to true, this indicates that 'Machine Learning Intelligence Action' checkbox has been checked on" + }, + "byThreatScore": { + "type": "integer" + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rule applies" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "baPolicyCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The threat categories to which the rule applies" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + } + } + } + } + } + } + } + }, + "/zia/api/v1/sandboxRules/{id}": { + "get": { + "operationId": "sandbox__sandbox_rules_Get", + "summary": "Get (Sandbox / Sandbox Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier generated for the rule" + }, + "name": { + "type": "string", + "description": "The name of the Sandbox rule" + }, + "description": { + "type": "string", + "description": "Additional information about the Sandbox rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Policy rules are evaluated in ascending numerical order (Rule 1 before Rule 2, and so on), and this field specifies the order of execution for the rule." + }, + "baRuleAction": { + "type": "string", + "description": "The action configured for the rule that must take place if the traffic matches the rule criteria. Supported values: \"ALLOW\" and \"BLOCK\"" + }, + "firstTimeEnable": { + "type": "boolean", + "description": "A Boolean value indicating whether a First-Time Action is specifically configured for the rule." + }, + "firstTimeOperation": { + "type": "string", + "description": "The action that must take place when users download unknown files for the first time\nSupported values: \"ALLOW_SCAN\", \"QUARANTINE\", \"ALLOW_NOSCAN\", \"QUARANTINE_ISOLATE\"" + }, + "mlActionEnabled": { + "type": "boolean", + "description": "When set to true, this indicates that 'Machine Learning Intelligence Action' checkbox has been checked on" + }, + "byThreatScore": { + "type": "integer" + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rule applies" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "baPolicyCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The threat categories to which the rule applies" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "sandbox__sandbox_rules_Update", + "summary": "Update (Sandbox / Sandbox Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier generated for the rule" + }, + "name": { + "type": "string", + "description": "The name of the Sandbox rule" + }, + "description": { + "type": "string", + "description": "Additional information about the Sandbox rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Policy rules are evaluated in ascending numerical order (Rule 1 before Rule 2, and so on), and this field specifies the order of execution for the rule." + }, + "baRuleAction": { + "type": "string", + "description": "The action configured for the rule that must take place if the traffic matches the rule criteria. Supported values: \"ALLOW\" and \"BLOCK\"" + }, + "firstTimeEnable": { + "type": "boolean", + "description": "A Boolean value indicating whether a First-Time Action is specifically configured for the rule." + }, + "firstTimeOperation": { + "type": "string", + "description": "The action that must take place when users download unknown files for the first time\nSupported values: \"ALLOW_SCAN\", \"QUARANTINE\", \"ALLOW_NOSCAN\", \"QUARANTINE_ISOLATE\"" + }, + "mlActionEnabled": { + "type": "boolean", + "description": "When set to true, this indicates that 'Machine Learning Intelligence Action' checkbox has been checked on" + }, + "byThreatScore": { + "type": "integer" + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rule applies" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "baPolicyCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The threat categories to which the rule applies" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier generated for the rule" + }, + "name": { + "type": "string", + "description": "The name of the Sandbox rule" + }, + "description": { + "type": "string", + "description": "Additional information about the Sandbox rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Policy rules are evaluated in ascending numerical order (Rule 1 before Rule 2, and so on), and this field specifies the order of execution for the rule." + }, + "baRuleAction": { + "type": "string", + "description": "The action configured for the rule that must take place if the traffic matches the rule criteria. Supported values: \"ALLOW\" and \"BLOCK\"" + }, + "firstTimeEnable": { + "type": "boolean", + "description": "A Boolean value indicating whether a First-Time Action is specifically configured for the rule." + }, + "firstTimeOperation": { + "type": "string", + "description": "The action that must take place when users download unknown files for the first time\nSupported values: \"ALLOW_SCAN\", \"QUARANTINE\", \"ALLOW_NOSCAN\", \"QUARANTINE_ISOLATE\"" + }, + "mlActionEnabled": { + "type": "boolean", + "description": "When set to true, this indicates that 'Machine Learning Intelligence Action' checkbox has been checked on" + }, + "byThreatScore": { + "type": "integer" + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rule applies" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "baPolicyCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The threat categories to which the rule applies" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + } + } + } + } + } + } + }, + "delete": { + "operationId": "sandbox__sandbox_rules_Delete", + "summary": "Delete (Sandbox / Sandbox Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier generated for the rule" + }, + "name": { + "type": "string", + "description": "The name of the Sandbox rule" + }, + "description": { + "type": "string", + "description": "Additional information about the Sandbox rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Policy rules are evaluated in ascending numerical order (Rule 1 before Rule 2, and so on), and this field specifies the order of execution for the rule." + }, + "baRuleAction": { + "type": "string", + "description": "The action configured for the rule that must take place if the traffic matches the rule criteria. Supported values: \"ALLOW\" and \"BLOCK\"" + }, + "firstTimeEnable": { + "type": "boolean", + "description": "A Boolean value indicating whether a First-Time Action is specifically configured for the rule." + }, + "firstTimeOperation": { + "type": "string", + "description": "The action that must take place when users download unknown files for the first time\nSupported values: \"ALLOW_SCAN\", \"QUARANTINE\", \"ALLOW_NOSCAN\", \"QUARANTINE_ISOLATE\"" + }, + "mlActionEnabled": { + "type": "boolean", + "description": "When set to true, this indicates that 'Machine Learning Intelligence Action' checkbox has been checked on" + }, + "byThreatScore": { + "type": "integer" + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocols to which the rule applies" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "baPolicyCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The threat categories to which the rule applies" + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/security": { + "put": { + "operationId": "security_policy_settings_UpdateWhiteListUrls", + "summary": "UpdateWhiteListUrls (Security Policy Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "whitelistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Allowlist URLs whose contents will not be scanned. Allows up to 255 URLs. There may be trusted websites the content of which might be blocked due to anti-virus, anti-spyware, or anti-malware policies. Enter the URLs of sites you do not want scanned. The service allows users to download content from these URLs without inspecting the traffic. The allowlist applies to the Malware Protection, Advanced Threats Protection, and Sandbox policies." + }, + "blacklistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs on the denylist for your organization. Allow up to 25000 URLs." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "whitelistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Allowlist URLs whose contents will not be scanned. Allows up to 255 URLs. There may be trusted websites the content of which might be blocked due to anti-virus, anti-spyware, or anti-malware policies. Enter the URLs of sites you do not want scanned. The service allows users to download content from these URLs without inspecting the traffic. The allowlist applies to the Malware Protection, Advanced Threats Protection, and Sandbox policies." + }, + "blacklistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs on the denylist for your organization. Allow up to 25000 URLs." + } + } + } + } + } + } + }, + "get": { + "operationId": "security_policy_settings_GetWhiteListUrls", + "summary": "GetWhiteListUrls (Security Policy Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "whitelistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Allowlist URLs whose contents will not be scanned. Allows up to 255 URLs. There may be trusted websites the content of which might be blocked due to anti-virus, anti-spyware, or anti-malware policies. Enter the URLs of sites you do not want scanned. The service allows users to download content from these URLs without inspecting the traffic. The allowlist applies to the Malware Protection, Advanced Threats Protection, and Sandbox policies." + }, + "blacklistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs on the denylist for your organization. Allow up to 25000 URLs." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/security/advanced": { + "put": { + "operationId": "security_policy_settings_UpdateBlackListUrls", + "summary": "UpdateBlackListUrls (Security Policy Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "whitelistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Allowlist URLs whose contents will not be scanned. Allows up to 255 URLs. There may be trusted websites the content of which might be blocked due to anti-virus, anti-spyware, or anti-malware policies. Enter the URLs of sites you do not want scanned. The service allows users to download content from these URLs without inspecting the traffic. The allowlist applies to the Malware Protection, Advanced Threats Protection, and Sandbox policies." + }, + "blacklistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs on the denylist for your organization. Allow up to 25000 URLs." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "whitelistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Allowlist URLs whose contents will not be scanned. Allows up to 255 URLs. There may be trusted websites the content of which might be blocked due to anti-virus, anti-spyware, or anti-malware policies. Enter the URLs of sites you do not want scanned. The service allows users to download content from these URLs without inspecting the traffic. The allowlist applies to the Malware Protection, Advanced Threats Protection, and Sandbox policies." + }, + "blacklistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs on the denylist for your organization. Allow up to 25000 URLs." + } + } + } + } + } + } + }, + "get": { + "operationId": "security_policy_settings_GetBlackListUrls", + "summary": "GetBlackListUrls (Security Policy Settings)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "whitelistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Allowlist URLs whose contents will not be scanned. Allows up to 255 URLs. There may be trusted websites the content of which might be blocked due to anti-virus, anti-spyware, or anti-malware policies. Enter the URLs of sites you do not want scanned. The service allows users to download content from these URLs without inspecting the traffic. The allowlist applies to the Malware Protection, Advanced Threats Protection, and Sandbox policies." + }, + "blacklistUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs on the denylist for your organization. Allow up to 25000 URLs." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/shadowIT/applications/%s/exportCsv": { + "post": { + "operationId": "shadowitreport_CreateCloudApplicationsExportCSV", + "summary": "CreateCloudApplicationsExportCSV (Shadowitreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "sanctionedState": { + "type": "string" + }, + "applicationIds": { + "type": "array", + "items": { + "type": "integer" + } + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the cloud application" + }, + "name": { + "type": "string", + "description": "The name of the cloud application" + } + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "sanctionedState": { + "type": "string" + }, + "applicationIds": { + "type": "array", + "items": { + "type": "integer" + } + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the cloud application" + }, + "name": { + "type": "string", + "description": "The name of the cloud application" + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/shadowIT/applications/export": { + "post": { + "operationId": "shadowitreport_CreateCloudApplicationsExport", + "summary": "CreateCloudApplicationsExport (Shadowitreport)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "sanctionedState": { + "type": "string" + }, + "applicationIds": { + "type": "array", + "items": { + "type": "integer" + } + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the cloud application" + }, + "name": { + "type": "string", + "description": "The name of the cloud application" + } + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "sanctionedState": { + "type": "string" + }, + "applicationIds": { + "type": "array", + "items": { + "type": "integer" + } + }, + "customTags": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier of the cloud application" + }, + "name": { + "type": "string", + "description": "The name of the cloud application" + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/smpcInstance": { + "get": { + "operationId": "smpc_instance_GetAll", + "summary": "GetAll (Smpc Instance)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "data": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "datacenterName": { + "type": "string" + }, + "city": { + "type": "string" + }, + "countryCode": { + "type": "string" + }, + "zscmIsolationEnabled": { + "type": "integer" + }, + "zscmIsolationEnabledApiFlag": { + "type": "boolean" + }, + "connectionStatus": { + "type": "string" + }, + "dcIsolationStatus": { + "type": "string" + }, + "nodes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "nodeName": { + "type": "string" + }, + "instanceId": { + "type": "integer" + }, + "adminIsolationEnabled": { + "type": "boolean" + }, + "connectionState": { + "type": "integer" + }, + "lastTimestamp": { + "type": "integer" + } + } + } + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/sslInspectionRules": { + "get": { + "operationId": "sslinspection_GetByName", + "summary": "GetByName (Sslinspection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for the SSL inspection rule" + }, + "name": { + "type": "string", + "description": "The name of the SSL Inspection rule" + }, + "description": { + "type": "string", + "description": "Additional information about the SSL Inspection rule" + }, + "action": { + "type": "object", + "properties": { + "type": { + "type": "string", + "description": "Supported values: \"BLOCK\", \"DECRYPT\", \"DO_NOT_DECRYPT\"," + }, + "showEUN": { + "type": "boolean" + }, + "showEUNATP": { + "type": "boolean" + }, + "overrideDefaultCertificate": { + "type": "boolean" + }, + "sslInterceptionCert": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "defaultCertificate": { + "type": "boolean" + } + } + }, + "decryptSubActions": { + "type": "object", + "properties": { + "serverCertificates": { + "type": "string" + }, + "ocspCheck": { + "type": "boolean" + }, + "blockSslTrafficWithNoSniEnabled": { + "type": "boolean" + }, + "minClientTLSVersion": { + "type": "string" + }, + "minServerTLSVersion": { + "type": "string" + }, + "blockUndecrypt": { + "type": "boolean" + }, + "http2Enabled": { + "type": "boolean" + } + } + }, + "doNotDecryptSubActions": { + "type": "object", + "properties": { + "bypassOtherPolicies": { + "type": "boolean" + }, + "serverCertificates": { + "type": "string", + "description": "ALLOW, BLOCK, PASS_THRU" + }, + "ocspCheck": { + "type": "boolean" + }, + "blockSslTrafficWithNoSniEnabled": { + "type": "boolean" + }, + "minTLSVersion": { + "type": "string" + } + } + } + }, + "description": "The action taken when traffic matches the SSL Inspection rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the SSL Inspection rule." + }, + "accessControl": { + "type": "string", + "description": "Access privilege to this rule based on the admin's RBA" + }, + "order": { + "type": "integer", + "description": "Order of rule execution with respect to other SSL inspection rules." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "platforms": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Zscaler Client Connector device platforms for which the rule must be applied." + }, + "roadWarriorForKerberos": { + "type": "boolean", + "description": "When set to true, the rule is applied to remote users that use PAC with Kerberos authentication." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of URL categories for which rule must be applied" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User agent type list" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignore if the request is POST or PUT" + }, + "lastModifiedBy": { + "type": "object", + "description": "Admin user that last modified the rule. Ignore if the request is POST or PUT." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IP address group." + }, + "proxyGateways": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The proxy chaining gateway for which this rule is applicable.\nIgnore if the forwarding method is not Proxy Chaining." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of rule labels associated with the rule" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time intervals during which the rule applies" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/sslInspectionRules/{id}": { + "get": { + "operationId": "sslinspection_Get", + "summary": "Get (Sslinspection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for the SSL inspection rule" + }, + "name": { + "type": "string", + "description": "The name of the SSL Inspection rule" + }, + "description": { + "type": "string", + "description": "Additional information about the SSL Inspection rule" + }, + "action": { + "type": "object", + "properties": { + "type": { + "type": "string", + "description": "Supported values: \"BLOCK\", \"DECRYPT\", \"DO_NOT_DECRYPT\"," + }, + "showEUN": { + "type": "boolean" + }, + "showEUNATP": { + "type": "boolean" + }, + "overrideDefaultCertificate": { + "type": "boolean" + }, + "sslInterceptionCert": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "defaultCertificate": { + "type": "boolean" + } + } + }, + "decryptSubActions": { + "type": "object", + "properties": { + "serverCertificates": { + "type": "string" + }, + "ocspCheck": { + "type": "boolean" + }, + "blockSslTrafficWithNoSniEnabled": { + "type": "boolean" + }, + "minClientTLSVersion": { + "type": "string" + }, + "minServerTLSVersion": { + "type": "string" + }, + "blockUndecrypt": { + "type": "boolean" + }, + "http2Enabled": { + "type": "boolean" + } + } + }, + "doNotDecryptSubActions": { + "type": "object", + "properties": { + "bypassOtherPolicies": { + "type": "boolean" + }, + "serverCertificates": { + "type": "string", + "description": "ALLOW, BLOCK, PASS_THRU" + }, + "ocspCheck": { + "type": "boolean" + }, + "blockSslTrafficWithNoSniEnabled": { + "type": "boolean" + }, + "minTLSVersion": { + "type": "string" + } + } + } + }, + "description": "The action taken when traffic matches the SSL Inspection rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the SSL Inspection rule." + }, + "accessControl": { + "type": "string", + "description": "Access privilege to this rule based on the admin's RBA" + }, + "order": { + "type": "integer", + "description": "Order of rule execution with respect to other SSL inspection rules." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "platforms": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Zscaler Client Connector device platforms for which the rule must be applied." + }, + "roadWarriorForKerberos": { + "type": "boolean", + "description": "When set to true, the rule is applied to remote users that use PAC with Kerberos authentication." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of URL categories for which rule must be applied" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User agent type list" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignore if the request is POST or PUT" + }, + "lastModifiedBy": { + "type": "object", + "description": "Admin user that last modified the rule. Ignore if the request is POST or PUT." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IP address group." + }, + "proxyGateways": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The proxy chaining gateway for which this rule is applicable.\nIgnore if the forwarding method is not Proxy Chaining." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of rule labels associated with the rule" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time intervals during which the rule applies" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "delete": { + "operationId": "sslinspection_Delete", + "summary": "Delete (Sslinspection)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for the SSL inspection rule" + }, + "name": { + "type": "string", + "description": "The name of the SSL Inspection rule" + }, + "description": { + "type": "string", + "description": "Additional information about the SSL Inspection rule" + }, + "action": { + "type": "object", + "properties": { + "type": { + "type": "string", + "description": "Supported values: \"BLOCK\", \"DECRYPT\", \"DO_NOT_DECRYPT\"," + }, + "showEUN": { + "type": "boolean" + }, + "showEUNATP": { + "type": "boolean" + }, + "overrideDefaultCertificate": { + "type": "boolean" + }, + "sslInterceptionCert": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "defaultCertificate": { + "type": "boolean" + } + } + }, + "decryptSubActions": { + "type": "object", + "properties": { + "serverCertificates": { + "type": "string" + }, + "ocspCheck": { + "type": "boolean" + }, + "blockSslTrafficWithNoSniEnabled": { + "type": "boolean" + }, + "minClientTLSVersion": { + "type": "string" + }, + "minServerTLSVersion": { + "type": "string" + }, + "blockUndecrypt": { + "type": "boolean" + }, + "http2Enabled": { + "type": "boolean" + } + } + }, + "doNotDecryptSubActions": { + "type": "object", + "properties": { + "bypassOtherPolicies": { + "type": "boolean" + }, + "serverCertificates": { + "type": "string", + "description": "ALLOW, BLOCK, PASS_THRU" + }, + "ocspCheck": { + "type": "boolean" + }, + "blockSslTrafficWithNoSniEnabled": { + "type": "boolean" + }, + "minTLSVersion": { + "type": "string" + } + } + } + }, + "description": "The action taken when traffic matches the SSL Inspection rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the SSL Inspection rule." + }, + "accessControl": { + "type": "string", + "description": "Access privilege to this rule based on the admin's RBA" + }, + "order": { + "type": "integer", + "description": "Order of rule execution with respect to other SSL inspection rules." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "platforms": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Zscaler Client Connector device platforms for which the rule must be applied." + }, + "roadWarriorForKerberos": { + "type": "boolean", + "description": "When set to true, the rule is applied to remote users that use PAC with Kerberos authentication." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of URL categories for which rule must be applied" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User agent type list" + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignore if the request is POST or PUT" + }, + "lastModifiedBy": { + "type": "object", + "description": "Admin user that last modified the rule. Ignore if the request is POST or PUT." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IP address group." + }, + "proxyGateways": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The proxy chaining gateway for which this rule is applicable.\nIgnore if the forwarding method is not Proxy Chaining." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of rule labels associated with the rule" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time intervals during which the rule applies" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/staticIP": { + "get": { + "operationId": "trafficforwarding__staticips_GetByIPAddress", + "summary": "GetByIPAddress (Trafficforwarding / Staticips)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the static IP address" + }, + "ipAddress": { + "type": "string", + "description": "The static IP address" + }, + "geoOverride": { + "type": "boolean", + "description": "If not set, geographic coordinates and city are automatically determined from the IP address. Otherwise, the latitude and longitude coordinates must be provided." + }, + "latitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "routableIP": { + "type": "boolean", + "description": "Indicates whether a non-RFC 1918 IP address is publicly routable. This attribute is ignored if there is no ZIA Private Service Edge associated to the organization." + }, + "city": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + } + } + }, + "lastModificationTime": { + "type": "integer", + "description": "When the static IP address was last modified" + }, + "comment": { + "type": "string", + "description": "Additional information about this static IP address" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the static IP address last" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "trafficforwarding__staticips_Create", + "summary": "Create (Trafficforwarding / Staticips)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the static IP address" + }, + "ipAddress": { + "type": "string", + "description": "The static IP address" + }, + "geoOverride": { + "type": "boolean", + "description": "If not set, geographic coordinates and city are automatically determined from the IP address. Otherwise, the latitude and longitude coordinates must be provided." + }, + "latitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "routableIP": { + "type": "boolean", + "description": "Indicates whether a non-RFC 1918 IP address is publicly routable. This attribute is ignored if there is no ZIA Private Service Edge associated to the organization." + }, + "city": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + } + } + }, + "lastModificationTime": { + "type": "integer", + "description": "When the static IP address was last modified" + }, + "comment": { + "type": "string", + "description": "Additional information about this static IP address" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the static IP address last" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the static IP address" + }, + "ipAddress": { + "type": "string", + "description": "The static IP address" + }, + "geoOverride": { + "type": "boolean", + "description": "If not set, geographic coordinates and city are automatically determined from the IP address. Otherwise, the latitude and longitude coordinates must be provided." + }, + "latitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "routableIP": { + "type": "boolean", + "description": "Indicates whether a non-RFC 1918 IP address is publicly routable. This attribute is ignored if there is no ZIA Private Service Edge associated to the organization." + }, + "city": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + } + } + }, + "lastModificationTime": { + "type": "integer", + "description": "When the static IP address was last modified" + }, + "comment": { + "type": "string", + "description": "Additional information about this static IP address" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the static IP address last" + } + } + } + } + } + } + } + }, + "/zia/api/v1/staticIP/{id}": { + "get": { + "operationId": "trafficforwarding__staticips_Get", + "summary": "Get (Trafficforwarding / Staticips)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the static IP address" + }, + "ipAddress": { + "type": "string", + "description": "The static IP address" + }, + "geoOverride": { + "type": "boolean", + "description": "If not set, geographic coordinates and city are automatically determined from the IP address. Otherwise, the latitude and longitude coordinates must be provided." + }, + "latitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "routableIP": { + "type": "boolean", + "description": "Indicates whether a non-RFC 1918 IP address is publicly routable. This attribute is ignored if there is no ZIA Private Service Edge associated to the organization." + }, + "city": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + } + } + }, + "lastModificationTime": { + "type": "integer", + "description": "When the static IP address was last modified" + }, + "comment": { + "type": "string", + "description": "Additional information about this static IP address" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the static IP address last" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "trafficforwarding__staticips_Update", + "summary": "Update (Trafficforwarding / Staticips)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the static IP address" + }, + "ipAddress": { + "type": "string", + "description": "The static IP address" + }, + "geoOverride": { + "type": "boolean", + "description": "If not set, geographic coordinates and city are automatically determined from the IP address. Otherwise, the latitude and longitude coordinates must be provided." + }, + "latitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "routableIP": { + "type": "boolean", + "description": "Indicates whether a non-RFC 1918 IP address is publicly routable. This attribute is ignored if there is no ZIA Private Service Edge associated to the organization." + }, + "city": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + } + } + }, + "lastModificationTime": { + "type": "integer", + "description": "When the static IP address was last modified" + }, + "comment": { + "type": "string", + "description": "Additional information about this static IP address" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the static IP address last" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the static IP address" + }, + "ipAddress": { + "type": "string", + "description": "The static IP address" + }, + "geoOverride": { + "type": "boolean", + "description": "If not set, geographic coordinates and city are automatically determined from the IP address. Otherwise, the latitude and longitude coordinates must be provided." + }, + "latitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "routableIP": { + "type": "boolean", + "description": "Indicates whether a non-RFC 1918 IP address is publicly routable. This attribute is ignored if there is no ZIA Private Service Edge associated to the organization." + }, + "city": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + } + } + }, + "lastModificationTime": { + "type": "integer", + "description": "When the static IP address was last modified" + }, + "comment": { + "type": "string", + "description": "Additional information about this static IP address" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the static IP address last" + } + } + } + } + } + } + }, + "delete": { + "operationId": "trafficforwarding__staticips_Delete", + "summary": "Delete (Trafficforwarding / Staticips)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the static IP address" + }, + "ipAddress": { + "type": "string", + "description": "The static IP address" + }, + "geoOverride": { + "type": "boolean", + "description": "If not set, geographic coordinates and city are automatically determined from the IP address. Otherwise, the latitude and longitude coordinates must be provided." + }, + "latitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Latitude with 7 digit precision after decimal point, ranges between -90 and 90 degrees." + }, + "longitude": { + "type": "number", + "description": "Required only if the geoOverride attribute is set. Longitude with 7 digit precision after decimal point, ranges between -180 and 180 degrees." + }, + "routableIP": { + "type": "boolean", + "description": "Indicates whether a non-RFC 1918 IP address is publicly routable. This attribute is ignored if there is no ZIA Private Service Edge associated to the organization." + }, + "city": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + } + } + }, + "lastModificationTime": { + "type": "integer", + "description": "When the static IP address was last modified" + }, + "comment": { + "type": "string", + "description": "Additional information about this static IP address" + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + }, + "lastModifiedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + }, + "description": "Who modified the static IP address last" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/status": { + "get": { + "operationId": "activation_GetActivationStatus", + "summary": "GetActivationStatus (Activation)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "status": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/status/activate": { + "post": { + "operationId": "activation_CreateActivation", + "summary": "CreateActivation (Activation)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "status": { + "type": "string" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "status": { + "type": "string" + } + } + } + } + } + } + } + }, + "/zia/api/v1/subclouds": { + "get": { + "operationId": "trafficforwarding__sub_clouds_GetAll", + "summary": "GetAll (Trafficforwarding / Sub Clouds)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dcs": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "country": { + "type": "string" + } + } + } + }, + "exclusions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "datacenter": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedUser": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "country": { + "type": "string" + }, + "expired": { + "type": "boolean" + }, + "disabledByOps": { + "type": "boolean" + }, + "createTime": { + "type": "integer" + }, + "startTime": { + "type": "integer" + }, + "endTime": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/subclouds/{id}": { + "put": { + "operationId": "trafficforwarding__sub_clouds_Update", + "summary": "Update (Trafficforwarding / Sub Clouds)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dcs": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "country": { + "type": "string" + } + } + } + }, + "exclusions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "datacenter": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedUser": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "country": { + "type": "string" + }, + "expired": { + "type": "boolean" + }, + "disabledByOps": { + "type": "boolean" + }, + "createTime": { + "type": "integer" + }, + "startTime": { + "type": "integer" + }, + "endTime": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dcs": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "country": { + "type": "string" + } + } + } + }, + "exclusions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "datacenter": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedUser": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "country": { + "type": "string" + }, + "expired": { + "type": "boolean" + }, + "disabledByOps": { + "type": "boolean" + }, + "createTime": { + "type": "integer" + }, + "startTime": { + "type": "integer" + }, + "endTime": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + } + } + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "trafficforwarding__sub_clouds_Delete", + "summary": "Delete (Trafficforwarding / Sub Clouds)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dcs": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "country": { + "type": "string" + } + } + } + }, + "exclusions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "datacenter": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedUser": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "country": { + "type": "string" + }, + "expired": { + "type": "boolean" + }, + "disabledByOps": { + "type": "boolean" + }, + "createTime": { + "type": "integer" + }, + "startTime": { + "type": "integer" + }, + "endTime": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "get": { + "operationId": "trafficforwarding__sub_clouds_Get", + "summary": "Get (Trafficforwarding / Sub Clouds)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "dcs": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "country": { + "type": "string" + } + } + } + }, + "exclusions": { + "type": "array", + "items": { + "type": "object", + "properties": { + "datacenter": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "lastModifiedUser": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "country": { + "type": "string" + }, + "expired": { + "type": "boolean" + }, + "disabledByOps": { + "type": "boolean" + }, + "createTime": { + "type": "integer" + }, + "startTime": { + "type": "integer" + }, + "endTime": { + "type": "integer" + }, + "lastModifiedTime": { + "type": "integer" + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/subscriptions": { + "get": { + "operationId": "organization_details_GetSubscriptions", + "summary": "GetSubscriptions (Organization Details)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "The unique identifier of the subscription" + }, + "status": { + "type": "string", + "description": "The status of the subscription indicating whether it is on trial, expired and disabled, not subscribed, subscribed, or temporarily extended" + }, + "state": { + "type": "string", + "description": "The current state of the subscription indicating whether it is active, expired, disabled, or not started." + }, + "licenses": { + "type": "integer", + "description": "The number of licenses owned by the tenant under the subscription. The license could be for users, Virtual Service Edges, proxy ports, NSS feeds, etc." + }, + "startDate": { + "type": "integer", + "description": "The subscription start time in Unix time format" + }, + "strStartDate": { + "type": "string", + "description": "The subscription start date in MM/DD/YYYY