---
title: Threat Events
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Cloudforce One](https://developers.cloudflare.com/api/python/resources/cloudforce_one)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Threat Events

##### [Filter and list events](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/list)

cloudforce\_one.threat\_events.list(ThreatEventListParams\*\*kwargs) -> [ThreatEventListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events

##### [Reads an event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/get)

Deprecated

cloudforce\_one.threat\_events.get(strevent\_id, ThreatEventGetParams\*\*kwargs) -> [ThreatEventGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/{event\_id}

##### [Creates a new event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/create)

cloudforce\_one.threat\_events.create(ThreatEventCreateParams\*\*kwargs) -> [ThreatEventCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/create

##### [Updates an event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/edit)

cloudforce\_one.threat\_events.edit(strevent\_id, ThreatEventEditParams\*\*kwargs) -> [ThreatEventEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/{event\_id}

##### [Creates bulk events](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/bulk_create)

cloudforce\_one.threat\_events.bulk\_create(ThreatEventBulkCreateParams\*\*kwargs) -> [ThreatEventBulkCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/create/bulk

##### [Creates bulk DOS event with relationships and indicators](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/methods/bulk_create_relationships)

Deprecated

cloudforce\_one.threat\_events.bulk\_create\_relationships(ThreatEventBulkCreateRelationshipsParams\*\*kwargs) -> [ThreatEventBulkCreateRelationshipsResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/create/bulk/relationships

##### ModelsExpand Collapse

<details>

<summary>

List\[ThreatEventListResponseItem]

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_list_response%20%3E%20(schema)>)

<details>

<summary>

class ThreatEventGetResponse: …

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_get_response%20%3E%20(schema)>)

<details>

<summary>

class ThreatEventCreateResponse: …

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_create_response%20%3E%20(schema)>)

<details>

<summary>

class ThreatEventEditResponse: …

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_edit_response%20%3E%20(schema)>)

<details>

<summary>

class ThreatEventBulkCreateResponse: …

Detailed result of bulk event creation with auto-tag management

</summary>

created\_events\_count: float

Number of events created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdEventsCount">Link to this property</a>

created\_tags\_count: float

Number of new tags created in SoT

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdTagsCount">Link to this property</a>

error\_count: float

Number of errors encountered

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20errorCount">Link to this property</a>

queued\_indicators\_count: float

Number of indicators queued for async processing

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20queuedIndicatorsCount">Link to this property</a>

create\_bulk\_events\_request\_id: Optional\[str]

Correlation ID for async indicator processing

formatuuid

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createBulkEventsRequestId">Link to this property</a>

<details>

<summary>

created\_events: Optional\[List\[CreatedEvent]]

Array of created events with UUIDs and shard locations. Only present when includeCreatedEvents=true

</summary>

event\_index: float

Original index in the input data array

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdEvents%20%3E%20(items)%20%3E%20(property)%20eventIndex">Link to this property</a>

shard\_id: str

Dataset ID of the shard where the event was created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdEvents%20%3E%20(items)%20%3E%20(property)%20shardId">Link to this property</a>

uuid: str

UUID of the created event

formatuuid

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdEvents%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20createdEvents">Link to this property</a>

<details>

<summary>

errors: Optional\[List\[Error]]

Array of error details

</summary>

error: str

Error message

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

event\_index: float

Index of the event that caused the error

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20eventIndex">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_response%20%3E%20(schema)>)

<details>

<summary>

class ThreatEventBulkCreateRelationshipsResponse: …

Result of bulk relationship creation operation

</summary>

created\_events\_count: float

Number of events created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20createdEventsCount">Link to this property</a>

created\_indicators\_count: float

Number of indicators created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20createdIndicatorsCount">Link to this property</a>

created\_relationships\_count: float

Number of relationships created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20createdRelationshipsCount">Link to this property</a>

error\_count: float

Number of errors encountered

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20errorCount">Link to this property</a>

<details>

<summary>

errors: Optional\[List\[Error]]

Array of error details

</summary>

error: str

Error message

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

event\_index: float

Index of the event that caused the error

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20eventIndex">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20threat_event_bulk_create_relationships_response%20%3E%20(schema)>)

#### Threat EventsAggregate

##### [Aggregate events by single or multiple columns with optional date filtering](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/aggregate/methods/list)

cloudforce\_one.threat\_events.aggregate.list(AggregateListParams\*\*kwargs) -> [AggregateListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/aggregate

##### ModelsExpand Collapse

<details>

<summary>

class AggregateListResponse: …

</summary>

aggregate\_by: str

Column(s) that were aggregated by

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregateBy">Link to this property</a>

<details>

<summary>

aggregations: List\[Aggregation]

Array of aggregation results with dynamic fields based on aggregateBy columns

</summary>

count: float

Number of events for this aggregation

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregations%20%3E%20(items)%20%3E%20(property)%20count">Link to this property</a>

date: Optional\[str]

Date (if groupByDate is true)

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregations%20%3E%20(items)%20%3E%20(property)%20date">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregations">Link to this property</a>

total: float

Total number of events in the aggregation

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20total">Link to this property</a>

<details>

<summary>

date\_range: Optional\[DateRange]

Date range used for filtering

</summary>

end\_date: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20dateRange%20%3E%20(property)%20endDate">Link to this property</a>

start\_date: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20dateRange%20%3E%20(property)%20startDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20dateRange">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)>)

#### Threat EventsGraphql

##### [GraphQL endpoint for event aggregation](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/graphql/methods/create)

cloudforce\_one.threat\_events.graphql.create(GraphqlCreateParams\*\*kwargs) -> [GraphqlCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.graphql%20%3E%20(model)%20graphql_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/graphql

##### ModelsExpand Collapse

<details>

<summary>

class GraphqlCreateResponse: …

</summary>

data: Optional\[object]

<a href="#(resource)%20cloudforce_one.threat_events.graphql%20%3E%20(model)%20graphql_create_response%20%3E%20(schema)%20%3E%20(property)%20data">Link to this property</a>

errors: Optional\[List\[object]]

<a href="#(resource)%20cloudforce_one.threat_events.graphql%20%3E%20(model)%20graphql_create_response%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.graphql%20%3E%20(model)%20graphql_create_response%20%3E%20(schema)>)

#### Threat EventsGraph

##### [Query graph neighborhood from R2 Data Catalog](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/graph/methods/list)

cloudforce\_one.threat\_events.graph.list(GraphListParams\*\*kwargs) -> [GraphListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/graph

##### ModelsExpand Collapse

<details>

<summary>

class GraphListResponse: …

</summary>

<details>

<summary>

edges: List\[Edge]

</summary>

id: str

Deterministic composite edge id (source→target:relationshipType)

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

relationship\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20relationshipType">Link to this property</a>

source: str

Compact id of the source node (type:uuid)

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20source">Link to this property</a>

source\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20sourceId">Link to this property</a>

source\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20sourceType">Link to this property</a>

target: str

Compact id of the target node (type:uuid)

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20target">Link to this property</a>

target\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20targetId">Link to this property</a>

target\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges%20%3E%20(items)%20%3E%20(property)%20targetType">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20edges">Link to this property</a>

node: Optional\[Dict\[str, object]]

Focal node object (legacy single-seed). Null when unavailable.

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20node">Link to this property</a>

nodes: List\[Dict\[str, object]]

<a href="#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)%20%3E%20(property)%20nodes">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.graph%20%3E%20(model)%20graph_list_response%20%3E%20(schema)>)

#### Threat EventsQueries

##### [List all saved event queries](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/list)

cloudforce\_one.threat\_events.queries.list(QueryListParams\*\*kwargs) -> [QueryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/queries

##### [Create a saved event query](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/create)

cloudforce\_one.threat\_events.queries.create(QueryCreateParams\*\*kwargs) -> [QueryCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/queries/create

##### [Read a saved event query](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/get)

cloudforce\_one.threat\_events.queries.get(intquery\_id, QueryGetParams\*\*kwargs) -> [QueryGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/queries/{query\_id}

##### [Update a saved event query](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/edit)

cloudforce\_one.threat\_events.queries.edit(intquery\_id, QueryEditParams\*\*kwargs) -> [QueryEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/queries/{query\_id}

##### [Delete a saved event query](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/queries/methods/delete)

cloudforce\_one.threat\_events.queries.delete(intquery\_id, QueryDeleteParams\*\*kwargs)

DELETE/accounts/{account\_id}/cloudforce-one/events/queries/{query\_id}

##### ModelsExpand Collapse

<details>

<summary>

List\[QueryListResponseItem]

</summary>

id: int

Unique identifier for the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

account\_id: int

Account ID

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20account_id">Link to this property</a>

alert\_enabled: bool

Whether alerts are enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20alert_enabled">Link to this property</a>

alert\_rollup\_enabled: bool

Whether alert rollup is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20alert_rollup_enabled">Link to this property</a>

created\_at: str

Creation timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20created_at">Link to this property</a>

name: str

Name of the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

query\_json: str

JSON string containing the query parameters

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20query_json">Link to this property</a>

rule\_enabled: bool

Whether rule is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20rule_enabled">Link to this property</a>

updated\_at: str

Last update timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20updated_at">Link to this property</a>

user\_email: str

Email of the user who created the query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20user_email">Link to this property</a>

custom\_threat\_feed\_id: Optional\[int]

Intel Indicator Feed ID (numeric)

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20custom_threat_feed_id">Link to this property</a>

rule\_list\_id: Optional\[str]

WAF rules list ID for blocking

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20rule_list_id">Link to this property</a>

rule\_scope: Optional\[str]

Scope for the rule

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20rule_scope">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_list_response%20%3E%20(schema)>)

<details>

<summary>

class QueryCreateResponse: …

</summary>

id: int

Unique identifier for the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: int

Account ID

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20account_id">Link to this property</a>

alert\_enabled: bool

Whether alerts are enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20alert_enabled">Link to this property</a>

alert\_rollup\_enabled: bool

Whether alert rollup is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20alert_rollup_enabled">Link to this property</a>

created\_at: str

Creation timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

name: str

Name of the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

query\_json: str

JSON string containing the query parameters

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20query_json">Link to this property</a>

rule\_enabled: bool

Whether rule is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20rule_enabled">Link to this property</a>

updated\_at: str

Last update timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

user\_email: str

Email of the user who created the query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20user_email">Link to this property</a>

custom\_threat\_feed\_id: Optional\[int]

Intel Indicator Feed ID (numeric)

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20custom_threat_feed_id">Link to this property</a>

rule\_list\_id: Optional\[str]

WAF rules list ID for blocking

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20rule_list_id">Link to this property</a>

rule\_scope: Optional\[str]

Scope for the rule

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)%20%3E%20(property)%20rule_scope">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_create_response%20%3E%20(schema)>)

<details>

<summary>

class QueryGetResponse: …

</summary>

id: int

Unique identifier for the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: int

Account ID

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20account_id">Link to this property</a>

alert\_enabled: bool

Whether alerts are enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20alert_enabled">Link to this property</a>

alert\_rollup\_enabled: bool

Whether alert rollup is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20alert_rollup_enabled">Link to this property</a>

created\_at: str

Creation timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

name: str

Name of the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

query\_json: str

JSON string containing the query parameters

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20query_json">Link to this property</a>

rule\_enabled: bool

Whether rule is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20rule_enabled">Link to this property</a>

updated\_at: str

Last update timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

user\_email: str

Email of the user who created the query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20user_email">Link to this property</a>

custom\_threat\_feed\_id: Optional\[int]

Intel Indicator Feed ID (numeric)

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20custom_threat_feed_id">Link to this property</a>

rule\_list\_id: Optional\[str]

WAF rules list ID for blocking

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20rule_list_id">Link to this property</a>

rule\_scope: Optional\[str]

Scope for the rule

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)%20%3E%20(property)%20rule_scope">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_get_response%20%3E%20(schema)>)

<details>

<summary>

class QueryEditResponse: …

</summary>

id: int

Unique identifier for the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: int

Account ID

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20account_id">Link to this property</a>

alert\_enabled: bool

Whether alerts are enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20alert_enabled">Link to this property</a>

alert\_rollup\_enabled: bool

Whether alert rollup is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20alert_rollup_enabled">Link to this property</a>

created\_at: str

Creation timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20created_at">Link to this property</a>

name: str

Name of the saved query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

query\_json: str

JSON string containing the query parameters

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20query_json">Link to this property</a>

rule\_enabled: bool

Whether rule is enabled

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20rule_enabled">Link to this property</a>

updated\_at: str

Last update timestamp

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20updated_at">Link to this property</a>

user\_email: str

Email of the user who created the query

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20user_email">Link to this property</a>

custom\_threat\_feed\_id: Optional\[int]

Intel Indicator Feed ID (numeric)

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20custom_threat_feed_id">Link to this property</a>

rule\_list\_id: Optional\[str]

WAF rules list ID for blocking

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20rule_list_id">Link to this property</a>

rule\_scope: Optional\[str]

Scope for the rule

<a href="#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)%20%3E%20(property)%20rule_scope">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.queries%20%3E%20(model)%20query_edit_response%20%3E%20(schema)>)

#### Threat EventsRelationships

##### [Filter and list events related to specific event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/relationships/methods/list)

Deprecated

cloudforce\_one.threat\_events.relationships.list(strevent\_id, RelationshipListParams\*\*kwargs) -> [RelationshipListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/{event\_id}/relationships

##### ModelsExpand Collapse

<details>

<summary>

List\[RelationshipListResponseItem]

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.relationships%20%3E%20(model)%20relationship_list_response%20%3E%20(schema)>)

#### Threat EventsIndicators

##### [Lists indicators across multiple datasets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/methods/list)

cloudforce\_one.threat\_events.indicators.list(IndicatorListParams\*\*kwargs) -> [IndicatorListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/indicators

##### ModelsExpand Collapse

<details>

<summary>

class IndicatorListResponse: …

</summary>

<details>

<summary>

properties: Properties

</summary>

<details>

<summary>

completeness: PropertiesCompleteness

</summary>

<details>

<summary>

properties: PropertiesCompletenessProperties

</summary>

<details>

<summary>

complete: PropertiesCompletenessPropertiesComplete

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20complete%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20complete">Link to this property</a>

<details>

<summary>

failed\_datasets: PropertiesCompletenessPropertiesFailedDatasets

</summary>

<details>

<summary>

items: PropertiesCompletenessPropertiesFailedDatasetsItems

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedDatasets%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedDatasets%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedDatasets%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedDatasets">Link to this property</a>

<details>

<summary>

failed\_shards: PropertiesCompletenessPropertiesFailedShards

</summary>

<details>

<summary>

items: PropertiesCompletenessPropertiesFailedShardsItems

</summary>

<details>

<summary>

properties: PropertiesCompletenessPropertiesFailedShardsItemsProperties

</summary>

<details>

<summary>

dataset\_id: PropertiesCompletenessPropertiesFailedShardsItemsPropertiesDatasetID

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20properties%20%3E%20(property)%20datasetId%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20properties%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

shard\_id: PropertiesCompletenessPropertiesFailedShardsItemsPropertiesShardID

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20properties%20%3E%20(property)%20shardId%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20properties%20%3E%20(property)%20shardId">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20properties">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20failedShards">Link to this property</a>

<details>

<summary>

warnings: PropertiesCompletenessPropertiesWarnings

</summary>

<details>

<summary>

items: PropertiesCompletenessPropertiesWarningsItems

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20warnings%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20warnings%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20warnings%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties%20%3E%20(property)%20warnings">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20properties">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20completeness">Link to this property</a>

<details>

<summary>

indicators: PropertiesIndicators

</summary>

<details>

<summary>

items: PropertiesIndicatorsItems

</summary>

created\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20createdAt">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20indicatorType">Link to this property</a>

<details>

<summary>

sources: List\[PropertiesIndicatorsItemsSource]

RSS article sources from which this indicator was extracted.

