Policies and findings · GraphQL query

policyRulesList query

Lists a page of the organization's policy rules, sorted by name and then by creation time, optionally limited to one rule group. Deleted rules are not listed. A rule describes a check evaluated against graph objects; a failing check produces a Finding and an Issue. Manage rules with policyRulesAdd, policyRulesEdit, and policyRulesRemove.

Response

Returns a RulesListPayload!

Arguments

Name Description
orgId - OrganizationId! The Organization identifier.
input - RulesListInput! Filter and pagination input.
mockOptions - MockDataInput When enabled, returns mock rules from the mock policy service instead of the real store.

Example

Query

query policyRulesList(
  $orgId: OrganizationId!,
  $input: RulesListInput!,
  $mockOptions: MockDataInput
) {
  policyRulesList(
    orgId: $orgId,
    input: $input,
    mockOptions: $mockOptions
  ) {
    rules {
      id
      orgId
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      seen {
        ...SeenOnlineFragment
      }
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      group
      source
      applyTo
      applyToOptions {
        ...RuleApplyToOptionFragment
      }
      osNeutral
      name
      discoveryName
      description
      notes
      enabled
      severity
      type
      body {
        ... on RuleBodyConfiguration {
          ...RuleBodyConfigurationFragment
        }
        ... on RuleBodyFile {
          ...RuleBodyFileFragment
        }
        ... on RuleBodyProprietary {
          ...RuleBodyProprietaryFragment
        }
        ... on RuleBodySearch {
          ...RuleBodySearchFragment
        }
        ... on RuleBodyThreshold {
          ...RuleBodyThresholdFragment
        }
        ... on RuleBodyVulnerability {
          ...RuleBodyVulnerabilityFragment
        }
      }
      schedule {
        ...ScheduleFragment
      }
      mockOptions {
        ...MockDataOptionFragment
      }
      lastMockDataInput
      remediationInstructions {
        ...RemediationInstructionsFragment
      }
      securityFrameworks {
        ...SecurityFrameworkReferenceFragment
      }
      risks
      tactics
      createdBy {
        ...UserFragment
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
    totalCount
  }
}

Variables

{
  "orgId": "615f3b3b28284380e28a7342",
  "input": RulesListInput,
  "mockOptions": MockDataInput
}

Response

{
  "data": {
    "policyRulesList": {
      "rules": [Rule],
      "totalCount": "-8589934592"
    }
  }
}