- Home
- Documentation
- Applications
- Data Sources
- xcsh_app_setting (Data Source)
xcsh_app_setting (Data Source)
Retrieves information about App setting configuration in namespace metadata.namespace in F5 Distributed Cloud. This is a read-only data source.
~> Note: For more information, see the F5 Distributed Cloud API documentation.
Example Usage
Section titled “Example Usage”# AppSetting Data Source Example
terraform { required_version = ">= 1.0"
required_providers { xcsh = { source = "f5-sales-demo/xcsh" version = ">= 0.1.0" } }}
# Look up an existing AppSetting by namedata "xcsh_app_setting" "example" { name = "example-app-setting" namespace = "staging"}
output "app_setting_id" { value = data.xcsh_app_setting.example.id}Argument Reference
Section titled “Argument Reference”-> Syntax Rule: This provider uses OneOf groups for mutually exclusive options. Fields documented as “Optional Block” use block syntax field_name { ... }. Empty OneOf object attributes use field_name = {}; conditional selection uses condition ? {} : null. Boolean attributes (such as add_hsts and http_redirect) use = true or = false.
🔶 High Risk Operations — Some operations on this resource have high danger level. Destructive operations may require confirmation.
Metadata Argument Reference
Section titled “Metadata Argument Reference”• name - Required String
Name of the AppSetting
• namespace - Required String
Namespace where the AppSetting exists
Attributes Reference
Section titled “Attributes Reference”In addition to all arguments above, the following attributes are exported:
• annotations - Optional Map
Annotations applied to this resource
• app_type_settings - Optional List
List of settings to enable for each AppType, given instance of AppType Exist in this Namespace
• description - Optional String
Description of the AppSetting
• id - Optional String
Unique identifier for the resource
• labels - Optional Map
Labels applied to this resource
• app_type_ref - Optional List
The AppType of App instance in current Namespace. Associating an AppType reference, will enable analysis on this instance’s generated data
• business_logic_markup_setting - Optional String
Settings specifying how API Discovery will be performed
• timeseries_analyses_setting - Optional String
Configuration parameter for timeseries analyses setting
• user_behavior_analysis_setting - Optional String
Configuration for user behavior analysis
• kind - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then kind will hold the referred object’s kind (e.g. ‘route’)
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• uid - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then uid will hold the referred object’s(e.g. Route’s) uid
• disable_spec - Optional Object
Enable this option
• enable - Optional Object
Enable this option
• metric_selectors - Optional List
Define the metric selection criteria, i.e. The metrics source and the actual metrics that should be included in the detection logic
• metric - Optional List Defaults to NO_METRICS
Possible values are NO_METRICS, REQUEST_RATE, ERROR_RATE, LATENCY, THROUGHPUT
[Enum: NO_METRICS|REQUEST_RATE|ERROR_RATE|LATENCY|THROUGHPUT] Choose one or more metrics to be included in the detection logic
• metrics_source - Optional String
Possible values are NONE, NODES, EDGES, VIRTUAL_HOSTS
[Enum: NONE|NODES|EDGES|VIRTUAL_HOSTS] Supported sources from which Metrics can be analyzed All edges in the service mesh graph. Metrics are analyzed separately between all source and destination service combinations
• disable_detection - Optional Object
Configuration parameter for disable detection
• disable_learning - Optional Object
Configuration parameter for disable learning
• enable_detection - Optional String
Various factors about user activity are monitored and analysed to determine malicious users. These settings allow tuning those factors used by the system to detect malicious users
• enable_learning - Optional Object
Configuration parameter for enable learning
• bola_detection_automatic - Optional Object
Configuration parameter for bola detection automatic
• cooling_off_period - Optional Number
Malicious user detection assigns a threat level to each user based on their activity. Once a threat level is assigned, the system continues tracking activity from this user and if no further malicious activity is seen, it gradually reduces the threat assessment to lower levels
• exclude_bola_detection - Optional Object
Configuration parameter for exclude bola detection
• exclude_bot_defense_activity - Optional Object
Configuration parameter for exclude bot defense activity
• exclude_failed_login_activity - Optional Object
Configuration parameter for exclude failed login activity
• exclude_forbidden_activity - Optional Object
Configuration parameter for exclude forbidden activity
• exclude_ip_reputation - Optional Object
Enable this option
