zscaler.ziacloud.zia_casb_dlp_rules_info module – Gets information about CASB DLP rules
Note
This module is part of the zscaler.ziacloud collection (version 2.2.3).
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install zscaler.ziacloud.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: zscaler.ziacloud.zia_casb_dlp_rules_info.
New in zscaler.ziacloud 1.0.0
Synopsis
Gets a list of CASB DLP rules or retrieves a specific rule by ID or name.
The rule
typemust be specified to identify which rule category to query.
Requirements
The below requirements are needed on the host that executes this module.
Zscaler SDK Python can be obtained from PyPI https://pypi.org/project/zscaler-sdk-python/
Parameters
Parameter |
Comments |
|---|---|
A string that contains the obfuscated API key. |
|
The client ID for OAuth2 authentication. |
|
The client secret for OAuth2 authentication. |
|
The Zscaler cloud name provisioned for your organization. Choices:
|
|
The unique identifier for the CASB DLP rule. System-generated identifier for the SaaS Security Data at Rest Scanning DLP rule. |
|
Rule name. Used to look up a rule by name within the specified type. |
|
A string that contains the password for the API admin. |
|
The private key for JWT-based OAuth2 authentication. |
|
A dict containing authentication credentials. |
|
Obfuscated API key. |
|
OAuth2 client ID. |
|
OAuth2 client secret. |
|
Zscaler cloud name. Choices:
|
|
Password for the API admin. |
|
Private key for OAuth2 JWT. |
|
Sandbox Cloud environment. |
|
Sandbox API Key. |
|
Whether to use the legacy Zscaler API client. Choices:
|
|
Email ID of the API admin. |
|
Vanity domain for OAuth2. |
|
The Sandbox cloud environment for API access. |
|
A string that contains the Sandbox API Key. |
|
The type of SaaS Security Data at Rest Scanning DLP rule. This parameter is required to identify which rule category to query. Choices:
|
|
Whether to use the legacy Zscaler API client. Choices:
|
|
A string that contains the email ID of the API admin. |
|
The vanity domain provisioned by Zscaler for OAuth2 flows. |
Notes
Note
Check mode is not supported.
Examples
- name: Get all CASB DLP rules of type ITSM
zscaler.ziacloud.zia_casb_dlp_rules_info:
provider: '{{ provider }}'
type: OFLCASB_DLP_ITSM
- name: Get a CASB DLP rule by ID
zscaler.ziacloud.zia_casb_dlp_rules_info:
provider: '{{ provider }}'
type: OFLCASB_DLP_ITSM
id: 1070199
- name: Get a CASB DLP rule by name
zscaler.ziacloud.zia_casb_dlp_rules_info:
provider: '{{ provider }}'
type: OFLCASB_DLP_ITSM
name: "My DLP Rule"
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
A list of CASB DLP rules fetched based on the given criteria. Returned: always |
|
The configured action for the policy rule. Returned: when available |
|
User who inspects their buckets for sensitive data. Returned: when available |
|
Collaboration scope for the rule. Returned: when available |
|
List of components for which the rule is applied. Returned: when available |
|
The location for the content that the service inspects. Returned: when available |
|
An admin editable text-based description of the rule. Returned: when available |
|
The domain for the external organization sharing the channel. Returned: when available |
|
Email address of the external auditor for DLP alerts. Returned: when available |
|
File types for which the rule is applied. Returned: when available |
|
The unique identifier for the CASB DLP rule. Returned: always |
|
Rule name. Returned: always |
|
Order of rule execution with respect to other rules. Returned: always |
|
Admin rank assigned to the rule. Returned: when available |
|
The severity level of the incidents that match the policy rule. Returned: when available |
|
Administrative state of the rule (ENABLED, DISABLED). Returned: always |
|
The type of SaaS Security Data at Rest Scanning DLP rule. Returned: always |