</summary>

resource\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20resourceId">Link to this property</a>

resource\_type: Literal\["article"]

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20resourceType">Link to this property</a>

system: Literal\["threat-signals"]

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20system">Link to this property</a>

title: Optional\[str]

Threat Signals article title; null for historical provenance without a stored title.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20title">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20sources">Link to this property</a>

updated\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20updatedAt">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20value">Link to this property</a>

dataset\_id: Optional\[str]

The dataset ID this indicator belongs to. Included in list responses.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

related\_events: Optional\[List\[PropertiesIndicatorsItemsRelatedEvent]]

Related events, capped by <code>relatedEventsLimit</code> (default 2). Check <code>relatedEventsHasMore</code> to detect a capped list; pass <code>relatedEventsLimit=-1</code> to retrieve all of them.

</summary>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

event\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventId">Link to this property</a>

event\_date: Optional\[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20relatedEvents">Link to this property</a>

related\_events\_has\_more: Optional\[bool]

True when this indicator appears in more events than <code>relatedEvents</code> contains because <code>relatedEventsLimit</code> capped the list. Pass <code>relatedEventsLimit=-1</code> to retrieve every related event.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20relatedEventsHasMore">Link to this property</a>

<details>

<summary>

tags: Optional\[List\[PropertiesIndicatorsItemsTag]]

</summary>

category\_id: Optional\[str]

The UUID of the tag category, or null when the tag is uncategorized.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tags">Link to this property</a>

tlp: Optional\[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20indicators">Link to this property</a>

<details>

<summary>

pagination: PropertiesPagination

</summary>

<details>

<summary>

properties: PropertiesPaginationProperties

</summary>

<details>

<summary>

count: PropertiesPaginationPropertiesCount

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20count%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20count">Link to this property</a>

<details>

<summary>

cursor: PropertiesPaginationPropertiesCursor

</summary>

description: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20cursor%20%3E%20(property)%20description">Link to this property</a>

nullable: bool

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20cursor%20%3E%20(property)%20nullable">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20cursor%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20cursor">Link to this property</a>

<details>

<summary>

has\_more: PropertiesPaginationPropertiesHasMore

</summary>

description: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20has_more%20%3E%20(property)%20description">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20has_more%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20has_more">Link to this property</a>

<details>

<summary>

page: PropertiesPaginationPropertiesPage

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20page%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20page">Link to this property</a>

<details>

<summary>

per\_page: PropertiesPaginationPropertiesPerPage

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20per_page%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20per_page">Link to this property</a>

<details>

<summary>

total\_count: PropertiesPaginationPropertiesTotalCount

</summary>

description: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count%20%3E%20(property)%20description">Link to this property</a>

nullable: bool

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count%20%3E%20(property)%20nullable">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count">Link to this property</a>

<details>

<summary>

total\_count\_is\_exact: PropertiesPaginationPropertiesTotalCountIsExact

</summary>

description: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count_is_exact%20%3E%20(property)%20description">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count_is_exact%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties%20%3E%20(property)%20total_count_is_exact">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20properties">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties%20%3E%20(property)%20pagination">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20properties">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)>)

#### Threat EventsIndicatorsAggregate

##### [Aggregate indicators by column(s)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/aggregate/methods/list)

cloudforce\_one.threat\_events.indicators.aggregate.list(AggregateListParams\*\*kwargs) -> [AggregateListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/indicators/aggregate

##### ModelsExpand Collapse

<details>

<summary>

class AggregateListResponse: …

</summary>

aggregate\_by: str

Column(s) that were aggregated by

<a href="#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregateBy">Link to this property</a>

<details>

<summary>

aggregations: List\[Aggregation]

Array of aggregation results with dynamic fields based on aggregateBy columns

</summary>

count: float

Number of indicators for this aggregation

<a href="#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregations%20%3E%20(items)%20%3E%20(property)%20count">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20aggregations">Link to this property</a>

failed\_datasets: float

Number of datasets whose aggregation failed and were excluded from the result

<a href="#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20failedDatasets">Link to this property</a>

total: float

Total count in the aggregation: indicator rows when measure=indicators, or linked-event rows when measure=relationships

<a href="#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)%20%3E%20(property)%20total">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators.aggregate%20%3E%20(model)%20aggregate_list_response%20%3E%20(schema)>)

#### Threat EventsIndicatorsTypes

##### [Lists indicator types across multiple datasets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/types/methods/list)

cloudforce\_one.threat\_events.indicators.types.list(TypeListParams\*\*kwargs) -> [TypeListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators.types%20%3E%20(model)%20type_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/indicator-types

##### ModelsExpand Collapse

<details>

<summary>

class TypeListResponse: …

</summary>

<details>

<summary>

items: Items

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.types%20%3E%20(model)%20type_list_response%20%3E%20(schema)%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.types%20%3E%20(model)%20type_list_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.types%20%3E%20(model)%20type_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators.types%20%3E%20(model)%20type_list_response%20%3E%20(schema)>)

#### Threat EventsIndicatorsBy Dataset

##### [Lists indicators](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/by_dataset/methods/list)

Deprecated

cloudforce\_one.threat\_events.indicators.by\_dataset.list(strdataset\_id, ByDatasetListParams\*\*kwargs) -> [ByDatasetListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/indicators

##### [Reads an indicator](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/by_dataset/methods/get)

cloudforce\_one.threat\_events.indicators.by\_dataset.get(strindicator\_id, ByDatasetGetParams\*\*kwargs) -> [ByDatasetGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/indicators/{indicator\_id}

##### ModelsExpand Collapse

<details>

<summary>

class ByDatasetListResponse: …

</summary>

<details>

<summary>

indicators: List\[Indicator]

</summary>

created\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20createdAt">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

<details>

<summary>

sources: List\[IndicatorSource]

RSS article sources from which this indicator was extracted.

</summary>

resource\_id: str

formatuuid

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20resourceId">Link to this property</a>

resource\_type: Literal\["article"]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20resourceType">Link to this property</a>

system: Literal\["threat-signals"]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20system">Link to this property</a>

title: Optional\[str]

Threat Signals article title; null for historical provenance without a stored title.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20sources%20%3E%20(items)%20%3E%20(property)%20title">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20sources">Link to this property</a>

updated\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20updatedAt">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

dataset\_id: Optional\[str]

The dataset ID this indicator belongs to. Included in list responses.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

related\_events: Optional\[List\[IndicatorRelatedEvent]]

Related events, capped by <code>relatedEventsLimit</code> (default 2). Check <code>relatedEventsHasMore</code> to detect a capped list; pass <code>relatedEventsLimit=-1</code> to retrieve all of them.

</summary>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

event\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventId">Link to this property</a>

event\_date: Optional\[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents">Link to this property</a>

related\_events\_has\_more: Optional\[bool]

True when this indicator appears in more events than <code>relatedEvents</code> contains because <code>relatedEventsLimit</code> capped the list. Pass <code>relatedEventsLimit=-1</code> to retrieve every related event.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEventsHasMore">Link to this property</a>

<details>

<summary>

tags: Optional\[List\[IndicatorTag]]

</summary>

category\_id: Optional\[str]

The UUID of the tag category, or null when the tag is uncategorized.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

tlp: Optional\[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators">Link to this property</a>

<details>

<summary>

pagination: Pagination

</summary>

page: float

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20page">Link to this property</a>

page\_size: float

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20pageSize">Link to this property</a>

total\_count: float

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalCount">Link to this property</a>

total\_pages: float

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalPages">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

<details>

<summary>

class ByDatasetGetResponse: …

</summary>

created\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20createdAt">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20indicatorType">Link to this property</a>

updated\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20updatedAt">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

dataset\_id: Optional\[str]

The dataset ID this indicator belongs to. Included in list responses.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

related\_events: Optional\[List\[RelatedEvent]]

Related events, capped by <code>relatedEventsLimit</code> (default 2). Check <code>relatedEventsHasMore</code> to detect a capped list; pass <code>relatedEventsLimit=-1</code> to retrieve all of them.

</summary>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

event\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventId">Link to this property</a>

event\_date: Optional\[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20relatedEvents">Link to this property</a>

related\_events\_has\_more: Optional\[bool]

True when this indicator appears in more events than <code>relatedEvents</code> contains because <code>relatedEventsLimit</code> capped the list. Pass <code>relatedEventsLimit=-1</code> to retrieve every related event.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20relatedEventsHasMore">Link to this property</a>

<details>

<summary>

tags: Optional\[List\[Tag]]

</summary>

category\_id: Optional\[str]

The UUID of the tag category, or null when the tag is uncategorized.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

tlp: Optional\[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

<a href="#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators.by_dataset%20%3E%20(model)%20by_dataset_get_response%20%3E%20(schema)>)

#### Threat EventsIndicatorsBy DatasetTags

##### [List mirrored tags for an indicator dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/indicators/subresources/by_dataset/subresources/tags/methods/list)

cloudforce\_one.threat\_events.indicators.by\_dataset.tags.list(strdataset\_id, TagListParams\*\*kwargs) -> [TagListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.indicators.by_dataset.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/indicators/tags

##### ModelsExpand Collapse

List\[object]

Array of mirror tag rows

[Link to this property](<#(resource)%20cloudforce_one.threat_events.indicators.by_dataset.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)>)

#### Threat EventsAttackers

##### [Lists attackers across multiple datasets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/attackers/methods/list)

cloudforce\_one.threat\_events.attackers.list(AttackerListParams\*\*kwargs) -> [AttackerListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.attackers%20%3E%20(model)%20attacker_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/attackers

##### ModelsExpand Collapse

<details>

<summary>

class AttackerListResponse: …

</summary>

<details>

<summary>

items: Items

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.attackers%20%3E%20(model)%20attacker_list_response%20%3E%20(schema)%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.attackers%20%3E%20(model)%20attacker_list_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.attackers%20%3E%20(model)%20attacker_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.attackers%20%3E%20(model)%20attacker_list_response%20%3E%20(schema)>)

#### Threat EventsCategories

##### [Lists categories across multiple datasets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/list)

cloudforce\_one.threat\_events.categories.list(CategoryListParams\*\*kwargs) -> [CategoryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/categories

##### [Reads a category](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/get)

Deprecated

cloudforce\_one.threat\_events.categories.get(strcategory\_id, CategoryGetParams\*\*kwargs) -> [CategoryGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/categories/{category\_id}

##### [Creates a new category](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/create)

cloudforce\_one.threat\_events.categories.create(CategoryCreateParams\*\*kwargs) -> [CategoryCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/categories/create

##### [Updates a category](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/edit)

Deprecated

cloudforce\_one.threat\_events.categories.edit(strcategory\_id, CategoryEditParams\*\*kwargs) -> [CategoryEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/categories/{category\_id}

##### [Deletes a category](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/methods/delete)

Deprecated

cloudforce\_one.threat\_events.categories.delete(strcategory\_id, CategoryDeleteParams\*\*kwargs) -> [CategoryDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/categories/{category\_id}

##### ModelsExpand Collapse

<details>

<summary>

List\[CategoryListResponseItem]

</summary>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20killChain">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

mitre\_attack: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreCapec">Link to this property</a>

shortname: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20shortname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryGetResponse: …

</summary>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

mitre\_attack: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

shortname: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)%20%3E%20(property)%20shortname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_get_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryCreateResponse: …

</summary>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

mitre\_attack: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

shortname: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20shortname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryEditResponse: …

</summary>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

mitre\_attack: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

shortname: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20shortname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryDeleteResponse: …

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)>)

#### Threat EventsCategoriesCatalog

##### [Lists categories](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/categories/subresources/catalog/methods/list)

cloudforce\_one.threat\_events.categories.catalog.list(CatalogListParams\*\*kwargs) -> [CatalogListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/categories/catalog

##### ModelsExpand Collapse

<details>

<summary>

List\[CatalogListResponseItem]

</summary>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20killChain">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

mitre\_attack: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20mitreCapec">Link to this property</a>

shortname: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20shortname">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.categories.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)>)

#### Threat EventsCountries

##### [Retrieves countries information for all countries](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/countries/methods/list)

cloudforce\_one.threat\_events.countries.list(CountryListParams\*\*kwargs) -> [CountryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/countries

##### ModelsExpand Collapse

<details>

<summary>

List\[CountryListResponseItem]

</summary>

<details>

<summary>

result: List\[CountryListResponseItemResult]

</summary>

alpha2: str

<a href="#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20result%20%3E%20(items)%20%3E%20(property)%20alpha2">Link to this property</a>

alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20result%20%3E%20(items)%20%3E%20(property)%20alpha3">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20result%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20result">Link to this property</a>

success: str

<a href="#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.countries%20%3E%20(model)%20country_list_response%20%3E%20(schema)>)

#### Threat EventsCrons

#### Threat EventsDatasets

##### [Lists all datasets in an account](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/list)

cloudforce\_one.threat\_events.datasets.list(DatasetListParams\*\*kwargs) -> [DatasetListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset

##### [Reads a dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/get)

cloudforce\_one.threat\_events.datasets.get(strdataset\_id, DatasetGetParams\*\*kwargs) -> [DatasetGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}

##### [Creates a dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/create)

cloudforce\_one.threat\_events.datasets.create(DatasetCreateParams\*\*kwargs) -> [DatasetCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/dataset/create

##### [Updates an existing dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/edit)

cloudforce\_one.threat\_events.datasets.edit(strdataset\_id, DatasetEditParams\*\*kwargs) -> [DatasetEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}

##### [Delete a dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/delete)

cloudforce\_one.threat\_events.datasets.delete(strdataset\_id, DatasetDeleteParams\*\*kwargs) -> [DatasetDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}

##### [Reads raw data for an event by UUID](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/raw)

Deprecated

cloudforce\_one.threat\_events.datasets.raw(strevent\_id, DatasetRawParams\*\*kwargs) -> [DatasetRawResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/raw/{dataset\_id}/{event\_id}

##### ModelsExpand Collapse

<details>

<summary>

List\[DatasetListResponseItem]

</summary>

<details>

<summary>

indicator\_write\_mode: Literal\["read\_only", "create\_only", "full"]

Effective indicator mutation capability after account/dataset authorization and dataset storage capability are applied. API Gateway method permissions are separate and must also allow the requested operation.

</summary>

One of the following:

"read\_only"

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorWriteMode%20%3E%20(member)%200">Link to this property</a>

"create\_only"

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorWriteMode%20%3E%20(member)%201">Link to this property</a>

"full"

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorWriteMode%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorWriteMode">Link to this property</a>

is\_analytics: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20isAnalytics">Link to this property</a>

is\_public: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20isPublic">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

deleted\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20deletedAt">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_list_response%20%3E%20(schema)>)

<details>

<summary>

class DatasetGetResponse: …

</summary>

is\_analytics: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20isAnalytics">Link to this property</a>

is\_public: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20isPublic">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_get_response%20%3E%20(schema)>)

<details>

<summary>

class DatasetCreateResponse: …

</summary>

is\_analytics: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)%20%3E%20(property)%20isAnalytics">Link to this property</a>

is\_public: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)%20%3E%20(property)%20isPublic">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_create_response%20%3E%20(schema)>)

<details>

<summary>

class DatasetEditResponse: …

</summary>

is\_analytics: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)%20%3E%20(property)%20isAnalytics">Link to this property</a>

is\_public: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)%20%3E%20(property)%20isPublic">Link to this property</a>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_edit_response%20%3E%20(schema)>)

<details>

<summary>

class DatasetDeleteResponse: …

</summary>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_delete_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_delete_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_delete_response%20%3E%20(schema)>)

<details>

<summary>

class DatasetRawResponse: …

</summary>

id: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20accountId">Link to this property</a>

created: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

data: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20data">Link to this property</a>

source: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20source">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets%20%3E%20(model)%20dataset_raw_response%20%3E%20(schema)>)

#### Threat EventsDatasetsHealth

#### Threat EventsDatasetsEvents

##### [Reads an event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/datasets/subresources/events/methods/get)

cloudforce\_one.threat\_events.datasets.events.get(strevent\_id, EventGetParams\*\*kwargs) -> [EventGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/events/{event\_id}

##### ModelsExpand Collapse

<details>

<summary>

class EventGetResponse: …

</summary>

attacker: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20attacker">Link to this property</a>

attacker\_country: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountry">Link to this property</a>

attacker\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20attackerCountryAlpha3">Link to this property</a>

category: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20category">Link to this property</a>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20datasetId">Link to this property</a>

date: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20date">Link to this property</a>

event: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20event">Link to this property</a>

has\_children: bool

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20hasChildren">Link to this property</a>

indicator: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicator">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicatorType">Link to this property</a>

indicator\_type\_id: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20indicatorTypeId">Link to this property</a>

kill\_chain: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20killChain">Link to this property</a>

mitre\_attack: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreAttack">Link to this property</a>

mitre\_capec: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20mitreCapec">Link to this property</a>

num\_referenced: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20numReferenced">Link to this property</a>

num\_references: float

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20numReferences">Link to this property</a>

raw\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20rawId">Link to this property</a>

referenced: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20referenced">Link to this property</a>

referenced\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20referencedIds">Link to this property</a>

references: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20references">Link to this property</a>

references\_ids: List\[float]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20referencesIds">Link to this property</a>

tags: List\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

target\_country: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetCountry">Link to this property</a>

target\_country\_alpha3: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetCountryAlpha3">Link to this property</a>

target\_industry: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20targetIndustry">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

insight: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20insight">Link to this property</a>

releasability\_id: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)%20%3E%20(property)%20releasabilityId">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.datasets.events%20%3E%20(model)%20event_get_response%20%3E%20(schema)>)

#### Threat EventsRaw

##### [Reads data for a raw event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/raw/methods/get)

cloudforce\_one.threat\_events.raw.get(strraw\_id, RawGetParams\*\*kwargs) -> [RawGetResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/{event\_id}/raw/{raw\_id}

##### [Updates a raw event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/raw/methods/edit)

cloudforce\_one.threat\_events.raw.edit(strraw\_id, RawEditParams\*\*kwargs) -> [RawEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/{event\_id}/raw/{raw\_id}

##### ModelsExpand Collapse

<details>

<summary>

class RawGetResponse: …

</summary>

id: str

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

account\_id: float

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20accountId">Link to this property</a>

created: str

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20created">Link to this property</a>

data: object

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20data">Link to this property</a>

source: str

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20source">Link to this property</a>

tlp: str

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_get_response%20%3E%20(schema)>)

<details>

<summary>

class RawEditResponse: …

</summary>

id: str

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

data: object

<a href="#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_edit_response%20%3E%20(schema)%20%3E%20(property)%20data">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.raw%20%3E%20(model)%20raw_edit_response%20%3E%20(schema)>)

#### Threat EventsRelate

##### [Removes an event reference](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/relate/methods/delete)

cloudforce\_one.threat\_events.relate.delete(strevent\_id, RelateDeleteParams\*\*kwargs) -> [RelateDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.relate%20%3E%20(model)%20relate_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/relate/{event\_id}

##### ModelsExpand Collapse

<details>

<summary>

class RelateDeleteResponse: …

</summary>

success: bool

<a href="#(resource)%20cloudforce_one.threat_events.relate%20%3E%20(model)%20relate_delete_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.relate%20%3E%20(model)%20relate_delete_response%20%3E%20(schema)>)

#### Threat EventsTags

##### [Lists all tags (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/list)

cloudforce\_one.threat\_events.tags.list(TagListParams\*\*kwargs) -> [TagListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/tags

##### [Creates a new tag](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/create)

cloudforce\_one.threat\_events.tags.create(TagCreateParams\*\*kwargs) -> [TagCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/tags/create

##### [Updates a tag (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/edit)

cloudforce\_one.threat\_events.tags.edit(strtag\_uuid, TagEditParams\*\*kwargs) -> [TagEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/tags/{tag\_uuid}

##### [Deletes a tag (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/methods/delete)

cloudforce\_one.threat\_events.tags.delete(strtag\_uuid, TagDeleteParams\*\*kwargs) -> [TagDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/tags/{tag\_uuid}

##### ModelsExpand Collapse

<details>

<summary>

class TagListResponse: …

</summary>

<details>

<summary>

pagination: Pagination

</summary>

page: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20page">Link to this property</a>

page\_size: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20pageSize">Link to this property</a>

total\_count: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalCount">Link to this property</a>

total\_pages: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalPages">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination">Link to this property</a>

<details>

<summary>

tags: List\[Tag]

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

active\_duration: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration">Link to this property</a>

<details>

<summary>

active\_duration\_annotated: Optional\[TagActiveDurationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20activeDuration_annotated">Link to this property</a>

actor\_category: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory">Link to this property</a>

<details>

<summary>

actor\_category\_annotated: Optional\[TagActorCategoryAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20actorCategory_annotated">Link to this property</a>

<details>

<summary>

aliases: Optional\[List\[TagAlias]]

Structured aliases ({ value, confidence 1-10, tlp }). Public: returned to all accounts with per-entry TLP filtering (entries with tlp: purple are removed for non-CFONE accounts).

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliases">Link to this property</a>

alias\_group\_names: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliasGroupNames">Link to this property</a>

alias\_group\_names\_internal: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20aliasGroupNamesInternal">Link to this property</a>

attribution\_organization: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization">Link to this property</a>

<details>

<summary>

attribution\_organization\_annotated: Optional\[TagAttributionOrganizationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20attributionOrganization_annotated">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

category\_uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryUuid">Link to this property</a>

confidence: Optional\[int]

Overall tag confidence (1-10).

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20createdAt">Link to this property</a>

date\_of\_discovery: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20dateOfDiscovery">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

external\_reference\_links: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferenceLinks">Link to this property</a>

<details>

<summary>

external\_references: Optional\[List\[TagExternalReference]]

Structured external references ({ url, description }). Public: returned to all accounts.

</summary>

url: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20url">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences">Link to this property</a>

<details>

<summary>

external\_references\_annotated: Optional\[List\[TagExternalReferencesAnnotated]]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20externalReferences_annotated">Link to this property</a>

<details>

<summary>

internal\_aliases: Optional\[List\[TagInternalAlias]]

Owner-private structured aliases ({ value, confidence 1-10, tlp }). Returned to the owning account and omitted from shared-catalog non-owner responses.

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalAliases">Link to this property</a>

internal\_description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20internalDescription">Link to this property</a>

last\_seen: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20lastSeen">Link to this property</a>

motive: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive">Link to this property</a>

<details>

<summary>

motive\_annotated: Optional\[TagMotiveAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20motive_annotated">Link to this property</a>

opsec\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel">Link to this property</a>

<details>

<summary>

opsec\_level\_annotated: Optional\[TagOpsecLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20opsecLevel_annotated">Link to this property</a>

origin\_country\_iso: Optional\[str]

ISO country code (alpha-2 or alpha-3). Normalized to uppercase on read. Null when stored value is blank/whitespace.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO">Link to this property</a>

<details>

<summary>

origin\_country\_iso\_annotated: Optional\[TagOriginCountryISOAnnotated]

</summary>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20originCountryISO_annotated">Link to this property</a>

priority: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority">Link to this property</a>

<details>

<summary>

priority\_annotated: Optional\[TagPriorityAnnotated]

</summary>

value: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20priority_annotated">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Parsed custom field values. Null when the tag has no custom fields.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

sophistication\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel">Link to this property</a>

<details>

<summary>

sophistication\_level\_annotated: Optional\[TagSophisticationLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20sophisticationLevel_annotated">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

Tag-level TLP handling marking.

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20updatedAt">Link to this property</a>

version: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20version">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)%20%3E%20(property)%20tags">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_list_response%20%3E%20(schema)>)

<details>

<summary>

class TagCreateResponse: …

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

active\_duration: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration">Link to this property</a>

<details>

<summary>

active\_duration\_annotated: Optional\[ActiveDurationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated">Link to this property</a>

actor\_category: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory">Link to this property</a>

<details>

<summary>

actor\_category\_annotated: Optional\[ActorCategoryAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated">Link to this property</a>

<details>

<summary>

aliases: Optional\[List\[Alias]]

Structured aliases ({ value, confidence 1-10, tlp }). Public: returned to all accounts with per-entry TLP filtering (entries with tlp: purple are removed for non-CFONE accounts).

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliases">Link to this property</a>

alias\_group\_names: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliasGroupNames">Link to this property</a>

alias\_group\_names\_internal: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20aliasGroupNamesInternal">Link to this property</a>

attribution\_organization: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization">Link to this property</a>

<details>

<summary>

attribution\_organization\_annotated: Optional\[AttributionOrganizationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20categoryName">Link to this property</a>

category\_uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20categoryUuid">Link to this property</a>

confidence: Optional\[int]

Overall tag confidence (1-10).

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20confidence">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20createdAt">Link to this property</a>

date\_of\_discovery: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20dateOfDiscovery">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

external\_reference\_links: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferenceLinks">Link to this property</a>

<details>

<summary>

external\_references: Optional\[List\[ExternalReference]]

Structured external references ({ url, description }). Public: returned to all accounts.

</summary>

url: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20url">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences">Link to this property</a>

<details>

<summary>

external\_references\_annotated: Optional\[List\[ExternalReferencesAnnotated]]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated">Link to this property</a>

<details>

<summary>

internal\_aliases: Optional\[List\[InternalAlias]]

Owner-private structured aliases ({ value, confidence 1-10, tlp }). Returned to the owning account and omitted from shared-catalog non-owner responses.

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases">Link to this property</a>

internal\_description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20internalDescription">Link to this property</a>

last\_seen: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20lastSeen">Link to this property</a>

motive: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive">Link to this property</a>

<details>

<summary>

motive\_annotated: Optional\[MotiveAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated">Link to this property</a>

opsec\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel">Link to this property</a>

<details>

<summary>

opsec\_level\_annotated: Optional\[OpsecLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated">Link to this property</a>

origin\_country\_iso: Optional\[str]

ISO country code (alpha-2 or alpha-3). Normalized to uppercase on read. Null when stored value is blank/whitespace.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO">Link to this property</a>

<details>

<summary>

origin\_country\_iso\_annotated: Optional\[OriginCountryISOAnnotated]

</summary>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated">Link to this property</a>

priority: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

<details>

<summary>

priority\_annotated: Optional\[PriorityAnnotated]

</summary>

value: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Parsed custom field values. Null when the tag has no custom fields.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20properties">Link to this property</a>

sophistication\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel">Link to this property</a>

<details>

<summary>

sophistication\_level\_annotated: Optional\[SophisticationLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

Tag-level TLP handling marking.

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20updatedAt">Link to this property</a>

version: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_create_response%20%3E%20(schema)>)

<details>

<summary>

class TagEditResponse: …

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20value">Link to this property</a>

active\_duration: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration">Link to this property</a>

<details>

<summary>

active\_duration\_annotated: Optional\[ActiveDurationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20activeDuration_annotated">Link to this property</a>

actor\_category: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory">Link to this property</a>

<details>

<summary>

actor\_category\_annotated: Optional\[ActorCategoryAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20actorCategory_annotated">Link to this property</a>

<details>

<summary>

aliases: Optional\[List\[Alias]]

Structured aliases ({ value, confidence 1-10, tlp }). Public: returned to all accounts with per-entry TLP filtering (entries with tlp: purple are removed for non-CFONE accounts).

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliases">Link to this property</a>

alias\_group\_names: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliasGroupNames">Link to this property</a>

alias\_group\_names\_internal: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20aliasGroupNamesInternal">Link to this property</a>

attribution\_organization: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization">Link to this property</a>

<details>

<summary>

attribution\_organization\_annotated: Optional\[AttributionOrganizationAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20attributionOrganization_annotated">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20categoryName">Link to this property</a>

category\_uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20categoryUuid">Link to this property</a>

confidence: Optional\[int]

Overall tag confidence (1-10).

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20confidence">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20createdAt">Link to this property</a>

date\_of\_discovery: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20dateOfDiscovery">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

external\_reference\_links: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferenceLinks">Link to this property</a>

<details>

<summary>

external\_references: Optional\[List\[ExternalReference]]

Structured external references ({ url, description }). Public: returned to all accounts.

</summary>

url: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20url">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences">Link to this property</a>

<details>

<summary>

external\_references\_annotated: Optional\[List\[ExternalReferencesAnnotated]]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20externalReferences_annotated">Link to this property</a>

<details>

<summary>

internal\_aliases: Optional\[List\[InternalAlias]]

Owner-private structured aliases ({ value, confidence 1-10, tlp }). Returned to the owning account and omitted from shared-catalog non-owner responses.

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[int]

maximum10

minimum1

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalAliases">Link to this property</a>

internal\_description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20internalDescription">Link to this property</a>

last\_seen: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20lastSeen">Link to this property</a>

motive: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive">Link to this property</a>

<details>

<summary>

motive\_annotated: Optional\[MotiveAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20motive_annotated">Link to this property</a>

opsec\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel">Link to this property</a>

<details>

<summary>

opsec\_level\_annotated: Optional\[OpsecLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20opsecLevel_annotated">Link to this property</a>

origin\_country\_iso: Optional\[str]

ISO country code (alpha-2 or alpha-3). Normalized to uppercase on read. Null when stored value is blank/whitespace.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO">Link to this property</a>

<details>

<summary>

origin\_country\_iso\_annotated: Optional\[OriginCountryISOAnnotated]

</summary>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20originCountryISO_annotated">Link to this property</a>

priority: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

<details>

<summary>

priority\_annotated: Optional\[PriorityAnnotated]

</summary>

value: float

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20value">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20priority_annotated">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Parsed custom field values. Null when the tag has no custom fields.

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20properties">Link to this property</a>

sophistication\_level: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel">Link to this property</a>

<details>

<summary>

sophistication\_level\_annotated: Optional\[SophisticationLevelAnnotated]

</summary>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20value">Link to this property</a>

confidence: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20confidence">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20sophisticationLevel_annotated">Link to this property</a>

<details>

<summary>

tlp: Optional\[Literal\["red", "amber", "amber-strict", 4 more]]

Tag-level TLP handling marking.

</summary>

One of the following:

"red"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%200">Link to this property</a>

"amber"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%201">Link to this property</a>

"amber-strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%202">Link to this property</a>

"green"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%203">Link to this property</a>

"clear"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%204">Link to this property</a>

"purple"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%205">Link to this property</a>

"amber+strict"

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20tlp">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20updatedAt">Link to this property</a>

version: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)%20%3E%20(property)%20version">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_edit_response%20%3E%20(schema)>)

<details>

<summary>

class TagDeleteResponse: …

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags%20%3E%20(model)%20tag_delete_response%20%3E%20(schema)>)

#### Threat EventsTagsCategories

##### [Lists all tag categories (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/list)

cloudforce\_one.threat\_events.tags.categories.list(CategoryListParams\*\*kwargs) -> [CategoryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/tags/categories

##### [Creates a new tag category (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/create)

cloudforce\_one.threat\_events.tags.categories.create(CategoryCreateParams\*\*kwargs) -> [CategoryCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/tags/categories/create

##### [Updates a tag category (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/edit)

Deprecated

cloudforce\_one.threat\_events.tags.categories.edit(strcategory\_uuid, CategoryEditParams\*\*kwargs) -> [CategoryEditResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/cloudforce-one/events/tags/categories/{category\_uuid}

##### [Deletes a tag category (SoT)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/categories/methods/delete)

Deprecated

cloudforce\_one.threat\_events.tags.categories.delete(strcategory\_uuid, CategoryDeleteParams\*\*kwargs) -> [CategoryDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/tags/categories/{category\_uuid}

##### ModelsExpand Collapse

<details>

<summary>

class CategoryListResponse: …

</summary>

<details>

<summary>

categories: List\[Category]

</summary>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20createdAt">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

schema: Optional\[List\[CategorySchema]]

Parsed FieldDefinition\[] defining custom fields for this category, or null if none.

