Describes how a rule gathers the input its function evaluates. The type determines which body the rule carries — see RuleBody.
Values
| Enum Value | Description |
|---|---|
|
|
The rule checks an object's attributes against a required state. Evaluated whenever that object changes, so it carries no schedule. Its body is RuleBodyConfiguration. |
|
|
The rule checks the files your path sensors collect: that they exist or don't on each Endpoint, or that each matching file a sensor collected, listed on its EndpointPath, meets the rule's content, permission, and ownership expectations, one finding per failing file. Runs on the rule's Schedule. Its body is RuleBodyFile. |
|
|
The rule runs a check that ships with the platform rather than one authored as rule content, so it carries no query or function of its own. Runs on the rule's Schedule. Its body is RuleBodyProprietary. |
|
|
The rule flags every object its graph search finds, and clears the finding once an object no longer matches. Runs on the rule's Schedule. Its body is RuleBodySearch. |
|
|
The rule counts, for each object it applies to, the related objects its count path reaches, and flags every object whose count falls below its minimum or above its maximum. Runs on the rule's Schedule. Its body is RuleBodyThreshold. |
|
|
The rule matches the CPEs on the objects it applies to against known CVEs, raising a finding and issue for each vulnerability it identifies, or one per object listing them all. Runs on the rule's Schedule. Its body is RuleBodyVulnerability. |
Used by
Findingtype: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.Issuetype: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.Ruletype: A policy rule evaluated against graph objects.RuleInputinput: Input variant of Rule carrying its writable fields.
Related types
EndpointA Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.EndpointPathThe single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…
Example
Example
"CONFIGURATION"