Skip to content

Add data source for NG-SIEM Rules #175

@vova-bolotov

Description

@vova-bolotov

Description

When creating custom SIEM correlation rules, the rules are automatically assigned to the admin user who created them. During Fal.Con Europe 2025, I learned that if this admin account is later deleted, all rules owned by that admin are also deleted, which can lead to unintended data loss and operational disruptions.

To prevent this, it would be beneficial to allow rules to be created and managed via Terraform, ensuring that ownership is not tied to an individual user.

API Scopes Required

  • Correlation Rules Admin RIGHT
  • Correlation Rules READ RIGHT

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions