---
title: Cloudforce One
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Cloudforce One

#### Cloudforce OneBinary Storage

##### [Retrieves a file from Binary Storage](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/binary_storage/methods/get)

cloudforce\_one.binary\_storage.get(strhash, BinaryStorageGetParams\*\*kwargs)

GET/accounts/{account\_id}/cloudforce-one/binary/{hash}

##### [Posts a file to Binary Storage](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/binary_storage/methods/create)

cloudforce\_one.binary\_storage.create(BinaryStorageCreateParams\*\*kwargs) -> [BinaryStorageCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.binary_storage%20%3E%20(model)%20binary_storage_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/binary

##### ModelsExpand Collapse

<details>

<summary>

class BinaryStorageCreateResponse: …

</summary>

content\_type: str

<a href="#(resource)%20cloudforce_one.binary_storage%20%3E%20(model)%20binary_storage_create_response%20%3E%20(schema)%20%3E%20(property)%20content_type">Link to this property</a>

md5: str

<a href="#(resource)%20cloudforce_one.binary_storage%20%3E%20(model)%20binary_storage_create_response%20%3E%20(schema)%20%3E%20(property)%20md5">Link to this property</a>

sha1: str

<a href="#(resource)%20cloudforce_one.binary_storage%20%3E%20(model)%20binary_storage_create_response%20%3E%20(schema)%20%3E%20(property)%20sha1">Link to this property</a>

sha256: str

<a href="#(resource)%20cloudforce_one.binary_storage%20%3E%20(model)%20binary_storage_create_response%20%3E%20(schema)%20%3E%20(property)%20sha256">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.binary_storage%20%3E%20(model)%20binary_storage_create_response%20%3E%20(schema)>)

#### Cloudforce OneRequests

##### [List Requests](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/methods/list)

cloudforce\_one.requests.list(RequestListParams\*\*kwargs) -> SyncSinglePage\[[ListItem](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)>)]

POST/accounts/{account\_id}/cloudforce-one/requests

##### [Get a Request](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/methods/get)

cloudforce\_one.requests.get(strrequest\_id, RequestGetParams\*\*kwargs) -> [Item](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/requests/{request\_id}

##### [Create a New Request.](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/methods/create)

cloudforce\_one.requests.create(RequestCreateParams\*\*kwargs) -> [Item](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/requests/new

##### [Update a Request](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/methods/update)

cloudforce\_one.requests.update(strrequest\_id, RequestUpdateParams\*\*kwargs) -> [Item](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)>)

PUT/accounts/{account\_id}/cloudforce-one/requests/{request\_id}

##### [Delete a Request](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/methods/delete)

cloudforce\_one.requests.delete(strrequest\_id, RequestDeleteParams\*\*kwargs) -> [RequestDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/requests/{request\_id}

##### [Get Request Quota](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/methods/quota)

cloudforce\_one.requests.quota(RequestQuotaParams\*\*kwargs) -> [Quota](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20quota%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/requests/quota

##### [Get Request Types](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/methods/types)

cloudforce\_one.requests.types(RequestTypesParams\*\*kwargs) -> SyncSinglePage\[[RequestTypesResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_types_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/cloudforce-one/requests/types

##### [Get Request Priority, Status, and TLP constants](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/methods/constants)

cloudforce\_one.requests.constants(RequestConstantsParams\*\*kwargs) -> [RequestConstants](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/requests/constants

##### ModelsExpand Collapse

<details>

<summary>

class Item: …

</summary>

id: str

UUID.

maxLength36

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

content: str

Request content.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20content">Link to this property</a>

created: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

priority: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

request: str

Requested information from request.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20request">Link to this property</a>

summary: str

Brief description of the request.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20summary">Link to this property</a>

<details>

<summary>

tlp: Literal\["clear", "amber", "amber-strict", 2 more]

The CISA defined Traffic Light Protocol (TLP).

</summary>

One of the following:

"clear"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"red"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

updated: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20updated">Link to this property</a>

completed: Optional\[datetime]

formatdate-time

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20completed">Link to this property</a>

message\_tokens: Optional\[int]

Tokens for the request messages.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20message_tokens">Link to this property</a>

readable\_id: Optional\[str]

Readable Request ID.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20readable_id">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["open", "accepted", "reported", 3 more]]

Request Status.

</summary>

One of the following:

"open"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"accepted"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"reported"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"approved"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"completed"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

"declined"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

tokens: Optional\[int]

Tokens for the request.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)%20%3E%20(property)%20tokens">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)>)

<details>

<summary>

class ListItem: …

</summary>

id: str

UUID.

maxLength36

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created: datetime

Request creation time.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

<details>

<summary>

priority: Literal\["routine", "high", "urgent"]

</summary>

One of the following:

"routine"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20priority%20%3E%20(member)%200">Link to this property</a>

"high"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20priority%20%3E%20(member)%201">Link to this property</a>

"urgent"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20priority%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

request: str

Requested information from request.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20request">Link to this property</a>

summary: str

Brief description of the request.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20summary">Link to this property</a>

<details>

<summary>

tlp: Literal\["clear", "amber", "amber-strict", 2 more]

The CISA defined Traffic Light Protocol (TLP).

</summary>

One of the following:

"clear"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"red"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

updated: datetime

Request last updated time.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20updated">Link to this property</a>

completed: Optional\[datetime]

Request completion time.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20completed">Link to this property</a>

message\_tokens: Optional\[int]

Tokens for the request messages.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20message_tokens">Link to this property</a>

readable\_id: Optional\[str]

Readable Request ID.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20readable_id">Link to this property</a>

<details>

<summary>

status: Optional\[Literal\["open", "accepted", "reported", 3 more]]

Request Status.

</summary>

One of the following:

"open"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"accepted"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

"reported"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

"approved"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

"completed"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

"declined"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

tokens: Optional\[int]

Tokens for the request.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)%20%3E%20(property)%20tokens">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests%20%3E%20(model)%20list_item%20%3E%20(schema)>)

<details>

<summary>

class Quota: …

</summary>

anniversary\_date: Optional\[datetime]

Anniversary date is when annual quota limit is refreshed.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20quota%20%3E%20(schema)%20%3E%20(property)%20anniversary_date">Link to this property</a>

quarter\_anniversary\_date: Optional\[datetime]

Quarter anniversary date is when quota limit is refreshed each quarter.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20quota%20%3E%20(schema)%20%3E%20(property)%20quarter_anniversary_date">Link to this property</a>

quota: Optional\[int]

Tokens for the quarter.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20quota%20%3E%20(schema)%20%3E%20(property)%20quota">Link to this property</a>

remaining: Optional\[int]

Tokens remaining for the quarter.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20quota%20%3E%20(schema)%20%3E%20(property)%20remaining">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests%20%3E%20(model)%20quota%20%3E%20(schema)>)

<details>

<summary>

class RequestConstants: …

</summary>

<details>

<summary>

priority: Optional\[List\[Literal\["routine", "high", "urgent"]]]

</summary>

One of the following:

"routine"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20priority%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"high"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20priority%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"urgent"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20priority%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

<details>

<summary>

status: Optional\[List\[Literal\["open", "accepted", "reported", 3 more]]]

</summary>

One of the following:

"open"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"accepted"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"reported"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"approved"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"completed"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

"declined"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(items)%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

<details>

<summary>

tlp: Optional\[List\[Literal\["clear", "amber", "amber-strict", 2 more]]]

</summary>

One of the following:

"clear"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(items)%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(items)%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(items)%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(items)%20%3E%20(member)%203">Link to this property</a>

"red"

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(items)%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_constants%20%3E%20(schema)>)

List\[[RequestTypesResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_types_response%20%3E%20(schema)>)]

[Link to this property](<#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_types%20%3E%20(schema)>)

<details>

<summary>

class RequestDeleteResponse: …

</summary>

<details>

<summary>

errors: List\[Error]

</summary>

code: int

minimum1000

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: str

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: Optional\[ErrorSource]

</summary>

pointer: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

<details>

<summary>

messages: List\[Message]

</summary>

code: int

minimum1000

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: str

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: Optional\[MessageSource]

</summary>

pointer: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages">Link to this property</a>

success: Literal\[true]

Whether the API call was successful.

<a href="#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_delete_response%20%3E%20(schema)>)

str

Request Types.

[Link to this property](<#(resource)%20cloudforce_one.requests%20%3E%20(model)%20request_types_response%20%3E%20(schema)>)

#### Cloudforce OneRequestsMessage

##### [List Request Messages](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/message/methods/get)

cloudforce\_one.requests.message.get(strrequest\_id, MessageGetParams\*\*kwargs) -> SyncSinglePage\[[Message](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message%20%3E%20(schema)>)]

POST/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/message

##### [Create a New Request Message](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/message/methods/create)

cloudforce\_one.requests.message.create(strrequest\_id, MessageCreateParams\*\*kwargs) -> [Message](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/message/new

##### [Update a Request Message](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/message/methods/update)

cloudforce\_one.requests.message.update(intmessage\_id, MessageUpdateParams\*\*kwargs) -> [Message](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message%20%3E%20(schema)>)

PUT/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/message/{message\_id}

##### [Delete a Request Message](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/message/methods/delete)

cloudforce\_one.requests.message.delete(intmessage\_id, MessageDeleteParams\*\*kwargs) -> [MessageDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/message/{message\_id}

##### ModelsExpand Collapse

<details>

<summary>

class Message: …

</summary>

id: int

Message ID.

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

author: str

Author of message.

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message%20%3E%20(schema)%20%3E%20(property)%20author">Link to this property</a>

content: str

Content of message.

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message%20%3E%20(schema)%20%3E%20(property)%20content">Link to this property</a>

is\_follow\_on\_request: bool

Whether the message is a follow-on request.

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message%20%3E%20(schema)%20%3E%20(property)%20is_follow_on_request">Link to this property</a>

updated: datetime

Defines the message last updated time.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message%20%3E%20(schema)%20%3E%20(property)%20updated">Link to this property</a>

created: Optional\[datetime]

Defines the message creation time.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message%20%3E%20(schema)>)

<details>

<summary>

class MessageDeleteResponse: …

</summary>

<details>

<summary>

errors: List\[Error]

</summary>

code: int

minimum1000

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: str

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: Optional\[ErrorSource]

</summary>

pointer: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

<details>

<summary>

messages: List\[Message]

</summary>

code: int

minimum1000

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: str

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: Optional\[MessageSource]

</summary>

pointer: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages">Link to this property</a>

success: Literal\[true]

Whether the API call was successful.

<a href="#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests.message%20%3E%20(model)%20message_delete_response%20%3E%20(schema)>)

#### Cloudforce OneRequestsPriority

##### [Get a Priority Intelligence Requirement](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/priority/methods/get)

cloudforce\_one.requests.priority.get(strpriority\_id, PriorityGetParams\*\*kwargs) -> [Item](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/requests/priority/{priority\_id}

##### [Create a New Priority Intelligence Requirement](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/priority/methods/create)

cloudforce\_one.requests.priority.create(PriorityCreateParams\*\*kwargs) -> [Priority](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/requests/priority/new

##### [Update a Priority Intelligence Requirement](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/priority/methods/update)

cloudforce\_one.requests.priority.update(strpriority\_id, PriorityUpdateParams\*\*kwargs) -> [Item](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20item%20%3E%20(schema)>)

PUT/accounts/{account\_id}/cloudforce-one/requests/priority/{priority\_id}

##### [Delete a Priority Intelligence Requirement](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/priority/methods/delete)

cloudforce\_one.requests.priority.delete(strpriority\_id, PriorityDeleteParams\*\*kwargs) -> [PriorityDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/requests/priority/{priority\_id}

##### [Get Priority Intelligence Requirement Quota](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/priority/methods/quota)

cloudforce\_one.requests.priority.quota(PriorityQuotaParams\*\*kwargs) -> [Quota](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests%20%3E%20(model)%20quota%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/requests/priority/quota

##### ModelsExpand Collapse

str

[Link to this property](<#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20label%20%3E%20(schema)>)

<details>

<summary>

class Priority: …

</summary>

id: str

UUID.

maxLength36

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

created: datetime

Priority creation time.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

labels: List\[<a href="https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20label%20%3E%20(schema)">Label</a>]

List of labels.

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20labels">Link to this property</a>

priority: int

Priority.

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

requirement: str

Requirement.

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20requirement">Link to this property</a>

<details>

<summary>

tlp: Literal\["clear", "amber", "amber-strict", 2 more]

The CISA defined Traffic Light Protocol (TLP).

</summary>

One of the following:

"clear"

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"red"

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

updated: datetime

Priority last updated time.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)%20%3E%20(property)%20updated">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority%20%3E%20(schema)>)

<details>

<summary>

class PriorityEdit: …

</summary>

labels: List\[<a href="https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20label%20%3E%20(schema)">Label</a>]

List of labels.

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_edit%20%3E%20(schema)%20%3E%20(property)%20labels">Link to this property</a>

priority: int

Priority.

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_edit%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

requirement: str

Requirement.

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_edit%20%3E%20(schema)%20%3E%20(property)%20requirement">Link to this property</a>

<details>

<summary>

tlp: Literal\["clear", "amber", "amber-strict", 2 more]

The CISA defined Traffic Light Protocol (TLP).

</summary>

One of the following:

"clear"

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_edit%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_edit%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_edit%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_edit%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"red"

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_edit%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_edit%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_edit%20%3E%20(schema)>)

<details>

<summary>

class PriorityDeleteResponse: …

</summary>

<details>

<summary>

errors: List\[Error]

</summary>

code: int

minimum1000

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: str

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: Optional\[ErrorSource]

</summary>

pointer: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

<details>

<summary>

messages: List\[Message]

</summary>

code: int

minimum1000

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: str

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: Optional\[MessageSource]

</summary>

pointer: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages">Link to this property</a>

success: Literal\[true]

Whether the API call was successful.

<a href="#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests.priority%20%3E%20(model)%20priority_delete_response%20%3E%20(schema)>)

#### Cloudforce OneRequestsAssets

##### [Get a Request Asset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/assets/methods/get)

cloudforce\_one.requests.assets.get(strasset\_id, AssetGetParams\*\*kwargs) -> SyncSinglePage\[[AssetGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_get_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/asset/{asset\_id}

##### [List Request Assets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/assets/methods/create)

cloudforce\_one.requests.assets.create(strrequest\_id, AssetCreateParams\*\*kwargs) -> SyncSinglePage\[[AssetCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_create_response%20%3E%20(schema)>)]

POST/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/asset

##### [Update a Request Asset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/assets/methods/update)

cloudforce\_one.requests.assets.update(strasset\_id, AssetUpdateParams\*\*kwargs) -> [AssetUpdateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_update_response%20%3E%20(schema)>)

PUT/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/asset/{asset\_id}

##### [Delete a Request Asset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/requests/subresources/assets/methods/delete)

cloudforce\_one.requests.assets.delete(strasset\_id, AssetDeleteParams\*\*kwargs) -> [AssetDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/requests/{request\_id}/asset/{asset\_id}

##### ModelsExpand Collapse

<details>

<summary>

class AssetGetResponse: …

</summary>

id: int

Asset ID.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

name: str

Asset name.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

created: Optional\[datetime]

Defines the asset creation time.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_get_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

description: Optional\[str]

Asset description.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_get_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

file\_type: Optional\[str]

Asset file type.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_get_response%20%3E%20(schema)%20%3E%20(property)%20file_type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_get_response%20%3E%20(schema)>)

<details>

<summary>

class AssetCreateResponse: …

</summary>

id: int

Asset ID.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

name: str

Asset name.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

created: Optional\[datetime]

Defines the asset creation time.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_create_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

description: Optional\[str]

Asset description.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

file\_type: Optional\[str]

Asset file type.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_create_response%20%3E%20(schema)%20%3E%20(property)%20file_type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_create_response%20%3E%20(schema)>)

<details>

<summary>

class AssetUpdateResponse: …

</summary>

id: int

Asset ID.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_update_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

name: str

Asset name.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_update_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

created: Optional\[datetime]

Defines the asset creation time.

formatdate-time

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_update_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

description: Optional\[str]

Asset description.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_update_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

file\_type: Optional\[str]

Asset file type.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_update_response%20%3E%20(schema)%20%3E%20(property)%20file_type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_update_response%20%3E%20(schema)>)

<details>

<summary>

class AssetDeleteResponse: …

</summary>

<details>

<summary>

errors: List\[Error]

</summary>

code: int

minimum1000

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: str

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: Optional\[ErrorSource]

</summary>

pointer: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

<details>

<summary>

messages: List\[Message]

</summary>

code: int

minimum1000

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20code">Link to this property</a>

message: str

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: Optional\[MessageSource]

</summary>

pointer: Optional\[str]

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20messages">Link to this property</a>

success: Literal\[true]

Whether the API call was successful.

<a href="#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.requests.assets%20%3E%20(model)%20asset_delete_response%20%3E%20(schema)>)

#### Cloudforce OneScans

#### Cloudforce OneScansResults

##### [Get the Latest Scan Result](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/scans/subresources/results/methods/get)

cloudforce\_one.scans.results.get(strconfig\_id, ResultGetParams\*\*kwargs) -> [ResultGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20result_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/scans/results/{config\_id}

##### ModelsExpand Collapse

<details>

<summary>

class ScanResult: …

</summary>

number: Optional\[float]

<a href="#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20scan_result%20%3E%20(schema)%20%3E%20(property)%20number">Link to this property</a>

proto: Optional\[str]

<a href="#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20scan_result%20%3E%20(schema)%20%3E%20(property)%20proto">Link to this property</a>

status: Optional\[str]

<a href="#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20scan_result%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20scan_result%20%3E%20(schema)>)

<details>

<summary>

class ResultGetResponse: …

</summary>

<details>

<summary>

\_1\_1\_1\_1: List\[<a href="https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20scan_result%20%3E%20(schema)">ScanResult</a>]

</summary>

number: Optional\[float]

<a href="#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20scan_result%20%3E%20(schema)%20%3E%20(property)%20number">Link to this property</a>

proto: Optional\[str]

<a href="#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20scan_result%20%3E%20(schema)%20%3E%20(property)%20proto">Link to this property</a>

status: Optional\[str]

<a href="#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20scan_result%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20result_get_response%20%3E%20(schema)%20%3E%20(property)%201.1.1.1">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.scans.results%20%3E%20(model)%20result_get_response%20%3E%20(schema)>)

#### Cloudforce OneScansConfig

##### [List Scan Configs](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/scans/subresources/config/methods/list)

cloudforce\_one.scans.config.list(ConfigListParams\*\*kwargs) -> SyncSinglePage\[[ConfigListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/cloudforce-one/scans/config

##### [Create a new Scan Config](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/scans/subresources/config/methods/create)

cloudforce\_one.scans.config.create(ConfigCreateParams\*\*kwargs) -> [ConfigCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/scans/config

##### [Update an existing Scan Config](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/scans/subresources/config/methods/edit)

cloudforce\_one.scans.config.edit(strconfig\_id, ConfigEditParams\*\*kwargs) -> [ConfigEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/scans/config/{config\_id}

##### [Delete a Scan Config](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/scans/subresources/config/methods/delete)

cloudforce\_one.scans.config.delete(strconfig\_id, ConfigDeleteParams\*\*kwargs) -> object

DELETE/accounts/{account\_id}/cloudforce-one/scans/config/{config\_id}

##### ModelsExpand Collapse

<details>

<summary>

class ConfigListResponse: …

</summary>

id: str

Defines the Config ID.

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: str

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_list_response%20%3E%20(schema)%20%3E%20(property)%20account_id">Link to this property</a>

frequency: float

Defines the number of days between each scan (0 = One-off scan).

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_list_response%20%3E%20(schema)%20%3E%20(property)%20frequency">Link to this property</a>

ips: List\[str]

Defines a list of IP addresses or CIDR blocks to scan. The maximum number of total IP addresses allowed is 5000.

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_list_response%20%3E%20(schema)%20%3E%20(property)%20ips">Link to this property</a>

ports: List\[str]

Defines a list of ports to scan. Valid values are:“default”, “all”, or a comma-separated list of ports or range of ports (e.g. \[“1-80”, “443”]). “default” scans the 100 most commonly open ports.

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_list_response%20%3E%20(schema)%20%3E%20(property)%20ports">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_list_response%20%3E%20(schema)>)

<details>

<summary>

class ConfigCreateResponse: …

</summary>

id: str

Defines the Config ID.

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: str

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_create_response%20%3E%20(schema)%20%3E%20(property)%20account_id">Link to this property</a>

frequency: float

Defines the number of days between each scan (0 = One-off scan).

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_create_response%20%3E%20(schema)%20%3E%20(property)%20frequency">Link to this property</a>

ips: List\[str]

Defines a list of IP addresses or CIDR blocks to scan. The maximum number of total IP addresses allowed is 5000.

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_create_response%20%3E%20(schema)%20%3E%20(property)%20ips">Link to this property</a>

ports: List\[str]

Defines a list of ports to scan. Valid values are:“default”, “all”, or a comma-separated list of ports or range of ports (e.g. \[“1-80”, “443”]). “default” scans the 100 most commonly open ports.

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_create_response%20%3E%20(schema)%20%3E%20(property)%20ports">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_create_response%20%3E%20(schema)>)

<details>

<summary>

class ConfigEditResponse: …

</summary>

id: str

Defines the Config ID.

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: str

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_edit_response%20%3E%20(schema)%20%3E%20(property)%20account_id">Link to this property</a>

frequency: float

Defines the number of days between each scan (0 = One-off scan).

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_edit_response%20%3E%20(schema)%20%3E%20(property)%20frequency">Link to this property</a>

ips: List\[str]

Defines a list of IP addresses or CIDR blocks to scan. The maximum number of total IP addresses allowed is 5000.

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_edit_response%20%3E%20(schema)%20%3E%20(property)%20ips">Link to this property</a>

ports: List\[str]

Defines a list of ports to scan. Valid values are:“default”, “all”, or a comma-separated list of ports or range of ports (e.g. \[“1-80”, “443”]). “default” scans the 100 most commonly open ports.

<a href="#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_edit_response%20%3E%20(schema)%20%3E%20(property)%20ports">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.scans.config%20%3E%20(model)%20config_edit_response%20%3E%20(schema)>)

#### Cloudforce OneThreat Events

##### [Filter and list events](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/list)

cloudforce\_one.threat\_events.list(ThreatEventListParams\*\*kwargs) -> [ThreatEventListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events

##### [Reads an event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/get)

Deprecated

cloudforce\_one.threat\_events.get(strevent\_id, ThreatEventGetParams\*\*kwargs) -> [ThreatEventGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/{event\_id}

##### [Creates a new event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/create)

cloudforce\_one.threat\_events.create(ThreatEventCreateParams\*\*kwargs) -> [ThreatEventCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/create

##### [Updates an event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/edit)

cloudforce\_one.threat\_events.edit(strevent\_id, ThreatEventEditParams\*\*kwargs) -> [ThreatEventEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/{event\_id}

##### [Creates bulk events](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/bulk_create)

cloudforce\_one.threat\_events.bulk\_create(ThreatEventBulkCreateParams\*\*kwargs) -> [ThreatEventBulkCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/create/bulk

##### [Creates bulk DOS event with relationships and indicators](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/bulk_create_relationships)

Deprecated

cloudforce\_one.threat\_events.bulk\_create\_relationships(ThreatEventBulkCreateRelationshipsParams\*\*kwargs) -> [ThreatEventBulkCreateRelationshipsResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/create/bulk/relationships

##### ModelsExpand Collapse

<details>

<summary>

List\[ThreatEventListResponseItem]

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)>)

<details>

<summary>

class ThreatEventGetResponse: …

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)>)

<details>

<summary>

class ThreatEventCreateResponse: …

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)>)

<details>

<summary>

class ThreatEventEditResponse: …

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)>)

<details>

<summary>

class ThreatEventBulkCreateResponse: …

Detailed result of bulk event creation with auto-tag management

</summary>

created\_events\_count: float

Number of events created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdEventsCount">Link to this property</a>

created\_tags\_count: float

Number of new tags created in SoT

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdTagsCount">Link to this property</a>

error\_count: float

Number of errors encountered

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20errorCount">Link to this property</a>

queued\_indicators\_count: float

Number of indicators queued for async processing

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20queuedIndicatorsCount">Link to this property</a>

create\_bulk\_events\_request\_id: Optional\[str]

Correlation ID for async indicator processing

formatuuid

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createBulkEventsRequestId">Link to this property</a>

<details>

<summary>

created\_events: Optional\[List\[CreatedEvent]]

Array of created events with UUIDs and shard locations. Only present when includeCreatedEvents=true

</summary>

event\_index: float

Original index in the input data array

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdEvents%20%3E%20(items)%20%3E%20(property)%20eventIndex">Link to this property</a>

shard\_id: str

Dataset ID of the shard where the event was created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdEvents%20%3E%20(items)%20%3E%20(property)%20shardId">Link to this property</a>

uuid: str

UUID of the created event

formatuuid

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdEvents%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdEvents">Link to this property</a>

<details>

<summary>

errors: Optional\[List\[Error]]

Array of error details

</summary>

error: str

Error message

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

event\_index: float

Index of the event that caused the error

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20eventIndex">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)>)

<details>

<summary>

class ThreatEventBulkCreateRelationshipsResponse: …

Result of bulk relationship creation operation

</summary>

created\_events\_count: float

Number of events created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20createdEventsCount">Link to this property</a>

created\_indicators\_count: float

Number of indicators created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20createdIndicatorsCount">Link to this property</a>

created\_relationships\_count: float

Number of relationships created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20createdRelationshipsCount">Link to this property</a>

error\_count: float

Number of errors encountered

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20errorCount">Link to this property</a>

<details>

<summary>

errors: Optional\[List\[Error]]

Array of error details

</summary>

error: str

Error message

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

event\_index: float

Index of the event that caused the error

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20eventIndex">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsAggregate

##### [Aggregate events by single or multiple columns with optional date filtering](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/aggregate/methods/list)

cloudforce\_one.threat\_events.aggregate.list(AggregateListParams\*\*kwargs) -> [AggregateListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/aggregate

##### ModelsExpand Collapse

<details>

<summary>

class AggregateListResponse: …

</summary>

aggregate\_by: str

Column(s) that were aggregated by

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregateBy">Link to this property</a>

<details>

<summary>

aggregations: List\[Aggregation]

Array of aggregation results with dynamic fields based on aggregateBy columns

</summary>

count: float

Number of events for this aggregation

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregations%20%3E%20(items)%20%3E%20(property)%20count">Link to this property</a>

date: Optional\[str]

Date (if groupByDate is true)

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregations%20%3E%20(items)%20%3E%20(property)%20date">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregations">Link to this property</a>

total: float

Total number of events in the aggregation

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20total">Link to this property</a>

<details>

<summary>

date\_range: Optional\[DateRange]

Date range used for filtering

</summary>

end\_date: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20dateRange%20%3E%20(property)%20endDate">Link to this property</a>

start\_date: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20dateRange%20%3E%20(property)%20startDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20dateRange">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsGraphql

##### [GraphQL endpoint for event aggregation](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/graphql/methods/create)

cloudforce\_one.threat\_events.graphql.create(GraphqlCreateParams\*\*kwargs) -> [GraphqlCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.graphql%20%3E%20(model)%20graphql_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/graphql

##### ModelsExpand Collapse

<details>

<summary>

class GraphqlCreateResponse: …

</summary>

data: Optional\[object]

<a href="#(resource)%20cloudforce_one.threat_events.graphql%20%3E%20(model)%20graphql_create_response%20%3E%20(schema)%20%3E%20(property)%20data">Link to this property</a>

errors: Optional\[List\[object]]

<a href="#(resource)%20cloudforce_one.threat_events.graphql%20%3E%20(model)%20graphql_create_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.graphql%20%3E%20(model)%20graphql_create_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsGraph

##### [Query graph neighborhood from R2 Data Catalog](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/graph/methods/list)

cloudforce\_one.threat\_events.graph.list(GraphListParams\*\*kwargs) -> [GraphListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/graph

##### ModelsExpand Collapse

<details>

<summary>

class GraphListResponse: …

</summary>

<details>

<summary>

edges: List\[Edge]

</summary>

id: str

Deterministic composite edge id (source→target:relationshipType)

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

relationship\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20relationshipType">Link to this property</a>

source: str

Compact id of the source node (type:uuid)

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

source\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20sourceId">Link to this property</a>

source\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20sourceType">Link to this property</a>

target: str

Compact id of the target node (type:uuid)

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20target">Link to this property</a>

target\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20targetId">Link to this property</a>

target\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20targetType">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges">Link to this property</a>

node: Optional\[Dict\[str, object]]

Focal node object (legacy single-seed). Null when unavailable.

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20node">Link to this property</a>

nodes: List\[Dict\[str, object]]

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20nodes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsQueries

##### [List all saved event queries](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/list)

cloudforce\_one.threat\_events.queries.list(QueryListParams\*\*kwargs) -> [QueryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/queries

##### [Create a saved event query](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/create)

cloudforce\_one.threat\_events.queries.create(QueryCreateParams\*\*kwargs) -> [QueryCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/queries/create

##### [Read a saved event query](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/get)

cloudforce\_one.threat\_events.queries.get(intquery\_id, QueryGetParams\*\*kwargs) -> [QueryGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/queries/{query\_id}

##### [Update a saved event query](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/edit)

cloudforce\_one.threat\_events.queries.edit(intquery\_id, QueryEditParams\*\*kwargs) -> [QueryEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/queries/{query\_id}

##### [Delete a saved event query](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/delete)

cloudforce\_one.threat\_events.queries.delete(intquery\_id, QueryDeleteParams\*\*kwargs)

DELETE/accounts/{account\_id}/cloudforce-one/events/queries/{query\_id}

##### ModelsExpand Collapse

<details>

<summary>

List\[QueryListResponseItem]

</summary>

id: int

Unique identifier for the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

account\_id: int

Account ID

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20account_id">Link to this property</a>

alert\_enabled: bool

Whether alerts are enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20alert_enabled">Link to this property</a>

alert\_rollup\_enabled: bool

Whether alert rollup is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20alert_rollup_enabled">Link to this property</a>

created\_at: str

Creation timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

name: str

Name of the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

query\_json: str

JSON string containing the query parameters

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20query_json">Link to this property</a>

rule\_enabled: bool

Whether rule is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20rule_enabled">Link to this property</a>

updated\_at: str

Last update timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20updated_at">Link to this property</a>

user\_email: str

Email of the user who created the query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20user_email">Link to this property</a>

custom\_threat\_feed\_id: Optional\[int]

Intel Indicator Feed ID (numeric)

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20custom_threat_feed_id">Link to this property</a>

rule\_list\_id: Optional\[str]

WAF rules list ID for blocking

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20rule_list_id">Link to this property</a>

rule\_scope: Optional\[str]

Scope for the rule

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20rule_scope">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)>)

<details>

<summary>

class QueryCreateResponse: …

</summary>

id: int

Unique identifier for the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: int

Account ID

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20account_id">Link to this property</a>

alert\_enabled: bool

Whether alerts are enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20alert_enabled">Link to this property</a>

alert\_rollup\_enabled: bool

Whether alert rollup is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20alert_rollup_enabled">Link to this property</a>

created\_at: str

Creation timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

name: str

Name of the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

query\_json: str

JSON string containing the query parameters

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20query_json">Link to this property</a>

rule\_enabled: bool

Whether rule is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20rule_enabled">Link to this property</a>

updated\_at: str

Last update timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

user\_email: str

Email of the user who created the query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20user_email">Link to this property</a>

custom\_threat\_feed\_id: Optional\[int]

Intel Indicator Feed ID (numeric)

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20custom_threat_feed_id">Link to this property</a>

rule\_list\_id: Optional\[str]

WAF rules list ID for blocking

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20rule_list_id">Link to this property</a>

rule\_scope: Optional\[str]

Scope for the rule

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20rule_scope">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)>)

<details>

<summary>

class QueryGetResponse: …

</summary>

id: int

Unique identifier for the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: int

Account ID

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20account_id">Link to this property</a>

alert\_enabled: bool

Whether alerts are enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20alert_enabled">Link to this property</a>

alert\_rollup\_enabled: bool

Whether alert rollup is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20alert_rollup_enabled">Link to this property</a>

created\_at: str

Creation timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

name: str

Name of the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

query\_json: str

JSON string containing the query parameters

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20query_json">Link to this property</a>

rule\_enabled: bool

Whether rule is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20rule_enabled">Link to this property</a>

updated\_at: str

Last update timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

user\_email: str

Email of the user who created the query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20user_email">Link to this property</a>

custom\_threat\_feed\_id: Optional\[int]

Intel Indicator Feed ID (numeric)

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20custom_threat_feed_id">Link to this property</a>

rule\_list\_id: Optional\[str]

WAF rules list ID for blocking

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20rule_list_id">Link to this property</a>

rule\_scope: Optional\[str]

Scope for the rule

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20rule_scope">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)>)

<details>

<summary>

class QueryEditResponse: …

</summary>

id: int

Unique identifier for the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: int

Account ID

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20account_id">Link to this property</a>

alert\_enabled: bool

Whether alerts are enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20alert_enabled">Link to this property</a>

alert\_rollup\_enabled: bool

Whether alert rollup is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20alert_rollup_enabled">Link to this property</a>

created\_at: str

Creation timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

name: str

Name of the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

query\_json: str

JSON string containing the query parameters

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20query_json">Link to this property</a>

rule\_enabled: bool

Whether rule is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20rule_enabled">Link to this property</a>

updated\_at: str

Last update timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

user\_email: str

Email of the user who created the query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20user_email">Link to this property</a>

custom\_threat\_feed\_id: Optional\[int]

Intel Indicator Feed ID (numeric)

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20custom_threat_feed_id">Link to this property</a>

rule\_list\_id: Optional\[str]

WAF rules list ID for blocking

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20rule_list_id">Link to this property</a>

rule\_scope: Optional\[str]

Scope for the rule

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20rule_scope">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsRelationships

##### [Filter and list events related to specific event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/relationships/methods/list)

Deprecated

cloudforce\_one.threat\_events.relationships.list(strevent\_id, RelationshipListParams\*\*kwargs) -> [RelationshipListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/{event\_id}/relationships

##### ModelsExpand Collapse

<details>

<summary>

List\[RelationshipListResponseItem]

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsIndicators

##### [Lists indicators across multiple datasets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/methods/list)

cloudforce\_one.threat\_events.indicators.list(IndicatorListParams\*\*kwargs) -> [IndicatorListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/indicators

##### ModelsExpand Collapse

<details>

<summary>

class IndicatorListResponse: …

</summary>

<details>

<summary>

properties: Properties

</summary>

<details>

<summary>

completeness: PropertiesCompleteness

</summary>

<details>

<summary>

properties: PropertiesCompletenessProperties

</summary>

<details>

<summary>

complete: PropertiesCompletenessPropertiesComplete

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20complete%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20complete">Link to this property</a>

<details>

<summary>

failed\_datasets: PropertiesCompletenessPropertiesFailedDatasets

</summary>

<details>

<summary>

items: PropertiesCompletenessPropertiesFailedDatasetsItems

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedDatasets%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedDatasets%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedDatasets%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedDatasets">Link to this property</a>

<details>

<summary>

failed\_shards: PropertiesCompletenessPropertiesFailedShards

</summary>

<details>

<summary>

items: PropertiesCompletenessPropertiesFailedShardsItems

</summary>

<details>

<summary>

properties: PropertiesCompletenessPropertiesFailedShardsItemsProperties

</summary>

<details>

<summary>

dataset\_id: PropertiesCompletenessPropertiesFailedShardsItemsPropertiesDatasetID

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20properties%20%3E%20(property)%20datasetId%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20properties%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

shard\_id: PropertiesCompletenessPropertiesFailedShardsItemsPropertiesShardID

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20properties%20%3E%20(property)%20shardId%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20properties%20%3E%20(property)%20shardId">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20properties">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards">Link to this property</a>

<details>

<summary>

warnings: PropertiesCompletenessPropertiesWarnings

</summary>

<details>

<summary>

items: PropertiesCompletenessPropertiesWarningsItems

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20warnings%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20warnings%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20warnings%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20warnings">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness">Link to this property</a>

<details>

<summary>

indicators: PropertiesIndicators

</summary>

<details>

<summary>

items: PropertiesIndicatorsItems

</summary>

created\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20createdAt">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20indicatorType">Link to this property</a>

<details>

<summary>

sources: List\[PropertiesIndicatorsItemsSource]

RSS article sources from which this indicator was extracted.

</summary>

resource\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20resourceId">Link to this property</a>

resource\_type: Literal\["article"]

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20resourceType">Link to this property</a>

system: Literal\["threat-signals"]

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20system">Link to this property</a>

title: Optional\[str]

Threat Signals article title; null for historical provenance without a stored title.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20title">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20sources">Link to this property</a>

updated\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20updatedAt">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20value">Link to this property</a>

dataset\_id: Optional\[str]

The dataset ID this indicator belongs to. Included in list responses.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

related\_events: Optional\[List\[PropertiesIndicatorsItemsRelatedEvent]]

Related events, capped by <code>relatedEventsLimit</code> (default 2). Check <code>relatedEventsHasMore</code> to detect a capped list; pass <code>relatedEventsLimit=-1</code> to retrieve all of them.

</summary>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

event\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventId">Link to this property</a>

event\_date: Optional\[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20relatedEvents">Link to this property</a>

related\_events\_has\_more: Optional\[bool]

True when this indicator appears in more events than <code>relatedEvents</code> contains because <code>relatedEventsLimit</code> capped the list. Pass <code>relatedEventsLimit=-1</code> to retrieve every related event.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20relatedEventsHasMore">Link to this property</a>

<details>

<summary>

tags: Optional\[List\[PropertiesIndicatorsItemsTag]]

</summary>

category\_id: Optional\[str]

The UUID of the tag category, or null when the tag is uncategorized.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tags">Link to this property</a>

tlp: Optional\[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators">Link to this property</a>

<details>

<summary>

pagination: PropertiesPagination

</summary>

<details>

<summary>

properties: PropertiesPaginationProperties

</summary>

<details>

<summary>

count: PropertiesPaginationPropertiesCount

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20count%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20count">Link to this property</a>

<details>

<summary>

cursor: PropertiesPaginationPropertiesCursor

</summary>

description: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20cursor%20%3E%20(property)%20description">Link to this property</a>

nullable: bool

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20cursor%20%3E%20(property)%20nullable">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20cursor%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20cursor">Link to this property</a>

<details>

<summary>

has\_more: PropertiesPaginationPropertiesHasMore

</summary>

description: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20has_more%20%3E%20(property)%20description">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20has_more%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20has_more">Link to this property</a>

<details>

<summary>

page: PropertiesPaginationPropertiesPage

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20page%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20page">Link to this property</a>

<details>

<summary>

per\_page: PropertiesPaginationPropertiesPerPage

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20per_page%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20per_page">Link to this property</a>

<details>

<summary>

total\_count: PropertiesPaginationPropertiesTotalCount

</summary>

description: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count%20%3E%20(property)%20description">Link to this property</a>

nullable: bool

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count%20%3E%20(property)%20nullable">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count">Link to this property</a>

<details>

<summary>

total\_count\_is\_exact: PropertiesPaginationPropertiesTotalCountIsExact

</summary>

description: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count_is_exact%20%3E%20(property)%20description">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count_is_exact%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count_is_exact">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsIndicatorsAggregate

##### [Aggregate indicators by column(s)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/aggregate/methods/list)

cloudforce\_one.threat\_events.indicators.aggregate.list(AggregateListParams\*\*kwargs) -> [AggregateListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/indicators/aggregate

##### ModelsExpand Collapse

<details>

<summary>

class AggregateListResponse: …

</summary>

aggregate\_by: str

Column(s) that were aggregated by

<a href="#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregateBy">Link to this property</a>

<details>

<summary>

aggregations: List\[Aggregation]

Array of aggregation results with dynamic fields based on aggregateBy columns

</summary>

count: float

Number of indicators for this aggregation

<a href="#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregations%20%3E%20(items)%20%3E%20(property)%20count">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregations">Link to this property</a>

failed\_datasets: float

Number of datasets whose aggregation failed and were excluded from the result

<a href="#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20failedDatasets">Link to this property</a>

total: float

Total count in the aggregation: indicator rows when measure=indicators, or linked-event rows when measure=relationships

<a href="#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20total">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsIndicatorsTypes

##### [Lists indicator types across multiple datasets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/types/methods/list)

cloudforce\_one.threat\_events.indicators.types.list(TypeListParams\*\*kwargs) -> [TypeListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators.types%20%3E%20(model)%20type_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/indicator-types

##### ModelsExpand Collapse

<details>

<summary>

class TypeListResponse: …

</summary>

<details>

<summary>

items: Items

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.types%20%3E%20(model)%20type_list_response%20%3E%20(schema)%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.types%20%3E%20(model)%20type_list_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.types%20%3E%20(model)%20type_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators.types%20%3E%20(model)%20type_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsIndicatorsBy Dataset

##### [Lists indicators](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/by_dataset/methods/list)

Deprecated

cloudforce\_one.threat\_events.indicators.by\_dataset.list(strdataset\_id, ByDatasetListParams\*\*kwargs) -> [ByDatasetListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/indicators

##### [Reads an indicator](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/by_dataset/methods/get)

cloudforce\_one.threat\_events.indicators.by\_dataset.get(strindicator\_id, ByDatasetGetParams\*\*kwargs) -> [ByDatasetGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/indicators/{indicator\_id}

##### ModelsExpand Collapse

<details>

<summary>

class ByDatasetListResponse: …

</summary>

<details>

<summary>

indicators: List\[Indicator]

</summary>

created\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20createdAt">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

<details>

<summary>

sources: List\[IndicatorSource]

RSS article sources from which this indicator was extracted.

</summary>

resource\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20resourceId">Link to this property</a>

resource\_type: Literal\["article"]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20resourceType">Link to this property</a>

system: Literal\["threat-signals"]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20system">Link to this property</a>

title: Optional\[str]

Threat Signals article title; null for historical provenance without a stored title.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20title">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20sources">Link to this property</a>

updated\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20updatedAt">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

dataset\_id: Optional\[str]

The dataset ID this indicator belongs to. Included in list responses.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

related\_events: Optional\[List\[IndicatorRelatedEvent]]

Related events, capped by <code>relatedEventsLimit</code> (default 2). Check <code>relatedEventsHasMore</code> to detect a capped list; pass <code>relatedEventsLimit=-1</code> to retrieve all of them.

</summary>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

event\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventId">Link to this property</a>

event\_date: Optional\[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents">Link to this property</a>

related\_events\_has\_more: Optional\[bool]

True when this indicator appears in more events than <code>relatedEvents</code> contains because <code>relatedEventsLimit</code> capped the list. Pass <code>relatedEventsLimit=-1</code> to retrieve every related event.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEventsHasMore">Link to this property</a>

<details>

<summary>

tags: Optional\[List\[IndicatorTag]]

</summary>

category\_id: Optional\[str]

The UUID of the tag category, or null when the tag is uncategorized.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

tlp: Optional\[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators">Link to this property</a>

<details>

<summary>

pagination: Pagination

</summary>

page: float

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20page">Link to this property</a>

page\_size: float

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20pageSize">Link to this property</a>

total\_count: float

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalCount">Link to this property</a>

total\_pages: float

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalPages">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

<details>

<summary>

class ByDatasetGetResponse: …

</summary>

created\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20createdAt">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20indicatorType">Link to this property</a>

updated\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20updatedAt">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

dataset\_id: Optional\[str]

The dataset ID this indicator belongs to. Included in list responses.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

related\_events: Optional\[List\[RelatedEvent]]

Related events, capped by <code>relatedEventsLimit</code> (default 2). Check <code>relatedEventsHasMore</code> to detect a capped list; pass <code>relatedEventsLimit=-1</code> to retrieve all of them.

</summary>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

event\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventId">Link to this property</a>

event\_date: Optional\[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20relatedEvents">Link to this property</a>

related\_events\_has\_more: Optional\[bool]

True when this indicator appears in more events than <code>relatedEvents</code> contains because <code>relatedEventsLimit</code> capped the list. Pass <code>relatedEventsLimit=-1</code> to retrieve every related event.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20relatedEventsHasMore">Link to this property</a>

<details>

<summary>

tags: Optional\[List\[Tag]]

</summary>

category\_id: Optional\[str]

The UUID of the tag category, or null when the tag is uncategorized.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

tlp: Optional\[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsIndicatorsBy DatasetTags

##### [List mirrored tags for an indicator dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/by_dataset/subresources/tags/methods/list)

cloudforce\_one.threat\_events.indicators.by\_dataset.tags.list(strdataset\_id, TagListParams\*\*kwargs) -> [TagListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators.by_dataset.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/indicators/tags

##### ModelsExpand Collapse

List\[object]

Array of mirror tag rows

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators.by_dataset.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsAttackers

##### [Lists attackers across multiple datasets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/attackers/methods/list)

cloudforce\_one.threat\_events.attackers.list(AttackerListParams\*\*kwargs) -> [AttackerListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.attackers%20%3E%20(model)%20attacker_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/attackers

##### ModelsExpand Collapse

<details>

<summary>

class AttackerListResponse: …

</summary>

<details>

<summary>

items: Items

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.attackers%20%3E%20(model)%20attacker_list_response%20%3E%20(schema)%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.attackers%20%3E%20(model)%20attacker_list_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.attackers%20%3E%20(model)%20attacker_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.attackers%20%3E%20(model)%20attacker_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsCategories

##### [Lists categories across multiple datasets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/list)

cloudforce\_one.threat\_events.categories.list(CategoryListParams\*\*kwargs) -> [CategoryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/categories

##### [Reads a category](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/get)

Deprecated

cloudforce\_one.threat\_events.categories.get(strcategory\_id, CategoryGetParams\*\*kwargs) -> [CategoryGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/categories/{category\_id}

##### [Creates a new category](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/create)

cloudforce\_one.threat\_events.categories.create(CategoryCreateParams\*\*kwargs) -> [CategoryCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/categories/create

##### [Updates a category](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/edit)

Deprecated

cloudforce\_one.threat\_events.categories.edit(strcategory\_id, CategoryEditParams\*\*kwargs) -> [CategoryEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/categories/{category\_id}

##### [Deletes a category](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/delete)

Deprecated

cloudforce\_one.threat\_events.categories.delete(strcategory\_id, CategoryDeleteParams\*\*kwargs) -> [CategoryDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/categories/{category\_id}

##### ModelsExpand Collapse

<details>

<summary>

List\[CategoryListResponseItem]

</summary>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20killChain">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

mitre\_attack: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreCapec">Link to this property</a>

shortname: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20shortname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryGetResponse: …

</summary>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

mitre\_attack: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

shortname: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20shortname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryCreateResponse: …

</summary>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

mitre\_attack: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

shortname: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20shortname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryEditResponse: …

</summary>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

mitre\_attack: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

shortname: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20shortname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryDeleteResponse: …

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsCategoriesCatalog

##### [Lists categories](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/subresources/catalog/methods/list)

cloudforce\_one.threat\_events.categories.catalog.list(CatalogListParams\*\*kwargs) -> [CatalogListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/categories/catalog

##### ModelsExpand Collapse

<details>

<summary>

List\[CatalogListResponseItem]

</summary>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20killChain">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

mitre\_attack: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreCapec">Link to this property</a>

shortname: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20shortname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsCountries

##### [Retrieves countries information for all countries](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/countries/methods/list)

cloudforce\_one.threat\_events.countries.list(CountryListParams\*\*kwargs) -> [CountryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/countries

##### ModelsExpand Collapse

<details>

<summary>

List\[CountryListResponseItem]

</summary>

<details>

<summary>

result: List\[CountryListResponseItemResult]

</summary>

alpha2: str

<a href="#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20result%20%3E%20(items)%20%3E%20(property)%20alpha2">Link to this property</a>

alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20result%20%3E%20(items)%20%3E%20(property)%20alpha3">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20result%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20result">Link to this property</a>

success: str

<a href="#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsCrons

#### Cloudforce OneThreat EventsDatasets

##### [Lists all datasets in an account](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/list)

cloudforce\_one.threat\_events.datasets.list(DatasetListParams\*\*kwargs) -> [DatasetListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset

##### [Reads a dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/get)

cloudforce\_one.threat\_events.datasets.get(strdataset\_id, DatasetGetParams\*\*kwargs) -> [DatasetGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}

##### [Creates a dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/create)

cloudforce\_one.threat\_events.datasets.create(DatasetCreateParams\*\*kwargs) -> [DatasetCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/dataset/create

##### [Updates an existing dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/edit)

cloudforce\_one.threat\_events.datasets.edit(strdataset\_id, DatasetEditParams\*\*kwargs) -> [DatasetEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}

##### [Delete a dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/delete)

cloudforce\_one.threat\_events.datasets.delete(strdataset\_id, DatasetDeleteParams\*\*kwargs) -> [DatasetDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}

##### [Reads raw data for an event by UUID](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/raw)

Deprecated

cloudforce\_one.threat\_events.datasets.raw(strevent\_id, DatasetRawParams\*\*kwargs) -> [DatasetRawResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/raw/{dataset\_id}/{event\_id}

##### ModelsExpand Collapse

<details>

<summary>

List\[DatasetListResponseItem]

</summary>

<details>

<summary>

indicator\_write\_mode: Literal\["read\_only", "create\_only", "full"]

Effective indicator mutation capability after account/dataset authorization and dataset storage capability are applied. API Gateway method permissions are separate and must also allow the requested operation.

</summary>

One of the following:

"read\_only"

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorWriteMode%20%3E%20(member)%200">Link to this property</a>

"create\_only"

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorWriteMode%20%3E%20(member)%201">Link to this property</a>

"full"

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorWriteMode%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorWriteMode">Link to this property</a>

is\_analytics: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20isAnalytics">Link to this property</a>

is\_public: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20isPublic">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

deleted\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20deletedAt">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)>)

<details>

<summary>

class DatasetGetResponse: …

</summary>

is\_analytics: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20isAnalytics">Link to this property</a>

is\_public: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20isPublic">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)>)

<details>

<summary>

class DatasetCreateResponse: …

</summary>

is\_analytics: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)%20%3E%20(property)%20isAnalytics">Link to this property</a>

is\_public: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)%20%3E%20(property)%20isPublic">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)>)

<details>

<summary>

class DatasetEditResponse: …

</summary>

is\_analytics: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)%20%3E%20(property)%20isAnalytics">Link to this property</a>

is\_public: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)%20%3E%20(property)%20isPublic">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)>)

<details>

<summary>

class DatasetDeleteResponse: …

</summary>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_delete_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_delete_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_delete_response%20%3E%20(schema)>)

<details>

<summary>

class DatasetRawResponse: …

</summary>

id: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20accountId">Link to this property</a>

created: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

data: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20data">Link to this property</a>

source: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20source">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsDatasetsHealth

#### Cloudforce OneThreat EventsDatasetsEvents

##### [Reads an event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/subresources/events/methods/get)

cloudforce\_one.threat\_events.datasets.events.get(strevent\_id, EventGetParams\*\*kwargs) -> [EventGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/events/{event\_id}

##### ModelsExpand Collapse

<details>

<summary>

class EventGetResponse: …

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsRaw

##### [Reads data for a raw event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/raw/methods/get)

cloudforce\_one.threat\_events.raw.get(strraw\_id, RawGetParams\*\*kwargs) -> [RawGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/{event\_id}/raw/{raw\_id}

##### [Updates a raw event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/raw/methods/edit)

cloudforce\_one.threat\_events.raw.edit(strraw\_id, RawEditParams\*\*kwargs) -> [RawEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/{event\_id}/raw/{raw\_id}

##### ModelsExpand Collapse

<details>

<summary>

class RawGetResponse: …

</summary>

id: str

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: float

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20accountId">Link to this property</a>

created: str

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

data: object

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20data">Link to this property</a>

source: str

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20source">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)>)

<details>

<summary>

class RawEditResponse: …

</summary>

id: str

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

data: object

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_edit_response%20%3E%20(schema)%20%3E%20(property)%20data">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_edit_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsRelate

##### [Removes an event reference](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/relate/methods/delete)

cloudforce\_one.threat\_events.relate.delete(strevent\_id, RelateDeleteParams\*\*kwargs) -> [RelateDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.relate%20%3E%20(model)%20relate_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/relate/{event\_id}

##### ModelsExpand Collapse

<details>

<summary>

class RelateDeleteResponse: …

</summary>

success: bool

<a href="#(resource)%20cloudforce_one.threat_events.relate%20%3E%20(model)%20relate_delete_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.relate%20%3E%20(model)%20relate_delete_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsTags

##### [Lists all tags (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/list)

cloudforce\_one.threat\_events.tags.list(TagListParams\*\*kwargs) -> [TagListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/tags

##### [Creates a new tag](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/create)

cloudforce\_one.threat\_events.tags.create(TagCreateParams\*\*kwargs) -> [TagCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/tags/create

##### [Updates a tag (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/edit)

cloudforce\_one.threat\_events.tags.edit(strtag\_uuid, TagEditParams\*\*kwargs) -> [TagEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/tags/{tag\_uuid}

##### [Deletes a tag (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/delete)

cloudforce\_one.threat\_events.tags.delete(strtag\_uuid, TagDeleteParams\*\*kwargs) -> [TagDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/tags/{tag\_uuid}

##### ModelsExpand Collapse

<details>

<summary>

class TagListResponse: …

</summary>

<details>

<summary>

pagination: Pagination

</summary>

page: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20page">Link to this property</a>

page\_size: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20pageSize">Link to this property</a>

total\_count: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalCount">Link to this property</a>

total\_pages: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalPages">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination">Link to this property</a>

<details>

<summary>

tags: List\[Tag]

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

active\_duration: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration">Link to this property</a>

<details>

<summary>

active\_duration\_annotated: Optional\[TagActiveDurationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated">Link to this property</a>

actor\_category: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory">Link to this property</a>

<details>

<summary>

actor\_category\_annotated: Optional\[TagActorCategoryAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated">Link to this property</a>

<details>

<summary>

aliases: Optional\[List\[TagAlias]]

Structured aliases ({ value, confidence 1-10, tlp }). Public: returned to all accounts with per-entry TLP filtering (entries with tlp: purple are removed for non-CFONE accounts).

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases">Link to this property</a>

alias\_group\_names: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliasGroupNames">Link to this property</a>

alias\_group\_names\_internal: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliasGroupNamesInternal">Link to this property</a>

attribution\_organization: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization">Link to this property</a>

<details>

<summary>

attribution\_organization\_annotated: Optional\[TagAttributionOrganizationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

category\_uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryUuid">Link to this property</a>

confidence: Optional\[int]

Overall tag confidence (1-10).