format" + }, + "strEndDate": { + "type": "string", + "description": "The subscription end date in MM/DD/YYYY format" + }, + "endDate": { + "type": "integer", + "description": "The subscription end time in Unix time format" + }, + "sku": { + "type": "string", + "description": "The ID of the service enabled through the subscription" + }, + "cellCount": { + "type": "string" + }, + "updatedAtTimestamp": { + "type": "integer", + "description": "The timestamp in Unix time format when the subscription was last updated" + }, + "subscribed": { + "type": "boolean", + "description": "A Boolean value indicating that the subscription is active or is not started" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/tenancyRestrictionProfile": { + "get": { + "operationId": "tenancy_restriction_GetByName", + "summary": "GetByName (Tenancy Restriction)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "appType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "itemTypePrimary": { + "type": "string" + }, + "itemTypeSecondary": { + "type": "string" + }, + "restrictPersonalO365Domains": { + "type": "boolean" + }, + "allowGoogleConsumers": { + "type": "boolean" + }, + "msLoginServicesTrV2": { + "type": "boolean" + }, + "allowGoogleVisitors": { + "type": "boolean" + }, + "allowGcpCloudStorageRead": { + "type": "boolean" + }, + "itemDataPrimary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemDataSecondary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemValue": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedUserId": { + "type": "integer" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "tenancy_restriction_Create", + "summary": "Create (Tenancy Restriction)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "appType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "itemTypePrimary": { + "type": "string" + }, + "itemTypeSecondary": { + "type": "string" + }, + "restrictPersonalO365Domains": { + "type": "boolean" + }, + "allowGoogleConsumers": { + "type": "boolean" + }, + "msLoginServicesTrV2": { + "type": "boolean" + }, + "allowGoogleVisitors": { + "type": "boolean" + }, + "allowGcpCloudStorageRead": { + "type": "boolean" + }, + "itemDataPrimary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemDataSecondary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemValue": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedUserId": { + "type": "integer" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "appType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "itemTypePrimary": { + "type": "string" + }, + "itemTypeSecondary": { + "type": "string" + }, + "restrictPersonalO365Domains": { + "type": "boolean" + }, + "allowGoogleConsumers": { + "type": "boolean" + }, + "msLoginServicesTrV2": { + "type": "boolean" + }, + "allowGoogleVisitors": { + "type": "boolean" + }, + "allowGcpCloudStorageRead": { + "type": "boolean" + }, + "itemDataPrimary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemDataSecondary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemValue": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedUserId": { + "type": "integer" + } + } + } + } + } + } + } + }, + "/zia/api/v1/tenancyRestrictionProfile/{id}": { + "get": { + "operationId": "tenancy_restriction_Get", + "summary": "Get (Tenancy Restriction)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "appType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "itemTypePrimary": { + "type": "string" + }, + "itemTypeSecondary": { + "type": "string" + }, + "restrictPersonalO365Domains": { + "type": "boolean" + }, + "allowGoogleConsumers": { + "type": "boolean" + }, + "msLoginServicesTrV2": { + "type": "boolean" + }, + "allowGoogleVisitors": { + "type": "boolean" + }, + "allowGcpCloudStorageRead": { + "type": "boolean" + }, + "itemDataPrimary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemDataSecondary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemValue": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedUserId": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "tenancy_restriction_Update", + "summary": "Update (Tenancy Restriction)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "appType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "itemTypePrimary": { + "type": "string" + }, + "itemTypeSecondary": { + "type": "string" + }, + "restrictPersonalO365Domains": { + "type": "boolean" + }, + "allowGoogleConsumers": { + "type": "boolean" + }, + "msLoginServicesTrV2": { + "type": "boolean" + }, + "allowGoogleVisitors": { + "type": "boolean" + }, + "allowGcpCloudStorageRead": { + "type": "boolean" + }, + "itemDataPrimary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemDataSecondary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemValue": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedUserId": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "appType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "itemTypePrimary": { + "type": "string" + }, + "itemTypeSecondary": { + "type": "string" + }, + "restrictPersonalO365Domains": { + "type": "boolean" + }, + "allowGoogleConsumers": { + "type": "boolean" + }, + "msLoginServicesTrV2": { + "type": "boolean" + }, + "allowGoogleVisitors": { + "type": "boolean" + }, + "allowGcpCloudStorageRead": { + "type": "boolean" + }, + "itemDataPrimary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemDataSecondary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemValue": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedUserId": { + "type": "integer" + } + } + } + } + } + } + }, + "delete": { + "operationId": "tenancy_restriction_Delete", + "summary": "Delete (Tenancy Restriction)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "appType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "itemTypePrimary": { + "type": "string" + }, + "itemTypeSecondary": { + "type": "string" + }, + "restrictPersonalO365Domains": { + "type": "boolean" + }, + "allowGoogleConsumers": { + "type": "boolean" + }, + "msLoginServicesTrV2": { + "type": "boolean" + }, + "allowGoogleVisitors": { + "type": "boolean" + }, + "allowGcpCloudStorageRead": { + "type": "boolean" + }, + "itemDataPrimary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemDataSecondary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemValue": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedUserId": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/tenancyRestrictionProfile/{id}/{id2}": { + "get": { + "operationId": "tenancy_restriction_GetAppItemCount", + "summary": "GetAppItemCount (Tenancy Restriction)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "appType": { + "type": "string" + }, + "description": { + "type": "string" + }, + "itemTypePrimary": { + "type": "string" + }, + "itemTypeSecondary": { + "type": "string" + }, + "restrictPersonalO365Domains": { + "type": "boolean" + }, + "allowGoogleConsumers": { + "type": "boolean" + }, + "msLoginServicesTrV2": { + "type": "boolean" + }, + "allowGoogleVisitors": { + "type": "boolean" + }, + "allowGcpCloudStorageRead": { + "type": "boolean" + }, + "itemDataPrimary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemDataSecondary": { + "type": "array", + "items": { + "type": "string" + } + }, + "itemValue": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer" + }, + "lastModifiedUserId": { + "type": "integer" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/timeIntervals": { + "get": { + "operationId": "time_intervals_GetTimeIntervalByName", + "summary": "GetTimeIntervalByName (Time Intervals)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string", + "description": "Name to identify the time interval" + }, + "startTime": { + "type": "integer", + "description": "The time interval start time." + }, + "endTime": { + "type": "integer", + "description": "The time interval end time." + }, + "daysOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Values supported: `EVERYDAY`, `SUN`, `MON`, `TUE`, `WED`, `THU`, `FRI`, `SAT`" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "time_intervals_Create", + "summary": "Create (Time Intervals)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string", + "description": "Name to identify the time interval" + }, + "startTime": { + "type": "integer", + "description": "The time interval start time." + }, + "endTime": { + "type": "integer", + "description": "The time interval end time." + }, + "daysOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Values supported: `EVERYDAY`, `SUN`, `MON`, `TUE`, `WED`, `THU`, `FRI`, `SAT`" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string", + "description": "Name to identify the time interval" + }, + "startTime": { + "type": "integer", + "description": "The time interval start time." + }, + "endTime": { + "type": "integer", + "description": "The time interval end time." + }, + "daysOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Values supported: `EVERYDAY`, `SUN`, `MON`, `TUE`, `WED`, `THU`, `FRI`, `SAT`" + } + } + } + } + } + } + } + }, + "/zia/api/v1/timeIntervals/{id}": { + "get": { + "operationId": "time_intervals_Get", + "summary": "Get (Time Intervals)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string", + "description": "Name to identify the time interval" + }, + "startTime": { + "type": "integer", + "description": "The time interval start time." + }, + "endTime": { + "type": "integer", + "description": "The time interval end time." + }, + "daysOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Values supported: `EVERYDAY`, `SUN`, `MON`, `TUE`, `WED`, `THU`, `FRI`, `SAT`" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "time_intervals_Update", + "summary": "Update (Time Intervals)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string", + "description": "Name to identify the time interval" + }, + "startTime": { + "type": "integer", + "description": "The time interval start time." + }, + "endTime": { + "type": "integer", + "description": "The time interval end time." + }, + "daysOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Values supported: `EVERYDAY`, `SUN`, `MON`, `TUE`, `WED`, `THU`, `FRI`, `SAT`" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string", + "description": "Name to identify the time interval" + }, + "startTime": { + "type": "integer", + "description": "The time interval start time." + }, + "endTime": { + "type": "integer", + "description": "The time interval end time." + }, + "daysOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Values supported: `EVERYDAY`, `SUN`, `MON`, `TUE`, `WED`, `THU`, `FRI`, `SAT`" + } + } + } + } + } + } + }, + "delete": { + "operationId": "time_intervals_Delete", + "summary": "Delete (Time Intervals)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string", + "description": "Name to identify the time interval" + }, + "startTime": { + "type": "integer", + "description": "The time interval start time." + }, + "endTime": { + "type": "integer", + "description": "The time interval end time." + }, + "daysOfWeek": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Values supported: `EVERYDAY`, `SUN`, `MON`, `TUE`, `WED`, `THU`, `FRI`, `SAT`" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/timeWindows": { + "get": { + "operationId": "firewallpolicies__timewindow_GetAll", + "summary": "GetAll (Firewallpolicies / Timewindow)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "startTime": { + "type": "integer" + }, + "endTime": { + "type": "integer" + }, + "dayOfWeek": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/trafficCaptureRules": { + "post": { + "operationId": "traffic_capture_Create", + "summary": "Create (Traffic Capture)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Traffic Capture policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Traffic Capture policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Traffic Capture policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Traffic Capture policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Traffic Capture policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Traffic Capture policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "txnSizeLimit": { + "type": "string", + "description": "The maximum size of traffic to capture per connection" + }, + "txnSampling": { + "type": "string", + "description": "The percentage of connections sampled for capturing each time the rule is triggered" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Traffic Capture policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Traffic Capture policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Traffic Capture policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Traffic Capture policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Traffic Capture policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Traffic Capture policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "txnSizeLimit": { + "type": "string", + "description": "The maximum size of traffic to capture per connection" + }, + "txnSampling": { + "type": "string", + "description": "The percentage of connections sampled for capturing each time the rule is triggered" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + } + } + } + } + } + } + }, + "get": { + "operationId": "traffic_capture_GetAll", + "summary": "GetAll (Traffic Capture)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Traffic Capture policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Traffic Capture policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Traffic Capture policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Traffic Capture policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Traffic Capture policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Traffic Capture policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "txnSizeLimit": { + "type": "string", + "description": "The maximum size of traffic to capture per connection" + }, + "txnSampling": { + "type": "string", + "description": "The percentage of connections sampled for capturing each time the rule is triggered" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/trafficCaptureRules/{id}": { + "get": { + "operationId": "traffic_capture_Get", + "summary": "Get (Traffic Capture)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Traffic Capture policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Traffic Capture policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Traffic Capture policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Traffic Capture policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Traffic Capture policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Traffic Capture policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "txnSizeLimit": { + "type": "string", + "description": "The maximum size of traffic to capture per connection" + }, + "txnSampling": { + "type": "string", + "description": "The percentage of connections sampled for capturing each time the rule is triggered" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "traffic_capture_Update", + "summary": "Update (Traffic Capture)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Traffic Capture policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Traffic Capture policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Traffic Capture policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Traffic Capture policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Traffic Capture policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Traffic Capture policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "txnSizeLimit": { + "type": "string", + "description": "The maximum size of traffic to capture per connection" + }, + "txnSampling": { + "type": "string", + "description": "The percentage of connections sampled for capturing each time the rule is triggered" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Traffic Capture policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Traffic Capture policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Traffic Capture policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Traffic Capture policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Traffic Capture policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Traffic Capture policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "txnSizeLimit": { + "type": "string", + "description": "The maximum size of traffic to capture per connection" + }, + "txnSampling": { + "type": "string", + "description": "The percentage of connections sampled for capturing each time the rule is triggered" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + } + } + } + } + } + } + }, + "delete": { + "operationId": "traffic_capture_Delete", + "summary": "Delete (Traffic Capture)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Traffic Capture policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Traffic Capture policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Traffic Capture policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Traffic Capture policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "action": { + "type": "string", + "description": "The action the Traffic Capture policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Traffic Capture policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "txnSizeLimit": { + "type": "string", + "description": "The maximum size of traffic to capture per connection" + }, + "txnSampling": { + "type": "string", + "description": "The percentage of connections sampled for capturing each time the rule is triggered" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "srcIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group.\nNote: For organizations that have enabled IPv6, the srcIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "destIpv6Groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Destination IPv6 address groups for which the rule is applicable.\nIf not set, the rule is not restricted to a specific source IPv6 address group." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/urlCategories": { + "get": { + "operationId": "urlcategories_GetCustomURLCategories", + "summary": "GetCustomURLCategories (Urlcategories)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "urlcategories_CreateURLCategories", + "summary": "CreateURLCategories (Urlcategories)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + } + }, + "/zia/api/v1/urlCategories/{id}": { + "get": { + "operationId": "urlcategories_Get", + "summary": "Get (Urlcategories)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "urlcategories_UpdateURLCategories", + "summary": "UpdateURLCategories (Urlcategories)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + }, + "delete": { + "operationId": "urlcategories_DeleteURLCategories", + "summary": "DeleteURLCategories (Urlcategories)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/urlFilteringRules": { + "get": { + "operationId": "urlfilteringpolicies_GetByName", + "summary": "GetByName (Urlfilteringpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "urlfilteringpolicies_Create", + "summary": "Create (Urlfilteringpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + } + }, + "/zia/api/v1/urlFilteringRules/{id}": { + "get": { + "operationId": "urlfilteringpolicies_Get", + "summary": "Get (Urlfilteringpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "urlfilteringpolicies_Update", + "summary": "Update (Urlfilteringpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "delete": { + "operationId": "urlfilteringpolicies_Delete", + "summary": "Delete (Urlfilteringpolicies)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/userConfirmation": { + "get": { + "operationId": "end_user_notification_GetGlobalDefaultTemplates", + "summary": "GetGlobalDefaultTemplates (End User Notification)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "aupFrequency": { + "type": "string" + }, + "aupCustomFrequency": { + "type": "integer" + }, + "aupDayOffset": { + "type": "integer" + }, + "aupMessage": { + "type": "string" + }, + "notificationType": { + "type": "string" + }, + "displayReason": { + "type": "boolean" + }, + "displayCompName": { + "type": "boolean" + }, + "displayCompLogo": { + "type": "boolean" + }, + "customText": { + "type": "string" + }, + "urlCatReviewEnabled": { + "type": "boolean" + }, + "urlCatReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "urlCatReviewCustomLocation": { + "type": "string" + }, + "urlCatReviewText": { + "type": "string" + }, + "securityReviewEnabled": { + "type": "boolean" + }, + "securityReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "securityReviewCustomLocation": { + "type": "string" + }, + "securityReviewText": { + "type": "string" + }, + "webDlpReviewEnabled": { + "type": "boolean" + }, + "webDlpReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "webDlpReviewCustomLocation": { + "type": "string" + }, + "webDlpReviewText": { + "type": "string" + }, + "redirectUrl": { + "type": "string" + }, + "supportEmail": { + "type": "string" + }, + "supportPhone": { + "type": "string" + }, + "orgPolicyLink": { + "type": "string" + }, + "cautionAgainAfter": { + "type": "integer" + }, + "cautionPerDomain": { + "type": "boolean" + }, + "cautionCustomText": { + "type": "string" + }, + "idpProxyNotificationText": { + "type": "string" + }, + "quarantineCustomNotificationText": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/userConfirmation/{id}": { + "get": { + "operationId": "end_user_notification_GetEunTemplateByPolicy", + "summary": "GetEunTemplateByPolicy (End User Notification)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "aupFrequency": { + "type": "string" + }, + "aupCustomFrequency": { + "type": "integer" + }, + "aupDayOffset": { + "type": "integer" + }, + "aupMessage": { + "type": "string" + }, + "notificationType": { + "type": "string" + }, + "displayReason": { + "type": "boolean" + }, + "displayCompName": { + "type": "boolean" + }, + "displayCompLogo": { + "type": "boolean" + }, + "customText": { + "type": "string" + }, + "urlCatReviewEnabled": { + "type": "boolean" + }, + "urlCatReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "urlCatReviewCustomLocation": { + "type": "string" + }, + "urlCatReviewText": { + "type": "string" + }, + "securityReviewEnabled": { + "type": "boolean" + }, + "securityReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "securityReviewCustomLocation": { + "type": "string" + }, + "securityReviewText": { + "type": "string" + }, + "webDlpReviewEnabled": { + "type": "boolean" + }, + "webDlpReviewSubmitToSecurityCloud": { + "type": "boolean" + }, + "webDlpReviewCustomLocation": { + "type": "string" + }, + "webDlpReviewText": { + "type": "string" + }, + "redirectUrl": { + "type": "string" + }, + "supportEmail": { + "type": "string" + }, + "supportPhone": { + "type": "string" + }, + "orgPolicyLink": { + "type": "string" + }, + "cautionAgainAfter": { + "type": "integer" + }, + "cautionPerDomain": { + "type": "boolean" + }, + "cautionCustomText": { + "type": "string" + }, + "idpProxyNotificationText": { + "type": "string" + }, + "quarantineCustomNotificationText": { + "type": "string" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/users": { + "post": { + "operationId": "usermanagement__users_Create", + "summary": "Create (Usermanagement / Users)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "get": { + "operationId": "usermanagement__users_GetAllUsers", + "summary": "GetAllUsers (Usermanagement / Users)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/users/{id}": { + "get": { + "operationId": "usermanagement__users_Get", + "summary": "Get (Usermanagement / Users)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "usermanagement__users_Update", + "summary": "Update (Usermanagement / Users)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "delete": { + "operationId": "usermanagement__users_Delete", + "summary": "Delete (Usermanagement / Users)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/vips": { + "get": { + "operationId": "trafficforwarding__virtualipaddress_GetZscalerVIPs", + "summary": "GetZscalerVIPs (Trafficforwarding / Virtualipaddress)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "cloudName": { + "type": "string" + }, + "region": { + "type": "string" + }, + "city": { + "type": "string" + }, + "dataCenter": { + "type": "string" + }, + "location": { + "type": "string" + }, + "vpnIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "vpnDomainName": { + "type": "string" + }, + "greIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "greDomainName": { + "type": "string" + }, + "pacIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "pacDomainName": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/vips/groupByDatacenter": { + "get": { + "operationId": "trafficforwarding__region__datacenter_SearchByDatacenters", + "summary": "SearchByDatacenters (Trafficforwarding / Region / Datacenter)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "datacenter": { + "type": "object", + "description": "ast.StructType object" + }, + "greVips": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "virtualIp": { + "type": "string" + }, + "privateServiceEdge": { + "type": "boolean" + }, + "datacenter": { + "type": "string" + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/vips/recommendedList": { + "get": { + "operationId": "trafficforwarding__virtualipaddress_GetZSGREVirtualIPList", + "summary": "GetZSGREVirtualIPList (Trafficforwarding / Virtualipaddress)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "cloudName": { + "type": "string" + }, + "region": { + "type": "string" + }, + "city": { + "type": "string" + }, + "dataCenter": { + "type": "string" + }, + "location": { + "type": "string" + }, + "vpnIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "vpnDomainName": { + "type": "string" + }, + "greIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "greDomainName": { + "type": "string" + }, + "pacIps": { + "type": "array", + "items": { + "type": "string" + } + }, + "pacDomainName": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/virtualZenClusters": { + "get": { + "operationId": "vzen_clusters_GetClusterByName", + "summary": "GetClusterByName (Vzen Clusters)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated Virtual Service Edge cluster ID" + }, + "name": { + "type": "string", + "description": "Name of the Virtual Service Edge cluster" + }, + "status": { + "type": "string", + "description": "Specifies the status of the Virtual Service Edge cluster. The status is set to ENABLED by default.\nSupported Values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER" + }, + "ipAddress": { + "type": "string", + "description": "The Virtual Service Edge cluster IP address.\nIn a Virtual Service Edge cluster, the cluster IP address provides fault tolerance and is used to listen for user traffic.\nThis interface doesn't explicitly get an IP address.\nThe cluster IP address must be in the same VLAN as the proxy and load balancer IP addresses." + }, + "subnetMask": { + "type": "string", + "description": "The Virtual Service Edge cluster subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge cluster type\nSee https://help.zscaler.com/zia/service-edges#/virtualZenClusters-post for all types" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that specifies whether to terminate IPSec traffic from the client at selected Virtual Service Edge instances for the Virtual Service Edge cluster" + }, + "virtualZenNodes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + }, + "description": "The Virtual Service Edge instances you want to include in the cluster.\nA Virtual Service Edge cluster must contain at least two Virtual Service Edge instances." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "vzen_clusters_Create", + "summary": "Create (Vzen Clusters)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated Virtual Service Edge cluster ID" + }, + "name": { + "type": "string", + "description": "Name of the Virtual Service Edge cluster" + }, + "status": { + "type": "string", + "description": "Specifies the status of the Virtual Service Edge cluster. The status is set to ENABLED by default.\nSupported Values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER" + }, + "ipAddress": { + "type": "string", + "description": "The Virtual Service Edge cluster IP address.\nIn a Virtual Service Edge cluster, the cluster IP address provides fault tolerance and is used to listen for user traffic.\nThis interface doesn't explicitly get an IP address.\nThe cluster IP address must be in the same VLAN as the proxy and load balancer IP addresses." + }, + "subnetMask": { + "type": "string", + "description": "The Virtual Service Edge cluster subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge cluster type\nSee https://help.zscaler.com/zia/service-edges#/virtualZenClusters-post for all types" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that specifies whether to terminate IPSec traffic from the client at selected Virtual Service Edge instances for the Virtual Service Edge cluster" + }, + "virtualZenNodes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + }, + "description": "The Virtual Service Edge instances you want to include in the cluster.\nA Virtual Service Edge cluster must contain at least two Virtual Service Edge instances." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated Virtual Service Edge cluster ID" + }, + "name": { + "type": "string", + "description": "Name of the Virtual Service Edge cluster" + }, + "status": { + "type": "string", + "description": "Specifies the status of the Virtual Service Edge cluster. The status is set to ENABLED by default.\nSupported Values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER" + }, + "ipAddress": { + "type": "string", + "description": "The Virtual Service Edge cluster IP address.\nIn a Virtual Service Edge cluster, the cluster IP address provides fault tolerance and is used to listen for user traffic.\nThis interface doesn't explicitly get an IP address.\nThe cluster IP address must be in the same VLAN as the proxy and load balancer IP addresses." + }, + "subnetMask": { + "type": "string", + "description": "The Virtual Service Edge cluster subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge cluster type\nSee https://help.zscaler.com/zia/service-edges#/virtualZenClusters-post for all types" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that specifies whether to terminate IPSec traffic from the client at selected Virtual Service Edge instances for the Virtual Service Edge cluster" + }, + "virtualZenNodes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + }, + "description": "The Virtual Service Edge instances you want to include in the cluster.\nA Virtual Service Edge cluster must contain at least two Virtual Service Edge instances." + } + } + } + } + } + } + } + }, + "/zia/api/v1/virtualZenClusters/{id}": { + "get": { + "operationId": "vzen_clusters_Get", + "summary": "Get (Vzen Clusters)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated Virtual Service Edge cluster ID" + }, + "name": { + "type": "string", + "description": "Name of the Virtual Service Edge cluster" + }, + "status": { + "type": "string", + "description": "Specifies the status of the Virtual Service Edge cluster. The status is set to ENABLED by default.\nSupported Values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER" + }, + "ipAddress": { + "type": "string", + "description": "The Virtual Service Edge cluster IP address.\nIn a Virtual Service Edge cluster, the cluster IP address provides fault tolerance and is used to listen for user traffic.\nThis interface doesn't explicitly get an IP address.\nThe cluster IP address must be in the same VLAN as the proxy and load balancer IP addresses." + }, + "subnetMask": { + "type": "string", + "description": "The Virtual Service Edge cluster subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge cluster type\nSee https://help.zscaler.com/zia/service-edges#/virtualZenClusters-post for all types" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that specifies whether to terminate IPSec traffic from the client at selected Virtual Service Edge instances for the Virtual Service Edge cluster" + }, + "virtualZenNodes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + }, + "description": "The Virtual Service Edge instances you want to include in the cluster.\nA Virtual Service Edge cluster must contain at least two Virtual Service Edge instances." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "vzen_clusters_Update", + "summary": "Update (Vzen Clusters)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated Virtual Service Edge cluster ID" + }, + "name": { + "type": "string", + "description": "Name of the Virtual Service Edge cluster" + }, + "status": { + "type": "string", + "description": "Specifies the status of the Virtual Service Edge cluster. The status is set to ENABLED by default.\nSupported Values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER" + }, + "ipAddress": { + "type": "string", + "description": "The Virtual Service Edge cluster IP address.\nIn a Virtual Service Edge cluster, the cluster IP address provides fault tolerance and is used to listen for user traffic.\nThis interface doesn't explicitly get an IP address.\nThe cluster IP address must be in the same VLAN as the proxy and load balancer IP addresses." + }, + "subnetMask": { + "type": "string", + "description": "The Virtual Service Edge cluster subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge cluster type\nSee https://help.zscaler.com/zia/service-edges#/virtualZenClusters-post for all types" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that specifies whether to terminate IPSec traffic from the client at selected Virtual Service Edge instances for the Virtual Service Edge cluster" + }, + "virtualZenNodes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + }, + "description": "The Virtual Service Edge instances you want to include in the cluster.\nA Virtual Service Edge cluster must contain at least two Virtual Service Edge instances." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated Virtual Service Edge cluster ID" + }, + "name": { + "type": "string", + "description": "Name of the Virtual Service Edge cluster" + }, + "status": { + "type": "string", + "description": "Specifies the status of the Virtual Service Edge cluster. The status is set to ENABLED by default.\nSupported Values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER" + }, + "ipAddress": { + "type": "string", + "description": "The Virtual Service Edge cluster IP address.\nIn a Virtual Service Edge cluster, the cluster IP address provides fault tolerance and is used to listen for user traffic.\nThis interface doesn't explicitly get an IP address.\nThe cluster IP address must be in the same VLAN as the proxy and load balancer IP addresses." + }, + "subnetMask": { + "type": "string", + "description": "The Virtual Service Edge cluster subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge cluster type\nSee https://help.zscaler.com/zia/service-edges#/virtualZenClusters-post for all types" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that specifies whether to terminate IPSec traffic from the client at selected Virtual Service Edge instances for the Virtual Service Edge cluster" + }, + "virtualZenNodes": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExternalID object" + }, + "description": "The Virtual Service Edge instances you want to include in the cluster.\nA Virtual Service Edge cluster must contain at least two Virtual Service Edge instances." + } + } + } + } + } + } + } + }, + "/zia/api/v1/virtualZenNodes": { + "get": { + "operationId": "vzen_nodes_GetNodeByName", + "summary": "GetNodeByName (Vzen Nodes)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the Virtual Service Edge. Ignored for POST and PUT requests." + }, + "zgatewayId": { + "type": "integer", + "description": "The Zscaler service gateway ID" + }, + "name": { + "type": "string", + "description": "The Virtual Service Edge name" + }, + "status": { + "type": "string", + "description": "Indicates the Virtual Service Edge status. Supported values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER, IN_TRIAL" + }, + "inProduction": { + "type": "boolean", + "description": "Represents the Virtual Service Edge instances deployed for production purposes" + }, + "ipAddress": { + "type": "string", + "description": "The IP address to which you forward the traffic.\nAll user and server workload traffic is forwarded to the proxy IP address of the Virtual Service Edge.\nIf the Virtual Service Edge has to receive and service traffic from users or workloads over the internet, ensure that this IP address has access to both the internet and users." + }, + "subnetMask": { + "type": "string", + "description": "The corresponding subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge subscription type" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether IPSec is enabled. Enable this option to terminate IPSec traffic from the client at the Virtual Service Edge node." + }, + "onDemandSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not the On-Demand Support Tunnel is enabled" + }, + "establishSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not a support tunnel for Zscaler Support is enabled.\nEnable this option to allow the service to establish a support tunnel for Zscaler Support to access the Virtual Service Edge." + }, + "loadBalancerIpAddress": { + "type": "string", + "description": "The IP address of the load balancer. This field is applicable only when the 'deploymentMode' field is set to CLUSTER." + }, + "deploymentMode": { + "type": "string", + "description": "Specifies the deployment mode. Select either STANDALONE or CLUSTER if you have the VMware ESXi platform. Otherwise, select only STANDALONE.\nSupporteed Values: STANDALONE, CLUSTER" + }, + "clusterName": { + "type": "string", + "description": "Virtual Service Edge cluster name" + }, + "vzenSkuType": { + "type": "string", + "description": "The Virtual Service Edge SKU type\nSupported Values: SMALL, MEDIUM, LARGE" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "vzen_nodes_Create", + "summary": "Create (Vzen Nodes)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the Virtual Service Edge. Ignored for POST and PUT requests." + }, + "zgatewayId": { + "type": "integer", + "description": "The Zscaler service gateway ID" + }, + "name": { + "type": "string", + "description": "The Virtual Service Edge name" + }, + "status": { + "type": "string", + "description": "Indicates the Virtual Service Edge status. Supported values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER, IN_TRIAL" + }, + "inProduction": { + "type": "boolean", + "description": "Represents the Virtual Service Edge instances deployed for production purposes" + }, + "ipAddress": { + "type": "string", + "description": "The IP address to which you forward the traffic.