</summary>

key: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20key">Link to this property</a>

<details>

<summary>

kind: Literal\["string", "number", "enum", 3 more]

</summary>

One of the following:

"string"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%200">Link to this property</a>

"number"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%201">Link to this property</a>

"enum"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%202">Link to this property</a>

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%203">Link to this property</a>

"array"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%204">Link to this property</a>

"object"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind">Link to this property</a>

allowed\_values: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20allowedValues">Link to this property</a>

<details>

<summary>

annotations: Optional\[CategorySchemaAnnotations]

</summary>

confidence: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20confidence">Link to this property</a>

tlp: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations">Link to this property</a>

deprecated: Optional\[bool]

Marks a field as unavailable for new values while retaining its definition for historical values.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecated">Link to this property</a>

deprecated\_values: Optional\[List\[str]]

Enum values unavailable for new writes but retained in allowedValues for historical display.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecatedValues">Link to this property</a>

element: Optional\[object]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20element">Link to this property</a>

<details>

<summary>

enforcement: Optional\[Literal\["error", "warn", "off"]]

</summary>

One of the following:

"error"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%200">Link to this property</a>

"warn"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%201">Link to this property</a>

"off"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement">Link to this property</a>

<details>

<summary>

format: Optional\[Literal\["date", "url", "duration", "country"]]

</summary>

One of the following:

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%200">Link to this property</a>

"url"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%201">Link to this property</a>

"duration"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%202">Link to this property</a>

"country"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format">Link to this property</a>

label: Optional\[str]

maxLength128

minLength1

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20label">Link to this property</a>

max\_length: Optional\[int]

exclusiveMinimum

minimum0

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20maxLength">Link to this property</a>

<details>

<summary>

number\_constraint: Optional\[CategorySchemaNumberConstraint]

</summary>

integer: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20integer">Link to this property</a>

max: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20max">Link to this property</a>

min: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20min">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Map of property key to FieldDefinition for object fields. Required when kind is ‘object’. See FieldDefinition (recursive).

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

required: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20schema">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories%20%3E%20(items)%20%3E%20(property)%20updatedAt">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)%20%3E%20(property)%20categories">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_list_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryCreateResponse: …

</summary>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20createdAt">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

schema: Optional\[List\[Schema]]

Parsed FieldDefinition\[] defining custom fields for this category, or null if none.

</summary>

key: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20key">Link to this property</a>

<details>

<summary>

kind: Literal\["string", "number", "enum", 3 more]

</summary>

One of the following:

"string"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%200">Link to this property</a>

"number"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%201">Link to this property</a>

"enum"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%202">Link to this property</a>

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%203">Link to this property</a>

"array"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%204">Link to this property</a>

"object"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind">Link to this property</a>

allowed\_values: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20allowedValues">Link to this property</a>

<details>

<summary>

annotations: Optional\[SchemaAnnotations]

</summary>

confidence: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20confidence">Link to this property</a>

tlp: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations">Link to this property</a>

deprecated: Optional\[bool]

Marks a field as unavailable for new values while retaining its definition for historical values.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecated">Link to this property</a>

deprecated\_values: Optional\[List\[str]]

Enum values unavailable for new writes but retained in allowedValues for historical display.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecatedValues">Link to this property</a>

element: Optional\[object]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20element">Link to this property</a>

<details>

<summary>

enforcement: Optional\[Literal\["error", "warn", "off"]]

</summary>

One of the following:

"error"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%200">Link to this property</a>

"warn"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%201">Link to this property</a>

"off"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement">Link to this property</a>

<details>

<summary>

format: Optional\[Literal\["date", "url", "duration", "country"]]

</summary>

One of the following:

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%200">Link to this property</a>

"url"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%201">Link to this property</a>

"duration"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%202">Link to this property</a>

"country"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format">Link to this property</a>

label: Optional\[str]

maxLength128

minLength1

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20label">Link to this property</a>

max\_length: Optional\[int]

exclusiveMinimum

minimum0

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20maxLength">Link to this property</a>

<details>

<summary>

number\_constraint: Optional\[SchemaNumberConstraint]

</summary>

integer: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20integer">Link to this property</a>

max: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20max">Link to this property</a>

min: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20min">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Map of property key to FieldDefinition for object fields. Required when kind is ‘object’. See FieldDefinition (recursive).

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

required: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)%20%3E%20(property)%20updatedAt">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_create_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryEditResponse: …

</summary>

name: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

created\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20createdAt">Link to this property</a>

description: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

schema: Optional\[List\[Schema]]

Parsed FieldDefinition\[] defining custom fields for this category, or null if none.

</summary>

key: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20key">Link to this property</a>

<details>

<summary>

kind: Literal\["string", "number", "enum", 3 more]

</summary>

One of the following:

"string"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%200">Link to this property</a>

"number"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%201">Link to this property</a>

"enum"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%202">Link to this property</a>

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%203">Link to this property</a>

"array"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%204">Link to this property</a>

"object"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind%20%3E%20(member)%205">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20kind">Link to this property</a>

allowed\_values: Optional\[List\[str]]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20allowedValues">Link to this property</a>

<details>

<summary>

annotations: Optional\[SchemaAnnotations]

</summary>

confidence: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20confidence">Link to this property</a>

tlp: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20annotations">Link to this property</a>

deprecated: Optional\[bool]

Marks a field as unavailable for new values while retaining its definition for historical values.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecated">Link to this property</a>

deprecated\_values: Optional\[List\[str]]

Enum values unavailable for new writes but retained in allowedValues for historical display.

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20deprecatedValues">Link to this property</a>

element: Optional\[object]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20element">Link to this property</a>

<details>

<summary>

enforcement: Optional\[Literal\["error", "warn", "off"]]

</summary>

One of the following:

"error"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%200">Link to this property</a>

"warn"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%201">Link to this property</a>

"off"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20enforcement">Link to this property</a>

<details>

<summary>

format: Optional\[Literal\["date", "url", "duration", "country"]]

</summary>

One of the following:

"date"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%200">Link to this property</a>

"url"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%201">Link to this property</a>

"duration"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%202">Link to this property</a>

"country"

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format%20%3E%20(member)%203">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20format">Link to this property</a>

label: Optional\[str]

maxLength128

minLength1

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20label">Link to this property</a>

max\_length: Optional\[int]

exclusiveMinimum

minimum0

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20maxLength">Link to this property</a>

<details>

<summary>

number\_constraint: Optional\[SchemaNumberConstraint]

</summary>

integer: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20integer">Link to this property</a>

max: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20max">Link to this property</a>

min: Optional\[float]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint%20%3E%20(property)%20min">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20numberConstraint">Link to this property</a>

properties: Optional\[Dict\[str, object]]

Map of property key to FieldDefinition for object fields. Required when kind is ‘object’. See FieldDefinition (recursive).