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20createdAt">Link to this property</a>

date\_of\_discovery: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20dateOfDiscovery">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

external\_reference\_links: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferenceLinks">Link to this property</a>

<details>

<summary>

external\_references: Optional\[List\[TagExternalReference]]

Structured external references ({ url, description }). Public: returned to all accounts.

</summary>

url: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20url">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences">Link to this property</a>

<details>

<summary>

external\_references\_annotated: Optional\[List\[TagExternalReferencesAnnotated]]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated">Link to this property</a>

<details>

<summary>

internal\_aliases: Optional\[List\[TagInternalAlias]]

Owner-private structured aliases ({ value, confidence 1-10, tlp }). Returned to the owning account and omitted from shared-catalog non-owner responses.

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases">Link to this property</a>

internal\_description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalDescription">Link to this property</a>

last\_seen: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20lastSeen">Link to this property</a>

motive: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive">Link to this property</a>

<details>

<summary>

motive\_annotated: Optional\[TagMotiveAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated">Link to this property</a>

opsec\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel">Link to this property</a>

<details>

<summary>

opsec\_level\_annotated: Optional\[TagOpsecLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated">Link to this property</a>

origin\_country\_iso: Optional\[str]

ISO country code (alpha-2 or alpha-3). Normalized to uppercase on read. Null when stored value is blank/whitespace.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO">Link to this property</a>

<details>

<summary>

origin\_country\_iso\_annotated: Optional\[TagOriginCountryISOAnnotated]

</summary>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated">Link to this property</a>

priority: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority">Link to this property</a>

<details>

<summary>

priority\_annotated: Optional\[TagPriorityAnnotated]

</summary>

value: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Parsed custom field values. Null when the tag has no custom fields.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

sophistication\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel">Link to this property</a>

<details>

<summary>

sophistication\_level\_annotated: Optional\[TagSophisticationLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

Tag-level TLP handling marking.

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20updatedAt">Link to this property</a>

version: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20version">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)>)

<details>

<summary>

class TagCreateResponse: …

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

active\_duration: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration">Link to this property</a>

<details>

<summary>

active\_duration\_annotated: Optional\[ActiveDurationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated">Link to this property</a>

actor\_category: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory">Link to this property</a>

<details>

<summary>

actor\_category\_annotated: Optional\[ActorCategoryAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated">Link to this property</a>

<details>

<summary>

aliases: Optional\[List\[Alias]]

Structured aliases ({ value, confidence 1-10, tlp }). Public: returned to all accounts with per-entry TLP filtering (entries with tlp: purple are removed for non-CFONE accounts).

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases">Link to this property</a>

alias\_group\_names: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliasGroupNames">Link to this property</a>

alias\_group\_names\_internal: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliasGroupNamesInternal">Link to this property</a>

attribution\_organization: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization">Link to this property</a>

<details>

<summary>

attribution\_organization\_annotated: Optional\[AttributionOrganizationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20categoryName">Link to this property</a>

category\_uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20categoryUuid">Link to this property</a>

confidence: Optional\[int]

Overall tag confidence (1-10).

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20confidence">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20createdAt">Link to this property</a>

date\_of\_discovery: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20dateOfDiscovery">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

external\_reference\_links: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferenceLinks">Link to this property</a>

<details>

<summary>

external\_references: Optional\[List\[ExternalReference]]

Structured external references ({ url, description }). Public: returned to all accounts.

</summary>

url: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20url">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences">Link to this property</a>

<details>

<summary>

external\_references\_annotated: Optional\[List\[ExternalReferencesAnnotated]]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated">Link to this property</a>

<details>

<summary>

internal\_aliases: Optional\[List\[InternalAlias]]

Owner-private structured aliases ({ value, confidence 1-10, tlp }). Returned to the owning account and omitted from shared-catalog non-owner responses.

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases">Link to this property</a>

internal\_description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalDescription">Link to this property</a>

last\_seen: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20lastSeen">Link to this property</a>

motive: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive">Link to this property</a>

<details>

<summary>

motive\_annotated: Optional\[MotiveAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated">Link to this property</a>

opsec\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel">Link to this property</a>

<details>

<summary>

opsec\_level\_annotated: Optional\[OpsecLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated">Link to this property</a>

origin\_country\_iso: Optional\[str]

ISO country code (alpha-2 or alpha-3). Normalized to uppercase on read. Null when stored value is blank/whitespace.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO">Link to this property</a>

<details>

<summary>

origin\_country\_iso\_annotated: Optional\[OriginCountryISOAnnotated]

</summary>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated">Link to this property</a>

priority: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

<details>

<summary>

priority\_annotated: Optional\[PriorityAnnotated]

</summary>

value: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Parsed custom field values. Null when the tag has no custom fields.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20properties">Link to this property</a>

sophistication\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel">Link to this property</a>

<details>

<summary>

sophistication\_level\_annotated: Optional\[SophisticationLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

Tag-level TLP handling marking.

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20updatedAt">Link to this property</a>

version: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)>)

<details>

<summary>

class TagEditResponse: …

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

active\_duration: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration">Link to this property</a>

<details>

<summary>

active\_duration\_annotated: Optional\[ActiveDurationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated">Link to this property</a>

actor\_category: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory">Link to this property</a>

<details>

<summary>

actor\_category\_annotated: Optional\[ActorCategoryAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated">Link to this property</a>

<details>

<summary>

aliases: Optional\[List\[Alias]]

Structured aliases ({ value, confidence 1-10, tlp }). Public: returned to all accounts with per-entry TLP filtering (entries with tlp: purple are removed for non-CFONE accounts).

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases">Link to this property</a>

alias\_group\_names: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliasGroupNames">Link to this property</a>

alias\_group\_names\_internal: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliasGroupNamesInternal">Link to this property</a>

attribution\_organization: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization">Link to this property</a>

<details>

<summary>

attribution\_organization\_annotated: Optional\[AttributionOrganizationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20categoryName">Link to this property</a>

category\_uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20categoryUuid">Link to this property</a>

confidence: Optional\[int]

Overall tag confidence (1-10).

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20confidence">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20createdAt">Link to this property</a>

date\_of\_discovery: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20dateOfDiscovery">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

external\_reference\_links: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferenceLinks">Link to this property</a>

<details>

<summary>

external\_references: Optional\[List\[ExternalReference]]

Structured external references ({ url, description }). Public: returned to all accounts.

</summary>

url: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20url">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences">Link to this property</a>

<details>

<summary>

external\_references\_annotated: Optional\[List\[ExternalReferencesAnnotated]]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated">Link to this property</a>

<details>

<summary>

internal\_aliases: Optional\[List\[InternalAlias]]

Owner-private structured aliases ({ value, confidence 1-10, tlp }). Returned to the owning account and omitted from shared-catalog non-owner responses.

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases">Link to this property</a>

internal\_description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalDescription">Link to this property</a>

last\_seen: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20lastSeen">Link to this property</a>

motive: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive">Link to this property</a>

<details>

<summary>

motive\_annotated: Optional\[MotiveAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated">Link to this property</a>

opsec\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel">Link to this property</a>

<details>

<summary>

opsec\_level\_annotated: Optional\[OpsecLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated">Link to this property</a>

origin\_country\_iso: Optional\[str]

ISO country code (alpha-2 or alpha-3). Normalized to uppercase on read. Null when stored value is blank/whitespace.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO">Link to this property</a>

<details>

<summary>

origin\_country\_iso\_annotated: Optional\[OriginCountryISOAnnotated]

</summary>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated">Link to this property</a>

priority: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

<details>

<summary>

priority\_annotated: Optional\[PriorityAnnotated]

</summary>

value: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Parsed custom field values. Null when the tag has no custom fields.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20properties">Link to this property</a>

sophistication\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel">Link to this property</a>

<details>

<summary>

sophistication\_level\_annotated: Optional\[SophisticationLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

Tag-level TLP handling marking.

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20updatedAt">Link to this property</a>

version: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)>)

<details>

<summary>

class TagDeleteResponse: …

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsTagsCategories

##### [Lists all tag categories (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/list)

cloudforce\_one.threat\_events.tags.categories.list(CategoryListParams\*\*kwargs) -> [CategoryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/tags/categories

##### [Creates a new tag category (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/create)

cloudforce\_one.threat\_events.tags.categories.create(CategoryCreateParams\*\*kwargs) -> [CategoryCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/tags/categories/create

##### [Updates a tag category (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/edit)

Deprecated

cloudforce\_one.threat\_events.tags.categories.edit(strcategory\_uuid, CategoryEditParams\*\*kwargs) -> [CategoryEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/tags/categories/{category\_uuid}

##### [Deletes a tag category (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/delete)

Deprecated

cloudforce\_one.threat\_events.tags.categories.delete(strcategory\_uuid, CategoryDeleteParams\*\*kwargs) -> [CategoryDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/tags/categories/{category\_uuid}

##### ModelsExpand Collapse

<details>

<summary>

class CategoryListResponse: …

</summary>

<details>

<summary>

categories: List\[Category]

</summary>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20createdAt">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

schema: Optional\[List\[CategorySchema]]

Parsed FieldDefinition\[] defining custom fields for this category, or null if none.

</summary>

key: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20key">Link to this property</a>

<details>

<summary>

kind: Literal\["string", "number", "enum", 3 more]

</summary>

One of the following:

"string"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%200">Link to this property</a>

"number"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%201">Link to this property</a>

"enum"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%202">Link to this property</a>

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%203">Link to this property</a>

"array"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%204">Link to this property</a>

"object"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind">Link to this property</a>

allowed\_values: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20allowedValues">Link to this property</a>

<details>

<summary>

annotations: Optional\[CategorySchemaAnnotations]

</summary>

confidence: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20confidence">Link to this property</a>

tlp: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations">Link to this property</a>

deprecated: Optional\[bool]

Marks a field as unavailable for new values while retaining its definition for historical values.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecated">Link to this property</a>

deprecated\_values: Optional\[List\[str]]

Enum values unavailable for new writes but retained in allowedValues for historical display.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecatedValues">Link to this property</a>

element: Optional\[object]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20element">Link to this property</a>

<details>

<summary>

enforcement: Optional\[Literal\["error", "warn", "off"]]

</summary>

One of the following:

"error"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%200">Link to this property</a>

"warn"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%201">Link to this property</a>

"off"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement">Link to this property</a>

<details>

<summary>

format: Optional\[Literal\["date", "url", "duration", "country"]]

</summary>

One of the following:

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%200">Link to this property</a>

"url"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%201">Link to this property</a>

"duration"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%202">Link to this property</a>

"country"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format">Link to this property</a>

label: Optional\[str]

maxLength128

minLength1

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20label">Link to this property</a>

max\_length: Optional\[int]

exclusiveMinimum

minimum0

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20maxLength">Link to this property</a>

<details>

<summary>

number\_constraint: Optional\[CategorySchemaNumberConstraint]

</summary>

integer: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20integer">Link to this property</a>

max: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20max">Link to this property</a>

min: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20min">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Map of property key to FieldDefinition for object fields. Required when kind is ‘object’. See FieldDefinition (recursive).

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

required: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20updatedAt">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryCreateResponse: …

</summary>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20createdAt">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

schema: Optional\[List\[Schema]]

Parsed FieldDefinition\[] defining custom fields for this category, or null if none.

</summary>

key: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20key">Link to this property</a>

<details>

<summary>

kind: Literal\["string", "number", "enum", 3 more]

</summary>

One of the following:

"string"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%200">Link to this property</a>

"number"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%201">Link to this property</a>

"enum"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%202">Link to this property</a>

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%203">Link to this property</a>

"array"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%204">Link to this property</a>

"object"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind">Link to this property</a>

allowed\_values: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20allowedValues">Link to this property</a>

<details>

<summary>

annotations: Optional\[SchemaAnnotations]

</summary>

confidence: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20confidence">Link to this property</a>

tlp: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations">Link to this property</a>

deprecated: Optional\[bool]

Marks a field as unavailable for new values while retaining its definition for historical values.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecated">Link to this property</a>

deprecated\_values: Optional\[List\[str]]

Enum values unavailable for new writes but retained in allowedValues for historical display.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecatedValues">Link to this property</a>

element: Optional\[object]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20element">Link to this property</a>

<details>

<summary>

enforcement: Optional\[Literal\["error", "warn", "off"]]

</summary>

One of the following:

"error"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%200">Link to this property</a>

"warn"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%201">Link to this property</a>

"off"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement">Link to this property</a>

<details>

<summary>

format: Optional\[Literal\["date", "url", "duration", "country"]]

</summary>

One of the following:

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%200">Link to this property</a>

"url"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%201">Link to this property</a>

"duration"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%202">Link to this property</a>

"country"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format">Link to this property</a>

label: Optional\[str]

maxLength128

minLength1

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20label">Link to this property</a>

max\_length: Optional\[int]

exclusiveMinimum

minimum0

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20maxLength">Link to this property</a>

<details>

<summary>

number\_constraint: Optional\[SchemaNumberConstraint]

</summary>

integer: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20integer">Link to this property</a>

max: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20max">Link to this property</a>

min: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20min">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Map of property key to FieldDefinition for object fields. Required when kind is ‘object’. See FieldDefinition (recursive).

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

required: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20updatedAt">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryEditResponse: …

</summary>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20createdAt">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

schema: Optional\[List\[Schema]]

Parsed FieldDefinition\[] defining custom fields for this category, or null if none.

</summary>

key: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20key">Link to this property</a>

<details>

<summary>

kind: Literal\["string", "number", "enum", 3 more]

</summary>

One of the following:

"string"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%200">Link to this property</a>

"number"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%201">Link to this property</a>

"enum"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%202">Link to this property</a>

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%203">Link to this property</a>

"array"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%204">Link to this property</a>

"object"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind">Link to this property</a>

allowed\_values: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20allowedValues">Link to this property</a>

<details>

<summary>

annotations: Optional\[SchemaAnnotations]

</summary>

confidence: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20confidence">Link to this property</a>

tlp: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations">Link to this property</a>

deprecated: Optional\[bool]

Marks a field as unavailable for new values while retaining its definition for historical values.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecated">Link to this property</a>

deprecated\_values: Optional\[List\[str]]

Enum values unavailable for new writes but retained in allowedValues for historical display.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecatedValues">Link to this property</a>

element: Optional\[object]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20element">Link to this property</a>

<details>

<summary>

enforcement: Optional\[Literal\["error", "warn", "off"]]

</summary>

One of the following:

"error"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%200">Link to this property</a>

"warn"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%201">Link to this property</a>

"off"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement">Link to this property</a>

<details>

<summary>

format: Optional\[Literal\["date", "url", "duration", "country"]]

</summary>

One of the following:

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%200">Link to this property</a>

"url"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%201">Link to this property</a>

"duration"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%202">Link to this property</a>

"country"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format">Link to this property</a>

label: Optional\[str]

maxLength128

minLength1

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20label">Link to this property</a>

max\_length: Optional\[int]

exclusiveMinimum

minimum0

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20maxLength">Link to this property</a>

<details>

<summary>

number\_constraint: Optional\[SchemaNumberConstraint]

</summary>

integer: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20integer">Link to this property</a>

max: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20max">Link to this property</a>

min: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20min">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Map of property key to FieldDefinition for object fields. Required when kind is ‘object’. See FieldDefinition (recursive).

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

required: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20updatedAt">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryDeleteResponse: …

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsTagsIndicators

##### [List indicators related to a tag](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/indicators/methods/list)

cloudforce\_one.threat\_events.tags.indicators.list(strtag\_uuid, IndicatorListParams\*\*kwargs) -> [IndicatorListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/tags/{tag\_uuid}/indicators

##### ModelsExpand Collapse

<details>

<summary>

class IndicatorListResponse: …

</summary>

<details>

<summary>

indicators: List\[Indicator]

</summary>

created\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20createdAt">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

updated\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20updatedAt">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

dataset\_id: Optional\[str]

The dataset ID this indicator belongs to. Included in list responses.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

related\_events: Optional\[List\[IndicatorRelatedEvent]]

Related events, capped by <code>relatedEventsLimit</code> (default 2). Check <code>relatedEventsHasMore</code> to detect a capped list; pass <code>relatedEventsLimit=-1</code> to retrieve all of them.

</summary>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

event\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventId">Link to this property</a>

event\_date: Optional\[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents">Link to this property</a>

related\_events\_has\_more: Optional\[bool]

True when this indicator appears in more events than <code>relatedEvents</code> contains because <code>relatedEventsLimit</code> capped the list. Pass <code>relatedEventsLimit=-1</code> to retrieve every related event.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEventsHasMore">Link to this property</a>

<details>

<summary>

tags: Optional\[List\[IndicatorTag]]

</summary>

category\_id: Optional\[str]

The UUID of the tag category, or null when the tag is uncategorized.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

tlp: Optional\[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators">Link to this property</a>

<details>

<summary>

pagination: Pagination

</summary>

page: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20page">Link to this property</a>

page\_size: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20pageSize">Link to this property</a>

total\_count: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalCount">Link to this property</a>

total\_pages: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalPages">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsTagsIndicatorsBy Dataset

##### [List indicators related to a tag within a dataset (deprecated)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/indicators/subresources/by_dataset/methods/list)

Deprecated

cloudforce\_one.threat\_events.tags.indicators.by\_dataset.list(strtag\_uuid, ByDatasetListParams\*\*kwargs) -> [ByDatasetListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/tags/{tag\_uuid}/indicators

##### ModelsExpand Collapse

<details>

<summary>

class ByDatasetListResponse: …

</summary>

<details>

<summary>

indicators: List\[Indicator]

</summary>

created\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20createdAt">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

updated\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20updatedAt">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

dataset\_id: Optional\[str]

The dataset ID this indicator belongs to. Included in list responses.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

related\_events: Optional\[List\[IndicatorRelatedEvent]]

Related events, capped by <code>relatedEventsLimit</code> (default 2). Check <code>relatedEventsHasMore</code> to detect a capped list; pass <code>relatedEventsLimit=-1</code> to retrieve all of them.

</summary>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

event\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventId">Link to this property</a>

event\_date: Optional\[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents">Link to this property</a>

related\_events\_has\_more: Optional\[bool]

True when this indicator appears in more events than <code>relatedEvents</code> contains because <code>relatedEventsLimit</code> capped the list. Pass <code>relatedEventsLimit=-1</code> to retrieve every related event.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEventsHasMore">Link to this property</a>

<details>

<summary>

tags: Optional\[List\[IndicatorTag]]

</summary>

category\_id: Optional\[str]

The UUID of the tag category, or null when the tag is uncategorized.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

tlp: Optional\[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators">Link to this property</a>

<details>

<summary>

pagination: Pagination

</summary>

page: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20page">Link to this property</a>

page\_size: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20pageSize">Link to this property</a>

total\_count: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalCount">Link to this property</a>

total\_pages: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalPages">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsEvent Tags

##### [Adds a tag to an event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/event_tags/methods/create)

cloudforce\_one.threat\_events.event\_tags.create(strevent\_id, EventTagCreateParams\*\*kwargs) -> [EventTagCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/event\_tag/{event\_id}/create

##### [Removes a tag from an event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/event_tags/methods/delete)

cloudforce\_one.threat\_events.event\_tags.delete(strevent\_id, EventTagDeleteParams\*\*kwargs) -> [EventTagDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/event\_tag/{event\_id}

##### ModelsExpand Collapse

<details>

<summary>

class EventTagCreateResponse: …

</summary>

success: bool

<a href="#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_create_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_create_response%20%3E%20(schema)>)

<details>

<summary>

class EventTagDeleteResponse: …

</summary>

success: bool

<a href="#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_delete_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsTarget Industries

##### [Lists target industries across multiple datasets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/target_industries/methods/list)

cloudforce\_one.threat\_events.target\_industries.list(TargetIndustryListParams\*\*kwargs) -> [TargetIndustryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.target_industries%20%3E%20(model)%20target_industry_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/targetIndustries

##### ModelsExpand Collapse

<details>

<summary>

class TargetIndustryListResponse: …

</summary>

<details>

<summary>

items: Items

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries%20%3E%20(model)%20target_industry_list_response%20%3E%20(schema)%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.target_industries%20%3E%20(model)%20target_industry_list_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries%20%3E%20(model)%20target_industry_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.target_industries%20%3E%20(model)%20target_industry_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsTarget IndustriesBy Dataset

##### [Lists all target industries for a specific dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/target_industries/subresources/by_dataset/methods/list)

cloudforce\_one.threat\_events.target\_industries.by\_dataset.list(strdataset\_id, ByDatasetListParams\*\*kwargs) -> [ByDatasetListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.target_industries.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/targetIndustries

##### ModelsExpand Collapse

<details>

<summary>

class ByDatasetListResponse: …

</summary>

<details>

<summary>

items: Items

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.target_industries.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsTarget IndustriesCatalog

##### [Lists all target industries from industry map catalog](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/target_industries/subresources/catalog/methods/list)

cloudforce\_one.threat\_events.target\_industries.catalog.list(CatalogListParams\*\*kwargs) -> [CatalogListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.target_industries.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/targetIndustries/catalog

##### ModelsExpand Collapse

<details>

<summary>

class CatalogListResponse: …

</summary>

<details>

<summary>

items: Items

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.target_industries.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat EventsInsights

#### Cloudforce OneThreat Signals

Threat Signals API for managing threat intelligence feeds, articles, indicators, and AI skills in Cloudforce One.

## Prerequisites

1. **API token** — requests must use an API token with Cloudforce One permissions; write operations (creating, editing, or deleting feeds, skills, and tags) require write access.
2. **Plan limits** — access on the Free plan is limited; feed quotas and managed default skills apply.

#### Cloudforce OneThreat SignalsSearch

##### [Search Threat Signals articles using AI Search](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/search/methods/search)

cloudforce\_one.threat\_signals.search.search(SearchSearchParams\*\*kwargs) -> [SearchSearchResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.search%20%3E%20(model)%20search_search_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/search

##### ModelsExpand Collapse

<details>

<summary>

class SearchSearchResponse: …

</summary>

count: int

Number of unique article candidates returned in this response. Equal to results.length.

minimum0

<a href="#(resource)%20cloudforce_one.threat_signals.search%20%3E%20(model)%20search_search_response%20%3E%20(schema)%20%3E%20(property)%20count">Link to this property</a>

<details>

<summary>

results: List\[Result]

</summary>

article\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.search%20%3E%20(model)%20search_search_response%20%3E%20(schema)%20%3E%20(property)%20results%20%3E%20(items)%20%3E%20(property)%20article_id">Link to this property</a>

dataset\_id: Optional\[str]

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.search%20%3E%20(model)%20search_search_response%20%3E%20(schema)%20%3E%20(property)%20results%20%3E%20(items)%20%3E%20(property)%20dataset_id">Link to this property</a>

event\_id: Optional\[str]

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.search%20%3E%20(model)%20search_search_response%20%3E%20(schema)%20%3E%20(property)%20results%20%3E%20(items)%20%3E%20(property)%20event_id">Link to this property</a>

feed\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.search%20%3E%20(model)%20search_search_response%20%3E%20(schema)%20%3E%20(property)%20results%20%3E%20(items)%20%3E%20(property)%20feed_id">Link to this property</a>

score: float

<a href="#(resource)%20cloudforce_one.threat_signals.search%20%3E%20(model)%20search_search_response%20%3E%20(schema)%20%3E%20(property)%20results%20%3E%20(items)%20%3E%20(property)%20score">Link to this property</a>

text: str

<a href="#(resource)%20cloudforce_one.threat_signals.search%20%3E%20(model)%20search_search_response%20%3E%20(schema)%20%3E%20(property)%20results%20%3E%20(items)%20%3E%20(property)%20text">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.search%20%3E%20(model)%20search_search_response%20%3E%20(schema)%20%3E%20(property)%20results">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.search%20%3E%20(model)%20search_search_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsCategories

##### [List Threat Signals feed categories](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/categories/methods/list)

cloudforce\_one.threat\_signals.categories.list(CategoryListParams\*\*kwargs) -> [CategoryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/categories

##### ModelsExpand Collapse

<details>

<summary>

class CategoryListResponse: …

</summary>

<details>

<summary>

categories: List\[Category]

</summary>

id: str

Wire value accepted by the feed <code>category_id</code> field.

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

description: str

Plain-language description of the category.

<a href="#(resource)%20cloudforce_one.threat_signals.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

name: str

Human-readable display label.

<a href="#(resource)%20cloudforce_one.threat_signals.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsFeeds

##### [List Threat Signals feeds](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/feeds/methods/list)

cloudforce\_one.threat\_signals.feeds.list(FeedListParams\*\*kwargs) -> SyncV4PagePagination\[[FeedListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/feeds

##### [Create Threat Signals feed](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/feeds/methods/create)

cloudforce\_one.threat\_signals.feeds.create(FeedCreateParams\*\*kwargs) -> [FeedCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/v2/threat-signals/feeds

##### [Update Threat Signals feed](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/feeds/methods/edit)

cloudforce\_one.threat\_signals.feeds.edit(strfeed\_id, FeedEditParams\*\*kwargs) -> [FeedEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/v2/threat-signals/feeds/{feed\_id}

##### [Delete Threat Signals feed](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/feeds/methods/delete)

cloudforce\_one.threat\_signals.feeds.delete(strfeed\_id, FeedDeleteParams\*\*kwargs) -> [FeedDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/v2/threat-signals/feeds/{feed\_id}

##### [Trigger Threat Signals feed poll](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/feeds/methods/poll)

cloudforce\_one.threat\_signals.feeds.poll(FeedPollParams\*\*kwargs) -> [FeedPollResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/v2/threat-signals/feeds/poll

##### ModelsExpand Collapse

<details>

<summary>

class FeedListResponse: …

</summary>

count: int

Number of feeds on this page.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20count">Link to this property</a>

<details>

<summary>

feeds: List\[Feed]

</summary>

id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

category\_id: Optional\[str]

Feed category identifier. Null when unset.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20category_id">Link to this property</a>

category\_name: Optional\[str]

Display name of the feed category. Null when unset or unresolvable.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20category_name">Link to this property</a>

created\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

curated\_feed\_id: Optional\[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20curated_feed_id">Link to this property</a>

display\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20display_name">Link to this property</a>

enabled: bool

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20enabled">Link to this property</a>

last\_polled\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20last_polled_at">Link to this property</a>

poll\_interval\_s: int

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20poll_interval_s">Link to this property</a>

source\_type: str

<code>custom</code> for a feed added by URL, <code>curated</code> for a curated catalog feed.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20source_type">Link to this property</a>

status: str

Polling health: <code>active</code>, or <code>error</code> after a failed poll.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

subscribed\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20subscribed_at">Link to this property</a>

title: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20title">Link to this property</a>

updated\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20updated_at">Link to this property</a>

url: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20url">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20feeds">Link to this property</a>

page: int

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20page">Link to this property</a>

per\_page: int

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20per_page">Link to this property</a>

total\_count: int

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)%20%3E%20(property)%20total_count">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_list_response%20%3E%20(schema)>)

<details>

<summary>

class FeedCreateResponse: …

</summary>

id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

category\_id: Optional\[str]

Feed category identifier. Null when unset.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20category_id">Link to this property</a>

category\_name: Optional\[str]

Display name of the feed category. Null when unset or unresolvable.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20category_name">Link to this property</a>

created\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

curated\_feed\_id: Optional\[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20curated_feed_id">Link to this property</a>

display\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20display_name">Link to this property</a>

enabled: bool

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

last\_polled\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20last_polled_at">Link to this property</a>

poll\_interval\_s: int

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20poll_interval_s">Link to this property</a>

source\_type: str

<code>custom</code> for a feed added by URL, <code>curated</code> for a curated catalog feed.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20source_type">Link to this property</a>

status: str

Polling health: <code>active</code>, or <code>error</code> after a failed poll.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

subscribed\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20subscribed_at">Link to this property</a>

title: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20title">Link to this property</a>

updated\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

url: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)%20%3E%20(property)%20url">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_create_response%20%3E%20(schema)>)

<details>

<summary>

class FeedEditResponse: …

</summary>

id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

category\_id: Optional\[str]

Feed category identifier. Null when unset.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20category_id">Link to this property</a>

category\_name: Optional\[str]

Display name of the feed category. Null when unset or unresolvable.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20category_name">Link to this property</a>

created\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

curated\_feed\_id: Optional\[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20curated_feed_id">Link to this property</a>

display\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20display_name">Link to this property</a>

enabled: bool

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

last\_polled\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20last_polled_at">Link to this property</a>

poll\_interval\_s: int

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20poll_interval_s">Link to this property</a>

source\_type: str

<code>custom</code> for a feed added by URL, <code>curated</code> for a curated catalog feed.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20source_type">Link to this property</a>

status: str

Polling health: <code>active</code>, or <code>error</code> after a failed poll.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

subscribed\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20subscribed_at">Link to this property</a>

title: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20title">Link to this property</a>

updated\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

url: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)%20%3E%20(property)%20url">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_edit_response%20%3E%20(schema)>)

<details>

<summary>

class FeedDeleteResponse: …

</summary>

id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

category\_id: Optional\[str]

Feed category identifier. Null when unset.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20category_id">Link to this property</a>

category\_name: Optional\[str]

Display name of the feed category. Null when unset or unresolvable.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20category_name">Link to this property</a>

created\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

curated\_feed\_id: Optional\[str]

Curated catalog feed this subscription was created from. Null for custom feeds.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20curated_feed_id">Link to this property</a>

display\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20display_name">Link to this property</a>

enabled: bool

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

last\_polled\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20last_polled_at">Link to this property</a>

poll\_interval\_s: int

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20poll_interval_s">Link to this property</a>

source\_type: str

<code>custom</code> for a feed added by URL, <code>curated</code> for a curated catalog feed.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20source_type">Link to this property</a>

status: str

Polling health: <code>active</code>, or <code>error</code> after a failed poll.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

subscribed\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20subscribed_at">Link to this property</a>

title: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20title">Link to this property</a>

updated\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

url: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)%20%3E%20(property)%20url">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_delete_response%20%3E%20(schema)>)

<details>

<summary>

class FeedPollResponse: …

</summary>

errors: float

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

<details>

<summary>

feeds: List\[Feed]

</summary>

feed\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20feed_id">Link to this property</a>

<details>

<summary>

status: Literal\["workflow\_created", "error"]

</summary>

One of the following:

"workflow\_created"

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

"error"

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20status">Link to this property</a>

workflow\_id: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20workflow_id">Link to this property</a>

feed\_enabled: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)%20%3E%20(property)%20feeds%20%3E%20(items)%20%3E%20(property)%20feed_enabled">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)%20%3E%20(property)%20feeds">Link to this property</a>

triggered: float

<a href="#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)%20%3E%20(property)%20triggered">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.feeds%20%3E%20(model)%20feed_poll_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsFeedsRaw

##### [Get Threat Signals feed XML](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/feeds/subresources/raw/methods/get)

cloudforce\_one.threat\_signals.feeds.raw.get(strfeed\_id, RawGetParams\*\*kwargs) -> [RawGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.feeds.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/feeds/{feed\_id}/raw

##### ModelsExpand Collapse

str

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.feeds.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsFeedsSkills

##### [Get Threat Signals feed skills](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/feeds/subresources/skills/methods/get)

cloudforce\_one.threat\_signals.feeds.skills.get(strfeed\_id, SkillGetParams\*\*kwargs) -> [SkillGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/feeds/{feed\_id}/skills

##### [Set Threat Signals feed skills](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/feeds/subresources/skills/methods/update)

cloudforce\_one.threat\_signals.feeds.skills.update(strfeed\_id, SkillUpdateParams\*\*kwargs) -> [SkillUpdateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_update_response%20%3E%20(schema)>)

PUT/accounts/{account\_id}/cloudforce-one/v2/threat-signals/feeds/{feed\_id}/skills

##### ModelsExpand Collapse

<details>

<summary>

class SkillGetResponse: …

</summary>

feed\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20feed_id">Link to this property</a>

<details>

<summary>

skills: List\[Skill]

</summary>

id: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

config: Optional\[str]

JSON-encoded skill configuration. Always null for default skills.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20config">Link to this property</a>

created\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

is\_active: int

1 when active, 0 when inactive.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20is_active">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

output\_schema: Optional\[str]

JSON-encoded JSON Schema the skill output must satisfy.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20output_schema">Link to this property</a>

prompt: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20prompt">Link to this property</a>

<details>

<summary>

source: Literal\["default", "custom"]

<code>default</code> for Cloudforce One managed skills (read-only), <code>custom</code> for account skills.

</summary>

One of the following:

"default"

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(member)%200">Link to this property</a>

"custom"

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20skills">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)>)

<details>

<summary>

class SkillUpdateResponse: …

</summary>

feed\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_update_response%20%3E%20(schema)%20%3E%20(property)%20feed_id">Link to this property</a>

<details>

<summary>

skills: List\[Skill]

</summary>

position: int

Zero-based pipeline position.

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_update_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20position">Link to this property</a>

skill\_id: str

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_update_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20skill_id">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_update_response%20%3E%20(schema)%20%3E%20(property)%20skills">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.feeds.skills%20%3E%20(model)%20skill_update_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsArticles

##### [List Threat Signals articles](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/articles/methods/list)

cloudforce\_one.threat\_signals.articles.list(ArticleListParams\*\*kwargs) -> [ArticleListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/articles

##### [Bulk update Threat Signals article read status](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/articles/methods/bulk_edit)

cloudforce\_one.threat\_signals.articles.bulk\_edit(ArticleBulkEditParams\*\*kwargs) -> [ArticleBulkEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_bulk_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/v2/threat-signals/articles

##### [Get Threat Signals article](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/articles/methods/get)

cloudforce\_one.threat\_signals.articles.get(strarticle\_id, ArticleGetParams\*\*kwargs) -> [ArticleGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/articles/{article\_id}

##### [Update Threat Signals article read status](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/articles/methods/edit)

cloudforce\_one.threat\_signals.articles.edit(strarticle\_id, ArticleEditParams\*\*kwargs) -> [ArticleEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/v2/threat-signals/articles/{article\_id}

##### ModelsExpand Collapse

<details>

<summary>

class ArticleListResponse: …

</summary>

<details>

<summary>

articles: List\[Article]

</summary>

id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

dataset\_id: Optional\[str]

Threat Events dataset identifier for the article redirect. Null when the account feeds dataset mapping is unavailable.

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20dataset_id">Link to this property</a>

event\_id: Optional\[str]

Threat Events event identifier associated with this article for a UI redirect. Null when no event has been linked.

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20event_id">Link to this property</a>

feed\_display\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20feed_display_name">Link to this property</a>

feed\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20feed_id">Link to this property</a>

fetched\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20fetched_at">Link to this property</a>

link: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20link">Link to this property</a>

published\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20published_at">Link to this property</a>

read: bool

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20read">Link to this property</a>

read\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20read_at">Link to this property</a>

summary: Optional\[str]

Persisted enrichment summary. Null until enrichment produces a summary.

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20summary">Link to this property</a>

<details>

<summary>

tags: List\[ArticleTag]

</summary>

<details>

<summary>

applied\_by: Literal\["ai", "analyst", "system"]

</summary>

One of the following:

"ai"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%200">Link to this property</a>

"analyst"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%201">Link to this property</a>

"system"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by">Link to this property</a>

category\_id: Optional\[str]

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

uuid: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

title: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles%20%3E%20(items)%20%3E%20(property)%20title">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20articles">Link to this property</a>

has\_more: bool

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20has_more">Link to this property</a>

next\_cursor: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20next_cursor">Link to this property</a>

total\_count: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20total_count">Link to this property</a>

total\_count\_is\_exact: bool

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)%20%3E%20(property)%20total_count_is_exact">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_list_response%20%3E%20(schema)>)

<details>

<summary>

class ArticleBulkEditResponse: …

</summary>

updated\_count: float

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_bulk_edit_response%20%3E%20(schema)%20%3E%20(property)%20updated_count">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_bulk_edit_response%20%3E%20(schema)>)

<details>

<summary>

class ArticleGetResponse: …

</summary>

id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

bullet\_points: Optional\[BulletPoints]

</summary>

impact: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20bullet_points%20%3E%20(property)%20impact">Link to this property</a>

what\_happened: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20bullet_points%20%3E%20(property)%20what_happened">Link to this property</a>

who\_affected: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20bullet_points%20%3E%20(property)%20who_affected">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20bullet_points">Link to this property</a>

content\_r2\_key: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20content_r2_key">Link to this property</a>

feed\_display\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20feed_display_name">Link to this property</a>

feed\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20feed_id">Link to this property</a>

fetched\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20fetched_at">Link to this property</a>

<details>

<summary>

indicator\_extraction\_status: Literal\["in\_progress", "complete", "failed", "unknown"]

Progress of the article’s indicator extraction and IOC contextualization run. complete and failed are terminal; unknown means no run has been recorded.

</summary>

One of the following:

"in\_progress"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20indicator_extraction_status%20%3E%20(member)%200">Link to this property</a>

"complete"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20indicator_extraction_status%20%3E%20(member)%201">Link to this property</a>

"failed"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20indicator_extraction_status%20%3E%20(member)%202">Link to this property</a>

"unknown"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20indicator_extraction_status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20indicator_extraction_status">Link to this property</a>

link: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20link">Link to this property</a>

metadata: Optional\[Dict\[str, object]]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20metadata">Link to this property</a>

published\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20published_at">Link to this property</a>

read: bool

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20read">Link to this property</a>

read\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20read_at">Link to this property</a>

source\_count: float

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20source_count">Link to this property</a>

summary: Optional\[str]

Persisted enrichment summary. Null until enrichment produces a summary.

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20summary">Link to this property</a>

summary\_r2\_key: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20summary_r2_key">Link to this property</a>

<details>

<summary>

tags: List\[Tag]

</summary>

<details>

<summary>

applied\_by: Literal\["ai", "analyst", "system"]

</summary>

One of the following:

"ai"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%200">Link to this property</a>

"analyst"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%201">Link to this property</a>

"system"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by">Link to this property</a>

category\_id: Optional\[str]

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

uuid: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

title: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20title">Link to this property</a>

skill\_version: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20skill_version">Link to this property</a>

tag\_skill\_version: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)%20%3E%20(property)%20tag_skill_version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_get_response%20%3E%20(schema)>)

<details>

<summary>

class ArticleEditResponse: …

</summary>

id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

bullet\_points: Optional\[BulletPoints]

</summary>

impact: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20bullet_points%20%3E%20(property)%20impact">Link to this property</a>

what\_happened: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20bullet_points%20%3E%20(property)%20what_happened">Link to this property</a>

who\_affected: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20bullet_points%20%3E%20(property)%20who_affected">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20bullet_points">Link to this property</a>

content\_r2\_key: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20content_r2_key">Link to this property</a>

feed\_display\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20feed_display_name">Link to this property</a>

feed\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20feed_id">Link to this property</a>

fetched\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20fetched_at">Link to this property</a>

<details>

<summary>

indicator\_extraction\_status: Literal\["in\_progress", "complete", "failed", "unknown"]

Progress of the article’s indicator extraction and IOC contextualization run. complete and failed are terminal; unknown means no run has been recorded.

</summary>

One of the following:

"in\_progress"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicator_extraction_status%20%3E%20(member)%200">Link to this property</a>

"complete"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicator_extraction_status%20%3E%20(member)%201">Link to this property</a>

"failed"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicator_extraction_status%20%3E%20(member)%202">Link to this property</a>

"unknown"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicator_extraction_status%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicator_extraction_status">Link to this property</a>

link: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20link">Link to this property</a>

metadata: Optional\[Dict\[str, object]]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20metadata">Link to this property</a>

published\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20published_at">Link to this property</a>

read: bool

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20read">Link to this property</a>

read\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20read_at">Link to this property</a>

source\_count: float

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20source_count">Link to this property</a>

summary: Optional\[str]

Persisted enrichment summary. Null until enrichment produces a summary.