\nAll user and server workload traffic is forwarded to the proxy IP address of the Virtual Service Edge.\nIf the Virtual Service Edge has to receive and service traffic from users or workloads over the internet, ensure that this IP address has access to both the internet and users." + }, + "subnetMask": { + "type": "string", + "description": "The corresponding subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge subscription type" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether IPSec is enabled. Enable this option to terminate IPSec traffic from the client at the Virtual Service Edge node." + }, + "onDemandSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not the On-Demand Support Tunnel is enabled" + }, + "establishSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not a support tunnel for Zscaler Support is enabled.\nEnable this option to allow the service to establish a support tunnel for Zscaler Support to access the Virtual Service Edge." + }, + "loadBalancerIpAddress": { + "type": "string", + "description": "The IP address of the load balancer. This field is applicable only when the 'deploymentMode' field is set to CLUSTER." + }, + "deploymentMode": { + "type": "string", + "description": "Specifies the deployment mode. Select either STANDALONE or CLUSTER if you have the VMware ESXi platform. Otherwise, select only STANDALONE.\nSupporteed Values: STANDALONE, CLUSTER" + }, + "clusterName": { + "type": "string", + "description": "Virtual Service Edge cluster name" + }, + "vzenSkuType": { + "type": "string", + "description": "The Virtual Service Edge SKU type\nSupported Values: SMALL, MEDIUM, LARGE" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the Virtual Service Edge. Ignored for POST and PUT requests." + }, + "zgatewayId": { + "type": "integer", + "description": "The Zscaler service gateway ID" + }, + "name": { + "type": "string", + "description": "The Virtual Service Edge name" + }, + "status": { + "type": "string", + "description": "Indicates the Virtual Service Edge status. Supported values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER, IN_TRIAL" + }, + "inProduction": { + "type": "boolean", + "description": "Represents the Virtual Service Edge instances deployed for production purposes" + }, + "ipAddress": { + "type": "string", + "description": "The IP address to which you forward the traffic.\nAll user and server workload traffic is forwarded to the proxy IP address of the Virtual Service Edge.\nIf the Virtual Service Edge has to receive and service traffic from users or workloads over the internet, ensure that this IP address has access to both the internet and users." + }, + "subnetMask": { + "type": "string", + "description": "The corresponding subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge subscription type" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether IPSec is enabled. Enable this option to terminate IPSec traffic from the client at the Virtual Service Edge node." + }, + "onDemandSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not the On-Demand Support Tunnel is enabled" + }, + "establishSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not a support tunnel for Zscaler Support is enabled.\nEnable this option to allow the service to establish a support tunnel for Zscaler Support to access the Virtual Service Edge." + }, + "loadBalancerIpAddress": { + "type": "string", + "description": "The IP address of the load balancer. This field is applicable only when the 'deploymentMode' field is set to CLUSTER." + }, + "deploymentMode": { + "type": "string", + "description": "Specifies the deployment mode. Select either STANDALONE or CLUSTER if you have the VMware ESXi platform. Otherwise, select only STANDALONE.\nSupporteed Values: STANDALONE, CLUSTER" + }, + "clusterName": { + "type": "string", + "description": "Virtual Service Edge cluster name" + }, + "vzenSkuType": { + "type": "string", + "description": "The Virtual Service Edge SKU type\nSupported Values: SMALL, MEDIUM, LARGE" + } + } + } + } + } + } + } + }, + "/zia/api/v1/virtualZenNodes/{id}": { + "get": { + "operationId": "vzen_nodes_Get", + "summary": "Get (Vzen Nodes)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the Virtual Service Edge. Ignored for POST and PUT requests." + }, + "zgatewayId": { + "type": "integer", + "description": "The Zscaler service gateway ID" + }, + "name": { + "type": "string", + "description": "The Virtual Service Edge name" + }, + "status": { + "type": "string", + "description": "Indicates the Virtual Service Edge status. Supported values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER, IN_TRIAL" + }, + "inProduction": { + "type": "boolean", + "description": "Represents the Virtual Service Edge instances deployed for production purposes" + }, + "ipAddress": { + "type": "string", + "description": "The IP address to which you forward the traffic.\nAll user and server workload traffic is forwarded to the proxy IP address of the Virtual Service Edge.\nIf the Virtual Service Edge has to receive and service traffic from users or workloads over the internet, ensure that this IP address has access to both the internet and users." + }, + "subnetMask": { + "type": "string", + "description": "The corresponding subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge subscription type" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether IPSec is enabled. Enable this option to terminate IPSec traffic from the client at the Virtual Service Edge node." + }, + "onDemandSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not the On-Demand Support Tunnel is enabled" + }, + "establishSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not a support tunnel for Zscaler Support is enabled.\nEnable this option to allow the service to establish a support tunnel for Zscaler Support to access the Virtual Service Edge." + }, + "loadBalancerIpAddress": { + "type": "string", + "description": "The IP address of the load balancer. This field is applicable only when the 'deploymentMode' field is set to CLUSTER." + }, + "deploymentMode": { + "type": "string", + "description": "Specifies the deployment mode. Select either STANDALONE or CLUSTER if you have the VMware ESXi platform. Otherwise, select only STANDALONE.\nSupporteed Values: STANDALONE, CLUSTER" + }, + "clusterName": { + "type": "string", + "description": "Virtual Service Edge cluster name" + }, + "vzenSkuType": { + "type": "string", + "description": "The Virtual Service Edge SKU type\nSupported Values: SMALL, MEDIUM, LARGE" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "vzen_nodes_Update", + "summary": "Update (Vzen Nodes)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the Virtual Service Edge. Ignored for POST and PUT requests." + }, + "zgatewayId": { + "type": "integer", + "description": "The Zscaler service gateway ID" + }, + "name": { + "type": "string", + "description": "The Virtual Service Edge name" + }, + "status": { + "type": "string", + "description": "Indicates the Virtual Service Edge status. Supported values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER, IN_TRIAL" + }, + "inProduction": { + "type": "boolean", + "description": "Represents the Virtual Service Edge instances deployed for production purposes" + }, + "ipAddress": { + "type": "string", + "description": "The IP address to which you forward the traffic.\nAll user and server workload traffic is forwarded to the proxy IP address of the Virtual Service Edge.\nIf the Virtual Service Edge has to receive and service traffic from users or workloads over the internet, ensure that this IP address has access to both the internet and users." + }, + "subnetMask": { + "type": "string", + "description": "The corresponding subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge subscription type" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether IPSec is enabled. Enable this option to terminate IPSec traffic from the client at the Virtual Service Edge node." + }, + "onDemandSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not the On-Demand Support Tunnel is enabled" + }, + "establishSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not a support tunnel for Zscaler Support is enabled.\nEnable this option to allow the service to establish a support tunnel for Zscaler Support to access the Virtual Service Edge." + }, + "loadBalancerIpAddress": { + "type": "string", + "description": "The IP address of the load balancer. This field is applicable only when the 'deploymentMode' field is set to CLUSTER." + }, + "deploymentMode": { + "type": "string", + "description": "Specifies the deployment mode. Select either STANDALONE or CLUSTER if you have the VMware ESXi platform. Otherwise, select only STANDALONE.\nSupporteed Values: STANDALONE, CLUSTER" + }, + "clusterName": { + "type": "string", + "description": "Virtual Service Edge cluster name" + }, + "vzenSkuType": { + "type": "string", + "description": "The Virtual Service Edge SKU type\nSupported Values: SMALL, MEDIUM, LARGE" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the Virtual Service Edge. Ignored for POST and PUT requests." + }, + "zgatewayId": { + "type": "integer", + "description": "The Zscaler service gateway ID" + }, + "name": { + "type": "string", + "description": "The Virtual Service Edge name" + }, + "status": { + "type": "string", + "description": "Indicates the Virtual Service Edge status. Supported values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER, IN_TRIAL" + }, + "inProduction": { + "type": "boolean", + "description": "Represents the Virtual Service Edge instances deployed for production purposes" + }, + "ipAddress": { + "type": "string", + "description": "The IP address to which you forward the traffic.\nAll user and server workload traffic is forwarded to the proxy IP address of the Virtual Service Edge.\nIf the Virtual Service Edge has to receive and service traffic from users or workloads over the internet, ensure that this IP address has access to both the internet and users." + }, + "subnetMask": { + "type": "string", + "description": "The corresponding subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge subscription type" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether IPSec is enabled. Enable this option to terminate IPSec traffic from the client at the Virtual Service Edge node." + }, + "onDemandSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not the On-Demand Support Tunnel is enabled" + }, + "establishSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not a support tunnel for Zscaler Support is enabled.\nEnable this option to allow the service to establish a support tunnel for Zscaler Support to access the Virtual Service Edge." + }, + "loadBalancerIpAddress": { + "type": "string", + "description": "The IP address of the load balancer. This field is applicable only when the 'deploymentMode' field is set to CLUSTER." + }, + "deploymentMode": { + "type": "string", + "description": "Specifies the deployment mode. Select either STANDALONE or CLUSTER if you have the VMware ESXi platform. Otherwise, select only STANDALONE.\nSupporteed Values: STANDALONE, CLUSTER" + }, + "clusterName": { + "type": "string", + "description": "Virtual Service Edge cluster name" + }, + "vzenSkuType": { + "type": "string", + "description": "The Virtual Service Edge SKU type\nSupported Values: SMALL, MEDIUM, LARGE" + } + } + } + } + } + } + }, + "delete": { + "operationId": "vzen_nodes_Delete", + "summary": "Delete (Vzen Nodes)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System-generated identifier for the Virtual Service Edge. Ignored for POST and PUT requests." + }, + "zgatewayId": { + "type": "integer", + "description": "The Zscaler service gateway ID" + }, + "name": { + "type": "string", + "description": "The Virtual Service Edge name" + }, + "status": { + "type": "string", + "description": "Indicates the Virtual Service Edge status. Supported values: ENABLED, DISABLED, DISABLED_BY_SERVICE_PROVIDER, NOT_PROVISIONED_IN_SERVICE_PROVIDER, IN_TRIAL" + }, + "inProduction": { + "type": "boolean", + "description": "Represents the Virtual Service Edge instances deployed for production purposes" + }, + "ipAddress": { + "type": "string", + "description": "The IP address to which you forward the traffic.\nAll user and server workload traffic is forwarded to the proxy IP address of the Virtual Service Edge.\nIf the Virtual Service Edge has to receive and service traffic from users or workloads over the internet, ensure that this IP address has access to both the internet and users." + }, + "subnetMask": { + "type": "string", + "description": "The corresponding subnet mask" + }, + "defaultGateway": { + "type": "string", + "description": "The IP address of the default gateway to the internet" + }, + "type": { + "type": "string", + "description": "The Virtual Service Edge subscription type" + }, + "ipSecEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether IPSec is enabled. Enable this option to terminate IPSec traffic from the client at the Virtual Service Edge node." + }, + "onDemandSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not the On-Demand Support Tunnel is enabled" + }, + "establishSupportTunnelEnabled": { + "type": "boolean", + "description": "A Boolean value that indicates whether or not a support tunnel for Zscaler Support is enabled.\nEnable this option to allow the service to establish a support tunnel for Zscaler Support to access the Virtual Service Edge." + }, + "loadBalancerIpAddress": { + "type": "string", + "description": "The IP address of the load balancer. This field is applicable only when the 'deploymentMode' field is set to CLUSTER." + }, + "deploymentMode": { + "type": "string", + "description": "Specifies the deployment mode. Select either STANDALONE or CLUSTER if you have the VMware ESXi platform. Otherwise, select only STANDALONE.\nSupporteed Values: STANDALONE, CLUSTER" + }, + "clusterName": { + "type": "string", + "description": "Virtual Service Edge cluster name" + }, + "vzenSkuType": { + "type": "string", + "description": "The Virtual Service Edge SKU type\nSupported Values: SMALL, MEDIUM, LARGE" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/vpnCredentials": { + "get": { + "operationId": "trafficforwarding__vpncredentials_GetVPNByType", + "summary": "GetVPNByType (Trafficforwarding / Vpncredentials)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + } + } + } + } + } + }, + "post": { + "operationId": "trafficforwarding__vpncredentials_Create", + "summary": "Create (Trafficforwarding / Vpncredentials)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + } + } + } + } + } + }, + "/zia/api/v1/vpnCredentials/{id}": { + "get": { + "operationId": "trafficforwarding__vpncredentials_Get", + "summary": "Get (Trafficforwarding / Vpncredentials)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "trafficforwarding__vpncredentials_Update", + "summary": "Update (Trafficforwarding / Vpncredentials)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + } + } + } + } + }, + "delete": { + "operationId": "trafficforwarding__vpncredentials_Delete", + "summary": "Delete (Trafficforwarding / Vpncredentials)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "extensions": { + "type": "object" + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/webApplicationRules": { + "get": { + "operationId": "cloudappcontrol_GetRuleTypeMapping", + "summary": "GetRuleTypeMapping (Cloudappcontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/webApplicationRules/{id}": { + "get": { + "operationId": "cloudappcontrol_GetByRuleType", + "summary": "GetByRuleType (Cloudappcontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "post": { + "operationId": "cloudappcontrol_Create", + "summary": "Create (Cloudappcontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + } + }, + "/zia/api/v1/webApplicationRules/{id}/{id2}": { + "get": { + "operationId": "cloudappcontrol_GetByRuleID", + "summary": "GetByRuleID (Cloudappcontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "cloudappcontrol_Update", + "summary": "Update (Cloudappcontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "delete": { + "operationId": "cloudappcontrol_Delete", + "summary": "Delete (Cloudappcontrol)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + }, + { + "name": "id2", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/webDlpGlobalOptions": { + "get": { + "operationId": "dlp__dlp_global_options_GetDLPGlobalOptions", + "summary": "GetDLPGlobalOptions (Dlp / Dlp Global Options)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "urls": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "exemptUrlEncodedData": { + "type": "boolean" + }, + "enableNpkEdmTemplates": { + "type": "boolean" + }, + "enableNpkEdmTemplatesForOrg": { + "type": "boolean" + }, + "enableInlineDlpOcr": { + "type": "boolean" + }, + "enableCasbOcr": { + "type": "boolean" + }, + "enableEmailDlpOcr": { + "type": "boolean" + }, + "enableEvaluateAllDlpRules": { + "type": "boolean" + }, + "enableEdmPopularFormat": { + "type": "boolean" + }, + "httpGetCustomUrlCategories": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "put": { + "operationId": "dlp__dlp_global_options_UpdateDLPGlobalOptions", + "summary": "UpdateDLPGlobalOptions (Dlp / Dlp Global Options)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "urls": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "exemptUrlEncodedData": { + "type": "boolean" + }, + "enableNpkEdmTemplates": { + "type": "boolean" + }, + "enableNpkEdmTemplatesForOrg": { + "type": "boolean" + }, + "enableInlineDlpOcr": { + "type": "boolean" + }, + "enableCasbOcr": { + "type": "boolean" + }, + "enableEmailDlpOcr": { + "type": "boolean" + }, + "enableEvaluateAllDlpRules": { + "type": "boolean" + }, + "enableEdmPopularFormat": { + "type": "boolean" + }, + "httpGetCustomUrlCategories": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "urls": { + "type": "array", + "items": { + "type": "string" + } + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "exemptUrlEncodedData": { + "type": "boolean" + }, + "enableNpkEdmTemplates": { + "type": "boolean" + }, + "enableNpkEdmTemplatesForOrg": { + "type": "boolean" + }, + "enableInlineDlpOcr": { + "type": "boolean" + }, + "enableCasbOcr": { + "type": "boolean" + }, + "enableEmailDlpOcr": { + "type": "boolean" + }, + "enableEvaluateAllDlpRules": { + "type": "boolean" + }, + "enableEdmPopularFormat": { + "type": "boolean" + }, + "httpGetCustomUrlCategories": { + "type": "array", + "items": { + "type": "string" + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/webDlpRules": { + "get": { + "operationId": "dlp__dlp_web_rules_GetByName", + "summary": "GetByName (Dlp / Dlp Web Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "dlp__dlp_web_rules_Create", + "summary": "Create (Dlp / Dlp Web Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + } + }, + "/zia/api/v1/webDlpRules/{id}": { + "get": { + "operationId": "dlp__dlp_web_rules_Get", + "summary": "Get (Dlp / Dlp Web Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "dlp__dlp_web_rules_Update", + "summary": "Update (Dlp / Dlp Web Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "delete": { + "operationId": "dlp__dlp_web_rules_Delete", + "summary": "Delete (Dlp / Dlp Web Rules)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/workloadGroups": { + "get": { + "operationId": "workloadgroups_GetByName", + "summary": "GetByName (Workloadgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the workload group" + }, + "name": { + "type": "string", + "description": "The name of the workload group" + }, + "description": { + "type": "string", + "description": "The description of the workload group" + }, + "expression": { + "type": "string", + "description": "The workload group expression containing tag types, tags, and their relationships." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the workload group was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin that last modified the workload group" + }, + "expressionJson": { + "type": "object", + "properties": { + "expressionContainers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "tagType": { + "type": "string", + "description": "The tag type selected from a predefined list" + }, + "operator": { + "type": "string", + "description": "The operator (either AND or OR) used to create logical relationships among tag types" + }, + "tagContainer": { + "type": "object", + "description": "Contains one or more tags and the logical operator used to combine the tags within a tag type" + } + } + } + } + } + } + } + } + } + } + } + } + }, + "post": { + "operationId": "workloadgroups_Create", + "summary": "Create (Workloadgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the workload group" + }, + "name": { + "type": "string", + "description": "The name of the workload group" + }, + "description": { + "type": "string", + "description": "The description of the workload group" + }, + "expression": { + "type": "string", + "description": "The workload group expression containing tag types, tags, and their relationships." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the workload group was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin that last modified the workload group" + }, + "expressionJson": { + "type": "object", + "properties": { + "expressionContainers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "tagType": { + "type": "string", + "description": "The tag type selected from a predefined list" + }, + "operator": { + "type": "string", + "description": "The operator (either AND or OR) used to create logical relationships among tag types" + }, + "tagContainer": { + "type": "object", + "description": "Contains one or more tags and the logical operator used to combine the tags within a tag type" + } + } + } + } + } + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the workload group" + }, + "name": { + "type": "string", + "description": "The name of the workload group" + }, + "description": { + "type": "string", + "description": "The description of the workload group" + }, + "expression": { + "type": "string", + "description": "The workload group expression containing tag types, tags, and their relationships." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the workload group was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin that last modified the workload group" + }, + "expressionJson": { + "type": "object", + "properties": { + "expressionContainers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "tagType": { + "type": "string", + "description": "The tag type selected from a predefined list" + }, + "operator": { + "type": "string", + "description": "The operator (either AND or OR) used to create logical relationships among tag types" + }, + "tagContainer": { + "type": "object", + "description": "Contains one or more tags and the logical operator used to combine the tags within a tag type" + } + } + } + } + } + } + } + } + } + } + } + } + }, + "/zia/api/v1/workloadGroups/{id}": { + "get": { + "operationId": "workloadgroups_Get", + "summary": "Get (Workloadgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the workload group" + }, + "name": { + "type": "string", + "description": "The name of the workload group" + }, + "description": { + "type": "string", + "description": "The description of the workload group" + }, + "expression": { + "type": "string", + "description": "The workload group expression containing tag types, tags, and their relationships." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the workload group was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin that last modified the workload group" + }, + "expressionJson": { + "type": "object", + "properties": { + "expressionContainers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "tagType": { + "type": "string", + "description": "The tag type selected from a predefined list" + }, + "operator": { + "type": "string", + "description": "The operator (either AND or OR) used to create logical relationships among tag types" + }, + "tagContainer": { + "type": "object", + "description": "Contains one or more tags and the logical operator used to combine the tags within a tag type" + } + } + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "workloadgroups_Update", + "summary": "Update (Workloadgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the workload group" + }, + "name": { + "type": "string", + "description": "The name of the workload group" + }, + "description": { + "type": "string", + "description": "The description of the workload group" + }, + "expression": { + "type": "string", + "description": "The workload group expression containing tag types, tags, and their relationships." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the workload group was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin that last modified the workload group" + }, + "expressionJson": { + "type": "object", + "properties": { + "expressionContainers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "tagType": { + "type": "string", + "description": "The tag type selected from a predefined list" + }, + "operator": { + "type": "string", + "description": "The operator (either AND or OR) used to create logical relationships among tag types" + }, + "tagContainer": { + "type": "object", + "description": "Contains one or more tags and the logical operator used to combine the tags within a tag type" + } + } + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the workload group" + }, + "name": { + "type": "string", + "description": "The name of the workload group" + }, + "description": { + "type": "string", + "description": "The description of the workload group" + }, + "expression": { + "type": "string", + "description": "The workload group expression containing tag types, tags, and their relationships." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the workload group was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin that last modified the workload group" + }, + "expressionJson": { + "type": "object", + "properties": { + "expressionContainers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "tagType": { + "type": "string", + "description": "The tag type selected from a predefined list" + }, + "operator": { + "type": "string", + "description": "The operator (either AND or OR) used to create logical relationships among tag types" + }, + "tagContainer": { + "type": "object", + "description": "Contains one or more tags and the logical operator used to combine the tags within a tag type" + } + } + } + } + } + } + } + } + } + } + } + }, + "delete": { + "operationId": "workloadgroups_Delete", + "summary": "Delete (Workloadgroups)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the workload group" + }, + "name": { + "type": "string", + "description": "The name of the workload group" + }, + "description": { + "type": "string", + "description": "The description of the workload group" + }, + "expression": { + "type": "string", + "description": "The workload group expression containing tag types, tags, and their relationships." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the workload group was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin that last modified the workload group" + }, + "expressionJson": { + "type": "object", + "properties": { + "expressionContainers": { + "type": "array", + "items": { + "type": "object", + "properties": { + "tagType": { + "type": "string", + "description": "The tag type selected from a predefined list" + }, + "operator": { + "type": "string", + "description": "The operator (either AND or OR) used to create logical relationships among tag types" + }, + "tagContainer": { + "type": "object", + "description": "Contains one or more tags and the logical operator used to combine the tags within a tag type" + } + } + } + } + } + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + }, + "/zia/api/v1/zpaGateways": { + "get": { + "operationId": "forwarding_control_policy__zpa_gateways_GetByName", + "summary": "GetByName (Forwarding Control Policy / Zpa Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the ZPA gateway" + }, + "name": { + "type": "string", + "description": "The name of the ZPA gateway" + }, + "description": { + "type": "string", + "description": "Additional details about the ZPA gateway" + }, + "zpaServerGroup": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + }, + "description": "The ZPA Server Group that is configured for Source IP Anchoring" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + } + }, + "description": "All the Application Segments that are associated with the selected ZPA Server Group for which Source IP Anchoring is enabled" + }, + "zpaTenantId": { + "type": "integer", + "description": "The ID of the ZPA tenant where Source IP Anchoring is configured" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin user that last modified the ZPA gateway" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the ZPA gateway was last modified" + }, + "type": { + "type": "string", + "description": "Indicates whether the ZPA gateway is configured for Zscaler Internet Access (using option ZPA) or Zscaler Cloud Connector (using option ECZPA)\nSupported Values: \"ZPA\", \"ECZPA\"" + } + } + } + } + } + } + } + }, + "post": { + "operationId": "forwarding_control_policy__zpa_gateways_Create", + "summary": "Create (Forwarding Control Policy / Zpa Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the ZPA gateway" + }, + "name": { + "type": "string", + "description": "The name of the ZPA gateway" + }, + "description": { + "type": "string", + "description": "Additional details about the ZPA gateway" + }, + "zpaServerGroup": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + }, + "description": "The ZPA Server Group that is configured for Source IP Anchoring" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + } + }, + "description": "All the Application Segments that are associated with the selected ZPA Server Group for which Source IP Anchoring is enabled" + }, + "zpaTenantId": { + "type": "integer", + "description": "The ID of the ZPA tenant where Source IP Anchoring is configured" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin user that last modified the ZPA gateway" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the ZPA gateway was last modified" + }, + "type": { + "type": "string", + "description": "Indicates whether the ZPA gateway is configured for Zscaler Internet Access (using option ZPA) or Zscaler Cloud Connector (using option ECZPA)\nSupported Values: \"ZPA\", \"ECZPA\"" + } + } + } + } + } + } + }, + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the ZPA gateway" + }, + "name": { + "type": "string", + "description": "The name of the ZPA gateway" + }, + "description": { + "type": "string", + "description": "Additional details about the ZPA gateway" + }, + "zpaServerGroup": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + }, + "description": "The ZPA Server Group that is configured for Source IP Anchoring" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + } + }, + "description": "All the Application Segments that are associated with the selected ZPA Server Group for which Source IP Anchoring is enabled" + }, + "zpaTenantId": { + "type": "integer", + "description": "The ID of the ZPA tenant where Source IP Anchoring is configured" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin user that last modified the ZPA gateway" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the ZPA gateway was last modified" + }, + "type": { + "type": "string", + "description": "Indicates whether the ZPA gateway is configured for Zscaler Internet Access (using option ZPA) or Zscaler Cloud Connector (using option ECZPA)\nSupported Values: \"ZPA\", \"ECZPA\"" + } + } + } + } + } + } + } + }, + "/zia/api/v1/zpaGateways/{id}": { + "get": { + "operationId": "forwarding_control_policy__zpa_gateways_Get", + "summary": "Get (Forwarding Control Policy / Zpa Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the ZPA gateway" + }, + "name": { + "type": "string", + "description": "The name of the ZPA gateway" + }, + "description": { + "type": "string", + "description": "Additional details about the ZPA gateway" + }, + "zpaServerGroup": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + }, + "description": "The ZPA Server Group that is configured for Source IP Anchoring" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + } + }, + "description": "All the Application Segments that are associated with the selected ZPA Server Group for which Source IP Anchoring is enabled" + }, + "zpaTenantId": { + "type": "integer", + "description": "The ID of the ZPA tenant where Source IP Anchoring is configured" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin user that last modified the ZPA gateway" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the ZPA gateway was last modified" + }, + "type": { + "type": "string", + "description": "Indicates whether the ZPA gateway is configured for Zscaler Internet Access (using option ZPA) or Zscaler Cloud Connector (using option ECZPA)\nSupported Values: \"ZPA\", \"ECZPA\"" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + }, + "put": { + "operationId": "forwarding_control_policy__zpa_gateways_Update", + "summary": "Update (Forwarding Control Policy / Zpa Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the ZPA gateway" + }, + "name": { + "type": "string", + "description": "The name of the ZPA gateway" + }, + "description": { + "type": "string", + "description": "Additional details about the ZPA gateway" + }, + "zpaServerGroup": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + }, + "description": "The ZPA Server Group that is configured for Source IP Anchoring" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + } + }, + "description": "All the Application Segments that are associated with the selected ZPA Server Group for which Source IP Anchoring is enabled" + }, + "zpaTenantId": { + "type": "integer", + "description": "The ID of the ZPA tenant where Source IP Anchoring is configured" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin user that last modified the ZPA gateway" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the ZPA gateway was last modified" + }, + "type": { + "type": "string", + "description": "Indicates whether the ZPA gateway is configured for Zscaler Internet Access (using option ZPA) or Zscaler Cloud Connector (using option ECZPA)\nSupported Values: \"ZPA\", \"ECZPA\"" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the ZPA gateway" + }, + "name": { + "type": "string", + "description": "The name of the ZPA gateway" + }, + "description": { + "type": "string", + "description": "Additional details about the ZPA gateway" + }, + "zpaServerGroup": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + }, + "description": "The ZPA Server Group that is configured for Source IP Anchoring" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + } + }, + "description": "All the Application Segments that are associated with the selected ZPA Server Group for which Source IP Anchoring is enabled" + }, + "zpaTenantId": { + "type": "integer", + "description": "The ID of the ZPA tenant where Source IP Anchoring is configured" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin user that last modified the ZPA gateway" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the ZPA gateway was last modified" + }, + "type": { + "type": "string", + "description": "Indicates whether the ZPA gateway is configured for Zscaler Internet Access (using option ZPA) or Zscaler Cloud Connector (using option ECZPA)\nSupported Values: \"ZPA\", \"ECZPA\"" + } + } + } + } + } + } + }, + "delete": { + "operationId": "forwarding_control_policy__zpa_gateways_Delete", + "summary": "Delete (Forwarding Control Policy / Zpa Gateways)", + "responses": { + "200": { + "description": "OK", + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier assigned to the ZPA gateway" + }, + "name": { + "type": "string", + "description": "The name of the ZPA gateway" + }, + "description": { + "type": "string", + "description": "Additional details about the ZPA gateway" + }, + "zpaServerGroup": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + }, + "description": "The ZPA Server Group that is configured for Source IP Anchoring" + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The name of the Application Segment" + }, + "externalId": { + "type": "string", + "description": "An external identifier used for an entity that is managed outside of ZIA.\nExamples include zpaServerGroup and zpaAppSegments.