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20properties">Link to this property</a>

required: Optional\[bool]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema%20%3E%20(items)%20%3E%20(property)%20required">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20schema">Link to this property</a>

updated\_at: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)%20%3E%20(property)%20updatedAt">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_edit_response%20%3E%20(schema)>)

<details>

<summary>

class CategoryDeleteResponse: …

</summary>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.categories%20%3E%20(model)%20category_delete_response%20%3E%20(schema)>)

#### Threat EventsTagsIndicators

##### [List indicators related to a tag](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/indicators/methods/list)

cloudforce\_one.threat\_events.tags.indicators.list(strtag\_uuid, IndicatorListParams\*\*kwargs) -> [IndicatorListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/tags/{tag\_uuid}/indicators

##### ModelsExpand Collapse

<details>

<summary>

class IndicatorListResponse: …

</summary>

<details>

<summary>

indicators: List\[Indicator]

</summary>

created\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20createdAt">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

updated\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20updatedAt">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

dataset\_id: Optional\[str]

The dataset ID this indicator belongs to. Included in list responses.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

related\_events: Optional\[List\[IndicatorRelatedEvent]]

Related events, capped by <code>relatedEventsLimit</code> (default 2). Check <code>relatedEventsHasMore</code> to detect a capped list; pass <code>relatedEventsLimit=-1</code> to retrieve all of them.

</summary>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

event\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventId">Link to this property</a>

event\_date: Optional\[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents">Link to this property</a>

related\_events\_has\_more: Optional\[bool]

True when this indicator appears in more events than <code>relatedEvents</code> contains because <code>relatedEventsLimit</code> capped the list. Pass <code>relatedEventsLimit=-1</code> to retrieve every related event.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEventsHasMore">Link to this property</a>

<details>

<summary>

tags: Optional\[List\[IndicatorTag]]

</summary>

category\_id: Optional\[str]

The UUID of the tag category, or null when the tag is uncategorized.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

tlp: Optional\[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators">Link to this property</a>

<details>

<summary>

pagination: Pagination

</summary>

page: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20page">Link to this property</a>

page\_size: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20pageSize">Link to this property</a>

total\_count: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalCount">Link to this property</a>

total\_pages: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalPages">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.indicators%20%3E%20(model)%20indicator_list_response%20%3E%20(schema)>)

#### Threat EventsTagsIndicatorsBy Dataset

##### [List indicators related to a tag within a dataset (deprecated)](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/tags/subresources/indicators/subresources/by_dataset/methods/list)

Deprecated

cloudforce\_one.threat\_events.tags.indicators.by\_dataset.list(strtag\_uuid, ByDatasetListParams\*\*kwargs) -> [ByDatasetListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/tags/{tag\_uuid}/indicators

##### ModelsExpand Collapse

<details>

<summary>

class ByDatasetListResponse: …

</summary>

<details>

<summary>

indicators: List\[Indicator]

</summary>

created\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20createdAt">Link to this property</a>

indicator\_type: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

updated\_at: datetime

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20updatedAt">Link to this property</a>

uuid: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

dataset\_id: Optional\[str]

The dataset ID this indicator belongs to. Included in list responses.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

<details>

<summary>

related\_events: Optional\[List\[IndicatorRelatedEvent]]

Related events, capped by <code>relatedEventsLimit</code> (default 2). Check <code>relatedEventsHasMore</code> to detect a capped list; pass <code>relatedEventsLimit=-1</code> to retrieve all of them.

</summary>

dataset\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

event\_id: str

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventId">Link to this property</a>

event\_date: Optional\[str]

ISO 8601 date of the related event. Null for legacy relationships created before event-date tracking was added.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents%20%3E%20(items)%20%3E%20(property)%20eventDate">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEvents">Link to this property</a>

related\_events\_has\_more: Optional\[bool]

True when this indicator appears in more events than <code>relatedEvents</code> contains because <code>relatedEventsLimit</code> capped the list. Pass <code>relatedEventsLimit=-1</code> to retrieve every related event.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20relatedEventsHasMore">Link to this property</a>

<details>

<summary>

tags: Optional\[List\[IndicatorTag]]

</summary>

category\_id: Optional\[str]

The UUID of the tag category, or null when the tag is uncategorized.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryId">Link to this property</a>

category\_name: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20categoryName">Link to this property</a>

uuid: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

value: Optional\[str]

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

tlp: Optional\[str]

Traffic Light Protocol designation. UPPERCASE. Possible values: CLEAR, GREEN, AMBER, AMBER-STRICT, RED, PURPLE. Null when not set.

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20indicators">Link to this property</a>

<details>

<summary>

pagination: Pagination

</summary>

page: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20page">Link to this property</a>

page\_size: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20pageSize">Link to this property</a>

total\_count: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalCount">Link to this property</a>

total\_pages: float

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination%20%3E%20(property)%20totalPages">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20pagination">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.tags.indicators.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

#### Threat EventsEvent Tags

##### [Adds a tag to an event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/event_tags/methods/create)

cloudforce\_one.threat\_events.event\_tags.create(strevent\_id, EventTagCreateParams\*\*kwargs) -> [EventTagCreateResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/cloudforce-one/events/event\_tag/{event\_id}/create

##### [Removes a tag from an event](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/event_tags/methods/delete)

cloudforce\_one.threat\_events.event\_tags.delete(strevent\_id, EventTagDeleteParams\*\*kwargs) -> [EventTagDeleteResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/cloudforce-one/events/event\_tag/{event\_id}

##### ModelsExpand Collapse

<details>

<summary>

class EventTagCreateResponse: …

</summary>

success: bool

<a href="#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_create_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_create_response%20%3E%20(schema)>)

<details>

<summary>

class EventTagDeleteResponse: …

</summary>

success: bool

<a href="#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_delete_response%20%3E%20(schema)%20%3E%20(property)%20success">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.event_tags%20%3E%20(model)%20event_tag_delete_response%20%3E%20(schema)>)

#### Threat EventsTarget Industries

##### [Lists target industries across multiple datasets](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/target_industries/methods/list)

cloudforce\_one.threat\_events.target\_industries.list(TargetIndustryListParams\*\*kwargs) -> [TargetIndustryListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.target_industries%20%3E%20(model)%20target_industry_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/targetIndustries

##### ModelsExpand Collapse

<details>

<summary>

class TargetIndustryListResponse: …

</summary>

<details>

<summary>

items: Items

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries%20%3E%20(model)%20target_industry_list_response%20%3E%20(schema)%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.target_industries%20%3E%20(model)%20target_industry_list_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries%20%3E%20(model)%20target_industry_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.target_industries%20%3E%20(model)%20target_industry_list_response%20%3E%20(schema)>)

#### Threat EventsTarget IndustriesBy Dataset

##### [Lists all target industries for a specific dataset](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/target_industries/subresources/by_dataset/methods/list)

cloudforce\_one.threat\_events.target\_industries.by\_dataset.list(strdataset\_id, ByDatasetListParams\*\*kwargs) -> [ByDatasetListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.target_industries.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/dataset/{dataset\_id}/targetIndustries

##### ModelsExpand Collapse

<details>

<summary>

class ByDatasetListResponse: …

</summary>

<details>

<summary>

items: Items

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.target_industries.by_dataset%20%3E%20(model)%20by_dataset_list_response%20%3E%20(schema)>)

#### Threat EventsTarget IndustriesCatalog

##### [Lists all target industries from industry map catalog](https://developers.cloudflare.com/api/python/resources/cloudforce_one/subresources/threat_events/subresources/target_industries/subresources/catalog/methods/list)

cloudforce\_one.threat\_events.target\_industries.catalog.list(CatalogListParams\*\*kwargs) -> [CatalogListResponse](<https://developers.cloudflare.com/api/python/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events.target_industries.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/cloudforce-one/events/targetIndustries/catalog

##### ModelsExpand Collapse

<details>

<summary>

class CatalogListResponse: …

</summary>

<details>

<summary>

items: Items

</summary>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(property)%20items%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(property)%20items">Link to this property</a>

type: str

<a href="#(resource)%20cloudforce_one.threat_events.target_industries.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events.target_industries.catalog%20%3E%20(model)%20catalog_list_response%20%3E%20(schema)>)

#### Threat EventsInsights