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20summary">Link to this property</a>

summary\_r2\_key: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20summary_r2_key">Link to this property</a>

<details>

<summary>

tags: List\[Tag]

</summary>

<details>

<summary>

applied\_by: Literal\["ai", "analyst", "system"]

</summary>

One of the following:

"ai"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%200">Link to this property</a>

"analyst"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%201">Link to this property</a>

"system"

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by">Link to this property</a>

category\_id: Optional\[str]

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

uuid: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

title: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20title">Link to this property</a>

skill\_version: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20skill_version">Link to this property</a>

tag\_skill\_version: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)%20%3E%20(property)%20tag_skill_version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.articles%20%3E%20(model)%20article_edit_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsArticlesContent

##### [Get Threat Signals article content](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/articles/subresources/content/methods/get)

cloudforce\_one.threat\_signals.articles.content.get(strarticle\_id, ContentGetParams\*\*kwargs) -> [ContentGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.articles.content%20%3E%20(model)%20content_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/articles/{article\_id}/content

##### ModelsExpand Collapse

str

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.articles.content%20%3E%20(model)%20content_get_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsArticlesTags

##### [Add tag to Threat Signals article](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/articles/subresources/tags/methods/create)

cloudforce\_one.threat\_signals.articles.tags.create(strarticle\_id, TagCreateParams\*\*kwargs) -> [TagCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/v2/threat-signals/articles/{article\_id}/tags

##### [Remove tag from Threat Signals article](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/articles/subresources/tags/methods/delete)

cloudforce\_one.threat\_signals.articles.tags.delete(strtag\_id, TagDeleteParams\*\*kwargs) -> [TagDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/v2/threat-signals/articles/{article\_id}/tags/{tag\_id}

##### [Generate Threat Signals article AI tags](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/articles/subresources/tags/methods/generate)

cloudforce\_one.threat\_signals.articles.tags.generate(strarticle\_id, TagGenerateParams\*\*kwargs) -> [TagGenerateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/v2/threat-signals/articles/{article\_id}/tag

##### ModelsExpand Collapse

<details>

<summary>

class TagCreateResponse: …

</summary>

<details>

<summary>

applied\_by: Literal\["ai", "analyst", "system"]

</summary>

One of the following:

"ai"

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20applied_by%20%3E%20(member)%200">Link to this property</a>

"analyst"

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20applied_by%20%3E%20(member)%201">Link to this property</a>

"system"

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20applied_by%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20applied_by">Link to this property</a>

category\_id: Optional\[str]

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20categoryId">Link to this property</a>

uuid: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)>)

<details>

<summary>

class TagDeleteResponse: …

</summary>

<details>

<summary>

applied\_by: Literal\["ai", "analyst", "system"]

</summary>

One of the following:

"ai"

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20applied_by%20%3E%20(member)%200">Link to this property</a>

"analyst"

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20applied_by%20%3E%20(member)%201">Link to this property</a>

"system"

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20applied_by%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20applied_by">Link to this property</a>

category\_id: Optional\[str]

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20categoryId">Link to this property</a>

uuid: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)>)

<details>

<summary>

class TagGenerateResponse: …

</summary>

tag\_skill\_version: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)%20%3E%20(property)%20tag_skill_version">Link to this property</a>

<details>

<summary>

tags: List\[Tag]

Final hydrated assignment set; may be empty when no applicable tags are selected.

</summary>

<details>

<summary>

applied\_by: Literal\["ai", "analyst", "system"]

</summary>

One of the following:

"ai"

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%200">Link to this property</a>

"analyst"

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%201">Link to this property</a>

"system"

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20applied_by">Link to this property</a>

category\_id: Optional\[str]

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

uuid: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.articles.tags%20%3E%20(model)%20tag_generate_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsArticlesSkill Outputs

##### [Get Threat Signals article skill output](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/articles/subresources/skill_outputs/methods/get)

cloudforce\_one.threat\_signals.articles.skill\_outputs.get(strskill\_id, SkillOutputGetParams\*\*kwargs) -> [SkillOutputGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.articles.skill_outputs%20%3E%20(model)%20skill_output_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/articles/{article\_id}/skills/{skill\_id}/output

##### ModelsExpand Collapse

<details>

<summary>

class SkillOutputGetResponse: …

</summary>

article\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.articles.skill_outputs%20%3E%20(model)%20skill_output_get_response%20%3E%20(schema)%20%3E%20(property)%20article_id">Link to this property</a>

custom\_skill\_version: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.articles.skill_outputs%20%3E%20(model)%20skill_output_get_response%20%3E%20(schema)%20%3E%20(property)%20custom_skill_version">Link to this property</a>

output\_schema: Optional\[str]

JSON-encoded output schema of the skill. Null when the skill no longer exists.

<a href="#(resource)%20cloudforce_one.threat_signals.articles.skill_outputs%20%3E%20(model)%20skill_output_get_response%20%3E%20(schema)%20%3E%20(property)%20output_schema">Link to this property</a>

skill\_id: str

<a href="#(resource)%20cloudforce_one.threat_signals.articles.skill_outputs%20%3E%20(model)%20skill_output_get_response%20%3E%20(schema)%20%3E%20(property)%20skill_id">Link to this property</a>

custom\_output: Optional\[object]

Skill output. Parsed JSON when the stored output is valid JSON, otherwise the raw string.

<a href="#(resource)%20cloudforce_one.threat_signals.articles.skill_outputs%20%3E%20(model)%20skill_output_get_response%20%3E%20(schema)%20%3E%20(property)%20custom_output">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.articles.skill_outputs%20%3E%20(model)%20skill_output_get_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsIndicators

##### [List Threat Signals article indicators](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/indicators/methods/list)

cloudforce\_one.threat\_signals.indicators.list(IndicatorListParams\*\*kwargs) -> [IndicatorListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/indicators

##### ModelsExpand Collapse

<details>

<summary>

class IndicatorListResponse: …

</summary>

<details>

<summary>

indicators: List\[Indicator]

</summary>

id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

article\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20article_id">Link to this property</a>

article\_title: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20article_title">Link to this property</a>

dataset\_id: Optional\[str]

Threat Events dataset identifier for navigating from this indicator. Null when the account feeds dataset mapping is unavailable.

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20dataset_id">Link to this property</a>

feed\_display\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20feed_display_name">Link to this property</a>

feed\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20feed_id">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators">Link to this property</a>

<details>

<summary>

pagination: Pagination

</summary>

count: int

minimum0

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20count">Link to this property</a>

cursor: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20cursor">Link to this property</a>

has\_more: bool

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20has_more">Link to this property</a>

page: int

Ordinal of this cursor page; not a total-results offset.

minimum1

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20page">Link to this property</a>

per\_page: int

maximum100

minimum1

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20per_page">Link to this property</a>

total\_count: Optional\[int]

minimum0

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20total_count">Link to this property</a>

total\_count\_is\_exact: bool

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20total_count_is_exact">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsSkills

##### [List Threat Signals skills](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/skills/methods/list)

cloudforce\_one.threat\_signals.skills.list(SkillListParams\*\*kwargs) -> SyncV4PagePagination\[[SkillListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/skills

##### [Create Threat Signals skill](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/skills/methods/create)

cloudforce\_one.threat\_signals.skills.create(SkillCreateParams\*\*kwargs) -> [SkillCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/v2/threat-signals/skills

##### [Get Threat Signals skill](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/skills/methods/get)

cloudforce\_one.threat\_signals.skills.get(strskill\_id, SkillGetParams\*\*kwargs) -> [SkillGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/skills/{skill\_id}

##### [Update Threat Signals skill](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/skills/methods/edit)

cloudforce\_one.threat\_signals.skills.edit(strskill\_id, SkillEditParams\*\*kwargs) -> [SkillEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/v2/threat-signals/skills/{skill\_id}

##### [Delete Threat Signals skill](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/skills/methods/delete)

cloudforce\_one.threat\_signals.skills.delete(strskill\_id, SkillDeleteParams\*\*kwargs) -> [SkillDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/v2/threat-signals/skills/{skill\_id}

##### ModelsExpand Collapse

<details>

<summary>

class SkillListResponse: …

</summary>

count: int

Number of skills on this page.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20count">Link to this property</a>

custom\_skills\_available: bool

Whether the authenticated account may access custom-skill capabilities under Stakeout’s Threat Signals access-mode policy. This is a policy availability indicator, not a row-existence indicator. False for threat\_signals\_only mode; true for entitled, allowlisted, cfone\_internal, and service modes.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20custom_skills_available">Link to this property</a>

page: int

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20page">Link to this property</a>

per\_page: int

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20per_page">Link to this property</a>

<details>

<summary>

skills: List\[Skill]

</summary>

id: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

config: Optional\[str]

JSON-encoded skill configuration. Always null for default skills.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20config">Link to this property</a>

created\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

is\_active: int

1 when active, 0 when inactive.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20is_active">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

output\_schema: Optional\[str]

JSON-encoded JSON Schema the skill output must satisfy.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20output_schema">Link to this property</a>

prompt: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20prompt">Link to this property</a>

<details>

<summary>

source: Literal\["default", "custom"]

<code>default</code> for Cloudforce One managed skills (read-only), <code>custom</code> for account skills.

</summary>

One of the following:

"default"

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(member)%200">Link to this property</a>

"custom"

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20source%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills%20%3E%20(items)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20skills">Link to this property</a>

total\_count: int

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)%20%3E%20(property)%20total_count">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_list_response%20%3E%20(schema)>)

<details>

<summary>

class SkillCreateResponse: …

</summary>

id: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

config: Optional\[str]

JSON-encoded skill configuration. Always null for default skills.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20config">Link to this property</a>

created\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_active: int

1 when active, 0 when inactive.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20is_active">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

output\_schema: Optional\[str]

JSON-encoded JSON Schema the skill output must satisfy.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20output_schema">Link to this property</a>

prompt: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20prompt">Link to this property</a>

<details>

<summary>

source: Literal\["default", "custom"]

<code>default</code> for Cloudforce One managed skills (read-only), <code>custom</code> for account skills.

</summary>

One of the following:

"default"

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20source%20%3E%20(member)%200">Link to this property</a>

"custom"

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20source%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20source">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_create_response%20%3E%20(schema)>)

<details>

<summary>

class SkillGetResponse: …

</summary>

id: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

config: Optional\[str]

JSON-encoded skill configuration. Always null for default skills.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20config">Link to this property</a>

created\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_active: int

1 when active, 0 when inactive.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20is_active">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

output\_schema: Optional\[str]

JSON-encoded JSON Schema the skill output must satisfy.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20output_schema">Link to this property</a>

prompt: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20prompt">Link to this property</a>

<details>

<summary>

source: Literal\["default", "custom"]

<code>default</code> for Cloudforce One managed skills (read-only), <code>custom</code> for account skills.

</summary>

One of the following:

"default"

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20source%20%3E%20(member)%200">Link to this property</a>

"custom"

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20source%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20source">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_get_response%20%3E%20(schema)>)

<details>

<summary>

class SkillEditResponse: …

</summary>

id: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

config: Optional\[str]

JSON-encoded skill configuration. Always null for default skills.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20config">Link to this property</a>

created\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_active: int

1 when active, 0 when inactive.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20is_active">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

output\_schema: Optional\[str]

JSON-encoded JSON Schema the skill output must satisfy.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20output_schema">Link to this property</a>

prompt: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20prompt">Link to this property</a>

<details>

<summary>

source: Literal\["default", "custom"]

<code>default</code> for Cloudforce One managed skills (read-only), <code>custom</code> for account skills.

</summary>

One of the following:

"default"

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20source%20%3E%20(member)%200">Link to this property</a>

"custom"

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20source%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20source">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_edit_response%20%3E%20(schema)>)

<details>

<summary>

class SkillDeleteResponse: …

</summary>

id: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

config: Optional\[str]

JSON-encoded skill configuration. Always null for default skills.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20config">Link to this property</a>

created\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

is\_active: int

1 when active, 0 when inactive.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20is_active">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

output\_schema: Optional\[str]

JSON-encoded JSON Schema the skill output must satisfy.

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20output_schema">Link to this property</a>

prompt: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20prompt">Link to this property</a>

<details>

<summary>

source: Literal\["default", "custom"]

<code>default</code> for Cloudforce One managed skills (read-only), <code>custom</code> for account skills.

</summary>

One of the following:

"default"

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20source%20%3E%20(member)%200">Link to this property</a>

"custom"

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20source%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20source">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

updated\_at: str

<a href="#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.skills%20%3E%20(model)%20skill_delete_response%20%3E%20(schema)>)

#### Cloudforce OneThreat SignalsSkillsTag Categories

##### [Get Threat Signals skill tag categories](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/skills/subresources/tag_categories/methods/get)

cloudforce\_one.threat\_signals.skills.tag\_categories.get(Literal\["default-tagging-skill"]skill\_id, TagCategoryGetParams\*\*kwargs) -> [TagCategoryGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.skills.tag_categories%20%3E%20(model)%20tag_category_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/v2/threat-signals/skills/{skill\_id}/tag-categories

##### [Replace Threat Signals skill tag categories](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_signals/subresources/skills/subresources/tag_categories/methods/update)

cloudforce\_one.threat\_signals.skills.tag\_categories.update(Literal\["default-tagging-skill"]skill\_id, TagCategoryUpdateParams\*\*kwargs) -> [TagCategoryUpdateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_signals.skills.tag_categories%20%3E%20(model)%20tag_category_update_response%20%3E%20(schema)>)

PUT/accounts/{account\_id}/cloudforce-one/v2/threat-signals/skills/{skill\_id}/tag-categories

##### ModelsExpand Collapse

<details>

<summary>

class TagCategoryGetResponse: …

</summary>

category\_uuids: List\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.skills.tag_categories%20%3E%20(model)%20tag_category_get_response%20%3E%20(schema)%20%3E%20(property)%20category_uuids">Link to this property</a>

skill\_id: Literal\["default-tagging-skill"]

<a href="#(resource)%20cloudforce_one.threat_signals.skills.tag_categories%20%3E%20(model)%20tag_category_get_response%20%3E%20(schema)%20%3E%20(property)%20skill_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.skills.tag_categories%20%3E%20(model)%20tag_category_get_response%20%3E%20(schema)>)

<details>

<summary>

class TagCategoryUpdateResponse: …

</summary>

category\_uuids: List\[str]

<a href="#(resource)%20cloudforce_one.threat_signals.skills.tag_categories%20%3E%20(model)%20tag_category_update_response%20%3E%20(schema)%20%3E%20(property)%20category_uuids">Link to this property</a>

skill\_id: Literal\["default-tagging-skill"]

<a href="#(resource)%20cloudforce_one.threat_signals.skills.tag_categories%20%3E%20(model)%20tag_category_update_response%20%3E%20(schema)%20%3E%20(property)%20skill_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_signals.skills.tag_categories%20%3E%20(model)%20tag_category_update_response%20%3E%20(schema)>)