\nThis field is not applicable to ZIA-managed entities." + }, + "extensions": { + "type": "object" + } + } + }, + "description": "All the Application Segments that are associated with the selected ZPA Server Group for which Source IP Anchoring is enabled" + }, + "zpaTenantId": { + "type": "integer", + "description": "The ID of the ZPA tenant where Source IP Anchoring is configured" + }, + "lastModifiedBy": { + "type": "object", + "description": "Information about the admin user that last modified the ZPA gateway" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the ZPA gateway was last modified" + }, + "type": { + "type": "string", + "description": "Indicates whether the ZPA gateway is configured for Zscaler Internet Access (using option ZPA) or Zscaler Cloud Connector (using option ECZPA)\nSupported Values: \"ZPA\", \"ECZPA\"" + } + } + } + } + } + } + }, + "parameters": [ + { + "name": "id", + "in": "path", + "required": true, + "schema": { + "type": "string" + } + } + ] + } + } + }, + "components": { + "securitySchemes": { + "oneApiOAuth2": { + "type": "oauth2", + "flows": { + "clientCredentials": { + "tokenUrl": "https://VANITY-DOMAIN.zslogin.net/oauth2/v1/token", + "scopes": {} + } + } + } + } + } +} \ No newline at end of file diff --git a/Zscaler/ZIA/README.md b/Zscaler/ZIA/README.md new file mode 100644 index 0000000..6573229 --- /dev/null +++ b/Zscaler/ZIA/README.md @@ -0,0 +1,118 @@ +Zscaler Internet Access (ZIA) is Zscaler's cloud-delivered secure web gateway — firewall, URL filtering, DLP, and cloud app control enforced at the cloud edge. + +This project provides OpenAPI specs for automating against ZIA's REST API via an Integration Model, plus a Studio Project of ready-to-import CRUD workflows built on that model. + +## Table of Contents + +- [Contents](#contents) +- [Requirements](#requirements) +- [Integration Configuration](#integration-configuration) +- [OpenAPIs](#openapis) + - [`zscaler_zia_api-latest.json`](#zscaler_zia_api-latestjson) + - [`zscaler_zia_api-v3.8.46.json`](#zscaler_zia_api-v3846json) +- [Studio Projects](#studio-projects) + - [Zscaler ZIA Project](#zscaler-zia-project) + - [Folder Structure](#folder-structure) + - [Dependencies](#dependencies) + +## Contents + +| Asset | Description | +|---|---| +| [OpenAPIs/](./OpenAPIs/) | Zscaler ZIA API OpenAPI specs — curated `-latest` plus the full dated spec | +| [Studio Projects/](./Studio%20Projects/) | Itential Platform project containing all 111 workflows in 9 folders | + +## Requirements + +| Requirement | Version | +|---|---| +| Itential Platform | 6.x | +| `Zscaler Internet Access (ZIA) API:latest` Integration Model | Required to build automation against the OpenAPI spec, and to run the Studio Project below | +| Zscaler OneAPI access enabled for your organization | Required — not self-service; contact your Zscaler account team | + +## Integration Configuration + +Import `zscaler_zia_api-latest.json` as an Integration Model in **Admin > Integrations**, then create an integration pointing at Zscaler's OneAPI host. + +Authentication is OAuth2 client-credentials via Zscaler's unified OneAPI platform (brokered through Zidentity). Generate a client ID/secret at Admin Portal → API Key Management → OneAPI Credentials. + +The token request also requires a fixed `audience=https://api.zscaler.com` parameter alongside `client_id`/`client_secret` — configure this as an extra static token-request parameter on the integration if your platform version supports it. + +The instance's `authentication`/`server` properties should look like this once configured: + +```json +{ + "authentication": { + "oneApiOAuth2": { + "client_id": "", + "client_secret": "", + "token_url": "https://.zslogin.net/oauth2/v1/token" + } + }, + "server": { + "protocol": "https", + "host": "api.zsapi.net", + "base_path": "" + } +} +``` + +Non-production clouds use `api..zsapi.net` instead of `api.zsapi.net`. + +## OpenAPIs + +| Spec | Version | Operations | Description | +|---|---|---|---| +| [`zscaler_zia_api-latest.json`](./OpenAPIs/zscaler_zia_api-latest.json) | latest (curated) | 111 | Trimmed to 111 of 479 upstream operations covering common CRUD for automation — see breakdown below | +| [`zscaler_zia_api-v3.8.46.json`](./OpenAPIs/zscaler_zia_api-v3.8.46.json) | v3.8.46 | 479 | Full spec extracted from Zscaler's official SDK — the vendor's complete ZIA API surface | + +### `zscaler_zia_api-latest.json` + +Both specs in this folder were built directly from Zscaler's official, actively-maintained [`zscaler-sdk-go`](https://github.com/zscaler/zscaler-sdk-go) source — endpoint paths, HTTP verbs, and field-level request/response schemas (including per-field doc comments) were extracted from the SDK's typed Go structs and service functions. + +Trimmed to 111 of 479 upstream operations covering common CRUD for automation. The full SDK models ZIA's entire API surface, including DNS control, forwarding control, IPS/NAT control, SSL inspection, sandbox, traffic forwarding/GRE, NSS feeds, malware protection, bandwidth control, endpoint DLP, SaaS security, admin/role management, and dozens of other specialized areas — none of those are included here. + +Resources included, by category: + +- **Firewall Policies**: Filtering rules, network services/service groups, network applications/application groups, IP source/destination groups, time windows, app services/service groups +- **URL Filtering**: Rules, advanced URL filter & cloud app settings +- **URL Categories**: List, get, create, update, delete +- **Cloud App Control**: Web application rules by type +- **DLP**: Dictionaries, engines, web rules, notification templates, ICAP servers +- **File Type Control**: Rules, categories, custom file types +- **Locations**: Locations, sub-locations, location groups +- **Rule Labels**: List, get, create, update, delete +- **User Management**: Users, groups, departments + +A handful of resource names are prefixed with `Zscaler` (`Zscaler Group`/`Zscaler User` workflows) to avoid colliding with identically-named workflows already published for other products — workflow names are unique across the whole Itential Platform instance, not scoped per-project. + +### `zscaler_zia_api-v3.8.46.json` + +Full spec extracted from `zscaler-sdk-go` release `v3.8.46` (479 operations) — the vendor's complete ZIA API surface as implemented in the SDK, preserved as-is. See `zscaler_zia_api-latest.json` above for the curated subset if you just need common CRUD automation. + +## Studio Projects + +### Zscaler ZIA Project + +Backed by the **`Zscaler Internet Access (ZIA) API:latest`** Integration Model (see [`zscaler_zia_api-latest.json`](./OpenAPIs/zscaler_zia_api-latest.json) above). The project contains **111 workflows** organized into **9 folders**. + +#### Folder Structure + +| Folder | Workflows | Scope | +|---|---|---| +| Firewall Policies | 35 | Filtering rules and their supporting objects | +| DLP | 23 | Dictionaries, engines, web rules, notification templates, ICAP servers | +| User Management | 15 | Users, groups, departments | +| Locations | 8 | Locations, sub-locations, location groups | +| URL Filtering | 7 | Rules, advanced URL filter & cloud app settings | +| File Type Control | 7 | Rules, categories, custom file types | +| Cloud App Control | 6 | Web application rules by type | +| URL Categories | 5 | List, get, create, update, delete | +| Rule Labels | 5 | List, get, create, update, delete | + +#### Dependencies + +| Dependency | Notes | +|---|---| +| `Zscaler Internet Access (ZIA) API:latest` Integration Model | Import from [`zscaler_zia_api-latest.json`](./OpenAPIs/zscaler_zia_api-latest.json) before importing the project | +| `Zscaler` integration instance | Create in **Admin > Integrations** with the connection properties above. Workflows are wired to an integration instance named `Zscaler` — update the `adapter_id` value in each workflow task if yours is named differently | diff --git a/Zscaler/ZIA/Studio Projects/Zscaler ZIA.project.json b/Zscaler/ZIA/Studio Projects/Zscaler ZIA.project.json new file mode 100644 index 0000000..577bb93 --- /dev/null +++ b/Zscaler/ZIA/Studio Projects/Zscaler ZIA.project.json @@ -0,0 +1,25435 @@ +{ + "_id": "6a7f7e85fd87f0fb17f8d3ca", + "name": "Zscaler ZIA", + "description": "Firewall Policies, URL Filtering & Categories, Cloud App Control, DLP, File Type Control, Locations, Rule Labels, and User Management workflows backed by the Zscaler Internet Access (ZIA) API Integration Model.", + "components": [ + { + "iid": 0, + "reference": "f9bfa888-8fb8-4402-a871-72d690714485", + "type": "workflow", + "folder": "/Cloud App Control", + "document": { + "name": "Get Web Application Rule", + "description": "Get Web Application Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "cloudappcontrol_GetByRuleID", + "canvasName": "cloudappcontrol_GetByRuleID", + "summary": "cloudappcontrol_GetByRuleID", + "description": "cloudappcontrol_GetByRuleID", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "ruleType": "$var.job.ruleType", + "ruleId": "$var.job.ruleId" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "ruleType": { + "type": "string" + }, + "ruleId": { + "type": "string" + } + }, + "required": [ + "ruleType", + "ruleId" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "ruleType": { + "type": "string" + }, + "ruleId": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "f58ec0cd-a11f-4247-b67b-67f13d311b6b", + "created": "2026-08-14T20:45:27.411Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 1, + "reference": "694bb005-a4db-49de-b0bc-451267916e84", + "type": "workflow", + "folder": "/Cloud App Control", + "document": { + "name": "List Web Application Rules by Type", + "description": "List Web Application Rules by Type", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "cloudappcontrol_GetByRuleType", + "canvasName": "cloudappcontrol_GetByRuleType", + "summary": "cloudappcontrol_GetByRuleType", + "description": "cloudappcontrol_GetByRuleType", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "ruleType": "$var.job.ruleType" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "ruleType": { + "type": "string" + } + }, + "required": [ + "ruleType" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "ruleType": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "24840442-4f35-4cde-b7d9-b8b5ab8c291e", + "created": "2026-08-14T20:45:27.523Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 2, + "reference": "a3addaca-d3d7-4d8a-a611-e03539b5faa4", + "type": "workflow", + "folder": "/Cloud App Control", + "document": { + "name": "Create Web Application Rule", + "description": "Create Web Application Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "cloudappcontrol_Create", + "canvasName": "cloudappcontrol_Create", + "summary": "cloudappcontrol_Create", + "description": "cloudappcontrol_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "ruleType": "$var.job.ruleType", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "ruleType": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + }, + "required": [ + "ruleType", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "ruleType": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "e9a9f55c-75c6-4135-81ad-7ea9f0cda84d", + "created": "2026-08-14T20:45:27.597Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 3, + "reference": "d9d24706-ef5e-4335-8a42-e71f6ddf5d4f", + "type": "workflow", + "folder": "/Cloud App Control", + "document": { + "name": "Update Web Application Rule", + "description": "Update Web Application Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "cloudappcontrol_Update", + "canvasName": "cloudappcontrol_Update", + "summary": "cloudappcontrol_Update", + "description": "cloudappcontrol_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "ruleType": "$var.job.ruleType", + "ruleId": "$var.job.ruleId", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "ruleType": { + "type": "string" + }, + "ruleId": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + } + }, + "required": [ + "ruleType", + "ruleId", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "ruleType": { + "type": "string" + }, + "ruleId": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "description": { + "type": "string" + }, + "actions": { + "type": "array", + "items": { + "type": "string" + } + }, + "state": { + "type": "string" + }, + "rank": { + "type": "integer" + }, + "type": { + "type": "string" + }, + "order": { + "type": "integer" + }, + "timeQuota": { + "type": "integer" + }, + "sizeQuota": { + "type": "integer" + }, + "cascadingEnabled": { + "type": "boolean" + }, + "accessControl": { + "type": "string" + }, + "applications": { + "type": "array", + "items": { + "type": "string" + } + }, + "numberOfApplications": { + "type": "integer" + }, + "eunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "validityStartTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule is valid starting on this date and time." + }, + "validityEndTime": { + "type": "integer", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule ceases to be valid on this end date and time." + }, + "validityTimeZoneId": { + "type": "string", + "description": "If enforceTimeValidity is set to true, the URL Filtering rule date and time is valid based on this time zone ID." + }, + "userAgentTypes": { + "type": "array", + "items": { + "type": "string" + } + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "enforceTimeValidity": { + "type": "boolean", + "description": "Enforce a set a validity time period for the URL Filtering rule. To learn more, see Configuring the URL Filtering Policy." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "cloudAppInstances": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + } + } + } + }, + "tenancyProfileIds": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "FormSharingDomainProfiles []common.CommonEntityReferences `json:\"formSharingDomainProfiles,omitempty\"`\nSharingDomainProfiles []common.CommonEntityReferences `json:\"sharingDomainProfiles,omitempty\"`" + }, + "cloudAppRiskProfile": { + "type": "object", + "description": "common.IDCustom object" + }, + "cbiProfile": { + "type": "object", + "properties": { + "profileSeq": { + "type": "integer" + }, + "id": { + "type": "string", + "description": "The universally unique identifier (UUID) for the browser isolation profile" + }, + "name": { + "type": "string", + "description": "Name of the browser isolation profile" + }, + "url": { + "type": "string", + "description": "The browser isolation profile URL" + }, + "defaultProfile": { + "type": "boolean", + "description": "(Optional) Indicates whether this is a default browser isolation profile. Zscaler sets this field." + }, + "sandboxMode": { + "type": "boolean", + "description": "Indicates whether sandboxMode is enabled for this profile configured in Cloud Browser Isolation" + } + }, + "description": "The cloud browser isolation profile to which the ISOLATE action is applied in the URL Filtering Policy rules.\nNote: This parameter is required for the ISOLATE action and is not applicable to other actions." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "7001d07b-3df4-4cf6-80e1-37bed68752f7", + "created": "2026-08-14T20:45:27.660Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 4, + "reference": "45b57bcf-1679-4af5-9c61-08b95cc3fb35", + "type": "workflow", + "folder": "/Cloud App Control", + "document": { + "name": "Delete Web Application Rule", + "description": "Delete Web Application Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "cloudappcontrol_Delete", + "canvasName": "cloudappcontrol_Delete", + "summary": "cloudappcontrol_Delete", + "description": "cloudappcontrol_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "ruleType": "$var.job.ruleType", + "ruleId": "$var.job.ruleId" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "ruleType": { + "type": "string" + }, + "ruleId": { + "type": "string" + } + }, + "required": [ + "ruleType", + "ruleId" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "ruleType": { + "type": "string" + }, + "ruleId": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "11fe28ae-ce4c-4f2e-92ad-dddbd8fbd5c0", + "created": "2026-08-14T20:45:27.725Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 5, + "reference": "baed6de7-5d59-4f3c-9c8a-a9c7bbf6034f", + "type": "workflow", + "folder": "/Cloud App Control", + "document": { + "name": "List Web Application Rules", + "description": "List Web Application Rules", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "cloudappcontrol_GetRuleTypeMapping", + "canvasName": "cloudappcontrol_GetRuleTypeMapping", + "summary": "cloudappcontrol_GetRuleTypeMapping", + "description": "cloudappcontrol_GetRuleTypeMapping", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "97e8993e-4a92-4d0e-aa90-0a59be81bbd4", + "created": "2026-08-14T20:45:27.781Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 6, + "reference": "bcae79f9-e4c0-4abc-b7ff-29819bede1f8", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Get DLP Engine", + "description": "Get DLP Engine", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_engines_Get", + "canvasName": "dlp_engines_Get", + "summary": "dlp_engines_Get", + "description": "dlp_engines_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "eabd5c3c-f73f-4ab1-b74f-60167cd74748", + "created": "2026-08-14T20:45:27.844Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 7, + "reference": "5fff54e8-d4a2-4991-84d0-148d342b30df", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Create DLP Engine", + "description": "Create DLP Engine", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_engines_Create", + "canvasName": "dlp_engines_Create", + "summary": "dlp_engines_Create", + "description": "dlp_engines_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "9ac54b83-a16c-41bf-9827-001368a18c73", + "created": "2026-08-14T20:45:27.909Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 8, + "reference": "bfa57549-337c-4cd2-9603-64059aa5ac8b", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Update DLP Engine", + "description": "Update DLP Engine", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_engines_Update", + "canvasName": "dlp_engines_Update", + "summary": "dlp_engines_Update", + "description": "dlp_engines_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP engine." + }, + "name": { + "type": "string", + "description": "The DLP engine name as configured by the admin. This attribute is required in POST and PUT requests for custom DLP engines." + }, + "description": { + "type": "string", + "description": "The DLP engine's description." + }, + "predefinedEngineName": { + "type": "string", + "description": "The name of the predefined DLP engine." + }, + "engineExpression": { + "type": "string", + "description": "The boolean logical operator in which various DLP dictionaries are combined within a DLP engine's expression." + }, + "customDlpEngine": { + "type": "boolean", + "description": "Indicates whether this is a custom DLP engine. If this value is set to true, the engine is custom." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "f0805dce-e759-4c14-9eb8-80ca92fa08cb", + "created": "2026-08-14T20:45:28.006Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 9, + "reference": "ebf7f1de-73c3-474d-9c76-0a53eb1240ff", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Delete DLP Engine", + "description": "Delete DLP Engine", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_engines_Delete", + "canvasName": "dlp_engines_Delete", + "summary": "dlp_engines_Delete", + "description": "dlp_engines_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "e6358a9b-c06f-4aca-a0ba-a4a1e90f0f09", + "created": "2026-08-14T20:45:28.061Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 10, + "reference": "44c2b826-b2c8-425c-80e7-a68050896377", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "List DLP Engines", + "description": "List DLP Engines", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_engines_GetAll", + "canvasName": "dlp_engines_GetAll", + "summary": "dlp_engines_GetAll", + "description": "dlp_engines_GetAll", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "b8be0770-e0db-4b29-b94a-af00a169cdc9", + "created": "2026-08-14T20:45:28.102Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 11, + "reference": "3ce32171-7c36-4345-9ab0-d5af967a0540", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "List DLP Engines (Lite)", + "description": "List DLP Engines (Lite)", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_engines_GetAllEngineLite", + "canvasName": "dlp_engines_GetAllEngineLite", + "summary": "dlp_engines_GetAllEngineLite", + "description": "dlp_engines_GetAllEngineLite", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "0ddbeb92-79d3-4c65-acb5-112ada8b38d7", + "created": "2026-08-14T20:45:28.140Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 12, + "reference": "d90aa125-0b90-4e1c-ab71-2403afdb0ebd", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Get DLP ICAP Server", + "description": "Get DLP ICAP Server", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_icap_servers_Get", + "canvasName": "dlp_icap_servers_Get", + "summary": "dlp_icap_servers_Get", + "description": "dlp_icap_servers_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "0adce9ef-2739-4a8a-86e0-37785f104172", + "created": "2026-08-14T20:45:28.180Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 13, + "reference": "53b3534c-da4d-4080-a95b-2932814e21e5", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "List DLP ICAP Servers", + "description": "List DLP ICAP Servers", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_icap_servers_GetByName", + "canvasName": "dlp_icap_servers_GetByName", + "summary": "dlp_icap_servers_GetByName", + "description": "dlp_icap_servers_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "3586bfca-a424-49b3-b4ae-e24fb8703e6a", + "created": "2026-08-14T20:45:28.226Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 14, + "reference": "be918281-d80f-4ab2-a1e7-ea99f3ba2068", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Get DLP Notification Template", + "description": "Get DLP Notification Template", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_notification_templates_Get", + "canvasName": "dlp_notification_templates_Get", + "summary": "dlp_notification_templates_Get", + "description": "dlp_notification_templates_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "7a41bf43-96b4-4675-bd0d-a794845c0907", + "created": "2026-08-14T20:45:28.264Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 15, + "reference": "a68ebf87-04d9-4a6f-bf22-cee9429e9332", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "List DLP Notification Templates", + "description": "List DLP Notification Templates", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_notification_templates_GetByName", + "canvasName": "dlp_notification_templates_GetByName", + "summary": "dlp_notification_templates_GetByName", + "description": "dlp_notification_templates_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "a3e1966b-385d-47ca-9dd2-ba402ce728a3", + "created": "2026-08-14T20:45:28.314Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 16, + "reference": "bc0bd8d0-e40d-48c0-b29e-1e40baa1133b", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Create DLP Notification Template", + "description": "Create DLP Notification Template", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_notification_templates_Create", + "canvasName": "dlp_notification_templates_Create", + "summary": "dlp_notification_templates_Create", + "description": "dlp_notification_templates_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "504f6f7d-f67d-4868-9064-d1fe933116f3", + "created": "2026-08-14T20:45:28.353Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 17, + "reference": "8ffc6fd0-508f-4258-a99e-2d4bd5fa0bf7", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Update DLP Notification Template", + "description": "Update DLP Notification Template", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_notification_templates_Update", + "canvasName": "dlp_notification_templates_Update", + "summary": "dlp_notification_templates_Update", + "description": "dlp_notification_templates_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for a DLP notification template." + }, + "name": { + "type": "string", + "description": "The DLP notification template name." + }, + "subject": { + "type": "string", + "description": "The Subject line that is displayed within the DLP notification email." + }, + "attachContent": { + "type": "boolean", + "description": "If set to true, the content that is violation is attached to the DLP notification email." + }, + "plainTextMessage": { + "type": "string", + "description": "The template for the plain text UTF-8 message body that must be displayed in the DLP notification email." + }, + "htmlMessage": { + "type": "string", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + }, + "tlsEnabled": { + "type": "boolean", + "description": "The template for the HTML message body that must be displayed in the DLP notification email." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "ebcc950d-4e5d-4faf-a660-2630d6569475", + "created": "2026-08-14T20:45:28.391Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 18, + "reference": "6a020538-0d13-4777-a94a-ae7dcadb84c0", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Delete DLP Notification Template", + "description": "Delete DLP Notification Template", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_notification_templates_Delete", + "canvasName": "dlp_notification_templates_Delete", + "summary": "dlp_notification_templates_Delete", + "description": "dlp_notification_templates_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "9fb71584-2380-45bd-b03e-db3d41cdfb1e", + "created": "2026-08-14T20:45:28.432Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 19, + "reference": "d481e602-ab2d-4e5c-9fea-286b2a6a7da7", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Get DLP Web Rule", + "description": "Get DLP Web Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_web_rules_Get", + "canvasName": "dlp_web_rules_Get", + "summary": "dlp_web_rules_Get", + "description": "dlp_web_rules_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "9b06f150-2ede-41ae-a324-00325dd94f64", + "created": "2026-08-14T20:45:28.470Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 20, + "reference": "53c56858-f8ac-4b73-a225-b94bb07d6e1d", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "List DLP Web Rules", + "description": "List DLP Web Rules", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_web_rules_GetByName", + "canvasName": "dlp_web_rules_GetByName", + "summary": "dlp_web_rules_GetByName", + "description": "dlp_web_rules_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "ab7ca1d5-6636-4e45-a3db-2547439ff911", + "created": "2026-08-14T20:45:28.511Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 21, + "reference": "b038a9f6-05ad-40af-8209-3dad58a57d59", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Create DLP Web Rule", + "description": "Create DLP Web Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_web_rules_Create", + "canvasName": "dlp_web_rules_Create", + "summary": "dlp_web_rules_Create", + "description": "dlp_web_rules_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "21545b38-e965-4c72-8070-734cda0d161f", + "created": "2026-08-14T20:45:28.573Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 22, + "reference": "8cb8956f-dd59-42d9-8f68-4f8d829c02cd", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Update DLP Web Rule", + "description": "Update DLP Web Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_web_rules_Update", + "canvasName": "dlp_web_rules_Update", + "summary": "dlp_web_rules_Update", + "description": "dlp_web_rules_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "type": { + "type": "string" + }, + "tenant": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the DLP policy rule." + }, + "order": { + "type": "integer", + "description": "The rule order of execution for the DLP policy rule with respect to other rules." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The protocol criteria specified for the DLP policy rule." + }, + "rank": { + "type": "integer", + "description": "The admin rank of the admin who created the DLP policy rule." + }, + "name": { + "type": "string", + "description": "The DLP policy rule name." + }, + "description": { + "type": "string", + "description": "The description of the DLP policy rule." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the DLP policy rule must be applied." + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the DLP policy rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "The minimum file size (in KB) used for evaluation of the DLP policy rule." + }, + "action": { + "type": "string", + "description": "The action taken when traffic matches the DLP policy rule criteria." + }, + "state": { + "type": "string", + "description": "Enables or disables the DLP policy rule." + }, + "matchOnly": { + "type": "boolean", + "description": "The match only criteria for DLP engines." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the DLP policy rule was last modified." + }, + "withoutContentInspection": { + "type": "boolean", + "description": "Indicates a DLP policy rule without content inspection, when the value is set to true." + }, + "ocrEnabled": { + "type": "boolean", + "description": "Enables or disables image file scanning." + }, + "dlpDownloadScanEnabled": { + "type": "boolean", + "description": "If this field is set to true, DLP scan is enabled for file downloads from cloud applications configured in the rule.\nIf this field is set to false, DLP scan is disabled for downloads from the cloud applications." + }, + "zccNotificationsEnabled": { + "type": "boolean", + "description": "If this field is set to true, Zscaler Client Connector notification is enabled for the block action triggered by the web DLP rule.\nIf this field is set to false, Zscaler Client Connector notification is disabled." + }, + "zscalerIncidentReceiver": { + "type": "boolean", + "description": "Indicates whether a Zscaler Incident Receiver is associated to the DLP policy rule." + }, + "eunTemplateId": { + "type": "integer" + }, + "externalAuditorEmail": { + "type": "string", + "description": "The email address of an external auditor to whom DLP email notifications are sent." + }, + "auditor": { + "type": "object", + "description": "The auditor to which the DLP policy rule must be applied." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "notificationTemplate": { + "type": "object", + "description": "The template used for DLP notification emails." + }, + "icapServer": { + "type": "object", + "description": "The DLP server, using ICAP, to which the transaction content is forwarded." + }, + "receiver": { + "type": "object", + "description": "The admin that modified the DLP policy rule last." + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations to which the DLP policy rule must be applied." + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of locations groups to which the DLP policy rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of groups to which the DLP policy rule must be applied." + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of departments to which the DLP policy rule must be applied." + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of users to which the DLP policy rule must be applied." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "dlpEngines": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of DLP engines to which the DLP policy rule must be applied." + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of time windows to which the DLP policy rule must be applied." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The Name-ID pairs of rule labels associated to the DLP policy rule." + }, + "excludedGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the groups that are excluded from the DLP policy rule." + }, + "excludedDepartments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the departments that are excluded from the DLP policy rule." + }, + "excludedUsers": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The name-ID pairs of the users that are excluded from the DLP policy rule." + }, + "includedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules only to domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "excludedDomainProfiles": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The list of domain profiles that must be added to the DLP rule criteria in order to apply the DLP rules to all domains excluding the domains that are part of the specified profiles. A maximum of 8 profiles can be selected." + }, + "sourceIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "fileTypeCategories": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of file types to which the rule applies" + }, + "severity": { + "type": "string", + "description": "Indicates the severity selected for the DLP rule violation" + }, + "parentRule": { + "type": "integer", + "description": "The unique identifier of the parent rule under which an exception rule is added.\nNote: Exception rules can be configured only when the inline DLP rule evaluation type is set to evaluate all DLP rules in the DLP Advanced Settings." + }, + "subRules": { + "type": "array", + "items": { + "type": "object", + "description": "WebDLPRules object" + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "description": "The list of exception rules added to a parent rule.\nAll attributes within the WebDlpRule model are applicable to the sub-rules.\nValues for each rule are specified by using the WebDlpRule object." + }, + "userRiskScoreLevels": { + "type": "array", + "items": { + "type": "string" + } + }, + "dlpContentLocationsScopes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies one or more content locations from the available values as a match criteria for the rule to target specific sections of a file or transaction." + }, + "inspectHttpGetEnabled": { + "type": "boolean" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "06a35e44-7fe2-43a6-bd5a-9020b46676be", + "created": "2026-08-14T20:45:28.648Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 23, + "reference": "45937839-b635-43f8-a952-51db07233165", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Delete DLP Web Rule", + "description": "Delete DLP Web Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlp_web_rules_Delete", + "canvasName": "dlp_web_rules_Delete", + "summary": "dlp_web_rules_Delete", + "description": "dlp_web_rules_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "a43e4548-e99b-4616-a31c-31697e5d4012", + "created": "2026-08-14T20:45:28.698Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 24, + "reference": "705c277e-8f24-44db-9f21-3febddf438d0", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Get DLP Dictionary", + "description": "Get DLP Dictionary", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlpdictionaries_Get", + "canvasName": "dlpdictionaries_Get", + "summary": "dlpdictionaries_Get", + "description": "dlpdictionaries_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "44ed2b41-1a40-4ed5-a1aa-73f08a391f41", + "created": "2026-08-14T20:45:28.734Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 25, + "reference": "f7824de9-8ee3-47ed-bc6c-dc49cdac819f", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "List DLP Dictionarys", + "description": "List DLP Dictionarys", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlpdictionaries_GetByName", + "canvasName": "dlpdictionaries_GetByName", + "summary": "dlpdictionaries_GetByName", + "description": "dlpdictionaries_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "70ae7cfa-9043-4fdb-a3c8-407646553bc5", + "created": "2026-08-14T20:45:28.765Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 26, + "reference": "55f2f762-611e-4992-93d1-047000e0f5d1", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Create DLP Dictionary", + "description": "Create DLP Dictionary", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlpdictionaries_Create", + "canvasName": "dlpdictionaries_Create", + "summary": "dlpdictionaries_Create", + "description": "dlpdictionaries_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "3eaa6c39-597f-4cce-a559-c62506025329", + "created": "2026-08-14T20:45:28.803Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 27, + "reference": "63cd7378-c0c0-44ee-8fbe-e284cc9ecfea", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Update DLP Dictionary", + "description": "Update DLP Dictionary", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlpdictionaries_Update", + "canvasName": "dlpdictionaries_Update", + "summary": "dlpdictionaries_Update", + "description": "dlpdictionaries_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the DLP dictionary" + }, + "name": { + "type": "string", + "description": "The DLP dictionary's name" + }, + "description": { + "type": "string", + "description": "The description of the DLP dictionary" + }, + "confidenceThreshold": { + "type": "string", + "description": "The DLP confidence threshold" + }, + "customPhraseMatchType": { + "type": "string", + "description": "The DLP custom phrase match type" + }, + "nameL10nTag": { + "type": "boolean", + "description": "Indicates whether the name is localized or not. This is always set to True for predefined DLP dictionaries." + }, + "custom": { + "type": "boolean", + "description": "This value is set to true for custom DLP dictionaries." + }, + "thresholdType": { + "type": "string", + "description": "DLP threshold type" + }, + "dictionaryType": { + "type": "string", + "description": "The DLP dictionary type" + }, + "proximity": { + "type": "integer", + "description": "The DLP dictionary proximity length." + }, + "phrases": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using phrases" + }, + "phrase": { + "type": "string", + "description": "DLP dictionary phrase" + } + } + }, + "description": "List containing the phrases used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries." + }, + "patterns": { + "type": "array", + "items": { + "type": "object", + "properties": { + "action": { + "type": "string", + "description": "The action applied to a DLP dictionary using patterns" + }, + "pattern": { + "type": "string", + "description": "DLP dictionary pattern" + } + } + }, + "description": "List containing the patterns used within a custom DLP dictionary. This attribute is not applicable to predefined DLP dictionaries" + }, + "exactDataMatchDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "dictionaryEdmMappingId": { + "type": "integer", + "description": "The unique identifier for the EDM mapping." + }, + "schemaId": { + "type": "integer", + "description": "The unique identifier for the EDM template (or schema)." + }, + "primaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's primary field." + }, + "secondaryFields": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The EDM template's secondary fields." + }, + "secondaryFieldMatchOn": { + "type": "string", + "description": "The EDM secondary field to match on." + } + } + }, + "description": "Exact Data Match (EDM) related information for custom DLP dictionaries." + }, + "idmProfileMatchAccuracyDetails": { + "type": "array", + "items": { + "type": "object", + "properties": { + "adpIdmProfile": { + "type": "object", + "description": "The IDM template reference." + }, + "matchAccuracy": { + "type": "string", + "description": "The IDM template match accuracy." + } + } + }, + "description": "List of Indexed Document Match (IDM) profiles and their corresponding match accuracy for custom DLP dictionaries." + }, + "ignoreExactMatchIdmDict": { + "type": "boolean", + "description": "Indicates whether to exclude documents that are a 100% match to already-indexed documents from triggering an Indexed Document Match (IDM) Dictionary." + }, + "includeBinNumbers": { + "type": "boolean", + "description": "A true value denotes that the specified Bank Identification Number (BIN) values are included in the Credit Cards dictionary. A false value denotes that the specified BIN values are excluded from the Credit Cards dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "binNumbers": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "The list of Bank Identification Number (BIN) values that are included or excluded from the Credit Cards dictionary. BIN values can be specified only for Diners Club, Mastercard, RuPay, and Visa cards. Up to 512 BIN values can be configured in a dictionary.