Attribute keys that further scope which objects a rule applies to, in addition to its applyTo object type. A key is only valid when the rule's applyTo type can resolve it; invalid keys are rejected when the rule is saved. CONFIGURATION rules accept any key their applyTo type can resolve; FILE, PROPRIETARY, SEARCH, THRESHOLD, and VULNERABILITY rules accept only a single OS option with the EQUALS operator. See RuleApplyToOption.
Values
| Enum Value | Description |
|---|---|
|
|
Operating system platform. The value must be an OsPlatform (WINDOWS, DARWIN, LINUX). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Operating system version (for example 14.4). The value must be a parseable version string. Supports the ordering operators; IN and NOT_IN are not supported. |
|
|
The host's machine/domain role. The value must be an ActiveDirectoryRole other than NOT_SET. Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Linux distribution (for example UBUNTU, RHEL). The value must be a LinuxDistribution. Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Operating system edition/SKU. The value must be a WindowsEdition (for example ENTERPRISE, PROFESSIONAL), resolved from the endpoint's system information. Windows-only: non-Windows hosts carry no structured edition, and UNKNOWN is rejected. Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Hardware chassis type. The value must be a ChassisType (for example LAPTOP, NOTEBOOK, PORTABLE, DESKTOP, TOWER, TABLET), resolved from the endpoint's system information. UNKNOWN and OTHER are rejected. Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Service start type. Valid only when the rule's applyTo is SystemService; the value is resolved from the service object itself, not the endpoint. The value must be a ServiceStartType other than UNKNOWN (for example AUTO_START, DISABLED). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
User account classification. Valid only when the rule's applyTo is EndpointUser; the value is resolved from the user object itself, not the endpoint. The value must be an EndpointUserType other than UNKNOWN (LOCAL, DOMAIN, SYSTEM). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Disk hardware bus type. Valid only when the rule's applyTo is Disk; the value is resolved from the disk object itself, not the endpoint. The value must be a BusType other than UNKNOWN (for example USB, NVME, SATA, VIRTUAL). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Network classification. Valid only when the rule's applyTo is Network; the value is resolved from the network object itself. The value must be a NetworkType (PREMISE, REMOTE, LINK_LOCAL). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Device category. Valid only when the rule's applyTo is Device; the value is resolved from the device's fingerprint result. The value must be a DeviceTypeCategory other than UNKNOWN (for example PRINTER, CAMERA, IOT_DEVICE). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Whether the device is a network gateway. Valid only when the rule's applyTo is Device; the value is resolved from the device object itself. The value is "true" or "false". Supports EQUALS and NOT_EQUAL. |
|
|
Observed network-service type. Valid only when the rule's applyTo is Service; the value is resolved from the service object itself. The value must be a ServiceType other than UNKNOWN (for example SSH, HTTPS, SMB). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Whether the object is reachable from a public network. Valid when the rule's applyTo is Service or OpenPort; the value is resolved from the object itself. The value is "true" or "false". Supports EQUALS and NOT_EQUAL. |
|
|
IP transport protocol. Valid only when the rule's applyTo is OpenPort; the value is resolved from the port object itself. The value must be an IpProtocol other than UNKNOWN (TCP, UDP). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Network interface type (IANA ifType). Valid only when the rule's applyTo is Interface; the value is resolved from the interface object itself. The value must be an InterfaceType other than OTHER (for example ETHERNET_CSMACD, IEEE_80211, SOFTWARE_LOOPBACK). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Whether the interface is a loopback interface. Valid only when the rule's applyTo is Interface; the value is resolved from the interface object itself. The value is "true" or "false". Supports EQUALS and NOT_EQUAL. |
|
|
Wireless radio state. Valid only when the rule's applyTo is WlanInterface; the value is resolved from the interface object itself. The value must be a WlanInterfaceRadioState other than UNKNOWN (ON, OFF). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Wireless connection state. Valid only when the rule's applyTo is WlanInterface; the value is resolved from the interface object itself. The value must be a WlanInterfaceConnectionState other than UNKNOWN (for example CONNECTED, DISCONNECTED, ADHOC). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Wireless radio mode. Valid when the rule's applyTo is WlanNetwork or WlanAccessPoint; the value is resolved from the object itself. The value must be a WlanInterfaceMode other than UNKNOWN (for example INFRA_AP, INFRA_NON_AP, IBSS, MESH). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Wireless frequency band. Valid only when the rule's applyTo is WlanAccessPoint; the value is resolved from the access-point object itself. The value must be a WlanChannelBand other than UNKNOWN (GHZ_2, GHZ_5, GHZ_6). Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Mounted filesystem type. Valid only when the rule's applyTo is DiskMount; the value is resolved from the mount object itself. It is a free-form string (for example ext4, xfs, apfs, ntfs, tmpfs) — there is no closed enum. Supports EQUALS, NOT_EQUAL, IN and NOT_IN. |
|
|
Whether the position has a resolved geolocation. Valid only when the rule's applyTo is PositionSeen; the value is resolved from the position object itself. The value is "true" or "false". Supports EQUALS and NOT_EQUAL. |
Used by
RuleApplyToOptiontype: A single key/operator/value constraint that narrows which objects a rule applies to.RuleApplyToOptionInputinput: Input variant of RuleApplyToOption.
Related types
DeviceA physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…DiskA physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…DiskMountA file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).EndpointUserAn operating system or domain user account observed on an Endpoint.InterfaceA network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…NetworkAn IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…OpenPortOne TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…PositionSeenA geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.ServiceA network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…SystemServiceA background service or daemon configured on an Endpoint.WlanAccessPointA Wi-Fi access point radio, identified by the network name (SSID) it broadcasts and its BSSID, as heard by managed endpoints scanning for nearby…WlanInterfaceA wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.WlanNetworkA Wi-Fi network identified by its network name (SSID), visible to managed endpoints when they scan for nearby networks on Windows, macOS, or Linux.
Example
Example
"OS"