The body of a FILE rule. It checks only what your path sensors already collect: make sure a sensor covers the glob, and collects contents when the rule checks them.
A rule makes one kind of check. An existence check applies to Endpoint and raises one finding per endpoint; an endpoint no path sensor has collected on isn't judged. The contents, permissions, and ownership checks apply to EndpointPath, the files one path sensor collected on an endpoint, and raise one finding per failing file, keyed by the file's path. A file a check can't judge, such as one whose contents weren't collected, keeps its current findings until the check can. A file its sensor reports deleted counts as removed from the endpoint. Windows collects no file owners or meaningful permission bits, so a Windows glob can check only existence or contents.
Fields
| Field Name | Description |
|---|---|
pathGlob - String!
|
The paths checked, as an absolute glob such as /etc/ssh/sshd_config or /etc/cron.d/*. Each * stays within one directory. A Windows glob (starting with a drive letter or \) matches case-insensitively and accepts either slash. |
pathSensorId - PathSensorId
|
When set, only paths this path sensor collected are checked. |
existence - RuleFileExistence
|
Requires matching paths to be present or absent on each endpoint. See RuleFileExistence. |
contents - RuleFileContents
|
The content check each matching file must pass. See RuleFileContents. |
permissions - RuleFilePermissions
|
The permission check each matching file must pass. See RuleFilePermissions. |
ownership - RuleFileOwnership
|
The ownership check each matching file must pass. See RuleFileOwnership. |
Used by
RuleBodyunion: A polymorphic body for a rule type.RuleBodyFileInputinput: Input variant of RuleBodyFile.RuleTypeenum: Describes how a rule gathers the input its function evaluates.
Example
Example
{
"pathGlob": "xyz789",
"pathSensorId": PathSensorId,
"existence": "MUST_EXIST",
"contents": RuleFileContents,
"permissions": RuleFilePermissions,
"ownership": RuleFileOwnership
}