\nNote: This field is applicable only to the predefined Credit Cards dictionary and its clones." + }, + "dictTemplateId": { + "type": "integer", + "description": "ID of the predefined dictionary (original source dictionary) that is used for cloning. This field is applicable only to cloned dictionaries. Only a limited set of identification-based predefined dictionaries (e.g., Credit Cards, Social Security Numbers, National Identification Numbers, etc.) can be cloned. Up to 4 clones can be created from a predefined dictionary." + }, + "predefinedClone": { + "type": "boolean", + "description": "This field is set to true if the dictionary is cloned from a predefined dictionary. Otherwise, it is set to false." + }, + "predefinedCountActionType": { + "type": "string", + "description": "This field specifies whether duplicate matches of a phrase from a dictionary must be counted individually toward the match count or ignored, thereby maintaining a single count for multiple occurrences." + }, + "proximityLengthEnabled": { + "type": "boolean", + "description": "This value is set to true if proximity length and high confidence phrases are enabled for the DLP dictionary." + }, + "proximityEnabledForCustomDictionary": { + "type": "boolean", + "description": "A Boolean constant that indicates if proximity length is enabled or disabled for a custom DLP dictionary. A true value indicates that proximity length is enabled, whereas a false value indicates that it is disabled." + }, + "dictionaryCloningEnabled": { + "type": "boolean", + "description": "A Boolean constant that indicates that the cloning option is supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries." + }, + "customPhraseSupported": { + "type": "boolean", + "description": "A Boolean constant that indicates that custom phrases are supported for the DLP dictionary using the true value. This field is applicable only to predefined DLP dictionaries with a high confidence score threshold." + }, + "hierarchicalDictionary": { + "type": "boolean", + "description": "A true value indicates that the DLP dictionary is of hierarchical type that includes sub-dictionaries. A false value indicates that the dictionary is not hierarchical." + }, + "hierarchicalIdentifiers": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of identifiers selected within a DLP dictionary of hierarchical type. Each identifier represents a sub-dictionary that consists of specific patterns. To retrieve the list of identifiers that are available for selection within a specific hierarchical dictionary, send a GET request to /dlpDictionaries/{dictId}/predefinedIdentifiers." + }, + "predefinedPhrases": { + "type": "array", + "items": { + "type": "string" + } + }, + "thresholdAllowed": { + "type": "boolean" + }, + "confidenceLevelForPredefinedDict": { + "type": "string" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "6c0da7f1-ceae-453b-96c7-0fe32aa7dfbf", + "created": "2026-08-14T20:45:28.842Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 28, + "reference": "e8d0e250-f49a-46bb-86f3-2b7b2abd258f", + "type": "workflow", + "folder": "/DLP", + "document": { + "name": "Delete DLP Dictionary", + "description": "Delete DLP Dictionary", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "dlpdictionaries_DeleteDlpDictionary", + "canvasName": "dlpdictionaries_DeleteDlpDictionary", + "summary": "dlpdictionaries_DeleteDlpDictionary", + "description": "dlpdictionaries_DeleteDlpDictionary", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "de6d6ce1-708f-4202-bf25-776c0228dfb9", + "created": "2026-08-14T20:45:28.883Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 29, + "reference": "36fd21eb-8286-4947-a9bc-6cb6bf88e93f", + "type": "workflow", + "folder": "/File Type Control", + "document": { + "name": "Get File Type Rule", + "description": "Get File Type Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filetypecontrol_Get", + "canvasName": "filetypecontrol_Get", + "summary": "filetypecontrol_Get", + "description": "filetypecontrol_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "e391c889-ee5f-4390-8fc6-c3d2f925c812", + "created": "2026-08-14T20:45:28.927Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 30, + "reference": "19c9e2d7-6c6d-406f-8a9a-2dce6b82192b", + "type": "workflow", + "folder": "/File Type Control", + "document": { + "name": "List File Type Rules", + "description": "List File Type Rules", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filetypecontrol_GetByName", + "canvasName": "filetypecontrol_GetByName", + "summary": "filetypecontrol_GetByName", + "description": "filetypecontrol_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "142cc7f9-76da-48d7-9c18-46d53737c226", + "created": "2026-08-14T20:45:28.962Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 31, + "reference": "43ff2bdd-b0d6-4aea-9d81-4a618fd85d81", + "type": "workflow", + "folder": "/File Type Control", + "document": { + "name": "Create File Type Rule", + "description": "Create File Type Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filetypecontrol_Create", + "canvasName": "filetypecontrol_Create", + "summary": "filetypecontrol_Create", + "description": "filetypecontrol_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "b6c04d21-a1ae-4a35-9d2e-a24302874165", + "created": "2026-08-14T20:45:29.008Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 32, + "reference": "2c8501e4-b9f9-45a9-8ac5-800fc69d1416", + "type": "workflow", + "folder": "/File Type Control", + "document": { + "name": "Update File Type Rule", + "description": "Update File Type Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filetypecontrol_Update", + "canvasName": "filetypecontrol_Update", + "summary": "filetypecontrol_Update", + "description": "filetypecontrol_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "System generated identifier for a file-type policy" + }, + "name": { + "type": "string", + "description": "The name of the File Type rule" + }, + "description": { + "type": "string", + "description": "Additional information about the File Type rule" + }, + "state": { + "type": "string", + "description": "Rule State" + }, + "order": { + "type": "integer", + "description": "Order of policy execution with respect to other file-type policies. Order N indicates N-th file-type policy is evaluated. This field is not applicable to the Lite API." + }, + "filteringAction": { + "type": "string", + "description": "Action taken when traffic matches policy. This field is not applicable to the Lite API.\nSupported Values: \"BLOCK\", \"CAUTION\", \"ALLOW\"" + }, + "timeQuota": { + "type": "integer", + "description": "Time quota in minutes, after which the policy must be applied. If not set, no time quota is enforced. Ignored if action is BLOCK." + }, + "sizeQuota": { + "type": "integer", + "description": "Size quota in KB, beyond which the policy must be applied. If not set, size quota is not enforced. Ignored if action is BLOCK." + }, + "accessControl": { + "type": "string", + "description": "The access privilege for this DLP policy rule based on the admin's state." + }, + "rank": { + "type": "integer", + "description": "Admin rank of the admin who creates this rule" + }, + "capturePCAP": { + "type": "boolean", + "description": "A Boolean value that indicates whether packet capture (PCAP) is enabled or not" + }, + "passwordProtected": { + "type": "boolean", + "description": "A Boolean field indicating whether the rule applies to password-protected files." + }, + "operation": { + "type": "string", + "description": "File operation performed. This field is not applicable to the Lite API." + }, + "activeContent": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "unscannable": { + "type": "boolean", + "description": "Flag to check whether a file has active content or not" + }, + "browserEunTemplateId": { + "type": "integer" + }, + "cloudApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of cloud applications to which the File Type Control policy rule must be applied\nNew to Review that." + }, + "fileTypes": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of file types to which the Sandbox Rule must be applied." + }, + "minSize": { + "type": "integer", + "description": "Minimum file size (in KB) used for evaluation of the FTP rule" + }, + "maxSize": { + "type": "integer", + "description": "Maximum file size (in KB) used for evaluation of the FTP rule" + }, + "protocols": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Protocol for the given rule. This field is not applicable to the Lite API." + }, + "urlCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The list of URL categories to which the DLP policy rule must be applied." + }, + "lastModifiedTime": { + "type": "integer", + "description": "When the rule was last modified" + }, + "lastModifiedBy": { + "type": "object", + "description": "Who modified the rule last" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of locations for which rule must be applied" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of the location groups to which the rule must be applied." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of groups for which rule must be applied" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of departments for which rule must be applied" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of users for which rule must be applied" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of time interval during which rule must be enforced." + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The URL Filtering rule's label. Rule labels allow you to logically group your organization's policy rules. Policy rules that are not associated with a rule label are grouped under the Untagged label." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "92016d92-70cc-4ff6-bec5-8510bcee3005", + "created": "2026-08-14T20:45:29.047Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 33, + "reference": "33966b1b-35e6-472e-861c-1ef174bdcb6f", + "type": "workflow", + "folder": "/File Type Control", + "document": { + "name": "Delete File Type Rule", + "description": "Delete File Type Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filetypecontrol_Delete", + "canvasName": "filetypecontrol_Delete", + "summary": "filetypecontrol_Delete", + "description": "filetypecontrol_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "8f914623-bb94-44fc-a023-8051c9fcebad", + "created": "2026-08-14T20:45:29.091Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 34, + "reference": "ba847751-ef2a-4b6c-a930-2bf77a126376", + "type": "workflow", + "folder": "/File Type Control", + "document": { + "name": "List File Type Categories", + "description": "List File Type Categories", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filetypecontrol_GetFileTypeCategories", + "canvasName": "filetypecontrol_GetFileTypeCategories", + "summary": "filetypecontrol_GetFileTypeCategories", + "description": "filetypecontrol_GetFileTypeCategories", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "1cdb4d05-90df-4ef7-9c28-156cfa1d51cf", + "created": "2026-08-14T20:45:29.133Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 35, + "reference": "46227da4-c3df-43e6-93b0-953d535b85f2", + "type": "workflow", + "folder": "/File Type Control", + "document": { + "name": "List Custom File Types", + "description": "List Custom File Types", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filetypecontrol_GetCustomFileTypes", + "canvasName": "filetypecontrol_GetCustomFileTypes", + "summary": "filetypecontrol_GetCustomFileTypes", + "description": "filetypecontrol_GetCustomFileTypes", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "15e1a9e8-bf43-4e99-a049-4922c6ad5682", + "created": "2026-08-14T20:45:29.178Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 36, + "reference": "bd892a89-b27a-4973-b6cd-b952fdae3b8b", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "List App Services", + "description": "List App Services", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "applicationservices_GetByName", + "canvasName": "applicationservices_GetByName", + "summary": "applicationservices_GetByName", + "description": "applicationservices_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "2de68c31-0769-4f6b-8279-4e8e1bf0f902", + "created": "2026-08-14T20:45:29.218Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 37, + "reference": "5c9af1f8-057d-46fb-a940-1a7d4bff3b05", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "List App Service Groups", + "description": "List App Service Groups", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "appservicegroups_GetByName", + "canvasName": "appservicegroups_GetByName", + "summary": "appservicegroups_GetByName", + "description": "appservicegroups_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "cbb0b8bd-e2ce-4fcd-947a-700bd031b080", + "created": "2026-08-14T20:45:29.258Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 38, + "reference": "71bfb536-fe3e-4934-92eb-d72981dd8848", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Get Firewall Filtering Rule", + "description": "Get Firewall Filtering Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filteringrules_Get", + "canvasName": "filteringrules_Get", + "summary": "filteringrules_Get", + "description": "filteringrules_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "b49e4e50-f2a6-4aa1-8c73-ab0e4cf49deb", + "created": "2026-08-14T20:45:29.299Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 39, + "reference": "00099ea3-f24c-4f4b-bd04-8f47acb96fd0", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Create Firewall Filtering Rule", + "description": "Create Firewall Filtering Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filteringrules_Create", + "canvasName": "filteringrules_Create", + "summary": "filteringrules_Create", + "description": "filteringrules_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "a3eed3f0-23c7-4bf0-ab53-9266e4cb1ee6", + "created": "2026-08-14T20:45:29.378Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 40, + "reference": "9530e205-5902-4625-8671-c7ff42b0e343", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Update Firewall Filtering Rule", + "description": "Update Firewall Filtering Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filteringrules_Update", + "canvasName": "filteringrules_Update", + "summary": "filteringrules_Update", + "description": "filteringrules_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifier for the Firewall Filtering policy rule" + }, + "name": { + "type": "string", + "description": "Name of the Firewall Filtering policy rule" + }, + "order": { + "type": "integer", + "description": "Rule order number of the Firewall Filtering policy rule" + }, + "rank": { + "type": "integer", + "description": "Admin rank of the Firewall Filtering policy rule" + }, + "accessControl": { + "type": "string", + "description": "The admin\u2019s access privilege to this rule based on the assigned role" + }, + "enableFullLogging": { + "type": "boolean", + "description": "A Boolean value that indicates whether full logging is enabled. A true value indicates that full logging is enabled, whereas a false value indicates that aggregate logging is enabled." + }, + "action": { + "type": "string", + "description": "The action the Firewall Filtering policy rule takes when packets match the rule" + }, + "state": { + "type": "string", + "description": "Determines whether the Firewall Filtering policy rule is enabled or disabled" + }, + "description": { + "type": "string", + "description": "Additional information about the rule" + }, + "excludeContextShieldEndPoint": { + "type": "boolean" + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule was last modified. Ignored if the request is POST or PUT. For GET, ignored if or the rule is current version." + }, + "lastModifiedBy": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "srcIps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined source IP addresses for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address." + }, + "destAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of destination IP addresses for which the rule is applicable. CIDR notation can be used for destination IP addresses. If not set, the rule is not restricted to a specific destination addresses unless specified by destCountries, destIpGroups or destIpCategories." + }, + "destIpCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "IP address categories of destination for which the DNAT rule is applicable. If not set, the rule is not restricted to specific destination IP categories." + }, + "destCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "sourceCountries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination countries for which the rule is applicable. If not set, the rule is not restricted to specific destination countries." + }, + "excludeSrcCountries": { + "type": "boolean", + "description": "Indicates whether the countries specified in the sourceCountries field are included or excluded from the rule.\nA true value denotes that the specified source countries are excluded from the rule.\nA false value denotes that the rule is applied to the source countries if there is a match." + }, + "nwApplications": { + "type": "array", + "items": { + "type": "string" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "defaultRule": { + "type": "boolean", + "description": "If set to true, the default rule is applied" + }, + "predefined": { + "type": "boolean", + "description": "If set to true, a predefined rule is applied" + }, + "isEunEnabled": { + "type": "boolean" + }, + "eunTemplateId": { + "type": "integer" + }, + "locations": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The locations to which the Firewall Filtering policy rule applies" + }, + "locationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The location groups to which the Firewall Filtering policy rule applies" + }, + "departments": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The departments to which the Firewall Filtering policy rule applies" + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The groups to which the Firewall Filtering policy rule applies" + }, + "users": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The users to which the Firewall Filtering policy rule applies" + }, + "timeWindows": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "The time interval in which the Firewall Filtering policy rule applies" + }, + "nwApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service application group on which the rule is applied. If not set, the rule is not restricted to a specific network service application group." + }, + "appServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application services on which this rule is applied" + }, + "appServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Application service groups on which this rule is applied" + }, + "labels": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Labels that are applicable to the rule." + }, + "destIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined destination IP address groups on which the rule is applied. If not set, the rule is not restricted to a specific destination IP address group.\nNote: For organizations that have enabled IPv6, the destIpv6Groups field lists the IPv6 source address groups for which the rule is applicable." + }, + "nwServices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network services on which the rule is applied. If not set, the rule is not restricted to a specific network service." + }, + "nwServiceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "User-defined network service applications on which the rule is applied. If not set, the rule is not restricted to a specific network service application." + }, + "srcIpGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Source IP address groups for which the rule is applicable. If not set, the rule is not restricted to a specific source IP address group." + }, + "deviceTrustLevels": { + "type": "array", + "items": { + "type": "string" + }, + "description": "List of device trust levels for which the rule must be applied. This field is applicable for devices that are managed using Zscaler Client Connector. The trust levels are assigned to the devices based on your posture configurations in the Zscaler Client Connector Portal. If no value is set, this field is ignored during the policy evaluation." + }, + "deviceGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "This field is applicable for devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "devices": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Name-ID pairs of devices for which rule must be applied. Specifies devices that are managed using Zscaler Client Connector. If no value is set, this field is ignored during the policy evaluation." + }, + "workloadGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDName object" + }, + "description": "The list of preconfigured workload groups to which the policy must be applied." + }, + "zpaAppSegments": { + "type": "array", + "items": { + "type": "object", + "description": "common.ZPAAppSegments object" + }, + "description": "The list of ZPA Application Segments for which this rule is applicable. This field is applicable only for the ZPA Gateway forwarding method." + }, + "endPointApplications": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplications object" + } + }, + "endPointApplicationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.EndPointApplicationGroups object" + } + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "7794da02-4f09-41ee-b6e2-255ab34fdd7e", + "created": "2026-08-14T20:45:29.442Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 41, + "reference": "9f5637f8-bc93-4746-b91f-acf0cd724c85", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Delete Firewall Filtering Rule", + "description": "Delete Firewall Filtering Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filteringrules_Delete", + "canvasName": "filteringrules_Delete", + "summary": "filteringrules_Delete", + "description": "filteringrules_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "e2595317-6d5e-4291-b8fc-c9d757e5fdea", + "created": "2026-08-14T20:45:29.487Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 42, + "reference": "b8303290-d3b9-496e-8141-4ade09b352b3", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "List Firewall Filtering Rules", + "description": "List Firewall Filtering Rules", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "filteringrules_GetAll", + "canvasName": "filteringrules_GetAll", + "summary": "filteringrules_GetAll", + "description": "filteringrules_GetAll", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "31fdd1e8-4e17-4723-a70d-9cf0ae126119", + "created": "2026-08-14T20:45:29.527Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 43, + "reference": "dbdf62c6-ac81-4040-ab9e-04d4e361bf8c", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Get IP Destination Group", + "description": "Get IP Destination Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "ipdestinationgroups_Get", + "canvasName": "ipdestinationgroups_Get", + "summary": "ipdestinationgroups_Get", + "description": "ipdestinationgroups_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "21a0b5e2-1b92-4603-8880-28bf12662d5a", + "created": "2026-08-14T20:45:29.566Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 44, + "reference": "a87e82c5-cd05-40fd-8d99-076c632ace31", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Create IP Destination Group", + "description": "Create IP Destination Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "ipdestinationgroups_Create", + "canvasName": "ipdestinationgroups_Create", + "summary": "ipdestinationgroups_Create", + "description": "ipdestinationgroups_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "a93816d3-dc85-4b84-a4dc-3246a218a29e", + "created": "2026-08-14T20:45:29.598Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 45, + "reference": "b15d608b-2d22-4bd6-92e9-de97c87c3ae8", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Update IP Destination Group", + "description": "Update IP Destination Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "ipdestinationgroups_Update", + "canvasName": "ipdestinationgroups_Update", + "summary": "ipdestinationgroups_Update", + "description": "ipdestinationgroups_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identifer for the destination IP group" + }, + "name": { + "type": "string", + "description": "Destination IP group name" + }, + "description": { + "type": "string", + "description": "Additional information about the destination IP group" + }, + "type": { + "type": "string", + "description": "Destination IP group type (i.e., the group can contain destination IP addresses or FQDNs)" + }, + "addresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP addresses, FQDNs, or wildcard FQDNs added to the group." + }, + "ipCategories": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address URL categories. You can identify destinations based on the URL category of the domain." + }, + "countries": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Destination IP address countries. You can identify destinations based on the location of a server." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "e2525378-8472-4f05-8268-5b74a98280c4", + "created": "2026-08-14T20:45:29.641Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 46, + "reference": "4b53cad8-8376-4913-9355-284dcea86342", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Delete IP Destination Group", + "description": "Delete IP Destination Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "ipdestinationgroups_Delete", + "canvasName": "ipdestinationgroups_Delete", + "summary": "ipdestinationgroups_Delete", + "description": "ipdestinationgroups_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "63557739-c010-4f05-94c7-ba0bb606c542", + "created": "2026-08-14T20:45:29.712Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 47, + "reference": "548ab257-8827-469c-8b70-04d0e84fa202", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "List IP Destination Groups", + "description": "List IP Destination Groups", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "ipdestinationgroups_GetAll", + "canvasName": "ipdestinationgroups_GetAll", + "summary": "ipdestinationgroups_GetAll", + "description": "ipdestinationgroups_GetAll", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "dd2f59c2-0e65-42ab-a4b2-2675394ec52a", + "created": "2026-08-14T20:45:29.764Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 48, + "reference": "b587afb5-49dd-4b0d-b568-b9f2db6cb203", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Get IP Source Group", + "description": "Get IP Source Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "ipsourcegroups_Get", + "canvasName": "ipsourcegroups_Get", + "summary": "ipsourcegroups_Get", + "description": "ipsourcegroups_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "6361c4c8-054b-47d7-bc29-9d901aac83d9", + "created": "2026-08-14T20:45:29.820Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 49, + "reference": "457fba3a-128b-44ec-bf91-18b1a17ad807", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "List IP Source Groups", + "description": "List IP Source Groups", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "ipsourcegroups_GetByName", + "canvasName": "ipsourcegroups_GetByName", + "summary": "ipsourcegroups_GetByName", + "description": "ipsourcegroups_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "54f7372f-d024-44c5-abf9-164750a58a39", + "created": "2026-08-14T20:45:29.857Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 50, + "reference": "54c2c10f-6e7a-40fa-86c7-d726d635b911", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Create IP Source Group", + "description": "Create IP Source Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "ipsourcegroups_Create", + "canvasName": "ipsourcegroups_Create", + "summary": "ipsourcegroups_Create", + "description": "ipsourcegroups_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "4956cf6c-083b-486d-97bf-c49227cdbde2", + "created": "2026-08-14T20:45:29.895Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 51, + "reference": "caa5873d-3599-4011-b3a7-3fe2df3c12a3", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Update IP Source Group", + "description": "Update IP Source Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "ipsourcegroups_Update", + "canvasName": "ipsourcegroups_Update", + "summary": "ipsourcegroups_Update", + "description": "ipsourcegroups_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "A unique identifier of the source IP address group." + }, + "name": { + "type": "string", + "description": "The name of the source IP address group." + }, + "description": { + "type": "string", + "description": "The description of the source IP address group." + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Source IP addresses added to the group." + }, + "isNonEditable": { + "type": "boolean", + "description": "If set to true, the destination IP address group is non-editable. This field is applicable only to predefined IP address groups, which cannot be modified." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "cbad3ad0-a5d3-4801-952b-1310f3e64555", + "created": "2026-08-14T20:45:29.935Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 52, + "reference": "775a43a4-4b9a-4a53-964e-32304bde6bd9", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Delete IP Source Group", + "description": "Delete IP Source Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "ipsourcegroups_Delete", + "canvasName": "ipsourcegroups_Delete", + "summary": "ipsourcegroups_Delete", + "description": "ipsourcegroups_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "f1277a5b-e0a4-401b-a9c0-cb01abc0ddbd", + "created": "2026-08-14T20:45:29.971Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 53, + "reference": "37c59682-223c-43dd-b468-22c36df49913", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Get Network Application Group", + "description": "Get Network Application Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkapplicationgroups_GetNetworkApplicationGroups", + "canvasName": "networkapplicationgroups_GetNetworkApplicationGroups", + "summary": "networkapplicationgroups_GetNetworkApplicationGroups", + "description": "networkapplicationgroups_GetNetworkApplicationGroups", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "1d62c8e1-7bfa-44c9-992d-0e040842180d", + "created": "2026-08-14T20:45:30.018Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 54, + "reference": "d733392d-b3b3-4432-b977-178e3e281ad7", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "List Network Application Groups", + "description": "List Network Application Groups", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkapplicationgroups_GetNetworkApplicationGroupsByName", + "canvasName": "networkapplicationgroups_GetNetworkApplicationGroupsByName", + "summary": "networkapplicationgroups_GetNetworkApplicationGroupsByName", + "description": "networkapplicationgroups_GetNetworkApplicationGroupsByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "26462534-3c04-4a8f-b4d2-b3d17269833d", + "created": "2026-08-14T20:45:30.056Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 55, + "reference": "60f98048-6a1b-45a9-a9a3-a0b0b69cf724", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Create Network Application Group", + "description": "Create Network Application Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkapplicationgroups_Create", + "canvasName": "networkapplicationgroups_Create", + "summary": "networkapplicationgroups_Create", + "description": "networkapplicationgroups_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "c90653c3-09d1-4f51-a9d2-67712a46c360", + "created": "2026-08-14T20:45:30.091Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 56, + "reference": "d6a8d39b-4e4d-4c6a-a7f6-d4188b5025e7", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Update Network Application Group", + "description": "Update Network Application Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkapplicationgroups_Update", + "canvasName": "networkapplicationgroups_Update", + "summary": "networkapplicationgroups_Update", + "description": "networkapplicationgroups_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "networkApplications": { + "type": "array", + "items": { + "type": "string" + } + }, + "description": { + "type": "string" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "ab154431-6c9f-4d56-b28e-c19824c543bf", + "created": "2026-08-14T20:45:30.126Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 57, + "reference": "fe433820-dd56-4746-b7f9-7b950da01c2e", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Delete Network Application Group", + "description": "Delete Network Application Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkapplicationgroups_Delete", + "canvasName": "networkapplicationgroups_Delete", + "summary": "networkapplicationgroups_Delete", + "description": "networkapplicationgroups_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "bd5cde76-db85-4980-b302-4600aba3a3fd", + "created": "2026-08-14T20:45:30.163Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 58, + "reference": "1c2b2ffc-df9a-4e0c-8712-7002f0ae3dac", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Get Network Application", + "description": "Get Network Application", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkapplications_GetNetworkApplication", + "canvasName": "networkapplications_GetNetworkApplication", + "summary": "networkapplications_GetNetworkApplication", + "description": "networkapplications_GetNetworkApplication", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "63ee8470-45e1-494b-8106-0343a76ba502", + "created": "2026-08-14T20:45:30.196Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 59, + "reference": "1f81a9da-409a-4f72-9aed-27d2ea7629fb", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "List Network Applications", + "description": "List Network Applications", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkapplications_GetByName", + "canvasName": "networkapplications_GetByName", + "summary": "networkapplications_GetByName", + "description": "networkapplications_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "abb520d1-c1cf-4b4c-b85b-77961dd9b85c", + "created": "2026-08-14T20:45:30.230Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 60, + "reference": "c090c2c4-402f-48f5-8694-08af2e89a55d", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Get Network Service Group", + "description": "Get Network Service Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkservicegroups_GetNetworkServiceGroups", + "canvasName": "networkservicegroups_GetNetworkServiceGroups", + "summary": "networkservicegroups_GetNetworkServiceGroups", + "description": "networkservicegroups_GetNetworkServiceGroups", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "458c647a-615e-4b99-b05f-b227ffdb06f5", + "created": "2026-08-14T20:45:30.261Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 61, + "reference": "ea710d43-4cfe-4946-abe4-ee929ce84726", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "List Network Service Groups", + "description": "List Network Service Groups", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkservicegroups_GetNetworkServiceGroupsByName", + "canvasName": "networkservicegroups_GetNetworkServiceGroupsByName", + "summary": "networkservicegroups_GetNetworkServiceGroupsByName", + "description": "networkservicegroups_GetNetworkServiceGroupsByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "92946f84-c7db-4788-80d2-96a64de3f156", + "created": "2026-08-14T20:45:30.295Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 62, + "reference": "26427292-5ccb-4ce4-9324-7b34ebf35447", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Create Network Service Group", + "description": "Create Network Service Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkservicegroups_CreateNetworkServiceGroups", + "canvasName": "networkservicegroups_CreateNetworkServiceGroups", + "summary": "networkservicegroups_CreateNetworkServiceGroups", + "description": "networkservicegroups_CreateNetworkServiceGroups", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "75edc8f5-a5ae-4025-bc3a-aafd0380e384", + "created": "2026-08-14T20:45:30.327Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 63, + "reference": "dd897062-b1f5-4d1f-b815-9a17c6fa8ece", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Update Network Service Group", + "description": "Update Network Service Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkservicegroups_UpdateNetworkServiceGroups", + "canvasName": "networkservicegroups_UpdateNetworkServiceGroups", + "summary": "networkservicegroups_UpdateNetworkServiceGroups", + "description": "networkservicegroups_UpdateNetworkServiceGroups", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "services": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "description": "networkservices.NetworkPorts object" + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "description": { + "type": "string" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "f741c813-2ac2-4f4d-b42c-f26beace0d82", + "created": "2026-08-14T20:45:30.360Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 64, + "reference": "8c38084e-2f87-483b-a79d-a93bff2c81b3", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Delete Network Service Group", + "description": "Delete Network Service Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkservicegroups_DeleteNetworkServiceGroups", + "canvasName": "networkservicegroups_DeleteNetworkServiceGroups", + "summary": "networkservicegroups_DeleteNetworkServiceGroups", + "description": "networkservicegroups_DeleteNetworkServiceGroups", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "8153e1ae-b2f9-4663-9a54-046af752e36a", + "created": "2026-08-14T20:45:30.398Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 65, + "reference": "33b4a79d-5ad6-4c4c-b6ba-b888aca0860e", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Get