zscaler.ziacloud.zia_casb_malware_rules module – Manages CASB Malware rules
Note
This module is part of the zscaler.ziacloud collection (version 2.2.3).
It is not included in ansible-core.
To check whether it is installed, run ansible-galaxy collection list.
To install it, use: ansible-galaxy collection install zscaler.ziacloud.
You need further requirements to be able to use this module,
see Requirements for details.
To use it in a playbook, specify: zscaler.ziacloud.zia_casb_malware_rules.
New in zscaler.ziacloud 1.0.0
Synopsis
Adds, updates, or removes SaaS Security Data at Rest Scanning Malware rules.
Requirements
The below requirements are needed on the host that executes this module.
Zscaler SDK Python can be obtained from PyPI https://pypi.org/project/zscaler-sdk-python/
Parameters
Parameter |
Comments |
|---|---|
The configured action for the policy rule. Choices:
|
|
A string that contains the obfuscated API key. |
|
List of bucket IDs for the Zscaler service to inspect for sensitive data. |
|
Email label associated with the rule. Provide as dict with |
|
Quarantine tombstone template. Provide as dict with |
|
The client ID for OAuth2 authentication. |
|
The client secret for OAuth2 authentication. |
|
The Zscaler cloud name provisioned for your organization. Choices:
|
|
List of cloud application tenant IDs for which the rule is applied. |
|
An admin editable text-based description of the rule. Accepted for playbook compatibility; CASB Malware API may not support or return this field. |
|
Administrative state of the rule. If Choices:
|
|
The unique identifier for the CASB Malware rule. Used to reference an existing rule for update or delete. |
|
List of rule label IDs associated with the rule. |
|
Rule name. |
|
Order of rule execution with respect to other SaaS Security Data at Rest Scanning Malware rules. |
|
A string that contains the password for the API admin. |
|
The private key for JWT-based OAuth2 authentication. |
|
A dict containing authentication credentials. |
|
Obfuscated API key. |
|
OAuth2 client ID. |
|
OAuth2 client secret. |
|
Zscaler cloud name. Choices:
|
|
Password for the API admin. |
|
Private key for OAuth2 JWT. |
|
Sandbox Cloud environment. |
|
Sandbox API Key. |
|
Whether to use the legacy Zscaler API client. Choices:
|
|
Email ID of the API admin. |
|
Vanity domain for OAuth2. |
|
Location where all the quarantined files are moved and necessary actions are taken. |
|
Admin rank assigned to this rule. Mandatory when admin rank-based access restriction is enabled. Accepted for playbook compatibility; CASB Malware API may not support or return this field. |
|
The Sandbox cloud environment for API access. |
|
A string that contains the Sandbox API Key. |
|
Enables or disables the scan inbound email link. Choices:
|
|
Specifies the desired state of the resource. Choices:
|
|
The type of SaaS Security Data at Rest Scanning Malware rule. Choices:
|
|
Whether to use the legacy Zscaler API client. Choices:
|
|
A string that contains the email ID of the API admin. |
|
The vanity domain provisioned by Zscaler for OAuth2 flows. |
Notes
Note
Check mode is supported.
typeandnameare required for create.typewithidornamefor update/delete.
Examples
- name: Create a CASB Malware rule
zscaler.ziacloud.zia_casb_malware_rules:
provider: '{{ provider }}'
name: "My Malware Rule"
type: OFLCASB_AVP_REPO
order: 1
action: OFLCASB_AVP_REPORT_MALWARE
enabled: true
cloud_app_tenant_ids:
- 15881081
labels:
- 1441065
bucket_ids:
- 1442271
- 1442270
- name: Update a CASB Malware rule by ID
zscaler.ziacloud.zia_casb_malware_rules:
provider: '{{ provider }}'
id: 1072401
type: OFLCASB_AVP_REPO
name: "Updated Rule Name"
order: 1
- name: Delete a CASB Malware rule
zscaler.ziacloud.zia_casb_malware_rules:
provider: '{{ provider }}'
id: 1072401
type: OFLCASB_AVP_REPO
state: absent
Return Values
Common return values are documented here, the following are the fields unique to this module:
Key |
Description |
|---|---|
The CASB Malware rule resource record. Returned: on success |