• exclude_non_existent_url_activity - Optional Object
Enable this option
• exclude_rate_limit - Optional Object
Configuration parameter for exclude rate limit
• exclude_waf_activity - Optional Object
Configuration parameter for exclude WAF activity
• include_bot_defense_activity - Optional Object
Configuration parameter for include bot defense activity
• include_failed_login_activity - Optional String
When enabled, the system monitors persistent failed login attempts from a user. A failed login is detected if a request results in a response code of 401. These settings specify how to use failed login activity to determine suspicious behavior
• include_forbidden_activity - Optional String
When L7 policy rules are set up to disallow certain types of requests, the system monitors persistent attempts from a user to send requests which result in policy denies. These settings specify how to use disallowed request activity from a user to determine suspicious
behavior
• include_ip_reputation - Optional Object
Enable this option
• include_non_existent_url_activity_automatic - Optional String
Non-existent URL Automatic Activity Settings
• include_non_existent_url_activity_custom - Optional String
Non-existent URL Custom Activity Setting
• include_rate_limit - Optional Object
Configuration parameter for include rate limit
• include_waf_activity - Optional Object
Configuration parameter for include WAF activity
• login_failures_threshold - Optional Number
The number of failed logins beyond which the system will flag this user as malicious
• forbidden_requests_threshold - Optional Number
The number of forbidden requests beyond which the system will flag this user as malicious
• high - Optional Object
Enable this option
• low - Optional Object
Enable this option
• medium - Optional Object
Enable this option
• nonexistent_requests_threshold - Optional Number
The percentage of non-existent requests beyond which the system will flag this user as malicious
Common Types
Section titled “Common Types”The following type definitions are used throughout this resource. See the full definition here rather than repeated inline.
Object Reference {#common-object-reference}
Section titled “Object Reference {#common-object-reference}”Object references establish a direct reference from one configuration object to another in F5 Distributed Cloud. References use the format tenant/namespace/name.
| Field | Type | Description |
|---|---|---|
name | String | Name of the referenced object |
namespace | String | Namespace containing the referenced object |
tenant | String | Tenant of the referenced object (system-managed) |
Transformers {#common-transformers}
Section titled “Transformers {#common-transformers}”Transformers apply transformations to input values before matching. Multiple transformers can be applied in order.
| Value | Description |
|---|---|
LOWER_CASE | Convert to lowercase |
UPPER_CASE | Convert to uppercase |
BASE64_DECODE | Decodebase64 content |
NORMALIZE_PATH | Normalize URL path |
REMOVE_WHITESPACE | Remove whitespace characters |
URL_DECODE | Decode URL-encoded characters |
TRIM_LEFT | Trim leading whitespace |
TRIM_RIGHT | Trim trailing whitespace |
TRIM | Trim both leading and trailing whitespace |
HTTP Methods {#common-http-methods}
Section titled “HTTP Methods {#common-http-methods}”HTTP methods used for request matching.
| Value | Description |
|---|---|
ANY | Match any HTTP method |
GET | HTTP GET request |
HEAD | HTTP HEAD request |
POST | HTTP POST request |
PUT | HTTP PUT request |
DELETE | HTTP DELETE request |
CONNECT | HTTP CONNECT request |
OPTIONS | HTTP OPTIONS request |
TRACE | HTTP TRACE request |
PATCH | HTTP PATCH request |
COPY | HTTP COPY request (WebDAV) |
TLS Fingerprints {#common-tls-fingerprints}
Section titled “TLS Fingerprints {#common-tls-fingerprints}”TLS fingerprint categories for malicious client detection.
| Value | Description |
|---|---|
TLS_FINGERPRINT_NONE | No fingerprint matching |
ANY_MALICIOUS_FINGERPRINT | Match any known malicious fingerprint |
ADWARE | Adware-associated fingerprints |
DRIDEX | Dridex malware fingerprints |
GOOTKIT | Gootkit malware fingerprints |
RANSOMWARE | Ransomware-associated fingerprints |
TRICKBOT | Trickbot malware fingerprints |
IP Threat Categories {#common-ip-threat-categories}
Section titled “IP Threat Categories {#common-ip-threat-categories}”IP address threat categories for security filtering.
| Value | Description |
|---|---|
SPAM_SOURCES | Known spam sources |
WINDOWS_EXPLOITS | Windows exploit sources |
WEB_ATTACKS | Web attack sources |
BOTNETS | Known botnet IPs |
SCANNERS | Network scanner IPs |
REPUTATION | Poor reputation IPs |
PHISHING | Phishing-related IPs |
PROXY | Anonymous proxy IPs |
MOBILE_THREATS | Mobile threat sources |
TOR_PROXY | Tor exit nodes |
DENIAL_OF_SERVICE | DoS attack sources |
NETWORK | Known bad network ranges |