Network Service", + "description": "Get Network Service", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkservices_Get", + "canvasName": "networkservices_Get", + "summary": "networkservices_Get", + "description": "networkservices_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "8f196e6a-dc72-4bab-8d0b-04fc977e6dc7", + "created": "2026-08-14T20:45:30.437Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 66, + "reference": "210ae0c4-a722-45b3-8b2b-2bc53367a3ad", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "List Network Services", + "description": "List Network Services", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkservices_GetByName", + "canvasName": "networkservices_GetByName", + "summary": "networkservices_GetByName", + "description": "networkservices_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "e07fe417-a715-4b75-8d2b-5b574ce942fb", + "created": "2026-08-14T20:45:30.468Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 67, + "reference": "14708be9-d961-41da-90df-ea59d6b77eb1", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Create Network Service", + "description": "Create Network Service", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkservices_Create", + "canvasName": "networkservices_Create", + "summary": "networkservices_Create", + "description": "networkservices_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "33e1431d-f624-4d67-93fd-9491e09f46ca", + "created": "2026-08-14T20:45:30.503Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 68, + "reference": "1918936f-046c-43d1-bf63-b71c0f10667e", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Update Network Service", + "description": "Update Network Service", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkservices_Update", + "canvasName": "networkservices_Update", + "summary": "networkservices_Update", + "description": "networkservices_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer" + }, + "name": { + "type": "string" + }, + "tag": { + "type": "string" + }, + "srcTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destTcpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "srcUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "destUdpPorts": { + "type": "array", + "items": { + "type": "object", + "properties": { + "start": { + "type": "integer" + }, + "end": { + "type": "integer" + } + } + } + }, + "type": { + "type": "string" + }, + "description": { + "type": "string" + }, + "protocol": { + "type": "string" + }, + "isNameL10nTag": { + "type": "boolean" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "e9387fd5-a64a-4003-a610-7fdd4454fb7c", + "created": "2026-08-14T20:45:30.538Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 69, + "reference": "99d5c4c9-8db5-4ec4-b8c4-8bbb68727b18", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "Delete Network Service", + "description": "Delete Network Service", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "networkservices_Delete", + "canvasName": "networkservices_Delete", + "summary": "networkservices_Delete", + "description": "networkservices_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "6388d0cd-6771-4a73-a2a3-f323c25cd86f", + "created": "2026-08-14T20:45:30.577Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 70, + "reference": "87ddabb4-8a7e-485e-a81a-c8da4a9b3bf8", + "type": "workflow", + "folder": "/Firewall Policies", + "document": { + "name": "List Time Windows", + "description": "List Time Windows", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "timewindow_GetAll", + "canvasName": "timewindow_GetAll", + "summary": "timewindow_GetAll", + "description": "timewindow_GetAll", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "b5898b4c-9b41-4008-a5f8-19d2cc92f4b5", + "created": "2026-08-14T20:45:30.610Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 71, + "reference": "3babeca8-f675-47f5-9cf2-aff1d3a189bc", + "type": "workflow", + "folder": "/Locations", + "document": { + "name": "Get Location Group", + "description": "Get Location Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "locationgroups_GetLocationGroup", + "canvasName": "locationgroups_GetLocationGroup", + "summary": "locationgroups_GetLocationGroup", + "description": "locationgroups_GetLocationGroup", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "d6892e25-cc3f-473d-b6d2-89c7bf63d549", + "created": "2026-08-14T20:45:30.644Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 72, + "reference": "b52d3a7a-c895-41fa-9ac5-1d3d0134faef", + "type": "workflow", + "folder": "/Locations", + "document": { + "name": "List Location Groups", + "description": "List Location Groups", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "locationgroups_GetGroupType", + "canvasName": "locationgroups_GetGroupType", + "summary": "locationgroups_GetGroupType", + "description": "locationgroups_GetGroupType", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "13233e61-e2ff-4543-942c-d87bf8b5be20", + "created": "2026-08-14T20:45:30.677Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 73, + "reference": "9bd5cb83-737c-43ae-ae8d-ead7c88a1d0d", + "type": "workflow", + "folder": "/Locations", + "document": { + "name": "Get Location", + "description": "Get Location", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "locationmanagement_GetLocation", + "canvasName": "locationmanagement_GetLocation", + "summary": "locationmanagement_GetLocation", + "description": "locationmanagement_GetLocation", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "d42a26de-15bf-4617-bb17-0cae1f229463", + "created": "2026-08-14T20:45:30.716Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 74, + "reference": "aa8ed189-94f8-4c7d-972e-a8d20f532bed", + "type": "workflow", + "folder": "/Locations", + "document": { + "name": "List Sub-Locations", + "description": "List Sub-Locations", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "locationmanagement_GetSublocations", + "canvasName": "locationmanagement_GetSublocations", + "summary": "locationmanagement_GetSublocations", + "description": "locationmanagement_GetSublocations", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "e84d25a8-2a61-4926-ac7f-64f0b2f8639d", + "created": "2026-08-14T20:45:30.754Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 75, + "reference": "a25c8391-332c-465f-a8e3-3bdfe150659f", + "type": "workflow", + "folder": "/Locations", + "document": { + "name": "Create Location", + "description": "Create Location", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "locationmanagement_Create", + "canvasName": "locationmanagement_Create", + "summary": "locationmanagement_Create", + "description": "locationmanagement_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "03c37b34-845b-4943-bb98-32f7d8b09fd9", + "created": "2026-08-14T20:45:30.791Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 76, + "reference": "fb891498-df6a-4b5e-bbec-47eee2398a5b", + "type": "workflow", + "folder": "/Locations", + "document": { + "name": "Update Location", + "description": "Update Location", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "locationmanagement_Update", + "canvasName": "locationmanagement_Update", + "summary": "locationmanagement_Update", + "description": "locationmanagement_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Location ID" + }, + "name": { + "type": "string", + "description": "Location Name" + }, + "parentId": { + "type": "integer", + "description": "Parent Location ID. If this ID does not exist or is 0, it is implied that it is a parent location. Otherwise, it is a sub-location whose parent has this ID. x-applicableTo: SUB" + }, + "upBandwidth": { + "type": "integer", + "description": "Upload bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "dnBandwidth": { + "type": "integer", + "description": "Download bandwidth in kbps. The value 0 implies no Bandwidth Control enforcement" + }, + "country": { + "type": "string", + "description": "Country" + }, + "state": { + "type": "string" + }, + "language": { + "type": "string", + "description": "Language" + }, + "tz": { + "type": "string", + "description": "Timezone of the location. If not specified, it defaults to GMT." + }, + "childCount": { + "type": "integer" + }, + "matchInChild": { + "type": "boolean" + }, + "geoOverride": { + "type": "boolean" + }, + "ipAddresses": { + "type": "array", + "items": { + "type": "string" + }, + "description": "For locations: IP addresses of the egress points that are provisioned in the Zscaler Cloud. Each entry is a single IP address (e.g., 238.10.33.9).\nFor sub-locations: Egress, internal, or GRE tunnel IP addresses. Each entry is either a single IP address, CIDR (e.g., 10.10.33.0/24), or range (e.g., 10.10.33.1-10.10.33.10))." + }, + "ports": { + "type": "array", + "items": { + "type": "integer" + }, + "description": "IP ports that are associated with the location" + }, + "subLocScopeEnabled": { + "type": "boolean", + "description": "Indicates whether defining scopes is allowed for this sublocation. Sublocation scopes are available only for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScope": { + "type": "string", + "description": "Defines a scope for the sublocation from the available types to segregate workload traffic from a single sublocation to apply different Cloud Connector and ZIA security policies. This field is only available for the Workload traffic type sublocations whose parent locations are associated with Amazon Web Services (AWS) Cloud Connector groups." + }, + "subLocScopeValues": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "subLocAccIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Specifies values for the selected sublocation scope type" + }, + "vpnCredentials": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "VPN credential id" + }, + "type": { + "type": "string", + "description": "VPN authentication type (i.e., how the VPN credential is sent to the server). It is not modifiable after VpnCredential is created.\nNote: Zscaler no longer supports adding a new XAUTH VPN credential, but existing entries can be edited or deleted using the respective endpoints." + }, + "fqdn": { + "type": "string", + "description": "Fully Qualified Domain Name. Applicable only to UFQDN or XAUTH (or HOSTED_MOBILE_USERS) auth type." + }, + "ipAddress": { + "type": "string", + "description": "Static IP address for VPN that is self-provisioned or provisioned by Zscaler. This is a required field for IP auth type and is not applicable to other auth types.\nNote: If you want Zscaler to provision static IP addresses for your organization, contact Zscaler Support." + }, + "preSharedKey": { + "type": "string", + "description": "Pre-shared key. This is a required field for UFQDN and IP auth type." + }, + "comments": { + "type": "string", + "description": "Additional information about this VPN credential." + }, + "location": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "Location that is associated to this VPN credential. Non-existence means not associated to any location." + }, + "managedBy": { + "type": "array", + "items": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Identifier that uniquely identifies an entity" + }, + "name": { + "type": "string", + "description": "The configured name of the entity" + }, + "extensions": { + "type": "object" + } + } + }, + "description": "SD-WAN Partner that manages the location. If a partner does not manage the location, this is set to Self." + } + } + }, + "description": "VPN User Credentials that are associated with the location." + }, + "authRequired": { + "type": "boolean", + "description": "Enforce Authentication. Required when ports are enabled, IP Surrogate is enabled, or Kerberos Authentication is enabled." + }, + "basicAuthEnabled": { + "type": "boolean", + "description": "Enable Basic Authentication at the location" + }, + "digestAuthEnabled": { + "type": "boolean", + "description": "Enable Digest Authentication at the location" + }, + "kerberosAuth": { + "type": "boolean", + "description": "Enable Kerberos Authentication at the location" + }, + "iotDiscoveryEnabled": { + "type": "boolean", + "description": "Enable IOT Discovery at the location" + }, + "iotEnforcePolicySet": { + "type": "boolean" + }, + "cookiesAndProxy": { + "type": "boolean", + "description": "If set to true, the surrogateIPEnforcedForKnownBrowsers option is enabled for all authentication methods including cookie-based, Kerberos, Basic, and Digest authentication to leverage the existing IP address-to-user mapping (acquired from surrogate IP) to authenticate users and prevent further authentication challenges for traffic originating from that source IP address." + }, + "sslScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable SSL Inspection. Set to true in order to apply your SSL Inspection policy to HTTPS traffic in the location and inspect HTTPS transactions for data leakage, malicious content, and viruses." + }, + "zappSSLScanEnabled": { + "type": "boolean", + "description": "This parameter was deprecated and no longer has an effect on SSL policy. It remains supported in the API payload in order to maintain backwards compatibility with existing scripts, but it will be removed in future.\nEnable Zscaler App SSL Setting. When set to true, the Zscaler App SSL Scan Setting takes effect, irrespective of the SSL policy that is configured for the location." + }, + "xffForwardEnabled": { + "type": "boolean", + "description": "Enable XFF Forwarding for a location. When set to true, traffic is passed to Zscaler Cloud via the X-Forwarded-For (XFF) header.\nNote: For sub-locations, this attribute is a read-only field as the value is inherited from the parent location." + }, + "surrogateIP": { + "type": "boolean", + "description": "Enable Surrogate IP. When set to true, users are mapped to internal device IP addresses" + }, + "idleTimeInMinutes": { + "type": "integer", + "description": "Idle Time to Disassociation. The user mapping idle time (in minutes) is required if a Surrogate IP is enabled" + }, + "displayTimeUnit": { + "type": "string", + "description": "Display Time Unit. The time unit to display for IP Surrogate idle time to disassociation" + }, + "surrogateIPEnforcedForKnownBrowsers": { + "type": "boolean", + "description": "Enforce Surrogate IP for Known Browsers. When set to true, IP Surrogate is enforced for all known browsers" + }, + "surrogateRefreshTimeInMinutes": { + "type": "integer", + "description": "Refresh Time for re-validation of Surrogacy. The surrogate refresh time (in minutes) to re-validate the IP surrogates" + }, + "surrogateRefreshTimeUnit": { + "type": "string", + "description": "Display Refresh Time Unit. The time unit to display for refresh time for re-validation of surrogacy" + }, + "ofwEnabled": { + "type": "boolean", + "description": "Enable Firewall. When set to true, Firewall is enabled for the location." + }, + "ipsControl": { + "type": "boolean", + "description": "Enable IPS Control. When set to true, IPS Control is enabled for the location if Firewall is enabled." + }, + "aupEnabled": { + "type": "boolean", + "description": "Enable AUP. When set to true, AUP is enabled for the location" + }, + "cautionEnabled": { + "type": "boolean", + "description": "Enable Caution. When set to true, a caution notifcation is enabled for the location" + }, + "aupBlockInternetUntilAccepted": { + "type": "boolean", + "description": "For First Time AUP Behavior, Block Internet Access. When set, all internet access (including non-HTTP traffic) is disabled until the user accepts the AUP." + }, + "aupForceSslInspection": { + "type": "boolean", + "description": "For First Time AUP Behavior, Force SSL Inspection. When set, Zscaler forces SSL Inspection in order to enforce AUP for HTTPS traffic." + }, + "aupTimeoutInDays": { + "type": "integer", + "description": "Custom AUP Frequency. Refresh time (in days) to re-validate the AUP." + }, + "profile": { + "type": "string", + "description": "Profile tag that specifies the location traffic type. If not specified, this tag defaults to \"Unassigned\"." + }, + "excludeFromDynamicGroups": { + "type": "boolean" + }, + "excludeFromManualGroups": { + "type": "boolean" + }, + "description": { + "type": "string", + "description": "Additional notes or information regarding the location or sub-location. The description cannot exceed 1024 characters." + }, + "otherSubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv4 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other and it can be renamed, if required." + }, + "other6SubLocation": { + "type": "boolean", + "description": "If set to true, indicates that this is a default sub-location created by the Zscaler service to accommodate IPv6 addresses that are not part of any user-defined sub-locations. The default sub-location is created with the name Other6 and it can be renamed, if required. This field is applicable only if ipv6Enabled is set is true." + }, + "ecLocation": { + "type": "boolean" + }, + "ipv6Enabled": { + "type": "boolean", + "description": "If set to true, IPv6 is enabled for the location and IPv6 traffic from the location can be forwarded to the Zscaler service to enforce security policies." + }, + "defaultExtranetTsPool": { + "type": "boolean", + "description": "Indicates that the traffic selector specified in the extranet is the designated default traffic selector" + }, + "defaultExtranetDns": { + "type": "boolean", + "description": "Indicates that the DNS server configuration used in the extranet is the designated default DNS server" + }, + "extranet": { + "type": "object", + "description": "The ID of the extranet resource that must be assigned to the location" + }, + "extranetIpPool": { + "type": "object", + "description": "The ID of the traffic selector specified in the extranet" + }, + "extranetDns": { + "type": "object", + "description": "The ID of the DNS server configuration used in the extranet" + }, + "ipv6Dns64Prefix": { + "type": "boolean" + }, + "dynamiclocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "staticLocationGroups": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZenClusters": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + }, + "virtualZens": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + } + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "373cdbb5-e7c7-4bef-a732-cbc5da37f967", + "created": "2026-08-14T20:45:30.832Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 77, + "reference": "dcec20e6-81ee-4d3f-82c5-2fe9bcf8d139", + "type": "workflow", + "folder": "/Locations", + "document": { + "name": "Delete Location", + "description": "Delete Location", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "locationmanagement_Delete", + "canvasName": "locationmanagement_Delete", + "summary": "locationmanagement_Delete", + "description": "locationmanagement_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "5606d20e-b123-4b53-9a82-8d50d1788382", + "created": "2026-08-14T20:45:30.872Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 78, + "reference": "2dd9c525-5adf-4422-bf3f-b20aba49e9f3", + "type": "workflow", + "folder": "/Locations", + "document": { + "name": "List Locations", + "description": "List Locations", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "locationmanagement_GetAll", + "canvasName": "locationmanagement_GetAll", + "summary": "locationmanagement_GetAll", + "description": "locationmanagement_GetAll", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "f08661ae-3eb9-4e88-a0eb-568bda1a27da", + "created": "2026-08-14T20:45:30.906Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 79, + "reference": "135a1ea4-5a90-4f5b-a165-888d2357924f", + "type": "workflow", + "folder": "/Rule Labels", + "document": { + "name": "Get Rule Label", + "description": "Get Rule Label", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "rule_labels_Get", + "canvasName": "rule_labels_Get", + "summary": "rule_labels_Get", + "description": "rule_labels_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "c94d10de-9b7c-4e0c-a873-ca73e91356cc", + "created": "2026-08-14T20:45:30.944Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 80, + "reference": "f0e5ed25-2d6a-483f-b1b7-77ac2c687c05", + "type": "workflow", + "folder": "/Rule Labels", + "document": { + "name": "Create Rule Label", + "description": "Create Rule Label", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "rule_labels_Create", + "canvasName": "rule_labels_Create", + "summary": "rule_labels_Create", + "description": "rule_labels_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "ce7afb1f-e1e8-49e3-ab57-d4b21e835f41", + "created": "2026-08-14T20:45:30.980Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 81, + "reference": "ee9fa916-b6a0-4654-ab18-20353d544c83", + "type": "workflow", + "folder": "/Rule Labels", + "document": { + "name": "Update Rule Label", + "description": "Update Rule Label", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "rule_labels_Update", + "canvasName": "rule_labels_Update", + "summary": "rule_labels_Update", + "description": "rule_labels_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "The unique identifier for the rule label." + }, + "name": { + "type": "string", + "description": "The rule label name." + }, + "description": { + "type": "string", + "description": "The rule label description." + }, + "lastModifiedTime": { + "type": "integer", + "description": "Timestamp when the rule lable was last modified. This is a read-only field. Ignored by PUT and DELETE requests." + }, + "lastModifiedBy": { + "type": "object", + "description": "The admin that modified the rule label last. This is a read-only field. Ignored by PUT requests." + }, + "createdBy": { + "type": "object", + "description": "The admin that created the rule label. This is a read-only field. Ignored by PUT requests." + }, + "referencedRuleCount": { + "type": "integer", + "description": "The number of rules that reference the label." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "626facbb-c518-40eb-a429-93d564661e3a", + "created": "2026-08-14T20:45:31.018Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 82, + "reference": "8fcd0883-494d-4870-83fb-9e4f14da784a", + "type": "workflow", + "folder": "/Rule Labels", + "document": { + "name": "Delete Rule Label", + "description": "Delete Rule Label", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "rule_labels_Delete", + "canvasName": "rule_labels_Delete", + "summary": "rule_labels_Delete", + "description": "rule_labels_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "1be9d98f-c3ed-4237-ba8e-1b2f4b5c0eda", + "created": "2026-08-14T20:45:31.056Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 83, + "reference": "7482f1e1-e49f-41b9-8ad6-cb2cc2732b05", + "type": "workflow", + "folder": "/Rule Labels", + "document": { + "name": "List Rule Labels", + "description": "List Rule Labels", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "rule_labels_GetAll", + "canvasName": "rule_labels_GetAll", + "summary": "rule_labels_GetAll", + "description": "rule_labels_GetAll", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "6db3f1d1-b8dd-4dca-9114-cff45c89fdab", + "created": "2026-08-14T20:45:31.093Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 84, + "reference": "cd14c9dc-e2d1-4b75-941f-303cf01940d9", + "type": "workflow", + "folder": "/URL Categories", + "document": { + "name": "Get URL Category", + "description": "Get URL Category", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlcategories_Get", + "canvasName": "urlcategories_Get", + "summary": "urlcategories_Get", + "description": "urlcategories_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "74e90506-e86c-41a0-b6be-54865bc95da4", + "created": "2026-08-14T20:45:31.128Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 85, + "reference": "75407e6f-383e-42b5-973c-ebd99301fbff", + "type": "workflow", + "folder": "/URL Categories", + "document": { + "name": "List URL Categorys", + "description": "List URL Categorys", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlcategories_GetCustomURLCategories", + "canvasName": "urlcategories_GetCustomURLCategories", + "summary": "urlcategories_GetCustomURLCategories", + "description": "urlcategories_GetCustomURLCategories", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "b0c030d3-8ea6-4c78-9445-8a6e2d386a9a", + "created": "2026-08-14T20:45:31.166Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 86, + "reference": "ad7a7fba-d39d-4721-9cd3-84e59c6bbdd6", + "type": "workflow", + "folder": "/URL Categories", + "document": { + "name": "Create URL Category", + "description": "Create URL Category", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlcategories_CreateURLCategories", + "canvasName": "urlcategories_CreateURLCategories", + "summary": "urlcategories_CreateURLCategories", + "description": "urlcategories_CreateURLCategories", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "137f7fb9-435e-42a4-aa6a-eaaf3934e2a9", + "created": "2026-08-14T20:45:31.204Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 87, + "reference": "ac6bb9f7-a829-46b9-8533-c1e4e639f949", + "type": "workflow", + "folder": "/URL Categories", + "document": { + "name": "Update URL Category", + "description": "Update URL Category", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlcategories_UpdateURLCategories", + "canvasName": "urlcategories_UpdateURLCategories", + "summary": "urlcategories_UpdateURLCategories", + "description": "urlcategories_UpdateURLCategories", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "string", + "description": "URL category" + }, + "configuredName": { + "type": "string", + "description": "Name of the URL category. This is only required for custom URL categories." + }, + "keywords": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom keywords associated to a URL category. Up to 2048 custom keywords can be added per organization across all categories (including bandwidth classes)." + }, + "keywordsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Retained custom keywords from the parent URL category that is associated to a URL category. Up to 2048 retained parent keywords can be added per organization across all categories (including bandwidth classes)." + }, + "urls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom URLs to add to a URL category. Up to 25,000 custom URLs can be added per organization across all categories (including bandwidth classes)." + }, + "dbCategorizedUrls": { + "type": "array", + "items": { + "type": "string" + }, + "description": "URLs added to a custom URL category are also retained under the original parent URL category (i.e., the predefined category the URL previously belonged to). The URLs entered are covered by policies that reference the original parent URL category as well as those that reference the custom URL category. For example, if you add www.amazon.com, this URL is covered by policies that reference the custom URL category as well as policies that reference its parent URL category of \"Online Shopping\"." + }, + "customCategory": { + "type": "boolean" + }, + "scopes": { + "type": "array", + "items": { + "type": "object", + "properties": { + "scopeGroupMemberEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Only applicable for the LOCATION_GROUP admin scope type, in which case this attribute gives the list of ID/name pairs of locations within the location group. The attribute name is subject to change." + }, + "Type": { + "type": "string", + "description": "The admin scope type. The attribute name is subject to change." + }, + "ScopeEntities": { + "type": "array", + "items": { + "type": "object", + "description": "common.IDNameExtensions object" + }, + "description": "Based on the admin scope type, the entities can be the ID/name pair of departments, locations, or location groups. The attribute name is subject to change." + } + } + }, + "description": "Scope of the custom categories." + }, + "editable": { + "type": "boolean", + "description": "Value is set to false for custom URL category when due to scope user does not have edit permission" + }, + "description": { + "type": "string", + "description": "Description of the URL category. Contains tag name and needs to be localized on client side in case of predefined category (customCategory=null or =false), else it contains the user-entered description which does not have localization support." + }, + "type": { + "type": "string", + "description": "Type of the custom categories." + }, + "urlKeywordCounts": { + "type": "object", + "properties": { + "totalUrlCount": { + "type": "integer", + "description": "Custom URL count for the category." + }, + "retainParentUrlCount": { + "type": "integer", + "description": "Count of URLs with retain parent category." + }, + "totalKeywordCount": { + "type": "integer", + "description": "Total keyword count for the category." + }, + "retainParentKeywordCount": { + "type": "integer", + "description": "Count of total keywords with retain parent category." + } + }, + "description": "URL and keyword counts for the URL category." + }, + "val": { + "type": "integer" + }, + "customUrlsCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category." + }, + "superCategory": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "categoryGroup": { + "type": "string", + "description": "Super Category of the URL category. This field is required when creating custom URL categories." + }, + "urlType": { + "type": "string", + "description": "Specifies the type of URL match, such as using exact URLs or regex patterns.\nFor regex, the patterns can be specified using the regexPatterns and regexPatternsRetainingParentCategory fields.\nFor exact URLs, specify the required URLs, keywords, or IP ranges using the appropriate fields.\nSupported Values: EXACT, REGEX\nNote: To enable the Regex feature, contact Zscaler Support." + }, + "urlsRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom URLs associated to the URL category, that also need to be retained under the original parent category." + }, + "ipRanges": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Custom IP address ranges associated to a URL category. Up to 2000 custom IP address ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "ipRangesRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "The retaining parent custom IP address ranges associated to a URL category. Up to 2000 custom IP ranges and retaining parent custom IP address ranges can be added, per organization, across all categories." + }, + "customIpRangesCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category." + }, + "ipRangesRetainingParentCategoryCount": { + "type": "integer", + "description": "The number of custom IP address ranges associated to the URL category, that also need to be retained under the original parent category." + }, + "regexPatterns": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Regex patterns associated with this custom category to support full or partial matches with URLs. Multiple patterns can be added to a category. A pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + }, + "regexPatternsRetainingParentCategory": { + "type": "array", + "items": { + "type": "string" + }, + "description": "This field specifies regex patterns for URLs that must be covered by policies directly referencing this custom category as well as by policies referencing its parent URL category (e.g., Corporate Marketing). Multiple patterns can be added to a category.\nA pattern must be between 3 and 255 characters, and a maximum of 256 patterns can be added across all categories." + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "64d71ba6-c24e-49f5-95c2-0d7859b6fba0", + "created": "2026-08-14T20:45:31.242Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 88, + "reference": "7ac69411-218d-4e04-addc-955dc8279627", + "type": "workflow", + "folder": "/URL Categories", + "document": { + "name": "Delete URL Category", + "description": "Delete URL Category", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlcategories_DeleteURLCategories", + "canvasName": "urlcategories_DeleteURLCategories", + "summary": "urlcategories_DeleteURLCategories", + "description": "urlcategories_DeleteURLCategories", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "72882ac7-af95-4263-86ea-0cbed3566b37", + "created": "2026-08-14T20:45:31.277Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 89, + "reference": "62633a02-e9cf-42c7-8ca7-51d7433351c7", + "type": "workflow", + "folder": "/URL Filtering", + "document": { + "name": "Get URL Filtering Rule", + "description": "Get URL Filtering Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlfilteringpolicies_Get", + "canvasName": "urlfilteringpolicies_Get", + "summary": "urlfilteringpolicies_Get", + "description": "urlfilteringpolicies_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "7c1c6c6e-38fd-40ca-b02b-f4b5ab460574", + "created": "2026-08-14T20:45:31.326Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 90, + "reference": "791d8b30-f269-433b-9ba3-691b5ebe4475", + "type": "workflow", + "folder": "/URL Filtering", + "document": { + "name": "List URL Filtering Rules", + "description": "List URL Filtering Rules", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlfilteringpolicies_GetByName", + "canvasName": "urlfilteringpolicies_GetByName", + "summary": "urlfilteringpolicies_GetByName", + "description": "urlfilteringpolicies_GetByName", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "42fbdd24-ad82-4592-afde-6d8d51c86524", + "created": "2026-08-14T20:45:31.390Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 91, + "reference": "6b76335a-5db8-4874-8dde-fadb3de93317", + "type": "workflow", + "folder": "/URL Filtering", + "document": { + "name": "Create URL Filtering Rule", + "description": "Create URL Filtering Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlfilteringpolicies_Create", + "canvasName": "urlfilteringpolicies_Create", + "summary": "urlfilteringpolicies_Create", + "description": "urlfilteringpolicies_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "fc6c5350-912a-48ff-b90d-a9a0b5ac0439", + "created": "2026-08-14T20:45:31.427Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 92, + "reference": "1b9898a8-2003-406c-80b8-cf3b344d9012", + "type": "workflow", + "folder": "/URL Filtering", + "document": { + "name": "Update URL Filtering Rule", + "description": "Update URL Filtering Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlfilteringpolicies_Update", + "canvasName": "urlfilteringpolicies_Update", + "summary": "urlfilteringpolicies_Update", + "description": "urlfilteringpolicies_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "9a4d8fb4-3b59-4e49-9fb8-838acabfce2a", + "created": "2026-08-14T20:45:31.466Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 93, + "reference": "6c03a28d-e230-416f-94f3-77e645542c15", + "type": "workflow", + "folder": "/URL Filtering", + "document": { + "name": "Delete URL Filtering Rule", + "description": "Delete URL Filtering Rule", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlfilteringpolicies_Delete", + "canvasName": "urlfilteringpolicies_Delete", + "summary": "urlfilteringpolicies_Delete", + "description": "urlfilteringpolicies_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "7f20bd8f-7b8c-4c27-92e9-e111cdd8bb3e", + "created": "2026-08-14T20:45:31.504Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 94, + "reference": "c920ddfe-0ea5-4050-b226-5a91f79256da", + "type": "workflow", + "folder": "/URL Filtering", + "document": { + "name": "Get Advanced URL Filter and Cloud App Settings", + "description": "Get Advanced URL Filter and Cloud App Settings", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlfilteringpolicies_GetUrlAndAppSettings", + "canvasName": "urlfilteringpolicies_GetUrlAndAppSettings", + "summary": "urlfilteringpolicies_GetUrlAndAppSettings", + "description": "urlfilteringpolicies_GetUrlAndAppSettings", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "ff9ee210-03ed-44e8-9fa4-6e29ebbea58b", + "created": "2026-08-14T20:45:31.541Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 95, + "reference": "dd734afc-51b9-427a-9a0b-86f7987f6379", + "type": "workflow", + "folder": "/URL Filtering", + "document": { + "name": "Update Advanced URL Filter and Cloud App Settings", + "description": "Update Advanced URL Filter and Cloud App Settings", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "urlfilteringpolicies_UpdateUrlAndAppSettings", + "canvasName": "urlfilteringpolicies_UpdateUrlAndAppSettings", + "summary": "urlfilteringpolicies_UpdateUrlAndAppSettings", + "description": "urlfilteringpolicies_UpdateUrlAndAppSettings", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "enableDynamicContentCat": { + "type": "boolean", + "description": "A Boolean value that indicates if dynamic categorization of URLs by analyzing content of uncategorized websites using AI/ML tools is enabled or not." + }, + "considerEmbeddedSites": { + "type": "boolean", + "description": "A Boolean value that indicates if URL filtering rules must be applied to sites that are translated using translation services or not." + }, + "enforceSafeSearch": { + "type": "boolean", + "description": "A Boolean value that indicates whether only safe content must be returned for web, image, and video search." + }, + "enableOffice365": { + "type": "boolean", + "description": "Enable/Disable Microsoft Office 365 configuration" + }, + "enableMsftO365": { + "type": "boolean", + "description": "Enable/Disable Microsoft-recommended Office 365 one click configuration" + }, + "enableUcaasZoom": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Zoom traffic, without any manual configuration needed." + }, + "enableUcaasLogMeIn": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for GoTo traffic, without any manual configuration needed." + }, + "enableUcaasRingCentral": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for RingCentral traffic, without any manual configuration needed." + }, + "enableUcaasWebex": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Webex traffic, without any manual configuration needed." + }, + "enableUcaasTalkdesk": { + "type": "boolean", + "description": "A Boolean value indicating if the Zscaler service is allowed to automatically permit secure local breakout for Talkdesk traffic, with minimal or no manual configuration needed." + }, + "enableChatGptPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with ChatGPT by users should be categorized and logged" + }, + "enableMicrosoftCoPilotPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Microsoft Copilot by users should be categorized and logged" + }, + "enableGeminiPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Google Gemini by users should be categorized and logged" + }, + "enablePOEPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Poe by users should be categorized and logged" + }, + "enableMetaPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Meta AI by users should be categorized and logged" + }, + "enablePerPlexityPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Perplexity by users should be categorized and logged" + }, + "enableDeepSeekPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with DeepSeek by users should be categorized and logged" + }, + "enableWriterPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Writer by users should be categorized and logged" + }, + "enableGrokPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grok by users should be categorized and logged" + }, + "enableMistralAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Mistral AI by users should be categorized and logged" + }, + "enableClaudePrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Claude by users should be categorized and logged" + }, + "enableGrammarlyPrompt": { + "type": "boolean", + "description": "A Boolean value indicating if the use of generative AI prompts with Grammarly by users should be categorized and logged" + }, + "blockSkype": { + "type": "boolean", + "description": "A Boolean value indicating whether access to Skype is blocked or not.