Skip to content

/AWS1/IF_NWS=>GENERATERULECONFIGURATION()

About GenerateRuleConfiguration

Generates a rule configuration from a natural-language description. Provide a prompt along with the rule's firewall type and rule type. The service returns a configuration that you can use when you create or update a rule. If you also provide an existing configuration, the service edits that configuration instead of generating a new one.

Method Signature

METHODS /AWS1/IF_NWS~GENERATERULECONFIGURATION
  IMPORTING
    !IV_PROMPT TYPE /AWS1/NWSSENSITIVESTRING OPTIONAL
    !IV_RULEFIREWALLTYPE TYPE /AWS1/NWSRULEFIREWALLTYPE OPTIONAL
    !IV_RULETYPE TYPE /AWS1/NWSRULETYPE OPTIONAL
    !IV_WAFCONFIGDATATYPE TYPE /AWS1/NWSWAFCONFIGDATATYPE OPTIONAL
    !IV_CURRENTCONFIGURATION TYPE /AWS1/NWSSTRING OPTIONAL
    !IV_CLIENTTOKEN TYPE /AWS1/NWSIDEMPOTENCYTOKEN OPTIONAL
  RETURNING
    VALUE(OO_OUTPUT) TYPE REF TO /aws1/cl_nwsgenr8ruleconfrsp
  RAISING
    /AWS1/CX_NWSACCESSDENIEDEX
    /AWS1/CX_NWSINTERNALSERVEREX
    /AWS1/CX_NWSTHROTTLINGEX
    /AWS1/CX_NWSVLDTNEXCEPTION
    /AWS1/CX_NWSCLIENTEXC
    /AWS1/CX_NWSSERVEREXC
    /AWS1/CX_RT_TECHNICAL_GENERIC
    /AWS1/CX_RT_SERVICE_GENERIC.

IMPORTING

Required arguments:

iv_prompt TYPE /AWS1/NWSSENSITIVESTRING /AWS1/NWSSENSITIVESTRING

A natural-language description of the configuration that you want to generate.

iv_rulefirewalltype TYPE /AWS1/NWSRULEFIREWALLTYPE /AWS1/NWSRULEFIREWALLTYPE

The firewall type of the rule.

iv_ruletype TYPE /AWS1/NWSRULETYPE /AWS1/NWSRULETYPE

The type of the rule. CONFIGURATION rules contain firewall settings, and INSPECTION rules contain rule groups.

Optional arguments:

iv_wafconfigdatatype TYPE /AWS1/NWSWAFCONFIGDATATYPE /AWS1/NWSWAFCONFIGDATATYPE

For AWS WAF configuration rules, the specific AWS WAF configuration variant to generate. This is optional; if you omit it, the service selects the variant.

iv_currentconfiguration TYPE /AWS1/NWSSTRING /AWS1/NWSSTRING

An existing configuration to edit, as a JSON string. When you provide this value, the operation edits the configuration. When you omit it, the operation generates a new configuration.

iv_clienttoken TYPE /AWS1/NWSIDEMPOTENCYTOKEN /AWS1/NWSIDEMPOTENCYTOKEN

A unique, case-sensitive token that you provide to ensure that the operation completes no more than one time. If you retry a request with the same client token and the same parameters, the service returns the result of the original successful request.

RETURNING

oo_output TYPE REF TO /aws1/cl_nwsgenr8ruleconfrsp /AWS1/CL_NWSGENR8RULECONFRSP

Examples

Syntax Example

This is an example of the syntax for calling the method. It includes every possible argument and initializes every possible value. The data provided is not necessarily semantically accurate (for example the value "string" may be provided for something that is intended to be an instance ID, or in some cases two arguments may be mutually exclusive). The syntax shows the ABAP syntax for creating the various data structures.

DATA(lo_result) = lo_client->generateruleconfiguration(
  iv_clienttoken = |string|
  iv_currentconfiguration = |string|
  iv_prompt = |string|
  iv_rulefirewalltype = |string|
  iv_ruletype = |string|
  iv_wafconfigdatatype = |string|
).

This is an example of reading all possible response values

lo_result = lo_result.
IF lo_result IS NOT INITIAL.
  lv_string = lo_result->get_configuration( ).
  lv_string = lo_result->get_description( ).
ENDIF.

Generate a rule configuration from a description

Generates a firewall rule configuration from a natural language description. The response contains the generated configuration as a JSON string, ready to use as the configuration of a rule.

DATA(lo_result) = lo_client->generateruleconfiguration(
  iv_clienttoken = |550e8400-e29b-41d4-a716-446655440015|
  iv_prompt = |Create a rate limiting rule that blocks IP addresses sending more than 2000 requests in 5 minutes|
  iv_rulefirewalltype = |WAF|
  iv_ruletype = |INSPECTION|
).