\n\nDeprecated: the service no longer returns this field and rejects a request\nbody that carries it, so it keeps omitempty and is never sent as false." + }, + "enableNewlyRegisteredDomains": { + "type": "boolean", + "description": "A Boolean value indicating whether newly registered and observed domains that are identified within hours of going live are allowed or blocked" + }, + "enableBlockOverrideForNonAuthUser": { + "type": "boolean", + "description": "A Boolean value indicating if authorized users can temporarily override block action on websites by providing their authentication information" + }, + "enableCIPACompliance": { + "type": "boolean", + "description": "A Boolean value indicating if the predefined CIPA Compliance Rule is enabled or not." + }, + "safeSearchApps": { + "type": "array", + "items": { + "type": "string" + }, + "description": "list of applications for which the SafeSearch enforcement applies. You cannot modify this field when the enforceSafeSearch field is disabled.\nSupported Values: \"ANY\", \"DAILYMOTION\", \"BING\", \"GOOGLE\", \"YAHOO\", \"AOL\", \"FLICKR\", \"YOUTUBE\",\"DUCKDUCKGO\"\n\nKeeps omitempty: sending an empty list while EnforceSafeSearch is false is\nan attempt to modify a field the service locks in that state." + }, + "zveloDbLookupDisabled": { + "type": "boolean", + "description": "A Boolean value indicating if Zvelo database lookup is disabled." + }, + "enableCreativeCommonsSearchResults": { + "type": "boolean", + "description": "A Boolean value indicating if Creative Commons search results are enabled." + }, + "enableGoogleAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with Google AI by users should be categorized and logged" + }, + "enableQuillbotAIPrompt": { + "type": "boolean", + "description": "A Boolean value indicating whether the use of generative AI prompts with QuillBot by users should be categorized and logged" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "8798ae59-7635-4743-bf7d-f9492c9eb679", + "created": "2026-08-14T20:45:31.583Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 96, + "reference": "f6122486-6cc6-4aac-bfd6-30b160ab3e08", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Get Department", + "description": "Get Department", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "departments_GetDepartments", + "canvasName": "departments_GetDepartments", + "summary": "departments_GetDepartments", + "description": "departments_GetDepartments", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "de404cb5-e1aa-476d-9ff5-c8bf96105eea", + "created": "2026-08-14T20:45:31.619Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 97, + "reference": "f3b6787c-16ab-4472-860e-b423645c7d70", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Create Department", + "description": "Create Department", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "departments_Create", + "canvasName": "departments_Create", + "summary": "departments_Create", + "description": "departments_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "25a34b31-6b1a-4810-bac9-294a15ae4fd5", + "created": "2026-08-14T20:45:31.655Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 98, + "reference": "854ea3a5-67ef-4059-9ed5-a12b44d1d22d", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Update Department", + "description": "Update Department", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "departments_Update", + "canvasName": "departments_Update", + "summary": "departments_Update", + "description": "departments_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Department ID" + }, + "name": { + "type": "string", + "description": "Department name" + }, + "idpId": { + "type": "integer", + "description": "Identity provider (IdP) ID" + }, + "comments": { + "type": "string", + "description": "Additional information about this department" + }, + "deleted": { + "type": "boolean" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "4849f0af-8697-480e-bf5e-af1d48e3602e", + "created": "2026-08-14T20:45:31.694Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 99, + "reference": "2d6b95e1-60ac-4eb0-bcfa-8b8bb588b5ad", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Delete Department", + "description": "Delete Department", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "departments_Delete", + "canvasName": "departments_Delete", + "summary": "departments_Delete", + "description": "departments_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "d12e5506-244e-438b-8972-ed155867c2ab", + "created": "2026-08-14T20:45:31.735Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 100, + "reference": "175c30a5-3114-4dde-b69c-c32b1f2288aa", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "List Departments", + "description": "List Departments", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "departments_GetAll", + "canvasName": "departments_GetAll", + "summary": "departments_GetAll", + "description": "departments_GetAll", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "5b70c29e-500d-40b1-b93f-17b375f816b1", + "created": "2026-08-14T20:45:31.770Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 101, + "reference": "3351682d-15f5-4693-8465-993c1222176e", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Get Zscaler Group", + "description": "Get Zscaler Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "groups_GetGroups", + "canvasName": "groups_GetGroups", + "summary": "groups_GetGroups", + "description": "groups_GetGroups", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "1dfd57e9-1b18-44ab-8d34-c68086c74559", + "created": "2026-08-14T20:45:31.804Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 102, + "reference": "47606af5-2890-4679-8877-f5a94fad80b7", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Create Zscaler Group", + "description": "Create Zscaler Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "groups_Create", + "canvasName": "groups_Create", + "summary": "groups_Create", + "description": "groups_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "3ac51adb-649b-4d42-800e-21f7b350b78d", + "created": "2026-08-14T20:45:31.839Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 103, + "reference": "b2657789-da94-4a55-be85-3c1ddd5a7f7b", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Update Zscaler Group", + "description": "Update Zscaler Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "groups_Update", + "canvasName": "groups_Update", + "summary": "groups_Update", + "description": "groups_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "Unique identfier for the group" + }, + "name": { + "type": "string", + "description": "Group name" + }, + "idpId": { + "type": "integer", + "description": "Unique identfier for the identity provider (IdP)" + }, + "comments": { + "type": "string", + "description": "Additional information about the group" + }, + "isSystemDefined": { + "type": "boolean", + "description": "Additional information about the group" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "5f753c44-ef0b-4ab0-9e3d-4ba070f220e2", + "created": "2026-08-14T20:45:31.878Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 104, + "reference": "dc736cc9-ca37-4c42-91e0-0b53bd534712", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Delete Zscaler Group", + "description": "Delete Zscaler Group", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "groups_Delete", + "canvasName": "groups_Delete", + "summary": "groups_Delete", + "description": "groups_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "6ed97fc3-4186-44ed-a3f6-790f309c9261", + "created": "2026-08-14T20:45:31.914Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 105, + "reference": "510cae71-40c7-438c-920f-381ebb4761ec", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "List Zscaler Groups", + "description": "List Zscaler Groups", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "groups_GetAllGroups", + "canvasName": "groups_GetAllGroups", + "summary": "groups_GetAllGroups", + "description": "groups_GetAllGroups", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "466751ea-d5df-47d5-a7fa-3ea713c8ddd2", + "created": "2026-08-14T20:45:31.950Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 106, + "reference": "5d00c89c-d977-41b3-bf13-7b9a2d32b0c5", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Get Zscaler User", + "description": "Get Zscaler User", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "users_Get", + "canvasName": "users_Get", + "summary": "users_Get", + "description": "users_Get", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "a9b08f43-3ee4-4c6a-9c01-1b103e75984c", + "created": "2026-08-14T20:45:31.984Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 107, + "reference": "7ea2812e-ab0f-43f2-b3a0-abc83a5362ce", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Create User", + "description": "Create User", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "users_Create", + "canvasName": "users_Create", + "summary": "users_Create", + "description": "users_Create", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + }, + "required": [ + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "09b4b379-80a8-4f5a-ba46-3cdc0c1ea0ab", + "created": "2026-08-14T20:45:32.023Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 108, + "reference": "c2f4491a-8e85-4979-bee2-ab7d1b1c4e4e", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Update User", + "description": "Update User", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "users_Update", + "canvasName": "users_Update", + "summary": "users_Update", + "description": "users_Update", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id", + "bodyContentType": "application/json", + "requestBodyPayload": "$var.job.spec" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + } + }, + "required": [ + "id", + "spec" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "spec": { + "type": "object", + "properties": { + "id": { + "type": "integer", + "description": "User ID" + }, + "name": { + "type": "string", + "description": "User name. This appears when choosing users for policies." + }, + "email": { + "type": "string", + "description": "User email consists of a user name and domain name. It does not have to be a valid email address, but it must be unique and its domain must belong to the organization." + }, + "groups": { + "type": "array", + "items": { + "type": "object", + "description": "common.UserGroups object" + }, + "description": "List of Groups a user belongs to. Groups are used in policies." + }, + "department": { + "type": "object", + "description": "Department a user belongs to" + }, + "comments": { + "type": "string", + "description": "Additional information about this user." + }, + "tempAuthEmail": { + "type": "string", + "description": "Temporary Authentication Email. If you enabled one-time tokens or links, enter the email address to which the Zscaler service sends the tokens or links. If this is empty, the service sends the email to the User email." + }, + "authMethods": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Accepted Authentication Methods. Support values are \"BASIC\" and \"DIGEST\"" + }, + "password": { + "type": "string", + "description": "User's password. Applicable only when authentication type is Hosted DB. Password strength must follow what is defined in the auth settings." + }, + "adminUser": { + "type": "boolean", + "description": "True if this user is an Admin user" + }, + "type": { + "type": "string", + "description": "User type. Provided only if this user is not an end user." + }, + "deleted": { + "type": "boolean" + } + } + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "77973490-9b3d-4234-b502-a5af94572e15", + "created": "2026-08-14T20:45:32.066Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 109, + "reference": "2ccaa0f6-6bae-4840-8d09-fa1b1abb15c2", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "Delete User", + "description": "Delete User", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "users_Delete", + "canvasName": "users_Delete", + "summary": "users_Delete", + "description": "users_Delete", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler", + "id": "$var.job.id" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + } + }, + "required": [ + "id" + ] + }, + "outputSchema": { + "type": "object", + "properties": { + "id": { + "type": "string" + }, + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "efff2d28-d102-4f41-9aa5-f3eb2d317966", + "created": "2026-08-14T20:45:32.103Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + }, + { + "iid": 110, + "reference": "37ac86ea-9b79-4905-bf67-c037d9dac4e8", + "type": "workflow", + "folder": "/User Management", + "document": { + "name": "List Zscaler Users", + "description": "List Zscaler Users", + "type": "automation", + "font_size": 12, + "tasks": { + "workflow_start": { + "name": "workflow_start", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 0 + } + }, + "a1a1": { + "name": "users_GetAllUsers", + "canvasName": "users_GetAllUsers", + "summary": "users_GetAllUsers", + "description": "users_GetAllUsers", + "location": "Adapter", + "locationType": "Zscaler Internet Access (ZIA) API:latest", + "app": "Zscaler Internet Access (ZIA) API:latest", + "type": "automatic", + "displayName": "Zscaler", + "variables": { + "incoming": { + "adapter_id": "Zscaler" + }, + "outgoing": { + "response": null + }, + "error": "", + "decorators": [] + }, + "groups": [], + "actor": "Pronghorn", + "scheduled": false, + "nodeLocation": { + "x": 264, + "y": 150 + } + }, + "workflow_end": { + "name": "workflow_end", + "groups": [], + "nodeLocation": { + "x": 264, + "y": 300 + } + } + }, + "transitions": { + "workflow_start": { + "a1a1": { + "type": "standard", + "state": "success" + } + }, + "a1a1": { + "workflow_end": { + "type": "standard", + "state": "success" + } + }, + "workflow_end": {} + }, + "inputSchema": { + "type": "object", + "properties": {} + }, + "outputSchema": { + "type": "object", + "properties": { + "_id": { + "type": "string", + "pattern": "^[0-9a-f]{24}$" + }, + "initiator": { + "type": "string" + } + } + }, + "last_updated": "2026-08-14T20:46:00.398Z", + "last_updated_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "lastUpdatedVersion": "4.69.69", + "uuid": "704734a4-6706-4def-99a5-7cdd864e6c9f", + "created": "2026-08-14T20:45:32.138Z", + "created_by": { + "provenance": "LDAP", + "username": "admin@itential", + "firstname": "admin@itential", + "inactive": false + }, + "createdVersion": "5.55.5", + "scenarios": [], + "canvasVersion": 3, + "tags": [], + "groups": [], + "migrationVersion": 8 + } + } + ], + "folders": [ + { + "nodeType": "folder", + "name": "Cloud App Control", + "children": [ + { + "iid": 0, + "nodeType": "component" + }, + { + "iid": 1, + "nodeType": "component" + }, + { + "iid": 2, + "nodeType": "component" + }, + { + "iid": 3, + "nodeType": "component" + }, + { + "iid": 4, + "nodeType": "component" + }, + { + "iid": 5, + "nodeType": "component" + } + ] + }, + { + "nodeType": "folder", + "name": "DLP", + "children": [ + { + "iid": 6, + "nodeType": "component" + }, + { + "iid": 7, + "nodeType": "component" + }, + { + "iid": 8, + "nodeType": "component" + }, + { + "iid": 9, + "nodeType": "component" + }, + { + "iid": 10, + "nodeType": "component" + }, + { + "iid": 11, + "nodeType": "component" + }, + { + "iid": 12, + "nodeType": "component" + }, + { + "iid": 13, + "nodeType": "component" + }, + { + "iid": 14, + "nodeType": "component" + }, + { + "iid": 15, + "nodeType": "component" + }, + { + "iid": 16, + "nodeType": "component" + }, + { + "iid": 17, + "nodeType": "component" + }, + { + "iid": 18, + "nodeType": "component" + }, + { + "iid": 19, + "nodeType": "component" + }, + { + "iid": 20, + "nodeType": "component" + }, + { + "iid": 21, + "nodeType": "component" + }, + { + "iid": 22, + "nodeType": "component" + }, + { + "iid": 23, + "nodeType": "component" + }, + { + "iid": 24, + "nodeType": "component" + }, + { + "iid": 25, + "nodeType": "component" + }, + { + "iid": 26, + "nodeType": "component" + }, + { + "iid": 27, + "nodeType": "component" + }, + { + "iid": 28, + "nodeType": "component" + } + ] + }, + { + "nodeType": "folder", + "name": "File Type Control", + "children": [ + { + "iid": 29, + "nodeType": "component" + }, + { + "iid": 30, + "nodeType": "component" + }, + { + "iid": 31, + "nodeType": "component" + }, + { + "iid": 32, + "nodeType": "component" + }, + { + "iid": 33, + "nodeType": "component" + }, + { + "iid": 34, + "nodeType": "component" + }, + { + "iid": 35, + "nodeType": "component" + } + ] + }, + { + "nodeType": "folder", + "name": "Firewall Policies", + "children": [ + { + "iid": 36, + "nodeType": "component" + }, + { + "iid": 37, + "nodeType": "component" + }, + { + "iid": 38, + "nodeType": "component" + }, + { + "iid": 39, + "nodeType": "component" + }, + { + "iid": 40, + "nodeType": "component" + }, + { + "iid": 41, + "nodeType": "component" + }, + { + "iid": 42, + "nodeType": "component" + }, + { + "iid": 43, + "nodeType": "component" + }, + { + "iid": 44, + "nodeType": "component" + }, + { + "iid": 45, + "nodeType": "component" + }, + { + "iid": 46, + "nodeType": "component" + }, + { + "iid": 47, + "nodeType": "component" + }, + { + "iid": 48, + "nodeType": "component" + }, + { + "iid": 49, + "nodeType": "component" + }, + { + "iid": 50, + "nodeType": "component" + }, + { + "iid": 51, + "nodeType": "component" + }, + { + "iid": 52, + "nodeType": "component" + }, + { + "iid": 53, + "nodeType": "component" + }, + { + "iid": 54, + "nodeType": "component" + }, + { + "iid": 55, + "nodeType": "component" + }, + { + "iid": 56, + "nodeType": "component" + }, + { + "iid": 57, + "nodeType": "component" + }, + { + "iid": 58, + "nodeType": "component" + }, + { + "iid": 59, + "nodeType": "component" + }, + { + "iid": 60, + "nodeType": "component" + }, + { + "iid": 61, + "nodeType": "component" + }, + { + "iid": 62, + "nodeType": "component" + }, + { + "iid": 63, + "nodeType": "component" + }, + { + "iid": 64, + "nodeType": "component" + }, + { + "iid": 65, + "nodeType": "component" + }, + { + "iid": 66, + "nodeType": "component" + }, + { + "iid": 67, + "nodeType": "component" + }, + { + "iid": 68, + "nodeType": "component" + }, + { + "iid": 69, + "nodeType": "component" + }, + { + "iid": 70, + "nodeType": "component" + } + ] + }, + { + "nodeType": "folder", + "name": "Locations", + "children": [ + { + "iid": 71, + "nodeType": "component" + }, + { + "iid": 72, + "nodeType": "component" + }, + { + "iid": 73, + "nodeType": "component" + }, + { + "iid": 74, + "nodeType": "component" + }, + { + "iid": 75, + "nodeType": "component" + }, + { + "iid": 76, + "nodeType": "component" + }, + { + "iid": 77, + "nodeType": "component" + }, + { + "iid": 78, + "nodeType": "component" + } + ] + }, + { + "nodeType": "folder", + "name": "Rule Labels", + "children": [ + { + "iid": 79, + "nodeType": "component" + }, + { + "iid": 80, + "nodeType": "component" + }, + { + "iid": 81, + "nodeType": "component" + }, + { + "iid": 82, + "nodeType": "component" + }, + { + "iid": 83, + "nodeType": "component" + } + ] + }, + { + "nodeType": "folder", + "name": "URL Categories", + "children": [ + { + "iid": 84, + "nodeType": "component" + }, + { + "iid": 85, + "nodeType": "component" + }, + { + "iid": 86, + "nodeType": "component" + }, + { + "iid": 87, + "nodeType": "component" + }, + { + "iid": 88, + "nodeType": "component" + } + ] + }, + { + "nodeType": "folder", + "name": "URL Filtering", + "children": [ + { + "iid": 89, + "nodeType": "component" + }, + { + "iid": 90, + "nodeType": "component" + }, + { + "iid": 91, + "nodeType": "component" + }, + { + "iid": 92, + "nodeType": "component" + }, + { + "iid": 93, + "nodeType": "component" + }, + { + "iid": 94, + "nodeType": "component" + }, + { + "iid": 95, + "nodeType": "component" + } + ] + }, + { + "nodeType": "folder", + "name": "User Management", + "children": [ + { + "iid": 96, + "nodeType": "component" + }, + { + "iid": 97, + "nodeType": "component" + }, + { + "iid": 98, + "nodeType": "component" + }, + { + "iid": 99, + "nodeType": "component" + }, + { + "iid": 100, + "nodeType": "component" + }, + { + "iid": 101, + "nodeType": "component" + }, + { + "iid": 102, + "nodeType": "component" + }, + { + "iid": 103, + "nodeType": "component" + }, + { + "iid": 104, + "nodeType": "component" + }, + { + "iid": 105, + "nodeType": "component" + }, + { + "iid": 106, + "nodeType": "component" + }, + { + "iid": 107, + "nodeType": "component" + }, + { + "iid": 108, + "nodeType": "component" + }, + { + "iid": 109, + "nodeType": "component" + }, + { + "iid": 110, + "nodeType": "component" + } + ] + } + ], + "createdBy": { + "_id": "699f3e2b85569c9f5d8e1f38", + "provenance": "LDAP", + "username": "admin@itential" + }, + "lastUpdatedBy": { + "_id": "699f3e2b85569c9f5d8e1f38", + "provenance": "LDAP", + "username": "admin@itential" + }, + "created": "2026-08-14T20:45:58.496Z", + "lastUpdated": "2026-08-14T20:45:58.496Z", + "iid": 40, + "thumbnail": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAUoAAABkCAYAAADg+Hn3AAAABGdBTUEAALGPC/xhBQAAACBjSFJNAAB6JgAAgIQAAPoAAACA6AAAdTAAAOpgAAA6mAAAF3CculE8AAAAhGVYSWZNTQAqAAAACAAFARIAAwAAAAEAAQAAARoABQAAAAEAAABKARsABQAAAAEAAABSASgAAwAAAAEAAgAAh2kABAAAAAEAAABaAAAAAAAAAEgAAAABAAAASAAAAAEAA6ABAAMAAAABAAEAAKACAAQAAAABAAABSqADAAQAAAABAAAAZAAAAABcVM/PAAAACXBIWXMAAAsTAAALEwEAmpwYAAACymlUWHRYTUw6Y29tLmFkb2JlLnhtcAAAAAAAPHg6eG1wbWV0YSB4bWxuczp4PSJhZG9iZTpuczptZXRhLyIgeDp4bXB0az0iWE1QIENvcmUgNi4wLjAiPgogICA8cmRmOlJERiB4bWxuczpyZGY9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkvMDIvMjItcmRmLXN5bnRheC1ucyMiPgogICAgICA8cmRmOkRlc2NyaXB0aW9uIHJkZjphYm91dD0iIgogICAgICAgICAgICB4bWxuczp0aWZmPSJodHRwOi8vbnMuYWRvYmUuY29tL3RpZmYvMS4wLyIKICAgICAgICAgICAgeG1sbnM6ZXhpZj0iaHR0cDovL25zLmFkb2JlLmNvbS9leGlmLzEuMC8iPgogICAgICAgICA8dGlmZjpZUmVzb2x1dGlvbj43MjwvdGlmZjpZUmVzb2x1dGlvbj4KICAgICAgICAgPHRpZmY6UmVzb2x1dGlvblVuaXQ+MjwvdGlmZjpSZXNvbHV0aW9uVW5pdD4KICAgICAgICAgPHRpZmY6WFJlc29sdXRpb24+NzI8L3RpZmY6WFJlc29sdXRpb24+CiAgICAgICAgIDx0aWZmOk9yaWVudGF0aW9uPjE8L3RpZmY6T3JpZW50YXRpb24+CiAgICAgICAgIDxleGlmOlBpeGVsWERpbWVuc2lvbj4zMzA8L2V4aWY6UGl4ZWxYRGltZW5zaW9uPgogICAgICAgICA8ZXhpZjpDb2xvclNwYWNlPjE8L2V4aWY6Q29sb3JTcGFjZT4KICAgICAgICAgPGV4aWY6UGl4ZWxZRGltZW5zaW9uPjEyMDwvZXhpZjpQaXhlbFlEaW1lbnNpb24+CiAgICAgIDwvcmRmOkRlc2NyaXB0aW9uPgogICA8L3JkZjpSREY+CjwveDp4bXBtZXRhPgpwIzk+AABAAElEQVR4AXT9C4IjObIsidan76LeSmbns5mZqnwiogYyss8ZBOkOmKmpfQAHnWRk5J9//v/+r//7jz///POPf3/99QedX/z8+ccff/3iifjPX3/8+vMPfv7893R//vnXr3+RaSRSPU/wSf4AB572L7I6d3wndVgwRKutpjwlq590lLP/42/1Q+1IqNoIz4z+fxQZNg3Np/93fiYv3sPUB1tmf5V1Afz5d4H+9Rcl+VM/f/6iEH/8+9cvRn9THBR/6VkpFgx//YGTv6WQ9G8jAPPXH3/+RV+Q4j8JEFE2+EAgIPvk6K10gL/AViAhSpwaf05uiPaVGiIRGgfx5lf2f4rFKQRDDjHbzeY4GyP7ZVoMVOdLf7MUbuC2JhTxFRPBv2M/vXG0eobO0txuKEPdVg99eXLpZI90YSL/jgsvO8E/yN5gutM4CPM9fGw/ukmGPBxpfVqle8H99PiwIn/wh8+acij/Dddg8scliOdgp3c0wQe7mE7vSRsuP+eL9eVFt/rHZwDTZ/d0iVvziVkiywweZiCnJ1sEXfK4Ca3LpqZxkcz+1sLz6dmGH5YgFq7HrsI5KDIP+C4RTnSNkY7LVs2iCSGIjvlsKZirMf2+LkK55Fx3mo+zDgf95WM4jkDz8+uPf+VLfkJ2LAFc2+oQWqdi8vwfHFgKdgAN2xO44jTwikHmxifcunrFWIRiYuiZQLo4fv1yAzU2FYj1/69w7RzTim0FtI5knXvjMkAv+IfurBmglywuuvDwk4tdvwb0x69/pKfLAgoz8szRwNDFr5OMoV9I7GzJQPxy8RkXIf+DvcnrqNcQ1Gz9rSkYuPzJrQ3PvCjYv3/9Zan+/vMfXLWJmR+SdgpY2br+Zcc35l8W2Ea/VULy/6Jnc21MX+7WsvBqbmB6AGNVmhhi2wtTBQdIKf754/8l1yYFzJXOOcZbNQhbFeDDSWLIIcUOSYURQO6G2MrB/l/tWxxGL9dsUGXTNZSZZdOKeuFWzx70Yc4QSV375AZgfhWfkl5hGJtNd68j0fGIHvfsPjzFBxvY8h1FDAWC1XN6dSpjYhqGY8W6Y8IX2kEM40oVqjLTK9J3CmMtMXr4MjlA+Ln88MlAWZs3hJcKwq3JP5l4Y34M1re1y8tl1Ni78uIwz0Ukj13iIBYCb2648bFG7Q+q1KfLSu/f8W6SIL/YgL7pNFwuFgjAi/Ms1Xmdb0ajS0d3NoxCm0SJYG8MDKJJufodUh5LX+Kn5vLA3gUZu7ow4wZsJ50H/RCnNbg6gUY9jFe/qhpXtPdK8BYORrsW3bFMwGpMx1UiqsC1qTxcLBLH1yZrVMC8qrylqnJeXecdtm5DEqDGTbvJP/hCJb3JSGHF/+7Oy7CTcgIXwhSYV/P4032MsUFwcqJsf+d2E8bdXiV3f/oLvKtZCy926d4G/M/ulb07ldiNA6S3khIj+mvL0I0yywvLRQP4b4L7B9Xf0mj06x8PuiPRv9Cp/Q/ZgbZuTvO//3rbR4fA5AT8d6U2LiCg3TYpx1++CHjjWhz//oPd3zKsiNg1P+TihFVmTEyvBN2yVqeS45UFp2ZJ7YlK58XEqLis0d/xO84rwUpmUDzsA/aCuL4XWq936g2D9qbLGTAsw9HvZqQBpbW2qrcMGij42dB9WwHoHbK3JOiaQDg1YjjzaE14RqrmNatuFr57cLnZOgryyaBYb/lNOdxNA/aWGlRXBH1JbHSaHLpXqcKR42FkqkzaKsfASTKccukOXTLGFLZYQBSB5GBJuKGcXTwPhBdrrza5AcrLD0cmgkG2npGo/csAnGuxTy4Q8V9/72rIBo67+tRBoDU4u/RdO5svvU+Omjp0K4SkjcDNKZsdtzg+eKmyZvq44BgYY7Yy6nEQjjwc90odozLgU2lqvOKUT7oYfCcosOpYeJgLBz45u9AR+37PC9X1LYv3kUavm7+oDD4MNxfaoKoOyFYAywpY98gSD+9+3KrVPnIdiHhX78G1R9qBcAvTpcUm6UU4tvy2GpWI8ZpsBW4JuYkgdfpcPfTc5Y0SOFIzrMir+ULBW+H4VnYuF5t9tr1VEJZiWpgJjcFCGZvtFoZuetvLuCKSP6ZgfRACE+ErEfec7OPLeTfCVpqN69f/8VMGHfJSNONfbtBhEcBraL/Amj7czduvv/7Ffmmj5M6ezS+f3dMtKjZkdJsmzjhy0Ht0Z7zp45641wNU2nu7anr1y5Gutjx+/UMn7f9JLawJUGZ8+VKq4DYCu80ZkrgRKNtBFArDMrDR20vvXfhvDZS2xil2Jk2P/kaL8Pz5CqfwNM4D9rP9919AqZ3+8/PSszZxU2L903eob+7qOKyM1s39pTWjbWCW6F+sCmD5wrCsDDYCwqPPTQXycem/ZS8vffEuIpcUk/XHv3+zteLMae5MqblqIUEtnOh4Z4QjeTOuPr94ywXQ0DeFvFAu9k7q9GF9xns5wI4JzRfWyU4UlQ5pucXW9xwaKDXHqWGtSO1D66YwryHe0ZcNHjOWx4XjXYZNhwKBaIfu8a9MIA6SDjvxGEARR1psDAbRwI1HrAce2elLT64G3f/HMlshAM4W8yUnwaLgzO5Th5c5E0C84tvnGXNXqP40VhpzemOXRuGJGYDNobhlkD/I2DYiAOxEus8LqgByMKzpV7U65bSpuPxNhQeRuGViiztP4jz4WJEQkBD67iaQlxtGLDxnQf6tDpC2EZJPdm42eSUb960y652wehl0acs5d5u/3J1MkM2St+FVXLVxEq93pIZQgF0tdLvdMQ7L2KF+MbCxodexMSXaPGFnCM6HXUgLdGLj2qcK2D15AgPRgNh3pi/DP/jhY1hbdWmTZCwMBtMb0+1G4HYnSSc+LUeboA3gPGMrerj5qK8nIKaWfsI7ykaTQpDYjx9iQXLzQI+WK1fdDQDcepgSH+q80Gvh6ElUo3Ob6UdYjQQMbJi39wBZ7MbNq2I5NEESSoVJ9YLDaPlYhufiFjCdjtUJnpsuLubCmmyznPX2U+PQVmzbb6aMEGNCwl10BWIcAj0Ka4dHELM0py6DbQIKfVmWx5D8iAu8S8hY8oG4KmtvQu4snBlqXavfgmEo5jQv7m0gzSb6ZTqcfW3OZLo4I0Le8jUq40Mzg2qiaDFpAbSs7St98aRK2CFPNxncUZZsmyNdNssikYo0Cbu50DNDt+Yrt+e+MSgzLxBafbpe7d5aiadUeii6IJZUPp5G/722ZuemsXeD1lw7weMXb4PhKmapp/vJp6jAzU7bHF1QyMgNM4ReoO1SnOWV/FFfH6HWi6DeGxh7s5Add0h9eaNZPDsWnnlw19Bm6gsOrw6xnr1wAmUjdcGJq56UyelQ6cK3w25luF7PvXA5J5LsswIw1jaXIGgwOxfytdyTLKGquxJzRwpQMT54fEqmxDmUyltffTdhdJpDbH79Pxi4jBCp157T8mbYrqAdjdC8Q1YPDFBHexMwTjflyR9m59VB1Y80sxpcopBeCngq9lPhvtayEiXQaC7GhlqEw14DhC03hQISRHPjwEiNfTbPqzL5Jz8bZUmGGkaJPDmY36vFrKZj3X7nRpGzrQsC1btxbgwTc8E8ZqLQleHnmgjz3qyaux8btWY46gxR4zlm2KarXCcLsYTi6o4vznG8WJbW8Ur1ai8JS1cGzWotC3pdlHEvDGOZpTGaDkNzwtgwz1wQre1eMV0Yb5NWo7DcHNDsZ5svsA0S5sd49AeOM8Gi58sc4+NoHItnd88CoxAIVIOlq12b5BxYsLx77MIsEO9CZmH+qRqbZAJnsrkpibrxYP34fKtgFFeZ70sGgGXrJgCmO885EZ8WI1eLOAnZY8ze3DGatSqsGTL2KqfFcj4ZZC6lubj5P4hc3wqhPmyEsswFUWgsNmqttvFZZmpkEVKBg+NtRr7ShOWrmYRUMX/sfGZgLfZKvpU+nS6WB9RExzJ3Y+uduTkZDSffufshAYhqourystQ9mO9Fjk5/TgWbZqGWOwYG2AuNedA4yWMe8TDWNGGKHDecWH3IcVmaH1qp/kd7fM/uVTV+XDsWYzPf9SbzdZGAvNstrsOkFIhd+A6L7QP5wVNhGK92gCFTZr1k+GxoG8apKtoitOfzBeq5qDhH5/D4EOiiacXHM/PMNWY+0TBOxdismygXlnon7YU3unnWgDl1EJRhNYtjVxvkWjf3EjnogjZZN6TxXwzoxbZ2nCC9J8EqGpf+1pK+tmU+fBwvzOI2HGGYfJr7kGRTpfGAl2/ZERR12hiswwI5IiF1OYJYjkJTmBYDa+5NCXreehen+68F80ePQIzHVxPe2yGgobsYd+fpMuyWx9JRHG16k/eSBe/lLW7EeJRkoZsbLr66+oVlIbBSV+QdUG8M2fOFyBsUa+Bm18Z6lKgMp1lBzQz1ZQhelykdazs9Yb1PI3TTl9Z2eBqiXX1LZ7+wTJe+b0l5peYrmO1t6tJkhM7YZlRK1IyydLPoOsmvX3wZv5F1K17Jqa1U+PEGlMYc6NtJoPF51V9/r787UaQVDgz2Qty5Bv7YFjxX3S5yIHIJ9m6DL2/oicUOv7kD4oyRhzeneughxBHfTWGAVUEV7m7QnHXJeGB4YQD7gVXthqA17twqlvTPFTO9VLVI6R0Ns3kKToQgh/OUP0iLd4r01RDl9073CqBB8zs+c95FLf3yTuOU8TOrN7WX60XSVSLY2HxNbrnKYp+HxpT7VTSh84yOF0+U9/F7YOSe3WCagZsXOZ6e2P/ks1Be/AhE9sXo9UAIhMOxdxYWXydy0hiycDcjcPPtaYn5sSpvQHiitQiYNLGMtQmkuY9csf7JsZojl3LhgbWvBy3f3Wt0CLtudn9JpJJH6ikaRnIuI5elauj0pF8HF0yW2T1BMYyJAGivL/36OKnjAbOPMI/orNk13jMhKA/O29cMIQZdLmW+WojHgnzW/HVQefdSPlXL8H1MbwBlq0c3FKn179NJcIfYqBJsoNLb+ikYNH5EemONViZ5nLuS0itIwyntaLrpwUI+pMTr+imQAjsbVvRkhCUHP5uZxXAVGP8ttKIqYEulh21pLi4Wxa9/2cjcSCPm5EXDInUJFu8uoPwDbqV11/bCd2UZ6D8kZ6hsjHOJzM+IdP2PH8rz41v76gKkL9IICX4hJP7WKu7l4MEORXqbG0lpfcFydSP5Yi12gC9B+WYPUJqbvSqpjaT8dLyLHh2wrvToFmdQKYZvru9uTyfk4jT8fzXtLOsnnsYcUozbHCdwEzFYQQJOzvgxlIcptQbOXgNNOS9/9G0o50R5+HFWENG+MvCTT11BIqz7i+c7RrEwm4dXZYU6e+OVQ1vX3vlqoRen6tOLy0HOUKAqV2ouxnBYCn4Bt88WwZkQXwx9alQerqVdj/Dx0alCmjgMejFt3SFHI3VuPLS2l4lGitJ3iPyErQy45DDKxeJSFxAxJ1R6yMbqEHnbQxIdSO+a0cJxBWrQpKBB/OYtNIRQ4Eauc/U22uqD1CD0Wls/fB9uPbdLrlgVVWQuVL9Wc6wfnGNdCkukTVJWEDmx/5rXkG8vXUzoZf4EMRaQvkc8KecwIHe5vVe+RVwQWvBQstZdmew/ZUJrUDrxEWhnr19prLpmo2kDjm//85U5maqM5s+pKnmGTqy+50ZLBhdE0lWtxeavKrlY9e7C+A/dppHct3E2XqHB7IsssJroS0vmo/f+FhN5Cw2uYnBD1A55YyDovfgW7/xl2KQUhkLDPjf2T/IppRdONQM23LPZBokBnwwsa+y7IXWM3Kobo/lyxDpvx4Ya6qTqnAFG+tD0GTT6r4PctId8I9mSvzAd5Pc8w23ZykPdY0A2W8FGMuZJNUDcSTnPR8fIS6DcjRtyFnrjZYa/+HIQyV4GZF6b2TgsedQpPVwkUt80zhD83UAMyjEiTNoQiYriWs/axeB62Is32/UMeZF1jVwWnVexsxuHPMfR3f75ksKuxRFCVPQ5DT73XHvWQKyAbRZ0kPkdJQKWq0cerWe5JKXFax9dRQarE+l07PVnzbWmpxu6dpbTFpjWtW5P0KYXZ7Ry5cnj7GXPgAN7P3ohfgswCz3iyItRXVEWs8OQHtOJfJvoD6VdOXDjNAl/zdESWSffKI3jgJ/gEnOI4t2FWJQQMFkSI+/x7X6oRPo28pi9o3MxaD9fFtK+kSoy9WJRrcymGrEbkBAItNdEsEhZRpSBQNensymgenvyMU903DTaNJ2FHJPiqnWff86DHBD95W8BuAdLoh0vOrxLf5FDrE+04kUx6LNhlwWy+e3MuGiaCBcTlIqEeCg33TCgL6mELuDuaOorNl7lPJqJs7fAxfV/6JmmenUe19kpRdMByNwOVYHFG5PRffvKNgYN/PWD3OEYU5abcqkDPx+fEiQuS1TZHmmI4ErpmO3MI7N7VRv3lcoF8mqunXSN6zdSkE0vCFURtlycc23aBPXitlQEYTTMr1BryCOt9u4gniVjs9R7MWxSHc2AzejKf8sKrojiZr21sYV9OBGuJmE15yxnV+XbkOQRgociAcNwN0E5lRVNi8v1R57+wkbNAN+NhJtr19bpyMRSYS5vTn6smiULVAAPe8WL596v6dKosrEyCLY5B1X5sQyooNQ4evkTl9yfT+NQMywWzrdhelF0Sy2FLl9mkC+CgiPLcruCSJQ64UETIs/AM81X2HtfAb6rc+LH0HzniJ4BEK5J3K/lLGZduTF2O6PIYt4Ko+Pi8I6ulyNUW6X42WShw776GxFBzNxAuotD14waU29l1dvnafu5qfTt8Vvgq9VQgosB07PtFRRZQ/SluRlarAnUbr05jPK9CKBSsHzpU0vJaE2VduWCDMzWNjIXqcsGndekDW358O132HyeDsERcnYxYzfVfOUsP1dyv3uK7uJUN9HZmaNN0GK2OskU8WN954NjsSEN8LGMYQfRa9oI9zB7+lIAeKzz+Cn3B/fDIwbji5nCfbikHiVnLdTI7BVle7nRxal6p6zaF8OjdrDAYmAijFHu2dn3oxG8qIgdNougWesgcBon99kKkPPFHrHQ5OPqotakoU7QejLXwuKgrx7ykeHFK49mGb0LnBHS3PrZE5dYYbvjDY6W9e6/fNO+ewJJSsgODTOMXJQ48zJcAHtLjloHsIHIgAE9usWLfd6NOjkf6Ln+pG1u0sqhLGy7/6pDZLLkI12gww3/53/8OOX8SUD3cpPyXBWzg7kRUVK9CuTCPdocjMfDyijT+kayC+fyF0eLM6MKY8SwWHLrcnwh/XcvVNHisII05VDgGiB5d58qLIiTZIvrOgLLNgb2GcZiu3pWiD//ZTOutqxGF6Q+stE2n1gQB9FpH8j3Rkbhw1C2ETEw1D4TNK32hYUFk3eGpLhfHu+tvkEWfDtYvxBOAMZnuFKXFTI++kycf3pVykQNSpBUWXlqGWhvdVsSrFd/Is+WdJCVoa/DgWOaeyVukratqZ3DnTjd9ON6goMyDKnb4qY6paXASGgX+GIb/vbSAwx7TB/CJ1Wg7WflmLPczq+a5hK0OdjyB4KxpZt79dP5mqrMyjxdKtQxWG77h8vXpuAj657KWXX5b5/IZoFlDfc22niMrXWJT2MeZHeNUij5LD/6yMRo1to6/zkxcLVsUIUYISLXccuiq0FLfXkdGIq6uJBcAVg3/qK7m5j8cmplUcTwcPlUI7+Jd36R3slFroPcCspEMBhAx4icIIH6rcWEAFcZTMDxCy4Y0UxU//aJV+q47Mhp3t4d03GILKedIRyJZvTV0W4HwwA1/FnSv4L4neWZSQizBZ2pMa+XM3+dhBWnF27pIsQLaAlcDrbCpLsAvfqSVynUF7XIuZmV40LWNRhhNAbNWhJiJzq0GgroTjCUtqLXTLQVeRIjKyzV2wz3Oq9YHXS6kdtBi9nXPJTeTmvvP6UZVCw9DFwF6j6ftCNwnCw8sZ6MrwSp1DUAvecQawD46p8nHsCT3vpFZbpXQnl3446N//qwEMH6St1Gra+VzsiLEfX+BcxWk18XqTFXPdvXml7t1sgGfBFlp3DE1VtwlqY8504SxsdTd3arxeVVXeh73g5ZKHN2frY8ERmmycz2R+0Gf/O528Nzptnzxdmup62hGzCdyNzziQIlg2wc4c2h8WlYjMSgTN0sOtpfqVEqgaMYV4cwydFKlQ7Me33Nt7pDFoNUtqtPy5F1Nj9w+FqMYVW+V61NonLiMY/8w4HD+TwP/RqRfYGcwfnT9pYRti2f/Lc6WgvquvCw4WOf4nbHj8ZafnZ/ZPp0P5t73RSmH5uhaQVGcGEaoDwYcXS5KkDk6FPh0kIYeXODsodcArHSNn532aWgS0OIVrEDqIPbl0S9J4zqyJs9ZwVuzlqo/89pNNBQsghMp4i2tyjUVKM7cIX60uH+6e7S54KpQyyEM0JMRoiM6DVzLJwTmEtuJl1WcEl3mmP+QTLdl3RBTvrVYRc5hyg45lsftKIw88fjilbXK5hToKKSTkYBaQjaNSEVsDiVS9Vrh2/Fzbk7BoSePeXVfOnrQ/yqTSldajaRXB0uAQF2FTcB2LRJePUYnzaZjaskObgj9FBgvA45dRUhm8+PqfStL13HoT+FP850i0HZa3/5LwSWl3VNtYXyEF+TVgLw44z+8X/QdnYNPNxUB5Qjf4zNqfaj/6PLxXz64QaXRw/EXHdjhgjtH+eP7pNXwpcDMFe2MVKxr5nj49fBKiNMbEbJPh+AIdbgVbCeMvG12dT95PuoYG0tfDwSy/rDw8bQKHZs0E2pb0+HtQ7z5eZWHLvzYp25GdLuBSec+xGorfUxA0hWHncNBEPKchq5iwsz70W843Ox3W++dV0RCxoXn5F6OzPX48S00KOYJu6ghzQE3RmMMUOGSGWmyyLSOQGqTqW42bzxp1zqP7FEBbB5X1pZvnm55R9X2P5V84Z5yNuWwYHOs6RYvLvLbtmM3Vsl0mgTNy/LJ9N52tV8VBbVlJdLwpfYbFD4+KF3E3hjZ4q+Wtl7CbgVcqmen+PQ7vPUqA3vyLFwITzDSEsF6o8XUzv/iOcrnr4IaxfF0BdpTsaz19xewsBha5POZ30OxlEWz7mY17/zmUI4Oy2KJZasOfAj17M5HjdWn3D6s3a9H1BVsVcjekA+FvaMSUDnGaoXWFMeCVvFw3MH98SxZTv4bF5/HB+uOI/3+o1O5Gnd6x1vvtD48xDf7iwW40frvDD4oTPmCyta70JPkCbh+VCebpifNK8fMtx4Le/TPV5JXu5vc0sHMDnnd+k83Njmt9pC4ltN6HMgz0V1Dh3xxaFSSJrmnLCQMMqO8V6em+iS2+9ctjK+MaLppR48i+5zFRvbeADowxOHbiy1oc9YJxfrIvzeagggD0BuYsUFViqnSVve97a9+4JgvuDmRz1PfDhO9m41GMvmmz5zHR4h/zIHBgixE8IJXfkw/JFLI9m2GAD20lPds78gxS3sTTEU+vUBls3RTpuiHlXcWfGCEBNqAjdQQvRqn37VtPqvRY6NMzsHmGAXZmSuo0sHFiO0CpyV5/BcFtMj5vwzPpDFrCsJ9pYXp0yBd3WIPv77Ysd/eg7Wt8f7sz/0D6eLXMK5Nw6Gj8QkL7neb9m3pIZdXwQ4byPyq938RMnIza5YBDa9aFLuIsqvrnh2qgjOZePJZWXoQQ93R7H4oJd3SikcKrGYcRTd8XnhGg7HOGXMVLzWn9atkdqT5Ly4kmz44RBUJEpw8KwWI8rDizOsDpw/UaS/0cWiqNgwvlTieZF+VrWkekQw3GOFgUfzTqeovqSfGF6xP7NTgJFGa6+6nehcfXnjLCmR56fkGmfma+EuH81LrPkh4nM3974+xzdMtgBcurNDiwtf5Dkh82jHR8TxD5/hovuUFtl3f9CJyTVjQejrzK2ous0vR+QmNwuLSrw8+KNWhILu2TxU+GIh7ZKSAFQA7gLyw7Arzq1MjR605FeM29a4rJYv51Px1huAvjlJbCgzNSaj6ibGWEVKuKWyt5Nully8WHrdtjM5MfwBgcDqGK4P1NSPiHM+5ww/oZB+QldzzQ32Q4RsRPAtllABtKd9yNxYCiFhg8K4jwxzd2CCrMd5JZi8eErdLAQ1WyidCp2q3MNTrSL2CwX8SiQF7PcoYd3HfgfyZHH57MLKmB/N18eKZKX947ybADSrJbUGa14682WPE33i6PfinAv/ruXkLmztri7ZlHTuNiGMWTZ+kFKaqR+mFVFkr9TZuFKA6NoqEWlVMJIazu/6PD9IpbSBnSWiZLNNyiERxHLbT87R/J4M8aepqUH2tRX5bOseMYgHly/YE1weyE8SNs9XmHLO5mEuqmi9FlBaeE/88M+tLgrGkZ5PBtUR2ehAPz2/edALLwK3EltH9dUd7XvBPPtN3AF9ley6kxM/fXQjV+adja5lZAXuLTA9QXnRp0urs5emjpeyEXEBoLEjG/2gaJT3C+3B50Fft0lm+WLFnLZiEa4dDnPS3W6l291k7rrRaDMapTZ+Rmr8+ph/nGJjbG1dxuDCBuCnDPPJcV1dGHzwop8mfwO/46//eJdniJsXMvQLWOPBvC2BciDVFhYebrveSfkrfm4WRia6vczpJgiC79dynKgr6/ijEC4rhOHpjV7Tb9tm9iQi6jsrdHjo64Rprj8GYrNoou4kZn5ZQGcQydF8S7A/MvE4PfO05vItXc5ORxqyoGDTQUiAzk0vHOWvV7RMS/MszxneXajDF5MvabIWtAaGGrcVYMAycLZy7iT4V4hGXDC9F7E0q728LtQomka5aozeZ7CMP2ILhn+rEeHAk/I+R22aaJyMtc3kmTA4lvRFi4N55vgTfMN46L+18NzPRh8wPmcOU3y1impgFuFnuM5BjWI04xsNR8nPto1GK1e2jj7BPEvEdLWdr+W2fYbqNcX68YYhD1ffHGCIDk4vn6Y0lKuEcWtkayAnz4v102e2491ShL9AULrGrq9foMU3m9lOzbGHM01XXh90fBubEHmNUPerNr57mZF7ixd8Z12w07m5uSGSmKgo2ogeDULc7JtrEANtKXNk2Mp3W49HPTIIHdI/fmX6a0wBtDNz5cU3m4ppTJ+r9PZTUIMTy1z8CCU+uaA/5+/svxHRBd6aIZwSh8lxMLFuDfanrZVaCFhIR8fO1yrD2dBhEmPIfivtX+rekL31ytYdkkzYAxZ+netJPHFqQT5Mq/bODn70y//J/KuOp2v66xPXXdjo/FmlZkOcV+gfnI/fmLFdrFr5DZZhtmDiksy31V1kz3cbC6ZY7L0CnXj0AX6WUD1+Y7GFM8S1z13l7J5YnzJ/cfRWPSiue2DDbdlpw0NYNbVuD9ucjC49qM6IqucrwYUlizkIagkZDdc4RQjhWxvbDfvUBqbCVeeX/5UxEAdkS0kB7ew9jTFph9mhgVzdQf8n7kw+yyMkFo+Qcy8mCk7cP0FUTzCrAP0IELaH6Vefr/TnvdxJKtvFVpwf5+LF+qTnJUe/VekczCRzFJ1XOyfglJyf1zCjCBz3za86m2rbrfxcK3OO0r1/BYbxfFnRYmzbEKXcUnjuKu+12jXry78OmU03SXpOqfToPue3HvzMUBtgNS3ipNPG6yYrD80vORcjQ7jYFUZIHPrUqxIXZhwMW41FPeKPpxxqLtjgymeE0mQLWrOxuL1lVTDo/+N4Sjcot231vGVr15OWZcQf3+bH/vNt9FHqBwdN49zklYjEWpqj9SKjtijygBkK/fi55XxWDmC1ZNf/zDJjoa99+3DpgJOAn7b2V8FZpXuGxOMNGTYzQd4XLMaMuMk3jy9+JMhyhbyXLIYmRkNTiK6cBuot64tL/udTkm4ONEUuRTSe0VkqVRy4qGx2F2O/YqTumul/2qgMURfzfp2JfEcPSISxd+LwbbllaBJbM4D6UGeONFkNfnI8q/E40veC3tGNtL0GOXe0ASvdusVi2cPoPcS50gaBlNGq+6/gjXZtpfvgEH77X8zr5UFuQOabn+PaNYIO4fCvdC2seJXPIz2SvhlHOosVgj4Ohp18MekUL06J2gFi7M5T6Xe6kP8vLZufnGJ+8l3/fHxqYaDeV+zi3PLTsgQ+gbTRuhAwLz/jtAtrTrujbMyBd5RF7CbghREwRo25V0CvOfIO8+bQGg9v/+yuNLtrXQDZad7mo31ciI2x3ZsQwo5z5Lof/w83AHpc3RcRyFoq+PwgrZDj7Fe5ydv//sXf7StNgwHFE6AS9LklYUb8wQYDknB6cGEJ6PYueopEiJThcvA/61Jhe3v4CZ7c1IHz43ltZG908rdTfA0vyllLAYfJ2nCcANaLAXk99TwNzDwd2p7OTHSlXg7SL7mNUbD5//l/tEBfaMta/X+3Zfa4NNiTE6oMqhy2H2s2Fz+EsYqGJO0nBQNxrN9PH8r8gOWO124Yzyg+zM7K47NK9MvrcA6iPFyc6D5xHe6K2Sj+7FwZE4VfmIfhVHxfvUtvQuP49Nb5AT/Kk8z+GxdV+Wb3I+fhFjcML8mLwfRypF90+p9jF+BV67DP17cIPxURrKZPLJUsFdKQcvbhNWIfXThTZeF6y3uxeLAuDY4PfWticI9uICH+Kwdlz3R947lZQwC8uzdvEsT17MSQgTZ7pa42w/zYdRaXd8m1symvVHGAnyHu9MG4GZe8TTaHqmhC1nNUzwNxliL9PRizY/WXjzQXw2T6SZWyDK+mMLrCXJL592bFevEdAm/8LrYP1jr+6e9R9prF/YW3dn7Z7i9s0Ngs6Vr+/BFEuXen7mdbBmrzLfY/+GVs+LcGJDgia31er3pgfzQGXXw/RHZL9GQfAoTZmtXP5i1aih9nup9gtHMZentH9yJqYCUVYu94JjjsH9RMIN5WgteXRZuMPAnxLbKzJZLeoHDxd0X81ttZ24rQyz60P8OgzsTGzt+K1RpOrAPUiukWS9F+TD7prlzvCB7wqL0oxiOXvvIJJ35y3eQDGsyajGf+sppzg6imn2DiNhFtLao2tjb1dTf+cbxVFfjr81kivq5R2HWF2uyvt0Gwj+Dpz1gDM1GPKOk7E2hmHFKfiXm//JTPv73j/uDWmWa1Cj8BYOLG8UcjvOIAOEy6Cie7QmK6PD3N9ulSc3hXvwBI4z0/hfR4tKNu8iY/t6prn44+QVinTtiwDuy6eZnD9oxwxWWYkvphq3p6mdq1l2zZv403/rOTFaS76s9NbzzGhtqge/MUMysEdzY3127UdGoI56tdXqw4Lnd2hr3uzLKy0mV9+x0IgdDf5iy3/S39YWKO6j8x+T5Hd3xqy+ds0OuFS4iLe2+P9NzuqGf/+k77rlY23r7iAQZXBQH36ylpHFnrEi5t4VZResSqTcV6SPA9a//GdRSIinI45T9+n/OL11bja3Vvl9Z1QM80KRpLWUDa3m8SPI7ZsGCIFsxP7hi8GCyByfTaclJELrHw26QVpNSnVITghPVlJQInWkXHPvNcXMfPAE1RLHhx8UlEa/xcOPZ6ujbsG6lc/3ZFBWAVeuJ8I1Gr0dVMwTOOYzbmMQrrMYvepGh9UUgrWqx18Usv/ahWZ8fTz3biw5xWnOH+bM/wv8SP3Jge+Y8SjQHb5yd8UomKlJM5lOHUj+B8Zev0Z7HDy1nxqjH9Xu2CHtfyTxLH/H4K4tBaXfDyVruJPd7PepLO97zGqy3yVnBcDl3Ne2EXuS9tNAbnZz13d1dfIZsLNeBhMbyvoipO4yYdhHtO9sirdlzFe2/t735h2NWrtNz0Hld9EGwRu3ZyCpU1N4FWF1lNb0DoMEfHVc4IoH1zgMcgFrOjSeRWRZJbdrKGXNzrB24B+PsnVqvshPbXdvgvPHDelX0GUHgFs+y96+y3VtTYDORmYd0Fh5pQMk+snxxgsE1ydnoPxmExOsyu2SZDgfS/uI05/riTnJMLR4Dth/B1T/xhi9clSRG6XbHUs1zwM2zGEGhX4+7RlZJ5Qo1ukxTQHA3MvT8IjH1pFNtKcNpXoG4OtPGDkBqYpv/gW0OnOhtGsvtcgaZO8uLRbY2TD4C9q9XmxhGI6ZYj8G+HVklgxXr6Uv4mcZp09/P8RX8tC+mWHNLFLufxTvAZnlRXxzHA1vkDp/5iTvzVjoWX9y/wen5mmutm49UFvCbl8vRV4kWJXi5Ad8oDfS/a6vAU0oQ8YDZiVHDooe5EUzSyVMIk8LylqoCVY7yf1/5nL2q1dZX8mH0t+Hk6uY4T2b1ZlHgYN0EH5N8l8TaqCzjbNqEtmmLTlg6RtMRa4nIgNsz4OLgxEUehneyq0M6SwbYH/xR2CDh/xF0M8kx3qttAPS1IKwLmcZf9gsjFt+tm++LjjKfF9/HtpeGlmYDQXHmZb6WbsPa+qvQhfsoVO7L+l0L/EfSsiop+rnil6Q5JBlfUFhXGxRDv2NXXq/PpV4OMEBnWgpwnI3PD+ZT/2e4829kpuYQ/SsZvyUQ9jE4ELxhtLAeN5Onchqgg2Golz2JLqLZUXV7zuyUha9MhLIVqL6mv3adLepQpameoC/ml+gMeHrbxRoyh/BB8Nkj1iq2Zsahfq9v14GutOSrxpGvjfbh1tlgN5Noox53IYJ9y55/Dn/1PLDiRUd1v+hvr+X/qLrA0rw8OoNP2lWB8rddalT8b+I/Pb7Kz33odWp3AzN8l+4hWp1Vs/tP8wDvWtI39OJTMxQeYWVgT6RYlVHLNMg3w+vgGuoXCWULHN38PVU0wfhziKwVYO5OzEgOK46fNYzj0VGALUqzNpeub7fUda6/EGzk5eC7hPtiaXbxiMV/24QbPYqa3OW9OAOebU/TirE93n5EZxFtEI/B2hdoAwcrbu+40MTfljsTql08mpoijySJosusnS6nOb72d+/pQc+44x6gjCkiPDPjgzrN3UyinOFiGltvQ0HH65IbEx/BqLapnL9CL005t0adwvA74kTgZu5MMPMADp/spX7UtQtL0VlmzDtk3FfQKCvEAqRzx4M5VBhPQLJny51BxhSHn2yTN1jpKBkwz+GfNcQEpvBhFJHzBZsBhbR70MiZfLIzbIh8tfcf6f1aclYF74X8cO4eG5k2B54OaxcNEL5XlK/SxbC6wuaGQr9FGGJxU/xt94DdezWb65kCrQub8SQ/DJ5N0PCK/zdFHEsknouGt089AND2c81TeCP43bqHKPTg7PzFdiMiq4BSHhsu6foI6Ap0ai2tDf3LS17PLKSZl2R3vh8OxWJ8TGo/9xufswb/YZ+MZfPNtsIyzuX68h8W4EIVcPGJnj4zLyASf7771BqnP3pHTb4VuU4s0X5i55IqxAMXZKaj5JMQ5veUpkTYWlL4L78qHw/kkrh4jxh1+X4nvDCkgOPzscL+0L6UJ6t06rkWkjKF+PfN7lCAYC5vO3LX2f+2Co9/f8Y7KEZ9YdnV2dVERovajS9cO0YyyI1QY8H2Q8RsJx+fZ3jVTUN9d21uB8sxeszLBd3U4nsiOwj7qsp2X4/S0txCbzkpBd1HqN3qr9Jpe5eifHzpwVvx7Z7TdfQ05f5uhWYAD5R8Q6DNTa2VYWdI3I1/naPazp0/tisfdqjjyXjrDiq8Wk/l5oyGt2Ory4dTEq9G5tKvsgmz4Drr6fHTJFDm3L9a4AEopmXSuz9EiTZCSnBjku6WI6uJJLfbZrRZVHnF2+qTfSoLGGEb9PbYA5yo/ubrxp/+bjynLYTQJvl18PEPOyo3RHFb/2SswmvQpD6tMe1rXw3ofTqlscn1sf/LYfwT1Rb+AZtEqebFFtpjdTF8U9Z4vBrey6IE1iB72vxbF1kHrEk7vyLfXL+JxGScK7V266nmy9GL0snAuv1/yAPHPsLk5uFa2SbWZOr/4Ozrq6t3cjXXQlwGuUjdeRm24fpA597fS9YsIeX9qrXhEyAeHfv1S+Xa9nKmmwUTozef2wvwoh5O+jvIGLoOuLzjvW5g3X95Rrhga+aeUvBXEfU7OtiifOwNGvZJYLNz4n2PxH6yvHLkDYbh7GGZ80mrLgJ6HFPeLhQnTpZRCUHef9Cx5ggwtUi6+Bkf61D+xzl/2t28sOtmlNJvO9AuIAeky8p8pUd/bcOfAoFlaTpBGPi067VefZFzc6JuZVrhctDvx6sL6IB4xE+NDHp4Pc5HOJ6Btkjtr14Sqpe9igCgn82S5fmvS5g2Db46TuUa2lAwBQFjTkpRQ0S7XUaofh+OvJlsk76z24RaWxOPPMzE+fefPgXguhjg0fkC645rIpV7tnhyl0Iehu/GHQwCIHzgWMEVBcIkv7eeQeD/d1zmKx3kFUatIj1VMyrxPIcxmxeriqH44FNE/ltOJOL1cZ0mPPoptbNiA2RXyw07x7aL6s1atW/kUwOEySZdMdjHqtoQSj75rHQ7XGo634W1fWVTZsh9wbhNCJ1PT4w6RmYTw9dmnTrw0ldX3ytLCfci8VaDHZ9cgZz/m34R8fLJ7yih7NLvsEhnJ4pmPL8xxfjBBqh+tWwVy+UV2O09x9/WBwJwURV58Bz+n2C5Mw4rSyvgBOHod6I9qI+OfjUckA67yG48IjPlqvH/MXqGV0QB9SE4yQqU079AsXcLPKZWJZava2DYkqoFvoyApNBNdFTIr41nN2H6cDsX7y/J+2Gf/LBnBx6sXsoswnXKtvOvUnzxJCsIBw0vUTfXDqmq2YYZ84Sbq88b4NjQc6xgHVLBm9UqxT0CcXcXBFhsjv35aPseFUR9nAo1ENlq5cJ5sF0wL4sWxFEIWj0a1syiYcT25S+PTnv0PkV71azOryqQNoq90DJop87m+uKEW53C/HQXaWJ2rwRPIg23myKIa1/riHGNnTfeQae2g6ZFs6PH4H1/zgf5mINyD5WLZG4sXkkyqm+F6L243mZ96QOHkFn9P8zxf6rXhJoiem+Pj1pdGG3elcLlt1brXje0gylNiA9n+tXMir382N/GuMIdh26Tmohi8jkCCM5keeTcdjLTRowqbPLQ2QvoGK70iD9PTlXSxKgUSCMURSBEeEdr1IxnP4zOAbhMFx2tnzv5D7VhbbkbY4+B+XeOWRJe3Ug0E8DBgoYan00H7FSFDSC2+rxOHfTgTYMZ8uy5CxlE7SDIZAa95R3fudfObAWNFY7IAU2d4d8VszgbwZkUDXT4b667uyd6FUHLPV/w5MnY7EnTsYwde4qxFiZ58EJMQz8OPJ/yvYB3OGafrP06Ga6bsT/b2WVoY9lLL4HBVvqQR+JB7hhpcqR7+cT5jPSlb1HZZVDURDn1G3PFwSN8G9uptPIYYgpU0u3Ov7enLl756VkDU1Ztx8SN6XAtmTPOX0YB3HI/8wxm3RJ4/32QnmU+1KTllm9Ok//NAfI/vAm4F3wHR9O0a0X4Y47IeJf6YR3aiYY1i6+3r62D4fj119B/dj/ny/uFdJqI3B7rFAsHW5E2r4zFNF16M8vloeSk3vOOOt8NhuXa9YB53tncRzaf+uhssKWW75eIOIl/eSWwFu4cVUw51UjiSEwFw8XKTpLdqHBFLYzd6e8qM16hHYFVTKJksn2P1E3zrGX+ALDkc80iH+fQZ9q03zpt7bXivD5GfDrnZLOkWq28Xu3hRt5uacem8y6McELERGodlvKooNMuI2FguMQPlDmh5/UhOOZG8066+hqTpuf7pHw4xDuDyhlkdZ4bfqh1eXdLiOx/TgV0szotlECqCw64dR9pZKTpDr+7XV4Fqlhkz7DcHqJ+bavZCxF2zL6XnM03T221XSqMC4q4150kM6qffhzu4Km71FyeDqTcr6c6nclm9+Gy37Jb/4MlfIC7TlsAL7YNRc8LjLgLxMOTDRBeYkvEe9rwnH36hB3K1gW9O7BskoDg9y3V0Q/5GHTbOifMRGb1POB/dqLZCIj+NzLZ3NobTr2gNP3pU4lPZObjd12SSIl90phPoErzx9SUIX4nf3O+cHFJUx/c8bKzcQMLpT07H+nSc3W6ZghaLeLECuLFLIdb3IWx6vD315V/QX6xxy/+u0G2ECboEpej3NI+LfFtumHuHWQweuno5+9ZX3451a7vtJ4ExeXnjVb3LziXQ2A9SeNPnVd7YuOTzDa08BmSH0boC6PcC4WeTDPI1eWtsv0cZCj27lr4MiU0NPHTm0M0hIRcLIt9G62hf9xAzIx3tLblfKEEzW214CjA6B1azgBUXkB+C+SuRr/U3G9+glBjEt7MsMTyZWAM1xxXj8814OGSeKduzGyqlxoXnyco9zKqPqRu/X/hLg/pI6g8sD/pOu8NMbpy3cpa4/ELvsHO24Y3SWrYkwQizdHB44tMAjtnOhq7iWhrK7uA2vJYKQ+P94HTBiFVxuahRNlcJGVQGVNN+z8AursPf+HmQ2SkwTzl/dPJiLKZYC0CvMzaXnhuEQpes/S0rY0BeTPXCVELselt5xC9mWXJF5/XDI//ZHv6nzBK+alsM7W2d3yAJ1uknjOs52SCj6sNi/242cGIipINXHUXbZ3DK0CsDE/OdHb/6lC6BNt0M3DyUidefH+jNfr443s/j/Y67JPUhh085IPZHf9J3f5OOsdgnC8VchSdylGwBgtqI2EsWc1+4yMvYBfJ8dLPkmL++A4c1sU5at5fozLE/68YvReP5QRvEfxMzFPFRnG3wZ8/gKqSPbq2aAnOh83bv/ElY4+xGOW++IPiljBbGuv/2VCj/QgcZ/wwv3axNAV0+OODSZHtpoIfEvxYEjaH6s0OdZzMptmyS3PU4tFlak/H8Wrtpg/E9bAgPD0qB/OfrDfVzugqJqkh+yuV0docrJWxC+AlxLxCEdP8PN+lMCWbRcbSTP8nfQNlLQaWemXpOreoPVJxhqsBrr1F13833Kiwk6uP0Bb3GaY9Gxa15fDEid8npwsM+EFnwcBkWVJb6/QQC6hzG8Fw5NJpWbmsEm1bd06DL+T50EcqPmX0A9C2gk7i2s7FV2POVa7F0nILFh9WCQvHsZVkO9loccll7BTWjsO3c2kzwpCk/h0OV/1sPKZ/LO7+hfop/Zc6vOkOMq7PjF4fyb2P1NVb70oqPw7MY18M5oyYpx2Yg29AIiSPO/I0j3vPjRry8xM2nem0MoP66c0F/fAm3QgmgVcMlsryyw/T8cW5zdR167UHgPyX0rebukRDLAdy36jlwYvqC6DJD5zwWU1Wd/FZzcboysN1dowuNAEwPUwOZgTGZl0LzTOys0THnpaJiC9PExJhMLEPs34JIlFOVwLaapClSCRXrmX6yXGnnrxiiHDPhYIv4r/ar/iuVpnV2AiWpXVfD90cwdaTPXRmD/cT/tHvyR6cHN6Of8vEpMrB0wovC2SNYpFMo52mzotUIhEUWX5LTQidy7w3ULzn9C9R+G38z896jbobVavD1+nE61r4/Uk/E4vJPt5th6xKeg+5ANOScSS/Ti17BdB5FDlsYZL0Pa772j2fIszh3MaCoJlbMdmlsIB5/p9rFAP6RRiDSWQgpwcd59ZVv0sWd7cke0WECejj+zSdrvXl7Mz2UVdgLwhvv7HHs/z1esD9dvf7Df84oqucDQOX3fCMearP09SW0NXOwxi8Sr2YE/Yh7P/W12/Or6cL/TAXqmDy/uMbPON7pUad3I0oOOJtbcyrd6N4GOd5dEc0tXN5XIVcVTn8sz72NVtWdnAuWPpMgtf8C2PHFxO7Z2KW+NwQynMGYc9BVvbHAAMV/038iP2RyPmDbPvOWhe716nV8G2m8xWv8qAyhzbvZX7xJRWLHf1erYxei98PEzeiG9tRJRa+3xtxayuhBNXdaqY+9ENNYRarmzZ0fkUkQpgPCrJXaosiXSMHG8lb3mYSU+zfTwNFv6gE3OtGM7hjW4oC5uNssF98yR0fHFN/sJPfLJ2OqZBbOOHQ1Th3YL1RF3iXrhxz4NdTjEqTw2uu5VhT3gOPly7hpIRpzC35QTs6s0ayJTeYnNr1Qu06dTn0W1/vtItlGpu5jTifNBI2m9Oikf8Aizm42Zn65h93hxfYyHgNIOoUVj4OjO+E+zUEGkD+UX2ua1t1xZIXxuKrbkRURMe6tjSPbfFVrfX5yGGVTs2U7AccgBlyf0R4ZL+NUp//2C0NsBK2mi2GcieUEsP5tWBdUG5R0zqE8/njmsA1Q/JOnPb2yXQnDb2z/4QWEQRCfY+vR5lhQ0yvHsJ9PX5yb4cXFJAmRm45/sZC+Mgmzb3ryrTxRR/peRY/fGru3crJxri+RrjTRaX2dM7bPHagmcmnm55JdNDkMo1j4DDDZQIGt8LW244JBPz/iokOs6j9WHlVDL7HdDHFmY9C4zyGDAuJ6deOzMTJwjUs4Ot1YD+OWwhR3SysQ4WyzLOQbt5vabzcWq2PO62Z6Dj4c6T6ltXgYkUwxPbvnEFWV+BDaGVJXwej4RyigVGHNFPvBtW8kkExAbwV0yNPWUnHomKffcmvCeAgVCv6rbe0g1OeQ2QsjCK3aLE3rxYNMpMPXmii42hgQ/ozvwZbV4tl6+HLKY875fI45x3NxqP6oXqw/dMX05Azk2+w4cLRIXty3eL4lzEaccDwfd/kne4IQOShvh7Sf+fWJie4qoJpvdRfZYsnwYMo3f0+qYv2dXg7PdrVs5IGn06lLk188npWdbTgPyMV35hg+8W1oCtw4tH3P6Td2RSp/POOXT5vbJzLY54ZgGQ1/fcbvahN/yxXM6vBWa1znp3gWdv4lJR6y5nsdu25cTN77nHWx7sI5302Z77p9m509yXsLcgHeHSn6RJz/A2ev8sUt0lhPv3dujorXQIQxfq957uqCjQuQ36MYlhLfVXEbg5xIPIbzBCBHCJTZ51tvwnxXjj7IuLugMPh1K2+1Wla+dZHHT0sF6Sx2OLgVEI0Mt95GohObm10yTa/4mlA7hOFf2diAYbYKF+EH/8qjibYqTqmbeyRK35yEoSCcRRhvhowe3/EIp7sC2V1u5QfaWW0XLa3pF8NbZvPgUZ41Os8dgnEoY/ATo9dqdWYojaM0PDtYtRM61PzFVqGda9rLOgJA2yTkO4ecsm1OyaMzZDgw1McdGl1YjyqO7SfKSkwD78FcL9Rq6PoqILDEz0FWisWeGi77Rtia04TR1l/SxTfQcHnRZlgNoqg4Zn/jA4we6at3AjHrPOrhMIrgdMfxLmyx2d352Ub1QyZGnSul+WDgMmS4Z3M7THJtfaq/jeuDR7gNVP3X5rupaqP8Ntr/4sDVuPUpFxxtpjr79JFZe2Q9CbwzCG/s/uRX3YRfaL5n+mLbOG/IEnAj2k1XnNKw5Wir3I0K2/v2JR/I924ODD829X2WydgVaQ4ezNkmD72Z12fUJMlxTzruUE7CzGQiDCif3/5cq8JYz1B+auE/YeSlRVYM/Q69UESy87mBGXhMIiBxvxSaj6bDhRwmnKBzVTWXVs4W4FO/iApL/5cBsbw7MleWrS8vru/4Vcj+T9IgbLRV0goIoEmNDTE3NM7CZOwPe74nGqfLVaNNmIpXTbstSWbO4B5eNpw6+ULkYGprDo4zFxNyNDqW0T5Yyf1iQiXQJ4LxcbavyxN8cgMGVcO8q9cY96P41sEXZmW2zpC6SqI8Z8WOfrVafs/GPIa9MwrXy/iQtelxRj7EVpP9F6+lmAUY8fl6sY49RBz0Dvwi/+Jjxf6ABgH2w+1MNLhZB8b0nCNkm6n8v+DeBSrVtz3PM30vLEqfZlTz/JscEsdq2hDOwhx+f47pydS6esb1A0vxrJ9cdsIko39LuOWmv0Ho2T87HThG+WSKtlKVfX1t83z+Tq4eUPvacc79B5eSD+gAVnfVxUwVdj35hY0qP59MK9Tu8jE1J6flW2AyuEpReHcYtxAk8iTbxGrKLLf55WNUSQ0ivRPvQnDH34JAgxVj/pliELyto1xr4rj/CgI9ThHq2rjh9Y6ApqkBd5db5AwExy/G4PuAwhtO4OfMsts8wWjlezsta6hPJ0Ho5N7nHgvj9w3v3KGwBf6v7u5if9Plxzi6JznL2VY2q7NYKrz9QywMdQAAQABJREFUTYkFKMv5ssjOzC2pmfjysBy1w1KDD0/huhrTqD/uiZgo6nvVOuvLR8cRfcYr1OYV7ckHa6CJJNfeJGi3WUW1x0AoLGsxAnFWw4r/0SR8lfP91OIQQMYZT5Lj429jSzDO62LzI0Apro1n2GZKbn7M4YfD0POmfuswxnBoVld0M3sbbIJkXhvoBDyh3Zr50LnCBWH4uVykd/wUH/vF6jDVAR6u3FAU7cPI854A34aFCLmZcYxs/oxZHmXPLpn47IdLFxZ//40/7MNo79PWt+Cc3T/4Xcj5Uv7hevzERiI/4/AGy99NZFfr80l1lZDLyo2quHWCwvur9Met2BalmydqAJsBetXMjBHZ/2xeU2CHpCR2FWp4Kml1vVZMN5MfmWPs09EhVrdX1W4JDyaBa87GW2+OQO7aDPX+iV7T014yGlAaQrSPTQsfd92InqOqIa3Q57MNQz9+GeSOm88XD2cfbwi9ff6DwYSK36wO94DqBdE8m8HZPtltZMyw68CAejYjZ5blyaWxgJ57crCallTbHsUZQA3AXt91D5ipGuxijq1ozh16cIIwleXT4mXkt+TdjRrGEHrJ/zvLoNAW5HH2uXJmj/vZFeoszPDjW9wL/VEW2626L49M5CNIe852XR5qbv3YS/5w5/JjIN9WKJv1qOJ7i/zlbFWNc8TzVSy+gENuuRbP+s/PhfeGYNbe2eAq9Q/gR2cmV5wXx9M9fxJ+pgpq8y0fo3lg5QxmM7yqp07O4OWsJv2WT6OHUZMPjtu8jheDYRz/1LnZblV+9Odb+w+HMgYvzjbX7H7wPh7PxgZhnLOlUm6uyFJ9dFws1MTNT/yuHpXtTH7dqHSpinNTheqwELZjhbMo+tq5k92mTryOB5jIuXXsazrU86ng5J1QEYs1smly/Kf1VDzHkTvv3UyXdugCqQ+V/0aPtqUvqZFdeF0Z2v14WJmRjY+/HhTsuPvrOmfwrBzuijAImmMP3OvSeBt+/hKrzIDTz76rW9WT2S1dFe0pmx4Iu4vMIzNnjj/MKO1vtSh3hPzMg2cYtSmOpestePNiDABxsWDAPlt5lXa2Y8Mof3S9QP1noEMFDfs8mVvYIymexyMNAkPTUtL0+ngtHbAUzSQawZyYpOT2ESS6Xaw66vm/OIsFpDBbpk02W5x8CLIdsJg+cZ1Mo3B0unNlbOmk2fhiEY/cGMpRh7RHI14HQrL4gb3uXTunPz51P9sbn9f4PDj+8J5B2M9hFh97Oi0BsMY77foM2sjEWp/Onz4bjzJtxHkA8V1O3w0xHtT9OhKV+NhhIf7LMT/qf8fMtxuGvX7yObyebxPs9X8xDPs3A2YMxk9s3RGaD052U8aCijsUyAjkdCOcvZNvTBjzmMw7xSYWKnMDrMBwiiMb+koev6r0HR3FVYw31cmG8VrBGqzw1tAc5FdezHm6mQodhs8o/cQBNffKrnpKDuq0JpGdIaHzZUUQpy4sP8YsHJ1L71dKQUvE3htPyg14grurbEoFTfuNnLGlV28stWJoLopRWXZAdN9YAU/SKWE1D4P856VU5Kb5CfCQm954VGPmzx300t00guPjDlmOSnbuCfKizvlsJakXa2HuEDnllJu+/yqJVFseLa7l8kIx0Xd/r4wAefixA9ParGoMTwXwvKEzbjJ7PE79CLi7YpW0TMNnjnTyRsYUIGR4SXeXt7P+tVBmVlwaG2uaBZEYo3aLSjSj2Q8jeDh5uMPIphzlEGTqnrTrzOE1FbXTXkxPeqpKlfEHS+cze0eSk/nSWxe3MOSp7NsjCJdPqT3ZBwfC5QzsVvJsL64uLfvqPeyxs31ztY7qj3tnxvLy02ajf/uPC91HHufpRMml7GHq53I+fuIfTt5yOt5igYq34d4wpJObcZsegXvVOz+G6Tbz5s2tR/961PZqEA/g+0/B4GRzZS3EfR+QakSMyEbc5Ph2n2Wi6YIEM7XrCi8VfroAN8/Axn1HuXch9m9Okv6H+15D9WAaCfHH2cc2AW8sq44QxEZlL776HEhEilrWboY+Dmeedr2okw/6e18/JcWxrAB1vuESphzjMBJKdSUUez4qD0l5Brq7SHr0aQ9vHnIl1a86ngsZAaIO4cQKBXEbi79YPmuB6VExTYePUd7ixUzntlg8yJ7+ozPmyQLhEn+mS7uTeoQuE2upVMni4lh/cTVaTrGOh+6nzRqWJCpm8zDJ4xaAHoGp1sxthsGv+7/3My2zyvhZuASwvD6kc31O2oB1pq/O5uf4npy2HU85rqmV1D4B/y9DuIzqHtGKUlZEU42Gmj8qL3D14R7mv2QCxH82KvHKrlBxZPNZ3q5gSVv1LrfsPfvDpbANELx2CB7Hx07be86+D8py7NjPCuPPXn64MGC4vr7yB8+Tf/xGczGEb/kUE7NofJkXrZ8dyuWdZXUz6PD5CiO8ePxutMvGoVd84bnD2vMKV7CRghDFGXBX+mqAQG2orOfkWaV+GPRQFVRWm5hjb6n7q+KM+Vrb35dkJ9k/tiZWhk0kXr1zG68beu6VzYvsr5Kq/ObcC7d/pw04705L/YtMoJ8+7DI29WXhBW9rGpHq7ESeVs7JrGKhcx5SEgefU6VW1OtVahK4WfpgLSJBZnoe82OfVNb/zl5BrB5Gt1l9cebDOA8fqUsnHkZF7E1yXq2NXUqxroTPVm61455ebwvVMfFx9ENc4rmdNV94Me6qe/aYfdruxsbzQwx+vi7zBQBgNZj5J+4M33pQNz79fOzPY7SuI7Pn8ZOvuJSfvb21yW7BnRaNubn0VLsGroU2JkryOIyoMH+C7BfjsE5vZop/Ay+iJxtOAJzaHDYJg2mUL25DDHNn9cmmlmUb3vmNk8jfBpheHUbbgOSzf+dPHCDxKcanTl2d4h7XbL5jYQ9/JsX64ZYm3+BenAA//j++xxNEm7Ob300Ff7er6S62XXrDEXR3gpe/y/7Zj4qcCMg4bE+n4NP/X+Str0CZzf7iutJnr7YXX8kymq8wzykDdndFLTvPbJiWyQuMUWuNHo/WsEBdck/cdwymfmRdmFpKZ2JesdsJgIjbpjdiiQDf3WQklVGfYG+D7NeCEBnI/Dx/jE8sudM4/QlH+GyGFWA+TQO9KBB4ru92va45GsVV56SaVBBBRGl/9v71YzeyX3/55ZT9i2Od40+4WB6i2UBkTPe+YfHk8sU6GycL8faSi0P+1dsjrRyAoX/cUQmjQzNJVfpZDqOYNsQEzCEBKMASbXaMDUKwp3PyfCl+bMoeVJbpVH8iqa9OP+UG6uE21u5JAP7WluPTei4n/Z5vuW0/MZMge8IEIid44s/5JXEIJ8qIf4iL0U1KCu1muyvpCcwj3QEaQ/J4nIu3sairLxe83ppppufwDNq4bvzsdh6nV7HPn7zqH1aen/3hzoexnv5hxjVOg/mOjfYb1+wYPxlnr043GmxUo2PB0zuM03Z9AQ0DitDgowfnoHFMjodxqRrTtInD7eAY5VsQMxO8Juepo3hyzvyHZt287L9ymBY//OqQs5EZd3WkZrD++nofxflJvdjbFSNnfKCJRSDrjvS+0Q6OpMuYP6bB/x6+oL1xlCSbzvQI4CXUv4t+8gHzn0WXhT2tdzDcT7PL0wdfAJVtuQmYvN5tj+/yVWZMhnDWDOnR5pEs+rM9ChdoU+vnJrYXQiazS36HeE+XgXh3HM6LQeX8t6nwojRixHbM4ZG4G7X6jMkmF2rFm0f6t98q1EdIfVybOM7N/QSGtHwfFnmt6c2J8T6ttNUBjLLKoMkBzn0MireoHQqYcaW4/ldjaT5eFK8hqmLmhCRXHYatG/LZzmw5ra/VNiE5sLjauoyKF9iz9my2jS+eF5bnpwvBWCrjfrGb7xfnW2R9Hybs1QThbKfTrlpx9suMi4A3bF895mDmy/+pUN43dh0wLI7+F0P51Z/84bJB4Y964955XMNNLnZ60C8Oyqfcd5K+l8S4XxXSDmduAdp87x6zY4fhwnzvDMIYq3Ecn/HcI19Ok27GR+f6Fm1LW+dZnXL4h8N8cU7r6NuD1FGYj7TQSSv2lowgtrAz5Fd32tjuN+x0jwnK/SLj96JwUSF2N9KJ1bUkOvJ4Xcz3YuEmScukKs+h/GLTkvQf/4DoKzwkbtDB6JdFO+zJ3knLrDnbfX0vAqs4cXJzNgDmL7/zDcbNQeeiVNXP5ewAtgwk4+kJlB8ue2FViLe6XGb6qQaDerSmy9WRBEupkR8HEBdu4WOJjX84+tVMP9qcMkZt1MtnagE4MJwPJQxoBZqtff+e3WzSA5tTWQXzMIezjeszPD5JaYk7YJtgnlMi8cL0323L5c9nIzr3Y5v+oWK9WJO9ejLwV3CtgXbvmftFIrzyV+1wOc/3KyxXc7ZuknI426Lepl6kF9jXNdgmYuAuarqG+fCvn0Q5gq0k+nTU55mO9G1CyuFNTt+z8veC5zjb5I8T2XHFIZ9jlt7G9ven3D5+1Iv7yZOdvskNfW/zRRzX79j5Lqf8XCwZPl080BA1cq8EOk3Xy4u0ESJNScez/lTQzFVAJ4GTTp7ldE4Fpk1cNkzg6pTBrJ5+JJtkjVyQnPQ7oENmuotwfX8VnHpt8QxVvz+KoS1srGajV94QPi+s+1Zcyr11Hty3y60g/SLyP9ai2xJsE23IgbYdlwxNM/5i3cWvO2x9p650+++qERSbWEYFSN2ubGOV0rYdm86N5dLeAhVnZGgz7dRsiaLSbXzyaG7lEfB6SAkleg9s+RcFbT6uDVXyfafOQa2wVI+Q41RZZDec0v3LIC/fWza5NLeVIxoDNKwGBR1BMTyhXI/7cPq3K3s99Ib47lvtX65xz2xogVELcmbPVhez03gZzkOw/GSSZxEbPeQkT/Y9F9/btc5KU2NyGkU+qlkpNC5P5MX5rfGnf2NNn7F4Hrd8tUk5GceGYlrNjH/TK/9iWl5OjHg50TmL2dg/ucrJn2wC9YLVbZM014dZ3vkT3lPf6Bnoo03w4d0kn0wM/eJJ9vpP7li8PE/2zj94De98ff1dLCZF1cch3+RKnY3FbbSO1V/MjMQ6tn10h1FgPWra0Alvb4+b6ycXwJNJN2fBNxz+2aQE9DgzYdVkM6hvvRH/3pB4R+nLwCm60PxDvUn8Kso/CsEmdHo9hr3rzDGv4e3UV03xZTNgmwDWN6LTcomPmCKrLPY+m6RqdLk9CJxXenRzMTuycHfYVaJh6iUvLsVVHpilLBjr0U6bSStmRhW81ZEf/e9ZBfeCgGguNaZHK6btJvLjV6u0nn5uABCpbDuqHsN10RNefgpvc5hWfApi9mVaFD51W3iCvp3USr53iMdrBYw4Ow9rjqNnqNfQJ/tEcYCH+1hIA0Gn45OsjcY6PbvbeB7E89fmYsr3Y1Z7IM9fx3Cjc0z9VkcBi/0Uy6E4xtORwyef+hmdbJqbuGTfPnYM9mP/PZXctNNrdYs77myIoc0EV16ryhwDn7zx5IiGARj2jcUg0HZvyc823GE/3FHH/Tax3XWe/Hjk96lPN8NvjM8X8p+xHVbc49V6PFPGZ1eMvGfjuHw5fGXTq0D7m5zh/xjP/mYXkmwE0uRU4Okp6juedCfXqbi3IQrqjvKzGWWRFfPmEjNBv/XeekvjgeadXwtMD6TrVQR3rx064bdiuNly2TPCS3gxLna+74pdzeKPAs1KByi64Ivk3Q0++bxxxHcbya7Cr2EA41rWEur0N3v9IDMWw8yk80VnX3un87V5MM/IggupHAO9z20bBdhGMGx2srg5+PoyhODDXm9hjfdhVgZHaTVaI8wn8aXMR6FzahM6gjtlI16XZZTxGIpt0i9u0CJ008m2UTOAu7aihXXler4scZ+UyKFwa+WsF3eOABZLhvUSX4QPku+jmMwjPhZToh0+AjsvGnANl+Vn3rNYDr/P9jNdPMa/HMbYeN7aGOwmYz2YmUc9uwns7IKnL89hW0kMdn644wH49NoY29uAGqt//ACnn7+3WT372Y3v9/5ief6/eHwx6OfiS5ds8X6x5uTzuAiEbuMw1xfzbIbdWLRyW3L9ydBjvPaTfTAIaM9OsJIXQ8rs6yEf3lG9H7qtnrP30y4W6Ys7az+P/H0ZZSLllhn/vyqLMl5viQy5sb8W+m+3kb7LJH7b3SkaKl/2+u56a5IzptGEMwwE/sky3NQv6Kq7K8edVrdeEdkSrlVK/C4T8b69v89CF2Z5CdbuIzKDNjxjtHFCXZqeDe9t3+tnKsU4xNKIe943LkYwFctvusNow3MV1GjjSmA/lHIQbjFrniXXZ0xyyIKgODZK/0LNx1t5QsVMecYJJkXyfKUcf/EskgHCPCyDh/1suAaXEFr1AxwOkQTIrI2V+blJpks9jqCPw7ztG22deo6K+zt6gu/0BvpxMCY/s9xrqIo5eSkr4dJM3nTjr+lRsQg+eWmr749/8pdnsgVcJAhkVKmuzajhD/zTHc6p0+aWXOeNo7mP5IkU4Dgn91J4OP18Nz775zv5uB/Gt+766gueT2xfm5aSvh4GLrqfDTP9G3smjn7s89TunRl+7OLg8OGibA7CKORhPsqW11emOpVxCbmnnfoe6HUyv6aEUYRvPKMwwmmP9zMoJpm6+r7cGp3uY8f4XQZPta9arAAGLBluL13+bJKXmcSCtyqJsw3DjDP5k1/nWxarqj7bJPcbPwjvr6+yGWCEtjtR5MWrX9kv6+MQtkzd+LzjXXB+ZNjvaT71M13uSnvQufaqufJOCIb22Zy0WdSc+6BUNY3QjJjndgdF8s++8/N/OVQ57Nr9NIvb8pS5pf2t8UsCsMlZBKfbZi8U31DB8vSFlNMq5GGW8H8k+tIAgauak34NMQjHsOc3hnwAim2oRXxxp5m2VO0aGhyF6FlSAvWVdU6ZzC/45ItrnozrO55MPslt8lSaHZUn0uYUnMNnc/gPwau+2JG6odQ44YkfqXZ2oNoV47nM6YixhU95qxVdm0bFVb/nNi362pK/ty72k8eCDh7HybFb/3yrE4etX460+TUW55fM6LT54JSPn9Pv/ezAn7+H8xc2itfPNJ9/zn8zlsOm5vkuT+TL43ILo8PffRpdduLzP3ycJxv/4pocBU3f86/l9alvskHgvo56jfD//Dj8aG/Rv3yIfavnAPusTHMLzTqgJGBd1HGOaWtKXu4oKZ9vpPm48k/+bXZe0T95VFbYZc3//dNsxcaWZxIGyokdDEeV1C882CD5fyAM6jKLoUuj0HSJoRPWV93GEpEfVBq4Sxh4bg2qh1eWRLbucOvQv4SeLjH30/FHBubsjghu2KhMPOp+3yR12H8nuVow6tIBd3EZUvYSusDk0rFFse/A7tk55ulP+nThYUy6qi6ZMmJiOlPnJdjbBnn1BO9ng5u6m3+7s/6U5Xl5fh3bjIx5Xkp6v77d78cAw15wWmSpta1IxBfWVltd7jX9siCMcb4FnvkQLDrYrBGs5RIcavTiPi2jicHZeUtEiOla54yuJg5X1ZFML/i/5bPV2uccb6SPZJA9vecuh3TIAaUTQ6e46GxzYV0ch+P4PId9+If9ysNCHN/ZddcZr3htn93O+eMw2+PCe2MO/sjh+H2JMx7j/6mjr+TFefn+9DcdCnVx609ezgp/2CpkiH5nMY5f3Rw92cM6/sjrM8pug4d3Vchb+/1EXFtSGbo+WKG7auwzy4cvbgm6TBHepRbnj4OfUfrl7i1MvHpVunmeBy4YGrLzsrig/9Wf94FYV56kwAqcG8wy8xJQ7SbKmf8bog2V6vJL2zh1MxOqfwzHdOH9GMypydBewg0me/osL3XUEsLc+YwP/3ic1vc33TQYOj/mYFjH0sb3OIt5/guaMVHlKVvpryl9Tq2N+kNq4041IlH540xB6MYYX0VlOLJbjVKNTw+L057ytY+f2HbRdsd3F2FiLDcHcCDQtpCeL10gT0NfsVUrGEPntbW0UCy9w44JpFGeISO7POJbfDsmfDrjuLKEPbmWrbZnojIuNROeaIqOeR99yo0ToF9VFtNcogdnjiHt87SvvKc6OsUS9vpiMNxGM9nDxXc2j8er7F1pw83mp/z1h1sMkxkXeIKQ7+mN6av/KRe7PL426C/mOC7HOF7/5WTuTwbYeL9+1b2aiFp/5//qH4c6gdXwBz4x8vTJ7b+RXPd8slN5UmfjhYBFyCq+33VmMNU2mlDUyAXzW1PRKgLddfJDy20kamfXOznPfeg0ag2/QQKUW0EXLndgXT3v8nB6EnHarxRlHwEbJN8WL7aWjNl05WcU67x5I8JPnj1uxerjtVM7POMfnXVFL6xRhSW/2k7mvW0h8NnRv88ikx7/lTnO+iir8oo3Hwr4WKHoNKb9FvX0SM+4ebIWSTq/VdMkpToivb2qUDZfyzZGfk5ccG5RtveiVj/J9cCW0oXw6mclep1qfufzh+djkHsXdoINC75NCmJDdvM1xSvdLbg5bP5/fMMl9NHIma2dnE+zYxF2UU93EP0Ez0DLBE7LJHcc6OuL8TTixerF7rNrVA7mkbnnntbwcHdWbnMO7Lohvelr0zm79PS/m5r1nN/v5jb+7Djoy83sp238yrN9fJ5ff7px/o6b74f7afNiX25x4/f7i+6Tl7t55+tqQs7FefFwSi9Gq9/Hz2Yc0wUcTrzCa+O4VfBTzpzpMyOw1fsZuUmG3cVhLmvfK5KriI20Lcgtz9u9lPPEWvwEsbXx3nobHVDgfXkidVcVY366IXxj74MSc0hGDNiCMeouhv3hENf9x92nl5+ZoPQnVyVidC9jQ/BXcdTvEOR48vUVB/qpn0m3cM+eV5neZs/Br/319lWYNAjCF4kR0a1QjQjBVyZiqWSns8rZEHLy3fVdtVGpPtevCOJOiq9ypZhIFMb7DBTdtnc7jxxCM7jvwlYLjTPf65fAiZJ/dbi0BCpvZooc/NLX3xleLOrFl99Hd1kI/dH9RPwo0P3Yd+PxTYRsMwN4WAWP7nU+y+RAxd0MnFGn9U35kb308wH+e8cIw5luE4uxIO2pOvX6DOLi8DjVdwcm9vTx00/+bGBwQxLkpta/kMlmm5ZL422M5unTDalNTNvX1z7uwzMQm+1vmMc7HSZwHJZ+n2ueH/lcup7z9/iMT/mdXZdyND4Mp9mIkYfDT5l8Fg9p/OptX/nZae/zsAcb7uSchvG4xwQMzk3r6OLzn1J0u3egbOWw6avDFt6324baXze6FXhADbruHK/19yjN+P2FoDYA3nZ2ifhrPyj3d5IuHZ31y0FEhkhf9SRvszAmP75EIdbL0DBIA87VTkUfoQ7h3tzG1D+d1l6zZkqcDFoqo+MU/1fTb5elpmDsh/LbH0YOHPerS9ztvrEa+fVl04ehIC8e5er9P85xm1xYYFhUa/Na9hto6D99xLokRfk0Hjue/X1VtV+epKJeAoAA88yujUbDjSsHGjbySjNPmZvGypXjRb5Ajgs76+Db6vmHFif5yUZ7AxW1MN7ryAQIlfMMUejwTRBPXPpglLres9k5kvTifsrWV/azvehFx2stINdvz1gW889NbLF40cImMMH5bDwbvXrFeQGKG2fSyQto8rc5bsMZ7WRyfDcLOZ68L1Jw0Dg/32+pjc11Ll+bJbHUP5lzKubp0YJTJm4xaqd8G+/643123/z6VzzHx6nK7a+c0z9OuS1Cv7u5rhWaP+RT6zFYdnE9rHNTTHPwaiYGzdmvvxzo33ymDHXcRujDuTt+LTHof92yJ29Te/0EKj5xuOL5JUaL+ZpGtRO57k3IdiK/9abaaIiyP/Zgv7tDXDjb9FmKZjQ63pqaOM2xqvRyA+JABH6+V0OlWSOBeNWx4wXKNcrAjwltrNUXvss2vhwoBehey5gLGHfFFNcv/pWpgZIKq2aqrn7BI94JR10OxudHrEgb32cZCZ4sOwZZLmiPhkEi7nGuPI7bcFAU2yrsBo1OSUfSiufooPHiToZcXsugzBTGNc9pH+CwszSO8e1OTTOX4fg0scVJIOWpFsWVPr/hjic3HN62pr18xeaB5nwly/B44Z9nAT0wmseM3uH8ODy6aX7Ii4HxmJ3l4zm/GWRsFJeVXdpOxuJgc1ORUWwDGWr6bwy+Axve0/LzorW9C1tyNw1di/AsRnzn32TTPfxnI8tm34fOXts93/jd/X25v5jxzd/j7Jtx4lwcv3MNv7g/eJIPa24vF/rPL6LuJDubEyDr9fiNE3Fx1y1+RauJerHq9Dksg6e39/SJZ2c3fLLMOsSD7bt+jNm+cp8dEOjqDe22PCea3DygUX73RYah5Qfd2hPtekCO+pz4rbf31+DbsXzLHFDUwsnEDHobDLR7enQq3Pu665Sv5YbZvS+sGOCNo9R06lhT7AyG3cb9faA7G/5s0ODY/kn0R9/vmkhWY7kJ4GINadgh5kcPonS6MjkYYZeZYUvU3eOgIgp5vkGzQ4dREe/Oxm5ImquS1328fsP001wI4lVB2WcjjhTYHtFnnDDV68n9geHpSjIhUfgRq59l66U45PJzZ8ugIdLynvZkSLVTK64agrLO/qQ7+7IDyWM8z06OZuy5+XBDK/MnpsJg/EkErb5tul7/51HZ7AfSdPbPTvmzMOZd3Ld9qwCuP5fyWxJb7FrOtkuhvpjgcdrPDt3bOKfv4vvIxi1W2+neebrDp6MPUPlPvP09jeF7J/eREbQ2/a4k2N3pPZ7FPU76GL1432eNz664yK7L+fk09xcPOro/YlkfSJh0hxHY766Ax2r5nA7R8DOMc7IEoNR/MY2RNV2nE9R8avL/b+4MFxzJbSPsu13n/R84t5f6vgJIanZ9thP/CEdqkkChALJJqNXSzEzBhmI1RiwJy+CnN7KuTYm94PrQplNjqLqul6w+/MiXKeEijUnqrmC46QRrInQkCTXCLELA3YWcBfieS0z+Cvpv+W4lCz5kEAHIky+P06Ado90RBcIRrshZESn6wG+w+mR108cfMYxPoD6850fm6B1at9VgbZcWP0obAFwMyvQgzRxOBWIMOj8MHY8IJwaHkANMxugY167zKsfEoGkwRIJnJkuOeHKKCiYqLTgviBRT22BWdqtf4jNFhBcLsRHyU9ooaEGNnCYiG+VRJSoaYBw+CrwoOlzsMZ9Tl2Rdee1od2WKI0A9pkaQ8rK3/Ug0KurYp8G4ROXQdStVZKtoH5BxHEpYRnYgu7lHI2f5CddkE9UmO2TQdfOGHUwOraPLeJkL4qI+iev09woOjrXbpIhNZSSf9WlSjc/83tvlDTk/8qe9vvRrvNgTB/XGVM7GNDp4Mi3ladwxmSvL8sLpz+FLD97gqKNsXNNXNDLaAIzFJky1e+tRUcmLTW1pFa9y2tV1XdvOYWuXQTNV1op7MCt2AcMCuMthyNthTOzE6ir73r0Wikl+s637TpaNmjM0jiZqZ4yVakzqCXxj5D1pPCX84JmaOGImN6C1q0U5iJsWwYCzjdAyDpVW562BgK512/3yX8QNlSGBSUCOG6n3IyPbcEySh2caGy/d/U9r2C6OhrqJ0H5PmBt4case4eYi1Ek1kIswFjCZuP1QmKuzQm6yE79mMW0YsA6RdHnlDAk6x4+WMjpPDtTpE7ETwzECZOCQszEkRk4fBRLmRhjaJsBKRpe4iwUlAw2t7UekZY1sOz1gWKFTVHPI8/KlM5SF4svFVv7FJkZMt0zIht4N33iUD3bx+waDpEFpIosXcBF1s9NGNv1pkyB7ZVVdMRdX/Nvf9st3ZU1m9PNkpAz1+K2cfhNqde2je/tpx5Y5cxxR9q125PnBnq0aKvsbJ1wR1SYNOYkha0Isem0uBgtlg4OA2FuHbPCpaIqltTzIirE17VkzUbFG5QOXsvjT/pC5eMNNxCi6NnfvrQwW2iyttmdfiFfIv/CCJrheIsDFSw+S2OQQH34Qbt+PxcPITAGK2nuaeEqXX3vkbOxO0HPk7FjfkuO0kwJ57ZFNgTf2OOcu3wSB0kD2U2lGTTgtb2edh4PYDyLXZnn72dmqEG4gb942bu3KyULZSX0cEnpIjmbdwPi0H3/iq6olvuEmpFWmX2VrqZq+nEayCWV811dkx2kM6Mqb2GCugV6cSyD+AZNiyxgNnIKREJGxaf11cRlGsCzWnHDUOK1dCdOOf+cbrvQiF3IjylJZGR4p4RtyNuQWr/+nv+dPzuAV50CNzHEgX+4I63f0YyOWtgRjl/YmufJVea4O9VGfmzTxB4dvX8NnIjmyzpFJJwew/koD+GQtrxCPrFd7YqMHa3KMYGVNlvjKzMORePY3dzgX6qNgV9UWff3KEYNvWBlvdcjLFYao7A8XcseXudxYi408QNpwsUJJ4NgipLKd1nJGJF4I69IGUig6RtvILcW4tuhHXs7UdBLTDGXQVh4SigUIdF0zkw1cF0RcR+d4KCuBwB0AyZR+mONoRTPksP9oPBmDH+ZEz20/HXCvkpmbT3z+xh/mjSb3DLUBZSTeLNMLynhG4xAnTio/gMEWjoxGaFpcqUyUWLUQhUMkLIsqDmBTb/8ZIEJu0R11QecIvbfwOBXusJ1qWJezBB0Acb9JUqcAGjHdPBsp47Pj4jhhVVQVZ5L5idu0LCYMpnhxSGcewPS0r5JYEhMKRF+m4sQqPAdwQtvAVnuFgmYcoz9BE0JHBfSIx7HnLtJFMEvGo6/IXbGxCh7mchUDH/1Z1drVuwrU2nlmNKmWoy1p07JOBDN3JFn1Obj6ShPZzFf6s6rFKZdzY+wmLl1tGCdxWEOeDgvfvu3oYgAvdvv0qo2xKy8HPCbZwa0ukLEP7uWKH/liSITnK0WvLxPp8BPP0dXW2JYnOny+V5swnxeMiSMQ/VrjOf0+t11uhFGpMxmMXURYqet8FQSWsjaD0F65itouUJscrBV+aatjTRtzPwdwcQHuvmXet4Bj6Uk49WxH392tKvcouXcY9qxkfhpApsqoeR/NCudWppuAF9hoSFk44CySDPDTK0z3Q3pNP2hSOFv1GIXJMT2QbtKcKy5s/0gILIMUomgLt9OOWxN0PStX0wg54Re6xrJxUIWUhiuDOj1GjLuWg4iGCeDYt7GEu0lIDvW1AtUgozHJtxdbZxUUtm5gOxyYRcJBYd9Dens6Kjw6NaAlO/Oc4L3XqTyH4JmL7TY2vQxvMV0ygIt8E5nGemIOwHN8/BcwppFH7dwMFCtXRYI8cxuMXC/v4amGFft5Hm/cgwhHW/CCnZ7tousHub4Hhyv6TWp1bJIUVBvItIuazQQ7K/LUwdqnBpMaPLLiUqexyQkdH56sn8rTPwlssa9seMduuawf7sNFfPgfHXNCLPuhzSZoZOpmTAc/41w7cYwYzhxOPeNlwMqxG85UclPXT/qjTwWbWNprC0AMQgq+WEor3HZVnlpUW8RNh3PB6qSIyQEZ3fxGzaroKtwDPZVpqPFwHbs9I8uqzO8UMmN+os0QA3KtkkDiinuBRpTLRq4QM0remSOa/xuTlvepANaZ14VxwWpwuwRCiSW/Vx2S+Og2d9r4cIWv6/BlTXFgCSXx7Bjpr64jM6VXSsD4GoxABstj7qF1/53N7OzAubzYNJNpzcHRSMmcgJ16/UQU2lKJJ/Vo0KPjpVkZvgj9uKRD4UNy77nSVtA415/3NvLCxGvTTHFR+Ccm7MYHihSphx/VJrERFTRkBxscLMXUFe3bqpmeUNhA1gaxeBURieqIa99Fy1WyXAQ0OiwZ5nGMILgOh86WtneYQ6HyZ1Rt6gvfYxuxrTEwyQ4h08py5QzRlj+H3oGa9R77TQLW8IWryaQ2yFmJxfWt9uqpmyCxg3ueAWtnH9v7NhzcflrNOD5xT1+OJwb6M476T+KMrGNuzPp3DJXDzdQs3hhHf7GNPWHB3nkCIy62g0dPqfwTh1B5IbYhKrZC2lWkGjK3+GszkMVSs84P/gvWbkDiR0d1+m4Seo2ll4LVs/2/Sw6c1MM6SVbw2zWsV7x63eMn1tJnMSWx5umHHIg0OhUSviWPaadOz9klM90nSYLEHfr82fD2ECpmYoByxcduyhcXA03Te6INtlhBUTFLSkqQ7BOnHb5uEAPgCRPPbiO2sLGi1yJd26nlLYGWQNlRrYOKVDXaluI8qmMuhIfb2UJF6tMQigiQIc4zioanrB05eoIGBTa6EMPNHC0Judd5i6Q6AD8XdYhDQwgyjNC2srScYoBK6/d0q+/5NiJvZTizUcFLocKaI6iemPIpzoGNZtEOXSQxxPbwDN/K0VZUduLgyr029dMNXKTysYGzuNZNLrGFg7nOIgSj3OSDrNyuZnF9q2qiSb/y2IydNe08sUW/V5mV7VUnmDf5XZvFR20832MoFzOUS0Z9MEdplL842jFpkkQHHtnjBz32K6POQ+zOY/Vjix8w1mnTWvzYRuUYBYETOza2c6AeAHqa4qa9WvYCcc9qKKhwkBbs1BPolJVlBSRcklgxWwO7aDqzR1HMGq1Fj7lHmcSYq0pgOMvkTCKM17P54mm+Y8n64WozKItLZ5MfKyokTMBuVNq+EQu+ty0BMHSLg2DTSOfirCK8EeKMqDJOunl63YKfRhuduByqrziG/k02ovDjANSwlM/4AzGhTCwlh6V+9Mt+hpoYHFqajtjxodt5MICgKNqoSBxBShWA/tXDNrjUtnFBccyRYD+K8K1WjskyYl1GJ3Zg83afl0TC03lvH3QS8Us5lGlnbOAyL0rxm1IZ43ZEkRiQGCEz+AlTNUuB9SodHHl2od+5gtd3AQPqzMp45yixeGZm0pyBGaduCTeNCcH2Joa41LG6BqqI8MFQrl3b+FIXBb7w3qvM+miy6NUefvUVKj+gifEm1ftWt/PwfnCDHXhs+4wdfiau2tLPKo+QZe5VKDb2g49APD7H1qtFesRD/GNLsv/mWmc8cD1jmT5y5j+w2KMfTOadmXIO0lA+sQeijvSzeqPBIAU98wmINg3mVLvFyCBkMIMFp2Ht4dFk7FkOFHf14eJ0N250gWqDOuPLKptsRBqLrJ9JDG/6FGTr6672OkCeREn4cc/a3QiZMQpZqXFHQNNogxNPd0y4Ci2wowrEt+p9W20eVR/t71kqbhAEXPVhwbDz9ju9DbLOoosWSPnTMrTAJwTV2BsB9VhqhbC2Dbbo48cugwiGmACBp6mhNXAUdb7QGBmK8uhrQ++nckOK8WjLF9+coRQTB3HgLMVTS3vPYGeA7K5jBrq8+PbsGBC3MZhPWS6P4xoxKrGdD3nso6c38m1GvKd8VIRRJDHDl3LPXnSxvfLqEXTS0iDogHQ71vjVc7jZ9BQ2O/KIxp/djBfAzkKa6Y+Jjt30hZoEiNI5jgxu/PqMFXP3JgliBGMSEbeYta1+cRDB5WbRNvoQwAlHuUhi+FxdfYqJYWMaLC8S8C2X9fTFgpu35fJPf/j1wZhIqszBsd925wpdE11n0xh2LqIMnX5iXg65kHe8Rw5QXeJo0/mol/KQiIERS9dBgcpWjmhw1YJPi6UyxHQp7dcDKwQ1NYX22jG+LJ5VofY8AEa4fJybJVhbsC35FUnfEdOrlVeTDKYZhiuRKOxGwro8BRQiDP31HHQRYDFAd5Ow8MMz5uavOoSu9y5pPfSNYONqHjzqNMzWGBspAr3u1SuXwGyuiQ/ylo1h+6kbLfG01E34WD/8fzXPCvETVENKBgs1Y0NSiyDbtAuexv1AZ/VE6ulMlVuzfsumN32z/JfDzFs+WBIEmhRPSJjjnqGrbCjV5zjIDUsrxEuOEXYAw7GDkmrdoB2F6wG4ZXymjVoa5A2kFbrELx/HAa3bairssngwi8ceg4RYuxeDQ+Tl2Jphu5+ADpzNTwHDnJFgEK2+bcY0+vG/uE0e+zYUFD7Qq5ua/kmEyqoHU2x90O9b6chDVP29EvSKEJso1k4MfpFhg39tXx9wtc9y7RfTK2Ns9UNNHMg7J/ZnPtbfTEH9RRfkwces7cjgod+amdl2GtgkjnNOvuBFYDCN00x/29uAX5iHo12186Gfq1KXc4b4IbTXQ7AP/MgO4kPp/8xBlVDIdaxg2AXFhzOArzSya8wL0ucyB4n4oMUz9UxMt4G2PSAeLiDokzx2m5U2Pf3HovY9Bu8lF7UkHCxInIWdxUg3ScZF+PjcFQjDmpgYGDxT24SN3cp0z0jkVS4+B3ctkjFVjptT4HKaqFEooEonAXSWiAM69I3KQeT1iG9InbsFo9eZi21s4OZUXPrrC+HIHbn+ubJksJYx27lAs6oLMPAgTT7qS+wUCZ8xJArGUu1M3OlHunP86WLwDmPCooLlAk8rDeOQrv7YzJYFWXPYuCY5LGPwaH1miQoPH8utyWI91x764tPHVvtgw9FEknp4YINjkxtYMOcPUky/mPCG5F6lto0OG98uU0//+MIvP7G9b81rs5j98viJMXHJE3L48zhJz34OygKqfv0Gi//gaVB3/Mhqgx2tg5t+bdBdm2Lbj3h0re1DMnIbtCOqdCUr+xn7rhrGsQUO1msSlNLM09kEYNaO+q/KQ8lficigTYLMHgkQdYT5oJuv/jAlpAnOcjTuayaPT2pNRsBIrlxgufW4zyXCEctGNEQ14ZoU/cs62dJejAo9B9xBkp9YcVcH7lGnxo2D7A24KgTgLcUKQRyaiHFM0kBBJRiadNseI/UrQRkMKM1cLc5WGToj1WFzywQfoXLPYlq4E8TQbvEVx9uDCZeaCRw14TENjXWE8GRcag5VugyX02gDrJjBMQcFnyHztj6Q40u97r2QZnyOJKYEdHHYtccxDhLPrB2wV42CXVpQ5PVXPuyKLRdqxzsER+8uvP5pCQl+z8GYuLnrLBKEISQJNX7spo+zCJGbEODUZOqj++yzGqD1qjCG9DZhoeNUtz/yCOBfGZi9oiTB3U+5a2vS1ab94g3VcZAs6yN1iBl/+9T7LP7I0yBm9NYMXduLiyq68UlLP62xaZ+6HJVdPcTVDDY2lBcvRpwaupatjyBS5mz7R7+iEbijp81asUw/c5tt5a4x9lVTL9+kgVd127v4piZR9toL63xn3O2kMoJMihvFG2XlYOAW1cxaMMHnSMdNw0lIjPagksPbZvawREp+7iBwWkupbUPFrhcJuMmRtJ0YME3JAecUZnaadI/3jxeTjubA1tZhxN1L5WhysMSjw8ReNzM69GMkHjAzgXRNJSCeTpPdJqNyBQn54LUKpXedoaYNK5xDmZ5N5YTNYPEABqw+9NdehPj3fcDhAHTRtEhivS3dDWgCNzaiq6E4LJ0sZJJj3agi+nAh5Nqfxbn20cNFwjAad4hk3dhD5ulNmzHik6rzxkuplqPDf+dCTJZQV1FHgA0c9OBUquxJEsi1G5vhMClNG24TT2zh5wl3ryZ7BQi/yYs6HTBNdMSA3dqmlhd5cavr1WKxbXeumlB7GdHf1gnm+Il/ecLn6Vl+5q26+m98+BRnjGNDPOG785U2/X2OHgE4NPIMF53TVx8EpymFsZ3NAB7SKTS3Gwal6nuKj87GAF+b5TEmUgbK8bs6zb4YuRwXQC3o1t+5YHMAXcuOrZcl7MVME0c+H5A4R113a4Zmwk+j2RET2SetpR3Rs8WZ1qaJEJEI/wiFIk5t6ZigHRtsMVdnm5ZJM0djzpG6pms2HrGoAiMG74VY/izbiqEH04kKQH5iu1FrIy4ygeCCoYu1a6IhCJtDo27HwIw4aEoEtBxr2os1MP5APFfsgXECkLVtpGPYWWLo8xBDRE4XXuTtX3PK9op3guZ1hgDyygVF2tcPVLVXNsriNRK7GwOWz6LDitY/HBBM33YQ9Tl4J8L5dLwOHJaCTkwGGzFUE7ptLo9YPZTG2s2oW8FVLoaEh8S30AHZzoENzORoF+kmisrLrW780d77ktiRDK0jR/dxtRjnTX7lJ5Ymz5XXPzKTIHxiNr7pv74ZB7yMRZ+fXBtLdY0nMOMgvsY44wro6BgHOPjBbf22o3eurIdjZRjbLo/dEMGlHN342L4OXQ4DAnOUw+96QNiC/kMUQbxExI4cezAkjEmaco79VnAwR29B9hb/QCPTawLorPRlSodCe/nCWabEYfYic2SPSOnbwZt5YKGTSc7Kj7mppXpnjohIYqVI23f123MiFI67CJpBNMDfQOHhqpV66Nt2zhqWqiYefGPacdQIM+lsTHIqGQBbJiE644omGy7/6iKSGO48DaZG6RgTRjMZ6xqcQWAuCAnnIMkSqw6QSd+h7looZ7DhbFzY50kynPhIkNDJDBvYnQ2mwDZaZ6OfXc3puDOgYanDdH9PW1boo5v2w8hmYHGojp1Lw96Fe3bAWYYjVRcY2sQ13GiLAHBNVCOKK8QmtqMOR+ScI7RU4PU7R/ErT004i2vSqg1tsOj6DMvKYqSOWj+DC5APVl5ZrwaXK3Vsyo3t2g+fXG1vUrYOL1jajiY1N6nobszEyFjbx59IZdVVtvMFNo88GVfbO96IHSt6bEWlJgaMEDEXo2q/KhSgBmPz6FdRu/p1VYKvWTkBpj8izUZ0cBXencDKK+/lOoZP4ysnqq+y/G7iLGB+S5FPAYhy2dk7fvlxzTIQb1sawqC6/MeSPTvm8HI1MzchKy03HOm79Z1pDye8pG2iaLEBHA95bqJ1MxtHcewG5wjc7s5lwR5xNckiZJabTUYt0ZhOrqhfZFkFmBsYXDseaP1HaS+JgCcxEEfGiJhmxyLrQ6NuF8e8cPUT8ZiAM8V1lXae5VpOQBE43c5tIo5FYzcW7BvEYHkJPAOd0OLoxAB6hgVsC02eyqDcQtu8HO3xVcMJQ2T5K0dgK0JqjtVsHWGM2YSjsM0I6SufkyKkxtAu/IwB1Xmm0WSBLD/26xPO7WMgrijb9JtAmuTePsmqV5aDebgXBz8JzgSV2kQa2Sal4tYHfBe/HNo6nkl28bN8G/ti6Vc24398H5uNE07wjmPmQ9nTXszg0sX62GFLsQ4ZddutP/VCsVa5uGO/tq/glSFPOZxu0y/+RlbkPWJzlu9pXP3byn9h5L13/tw3f0x9v9SXTd00FihsXY1psG8RRWiW49qFnen3IasZLOmSnyS9JJgdRsy4SvJMJAMnVRksKQjiSZruMdp1hv8YMpI80262anJtfkR3fXgJ4S6ODNPR7sZ208KmAju33WWQKlr0KPHvP+UIDofol5SOcXbEsLKttfTQpiaPP8wyepykxZHZKi3cO+V/fsv1248seVELuCHcOOI1VP6RJtwz7x3ghMJw1gODgCPfPqj77FZnJ2bJdPDktOKUmQHs6J5hSTDMchkzo5f4zkBP0AQcPkKT7zFGgh07ewote/JVXlnOO75+gUU/7mV5k4kTGADz2mcdnEQxY1sdeES4oU3d5Ias/fvW+asOfZ+bEItlide2nE2A+IRfHzmsrrK5Ig1mudJ0q+jDbYAuVnLUHuzlXR2yO56jx+PgU32208dPIPpce2rKwU9bmXDiqHCgB9tzNHogCwCfQre7ezpTYUdB/57n009jdmiXU1YzCzxlTbWV5CtHbA9oAanhpiRRslcJq1thwZH22iAq17pw7gXNxsH9sEyeyOhyaqFTXqbl0xy3fjOIuUk7DzcvoHaNgy1qoeKPbvBdRkqOcOO4Q2da/KJjZOPJhqCAK4OGFj6NPoJRKYOaIgYdnexEBkMxtvZ6BksrED4n4uH0uwT/nVn5npuv+SPGeQs6LKGNrdONvzokLRFi+mSnjNcYcvCRA/YAuBLnfm5E6xax1rKgmNJMp6HwEPBWGCJRjmfamPifx4gEtriQD0U5nTmDaLRKnZrqQVK214ATevyskCaFAdxzWJkwYhPjFKhQHlnPRkQZAwkkJL3PNZzKAua/FGEDHtXarwyhsjSwMQ7aUEdQPLrRq6vcZBckyY65FKMP9sXg89u4sH3jVOZfjOR8/8Zv6OIHf9y3xDZxZoWhjG0UJrrI8Q/X/mUg2+l7L3J0i9n4exVLjBMDOGKkn13cdnmx1T5RpqmOcVHoE5t12ojp44dSObwjYz2gj2Yg6jhoq1UP2FDKkdr9+thVLQAM1JS3DaclQuSuAap0ji592q99Fn2mQofR3CLHdN/2RdwWiTIPdh8OOXE4SY98x3hz8KqDDcwHDDM2YU7h2EfQb0cCiKxssNYbbGPMwNZTlRGUcGagUmej/zpwBFE3QMKjE3lCHBfDxVebWIl1EaHJQf61GbojezCBEB8qadPAlRw5AwpRgJnadg7ix/JPXtIRkOTgoMocaJJDfTAKM1+HA2x4eHVoexzFIBfvcZ9Bx1UM8mAbGUoP9adfmoSCXv8I8rSvEkBEu6oMjldNFsFOqWElQkyxbKEF0rUxkyAv8oNLK0JcrQwT1PBZJKqW5kXjF/u1rM6kImM4RleKWsub5lp1ckQoky/dJhjiwEf78o0tPH1GnwZ4kyj49LU5tt/YPWSohIxnMBB5SY6dZ6k8wOT2D2HBWe7xEXvj0GfbvTLMck5MG//eczxXkSEJbbmIAfdypWaU+EQ+GFpvPPa1AZ+faTs/+PVZeZq3zyRt/7Ff2anR0UkhLus9sIyU79lXffHoKjIulhBLQJpRHL1IEbWZnafJ004MBUEVeebG/vLQ2TYN1u33Jj+3LaJhSJMZIyRfkNjhnFKMWBD8JFS+PEk9jzqABqaAvZ9JL/gI3HZg4cnzhCPzSu1cDF2S9GTxIYssCp4IOGEljCzDYlUNAwNCVTV4MkIEDCfQq8MkMh6IUbSbxnAou8LDGeD5gAMOOqzwLQWSlGxxcjofuqCZoijHxId+F2F0m2CIh8gGTqBl5gXsw1cQxVY6BFS7UDs+vIVSbMj8k3kTAQQ8ouSuQx5NBOweHKP4l0pMgwM806uVxh42chHiALSHy0yEo2PdlMlWAJ5H2cBHELWrFN14IVxk0hze2oLxiT7tYsNEPwfqk4yCUJ5LNJIOnLm32PCSFFe2NVhO4eHRHjt+yyO6EIjJAR/wrW1r5LU/usO3OmzqB5vji7bjmXEt/45BmxkPMrA50Aq0z2m7DLEPhqJ+cRVpqw7987QzmLUTFxBrsdwDWDsI3iUx8kWh/uBdhXUNHZFAqEhXlBGUPB2wHa9bKt3MnwTEaimdTT/MsYWWzTDxp24SzIiwc5OT+LrpgsvDl05MeGL7eko3V0AEnUAE7HRzXbRxN6ZuAVczXH0Uo/+gcK2XxJOzCjNlB4VOe13iYB6OSy0AHzt1dipts7AeC9Un1DPGjmamYX0zPBZpg4k5q45Chc48o2RdIskP8xU8sxSs89Kxee4QkpKun+GtyUxhmLh6bvqvE4YPHwcf2AWnDAj9PVITTQr3J6k4FGuYLKDjIFf4XCyJKQz0lxLjulD+NCP/6AnbAa4GSGFI4imPKyu1WOYt80Xbp8L2SRzOn1UOBJydiS9V2ETMqfLKSdzK5OXSIPC2AdN+E1IET4KE633LnH7e08JPIjzfh+RESVx8+doODDcTU2M1vmT56jahVpe/IrSL4ze+YG18GRdDqx0xp4OA53DTWxm4Yiqjv3p1dFPEq1v8yLWvQsyAmW79pWYdjumtV1AasdO0wvavyvrCDwUP7KXjyQAqL2KPi5g1vxF9IWTbRiQ9jbz1hoA+yyUtdqurg+6GkZ2Ry8OTLNn5wVSrY9tjkIpHe2Cga2KLLNcnWkRxNi5ivU9tP21CyU+OoGsgrYdxMWCrYHj/bxm5lGFBrGgmaFDI6qNWDhlc9AvR7kxbdXSzExgCc+aQmBJtGCJXtemo35fjiEw5qCQIgiFuEQxoBdR8uNLExCjymHlvfD0L0fC2HNLYSkNkJAblTlU6MpxxnfEpCX4FwdHMBaanrWchoo52PjAauro04DSnjEV6iHjCh946bUs62kTOoK591dhRWD8tiT9tuitCY1uZwz86pv1YMhcfWNZ74pQs9bd8mmVb3CYzZWSdk1D0w6mfpLl1bBdD8vWHeI4AAByfSURBVPMZf8hWzje+evVYrIkVvgD4AUdC9SqWOvbfuNnJiU2y/J57nfJmLOXveM/b++BTPpKkOGMOP8l09PmrQns2ScPOWYdfzogszQoxGo4Rt4+z97lKZKcdvzLNIfJVUYPbNbFyg4xu5Viie/u0VzoRh6sMX7FC51C7dn7CsWxTdoNBx3vmnIr84V5WSzJgwvAz7ygjMVTOTkZJ5kzJb+2wSWnaaOJpny2UFh0btrhdnZuFOQ1lGFPoAYutjZ2dBr3py4Hrm4Pn1e2UTmj9EIdI7MZ6AkDHkCTt8YmrUxHxRgMwo0LCuDUUj6mNwSakxG0uUjI67y5kAeLOA/53yERyHGnQcNOUHlEowZD+qsz2EEpALf1cbce0CxxHwzM4witXFH09cjYdGf2Uxqj3Wq0Te5EHjIhYDop2T4mxOb8MMqi4jMykI1MOkThRbmpmgPOdH2Y3KyoHPORBYjhl/KqiXYg4AnH3A9amhmAUZdDqQx4vRiNBweqiTxjlJXm0jZPaZniiiSkSriYPRnz0TTprq6ljII69l1juYENI2w9lwuSHTN/DSxS8wDKfTxy089nfJEnqXo0Sx++/k8QXn3p/0MlB3XjCc65ywfUDqGubMzVjy4AyVyRix778TGgK5y1XxC5fVpX+I59ky1bJlMYILLa26AQzbWQrh2j7Y7YW4llrW7CnvzzKY7Rc9BfTuRBxDusHwfIio/1ybHt14G8pWl2WLLdLUhwGy602zHpweaThlqEOLm3WuRatPNsIYlwV8g1p23jIzLpZIwOpOcPthxYMuFlKxfTYjGDh422htfysHNmhi+T6bGuPq9EpSFPHaCXARXgf93iRdKbjT17V/bNx9VSH2DQG4KfcKYoosR8yfTpwfpeQla3XNHXtcgUTiGRMmMY7seDVTV1orgwC0GQEQaXF5cswyZK+yRPujpuWQVnnVOju6GZ+o0SEC/3mYCqi1lDXu4LYUlnEgjQCM8NgqfS0kS6EtIsnWXRUvnplQ6TfB/aLFJ9PkDtZzirYRJZzhXuGkz9qq147bOHhQEy2W7MKESjDA23rwQ0eHBiSH3oSBbImK64E2/aKEJ0+ZGLK0ueQIMGNve0c/h6VV5sxkne4yo3tPueK8+iJKT7yXH/E1PjqRx9I9Dt4MNxvnTEZpXbo8dUkGbPTTtMEmSpzwDx3iSHHhtIKtitDjp+/KmP+ydNlLSl619KQvO2Xd3lWdvpp7DpUN4RTHRGNcme9d3U5lnnrLUVHJ12G5QcoT2yc4JziH/mb6E55E053j1dUYY2sUxdv7gT9I+sEsnCh9F7nYISwtmcqiTw9vFDb3bMgEcOg1HXbHJGPjhHGRooBNJdEj9zYM4p08cyj3tLEV/rB1TkvyfTnqhG6jtPI0mPQSrPwxrAfcoHERSPtQOggVhq7qJcnDZpypZ6GQhwaV0fk2Eo0Q9SxBBKGp6ydx5pGYwaDOhLua+4L17hjwAZsWJ3fE11k+C0zQTZc9cZcS/p8zckAWDFwg+1FJyMmqLEui1d7cLDsdJNNWmKWnFdAEkTW+UiNnn6evcqJZmWgCD9kfh0HDNiapA0LP8j6Q3j9qczEFMmboNqODDs4rdunvVh16MU8CWxl+E+7zyTJtPfPoqWp3dUvLzzY1Rbutb9+GQH4xTw1sfKMTltGC8fIkVGQdS6mj2zk1OHOmSqYeQfV3t1ti0e3BaDyFUytbQl+1nyRv13ab/+L8c/dDQANbSMvDB6709g+c0HJcuUbf7TiNGPOysrWUR0IDyYiXwTM1EXrrIwtsPzBGAwzQZjkKglCdxp92nSAiKkfemeEkoG1gcHY0UCmcWv4OJv78bJq9MYWKLsMZUpcvJTQ2OcAgvhScmUHgQ8FiB1zgIUo5jDEbTkqEO74NNiV+akTsoDTkK5TIglSOTnYUNxDVPo9Iudap7QC34kMjVNPBvmJBijn5Yx+jBGHWg5cMGUIuMpkYGift+bhAHXp2+0kkBE6GWLmZdM2BwbMUJyTdmzjaYLAf654d8wl9/ThkVOHj4AzRm24P6ftR1zYA6v9hx57C1FIdWttRhajTSrYm3CCN5GMrqE0uYCtbq7+1mZqvBHPx33IEJB4jh8xkYUI+X89nPi6MXR89M8V6okNXH0Vj2f87LjKE0jjHfmNAYGPjzmESybIVo8kbbiv7C4BoTn0VLtsEZ3ydra99YK+9hvZar/0FvyswYtMK3ogql2Lt921Xsy7htfm5dENJMPHXw9y03Rpu78ZdbpBeJn3JenAlkUPYogbTnYHG8SrtSYz59y1btQ4TYOtmVlnYiMouXtbj1FCuwaYYFBXmvMqZpKAoUF2s8Kd/vkwBxotYpzY7D7U+bXD3WQw8fY62pb4aKjpjhsjyIFwCpwKCPG6uweeeJWlxo6bv7nIyhUcOC7ik6lwkB5zApPdXY0bLwgw5G0DoDfXw7+HzC9r6sHzFYEwo08LD2umt7Jx9IVNpQACQNh4a/daV8fRoT5dZYZAaOmdQLO52HmW5SLM+PCGHmeVn+hmfJiuhboQeo5GWD2adVODnt3I6cJPHVoSA+DKmqyaTBbbBADjsYuNCUNT/Ode4fornTKpozgJK0b8vMlIztjCx/MkPPqR83ZbHnwOF3PWn3J7dYdeno1tamT4RDm1MdgbG9jij0IFlLhaI10ZrQI5FptjHkOvDDmF8dBmzaXFfVGXsXWvGNSDBScWJIKUrVkZt6z06q8usqs+YkQfHCwntChe/NPW5ksfkw+e6MWhSIO/HhR9lhXvl5pOquk6zjVX7shsWtQy08bKZKaw494dHjKKkzpYpWEMxtwZLYCgddW9oSQmwcKUQ7hCMh3B6UMNwnfA3tuTo5FKqOu4x+GUJTVeKeRgHI2hIRtvV0xMG0dTTXqFGBg6BTHAMSeMZyzyYKkSUw1Y6CeODqYXu4Qmhjh3zmj6pU9tGLwhz+j04ViQju6p0wwyKIAgct8I3xkjYC0V0OJ8oRQgugf7jCP4+a2gbiOI8vQcZHHUPjsChsChy7PzCVUKCdAyTnwHjgx6tueXAozllOrobOAiJxufPI7yAk1C6AzCBYmbzAGvfww/shy814acTmcLXdzOmQ6HbqbmdfgkxyjwTfLjLOclLle70Sr7PWcuV4/zNGHRji/wfPioXZoYcE+POezV5nBm7NwaYAquH2S1aRJsDMaPHGrrlUfGtCDjxzqYnVex1dWu2JjULkLsA1ew9gY0GABg1sdAFWb8XXNBhGraYDORTSjAxeqjPfs0P2ScQAveWmitdGu1r+IFrx3goZlqUdb/UPZFQZdB9YqScZFC3C5Z3dzHZT8zNey6SWCKjjt3I6uRkGIbUAswLqJcmIVHxCy7tdg9foHcHqM5vL4VDF1+t9l5NolzAQoiy+Zbf12RqcMpp5gcQOmRhis9vtsERYfRgWFf1TiN5x7L0TEtdIjX2pHw5SjHk0WPNDyjD2i2HGJNbOCXYsUYaY+MFcSqQsYxYscSF20xrjFBZNBWzjZ2HR/WXqbKxLKLiz0nAXEuUY3f/QMnwxdwnRvI+Iwukx+TnCM+QIt9wzZxoY1g53/c4oErahaQd2+Iq26pDSE5nBXD9CnTj9RppWAbBd+fwX8yMrBESE1MqfROBFjMUSxdJi/jl54UIyUBpQ1ViygYkaubdtTpfsjyf1I8td/CS0Ik0eABdhKiH95oF136Jicw8AShLC3+ayK6TZzWzmuY4pT13TliEI0LDtvYpkUfO9afpvSJaf2r1yRSfoiBY2vGRrf+bnvEKMZGGGbtl0K7aZYVLlGNw47zOuc+J1ufwxOVZ2FtNrahOBV6sJRtL0+lzzEAsWuwKvrjiE2/9su3sH+1xp4vnGdp5ZEq5H/m70PyEtFR8qoeVH5jIxBOKgFMFLzz0ybSbMDGxWrPkuYB7Ae3PGeCmLg0EWdqWa9VNCmnE5vuhFxk8b4YfdEl8YbiGIUdF+jridgxd6EFtBMIp+1i0QSYD5WGuWNKx9gQ4nerLMoGWvodSxFz3Dj7SQ7xqNhVcu07HOS4MQBXS50aZVUdEjjuG4bOuYxNOoAVZqihcgqCwEvwJWWiCTxCvW9AvFOPvVtSlpi01LzsyILiCy3SRdqxzG9HmTsAjXF2sC1DSwzWs1bkARqE7a6ZbnVcc5qxngAAzWkmMzAMjiYD5pWBwYUMPyRnepGRSGa80ALBPj86blv7xUfu2DqP/rZMfJCMmgA7BhOkPsrX5Jc28Q0fvm+7XsHJEx36jyRJn4gyBuSNo77LFZF6uOTmnNKwj6HzgAwxDz6FppFjxfCj2Dpt+2ugqYcXUwGSiy9f8UOuvhKAV8esZkxZO5ywW95O287/ANp+MWupDPWWAVF5mtNY9ah2C9ZiheCX439R93uUjDRzn7Hli1WZ6R0js8KAWRRcufhaFi8sUk8ddcL1fXGNCJ6WJ8W3ghFwJQMwR0vPg/OLT2QjijmgEUkFIP21JcmiHjtsi2dpTtNGSRRyUQhBX34Jsf1AplMRYoIkQV7JYN1y9b24J9TT1G2w/Ok1J8HZwKJjXF4NWNZReNGaGRDPaNLuvKdZl87PJE7JQOSPHpv0QSUJgukszxmMLx6hNfgeJx7m4sRCECkdd+A7L5GTXP2gZ2Kd08HY2K+QcD2UaDJAu6nT/rF/jigy5BS/DjhJtJLOP1zpA2vC6XsIaMqPrx1ETyMa4pTaRt7EavAmnPI2ScFR/jFyvsKrF/+tazhdImGGi6tk/UY4S+fIimPK1se08ZH9Unxkf8fnPIl52wHATdnkSA82bXM4cm1GLgJcn0PIiaiEqaNlXJNfq8nOmTmw37i1qzFmh/cRnTiRrfzU0zj9YFiDM7SDX+4yGCKiKWv9LMlHc9DApnNkaTBPvK/actluvKv739Z86h0XuVrIe0sviphy1o6142SjRMbQiQZl8Lwt5t0ZQP5qrecgmGhdeumby+Bx3ZdwdgZEWEIgq3J7SFISF+pMOZez0Rzoi6pYtm3eFAdQFY3uohJF6LAfdXEJec4wwBY0JOEI8qeAehXTwONJM1W+A64Rx2MPxtzuaNKBp4OJnFFKpg0OZVTMIf0c5rUBfOcEYMpMt2MjtSf4bO6JKbaMRZN+HYC9n3MCjmoGi+feKUmNiWmxl0xIUtx8w6fEMBgYv7vDzIbT7Y09XlPO0Hpqs5pJ6s6vs5k+JvjkYGbCjAyBgDDRp1CzqCRHLqAqeCFgWNB4rCF9dcpW3+GIDYwQeFLE6oNemJot02rY4IqhhjvPYDaeSZBUjYIwmargOCu+/S5z72XCByYGtWkfJ3kYFyPxKWfa1KOX1/7KF1v79AxcGxdacczRPPQbF9cX3Pjk8NZf2oJESGVLk2PHyFl+VupZmH1dKki9mh7UP32axxrlAqhTNsac+jecKv9Dx3X5Pc5y7cPZ0hdzuLoIu6kMiXXmDLPHvpFZ08uNySgzF4w/CN6q93Ur3RnODDVXl92onSS9BWOPNDto+zlg7e8KmYCwxQFBRMXbDK9SMxtjh4Fbtts8Zx6LFAmLYq/1gZxeCgmDxW5TFsU9ZFL07CVpRAw5fggCe41yvLvacUgWPQuZ0kDw5HpMfqlvvPIQw6Hw1DBEzC7iPhkcuhG/HSWo4O/pq6e84kXMtU5Oz298PJ5KztxDMXqP+M3TSlxe8ByUYXCvkbtshArET3NSMxrmP1HFAfheb9LpeAOAjmE0rJ0qxlJRPHRQ4VssjpQzSMfMdKeFJ+Gt7U6fM2JM+A41ayAXrhERLtOMDeGi5u1TpsOZUZ+B8QV1fheK2Al/fz+b5OcsYoNx+MQwLoD5jJMhrJ01fZ0uFkRkRT4f/BA31xpouiioiZvRegXMMPWFC7QoU6fhU95yEyd6a/SrGyynjxfQUB6eiNrpFNmtcuSrny4+v5b6GcXq4yXx4/KUn22rfl0fMA24DPpK4Tii9bXqr/2V/wfqpf6epcUq4s4QL5zOZarESv7jWnKGiQVbbl/6uHFZgwgzhGQbNgKxYd8SWxJBmJroGCsy+dNBmbKJI821hCXOgDhxeStrnw+NFHCVExnqJk7kKX7NJyyTPhheC/vvBKYIg3wEpeGB2eg4AN3VhddwJVajbxQISeXU0nmkH6wh0CTKgHI0vTfZMugIZ87UziFV0V6yB81ZIUfDRZn56ujrmPuZbCgo4PdkMWWdYl7SzJ/Zjjj1ARS6gCLIEzcYyBMQ2p0ABgNKGcsibylYLzJ4gAg2MBMK+nECsDMXhDOIM6+0MswmovDHmtGqy+pjBJIxJOQo1YNxRpY/fzQq64XcwhJleaBJHxmuEgpu0uBFOzU4woJmsMONXew5TPYhaZG37RJ3OPkk219RlAsGwwUnL3+0Ypp8GKBNKn2sb3hYbdbwhoInt8AaK3dV4A5m/DALziuxD18R6eCQKmVbF6Mwg4pOUHwxxpxI+nIWkmPtl0uBsrYqv9pthQN6jENbXrr6nMgWi6xyEH9dSnox218uNP8q12X5563l5Pzx1pY1kNVvyVB5j5SzxTJx3I6aM8XgO8vIA2GSY8ue6TRYzWQZejhzFnBowd5HDo7ScxSp+zAQOHPYCccI48YXOcsKQbybtGwSG9EkHIYhMYqUaRPj7RW7femqZ5HbxZTCQhqONIqk4qHDHBxu/4RElsZMxPjFwlWICdghsWtngME1FeE1BXFex9hBLLhM8FGH88xaZkRe7iXqCzfjkKH88IXF0xmefKATNd9i6CaOoJNoEM4RDufFSGrObZy4OQkrejjxulMV4/EIACkRNoyl4nJp9w2+YdUfuJrRaFtrZmA9OA0jjW2vvkxIgZB0TC7SwN2AwoYJUnwb0/pYn4y2c5F1AxHTRy2A009MkYHjDkbk3/Iiwe9lC4tG/wHwVaRNnNRQJLllhuGQp9Q1YJbmXTvA4zKNxkD8xIfvDWk5rdVmGzifuosEUnyVD1v7qSlwqqMNRunU7BCER9cFNSKxtJFey2Oi1ORIPCCYuJxnsOZjLc8prW/clVD7z4A+Rb+CFfGJWxn4jmYl/3699iRKRuQmzBRyddTkqBeSZ5IoS493IqCYqaCsM2amfdZRLKIjX+Xp1MDhFWAY6jE6bJibHtMi96YDeEqvcOEpyljUxXEHL7Xa9ImMd4qr9FzUYayGmHeI/OCxSXEXBczIGcmAEW2JaKREzoZzVxJc+hhOIecUmlrNXBGzWJilA4ZosAs1dshqyhCcKFc5Lw7jCEtQdh0RE1gpXI6gLya5RRK3vOUiKRFR8E1czDkhIeCAW6occ8rJg+xMQ0mbOkfOKiZ5v9ogNEKVp2/TQ7lTiIyyO11/YcJLCf246yQAmTHqd9GYSMjyRxukx4x7fCBMPIw5593pQezmBIUoNfOdWv4c0sQtUjng4ckxKEZl26+Cah6NPCBytZrxZSqdFlzhXA7bcOCLI3ZlbU27skyqL3zyIpMIsHY5OLuYOUW8Jh1bxrA81PxEQCJWHi7GyrTlCjSnl7M19qkxVj8yTotv9enHVlNnLAJkrWyc9sjoH9lpjMwZLpB1uWpmjLZL6bUHuooF/0KE3aPG6p+WxX+1XXf/lCAAsFx6ff/bH3kL7aeRpptounMCIEHaZw0nN7p9IjkrkYxDH0UaWU/tw+w7yl6kZo5CtOs/5rEJILK2YsxS5NThcMSwQamAY1ek1tgR/diLIVrfZKWXWHMYbWBpidmPHtCxaKcIDD2fVIs9BgAI/imE4dtt/KwKhnWZ5ccuV5vk7DcC7LMfGRIF4zzCBLYBKDLYHTdD4O0nC//PP/JSxWsYyxuGTrr4353oKGdnQWhonjLyJPDYcqiOlv/+AS5kLHD0lNAQFH7z7ARoIH+Y2Z5wA85BX2n6IgKP7SGL75g1rQgeP3ggSf/dZdOweA1iA+cYa+7hoTSOtBlFSQ0h3kBHwoNR4uRb1rPzYHiFdzSEHd6G7Z8ZaztH3GV6Yasss/wt76ti4ilsEuTKjWTIknBqeA2a7N0Zrn2GS0h5Yodb5PNcHX7qq9iZ5hJjHXzcECcT29gUX64A6qXcEDFX1moqh62Mt2Zsr1zmlRkLc71W1w6c0lFdRJcB/b5wf9pg12hpPQUh5SGS41P0qoW/h1/yPoCHWum6fCD/sLlphu/UZsU3jqxalppb1zzG6nPqo3G1ZmF4Uy+TmLfrHPGAkgWtfbejaYtlFJWK/Mm1nGvwwdbIqqnDvRXzFoLbokyT0PzwTeNes2DEGpwM5avoDMSlxS2FXFCRnTqVBi9XEgsD5NwRui1qB584CBNtDqMGwtAYNvdLM2a8F2iQIt6DnkKSrSZP8gIcPLlPSM3frnNaAFQGYCzHv9Hk1DBVwWQ0ZgRacDiExOW7AekR9/Jiou/QEKc0eYYkltgaW3jQeZrbwHnsnAzmwZI/m8dqMRNwjyMA/a/emEJpPy/AkzKqhpwp5pFDdExiTgUvzflTPxnOb/yCZzA/vBckjEtcDRhtdFCSQvURO1II41PeAUELOJCpc1skK4UkN4nOK0MowHgPMG10KOQ2VPuZboBhZOqSYfjBJ5sFTwmBfPnDnAk2TBDz5I7I+u0HTPWjLDDCRg4aU/qaps4onXlu6qDUX9mNURyjxxi790lQhy8N9gL6HGykbaGfRnV5IUBIh3FRb5m21dsePSLwXGtkbMmVu2jQJEiU4fSEYIN4ShHtrHjrxfxV/e9g/4rnV7rl5q13vo3Hm0YXXE4NZ8W5Z/kGx4AzdhKLN7gyZu5pkqBmPfq+NwJWvRdzWTTus7nvyeTERWRM5qQtqCleDEHkto0ANFdN+SrOqdNM0SIBukRjn6ssNyueXa3aJjS6wRMOxPVEvoqCmwsAqLY4uEgzBUHnUIv3VG/gzIT22Do9zbhSwbnjYiDQOGCYMn5XIaBo8MmcyHF9YmZs2IKvD4YcEm1j7FRGyVYiecc+OFhwigntNFFl2MxJ+h56nttDOE+T+EwLXFylnr21EwQxlokdJ+lY0doGwzIKziFzY0Rp0/LM+U4FLRHDjG2iyg7LISCYIyUidExe2b2YJish0g6DQCYWhskHQ+1GkXuGcJfa6fQUYM3EkKDEBmObDiKSW4Ihcwkg1DRRMq8pvkxET0gJhyCaEKPPRa197mUuBwRihpE44sHbCbYZZxyYrNNIDLjTJwf86h8Z7WyP378jaZhg09QdTcZg0CvPuhU94sMltgdklLKmET47CPG5gMuM5kBokySVBcu5zBTtKRUoBQie6dCfJmb/b4tfOM8UkvSYyvypIN5gOIQMkf+TmoG4M9Pkgi6dnJo/kgNJh8ydU897Eq4MjqR2VQeXn+DK5tFlwbxwpZQJiy51VOyCvHSbuLl8AW3J2k7P2GKSR0i1hZf8SXEI2IbD7QerheWYNvHHpaHApn58CM1hQolWb5rpL616LGVwBEUespSU5jDlGoCg9YPYNmqYKT3SYmwKToMewaLdoAABsM/JSIB5KJSMeSwmVshduEDKjnSAI0ROUmAg4uvOyPoqRhzRIInN0CtCEgFX7UwpqOCctlwGoSMZ5SKMVzeTStA5MbzRcFypOj7IOV9ZRKEh9RCNQsaR+CKbl25fhrm8IhzSblpA4ExqMpHmj92e15loy8ZqzuN52z0OzuAYRC/GHQpJrzc7GJtJN+GSzGgzMKKUnWSZXl0kXJgR+LNuUk/CIoMo9fwIJTSfqEjU2HOQXyWnvYz+l+kqxHm1CcYpuX4147Albd/PrCyUnsKeAFE2Jy4EQhe//acGU5Atm2yTTAZUxDSHhwTRlF9LV/tzbXxfxL+SfYH8n7r/A6isvic82r4AAAAAAElFTkSuQmCC", + "backgroundColor": "#FFFFFF", + "referencedComponentHashes": [] +} \ No newline at end of file