v4

latestSwagger 2.02026-08-0343714211.7 MB
siem_http_destinations
SIEM HTTP Destinations

Create SIEM HTTP Destination

Create SIEM HTTP Destination

post/siem_http_destinations

Response

The SiemHttpDestinations object.

idinteger

SIEM HTTP Destination ID

namestring

Name for this Destination

destination_type'generic' | 'splunk' | 'azure_legacy' | 'qradar' | 'sumo' | 'rapid7' | 'solar_winds' | 'new_relic' | 'datadog' | 'azure' | 'file' | 'crowdstrike' | 'splunk_compatible'

Destination Type

destination_urlstring

Destination Url

file_destination_pathstring

Applicable only for destination type: file. Destination folder path on Files.com.

file_format'json' | 'csv'

Applicable only for destination type: file. Generated file format.

file_interval_minutesinteger

Applicable only for destination type: file. Interval, in minutes, between file deliveries.

additional_headersobject

Additional HTTP Headers included in calls to the destination URL

sending_activeboolean

Whether this SIEM HTTP Destination is currently being sent to or not

generic_payload_type'json_newline' | 'json_array'

Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.

splunk_token_maskedstring

Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.

crowdstrike_token_maskedstring

Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.

azure_dcr_immutable_idstring

Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.

azure_stream_namestring

Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.

azure_oauth_client_credentials_tenant_idstring

Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.

azure_oauth_client_credentials_client_idstring

Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.

azure_oauth_client_credentials_client_secret_maskedstring

Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client Secret.

qradar_usernamestring

Applicable only for destination type: qradar. Basic auth username provided by QRadar.

qradar_password_maskedstring

Applicable only for destination type: qradar. Basic auth password provided by QRadar.

solar_winds_token_maskedstring

Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.

new_relic_api_key_maskedstring

Applicable only for destination type: new_relic. API key provided by New Relic.

datadog_api_key_maskedstring

Applicable only for destination type: datadog. API key provided by Datadog.

action_send_enabledboolean

Whether or not sending is enabled for action logs.

action_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

sftp_action_send_enabledboolean

Whether or not sending is enabled for sftp_action logs.

sftp_action_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

ftp_action_send_enabledboolean

Whether or not sending is enabled for ftp_action logs.

ftp_action_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

web_dav_action_send_enabledboolean

Whether or not sending is enabled for web_dav_action logs.

web_dav_action_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

sync_send_enabledboolean

Whether or not sending is enabled for sync logs.

sync_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

outbound_connection_send_enabledboolean

Whether or not sending is enabled for outbound_connection logs.

outbound_connection_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

automation_send_enabledboolean

Whether or not sending is enabled for automation logs.

automation_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

api_request_send_enabledboolean

Whether or not sending is enabled for api_request logs.

api_request_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

public_hosting_request_send_enabledboolean

Whether or not sending is enabled for public_hosting_request logs.

public_hosting_request_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

email_send_enabledboolean

Whether or not sending is enabled for email logs.

email_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

exavault_api_request_send_enabledboolean

Whether or not sending is enabled for exavault_api_request logs.

exavault_api_request_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

settings_change_send_enabledboolean

Whether or not sending is enabled for settings_change logs.

settings_change_entries_sentinteger

Number of log entries sent for the lifetime of this destination.

last_http_call_target_type'destination_url' | 'azure_oauth_client_credentials_url' | 'file_destination'

Type of URL that was last called. Can be destination_url or azure_oauth_client_credentials_url

last_http_call_successboolean

Was the last HTTP call made successful?

last_http_call_response_codeinteger

Last HTTP Call Response Code

last_http_call_response_bodystring

Last HTTP Call Response Body. Large responses are truncated.

last_http_call_error_messagestring

Last HTTP Call Error Message if applicable

last_http_call_timestring

Time of Last HTTP Call

last_http_call_duration_msinteger

Duration of the last HTTP Call in milliseconds

most_recent_http_call_success_timestring

Time of Most Recent Successful HTTP Call

connection_test_entrystring

Connection Test Entry

Example response

{
  "id": 1,
  "name": "example",
  "destination_type": "example",
  "destination_url": "example",
  "file_destination_path": "example",
  "file_format": "example",
  "file_interval_minutes": 1,
  "additional_headers": {
    "key": "example value"
  },
  "sending_active": true,
  "generic_payload_type": "example",
  "splunk_token_masked": "example",
  "crowdstrike_token_masked": "example",
  "azure_dcr_immutable_id": "example",
  "azure_stream_name": "example",
  "azure_oauth_client_credentials_tenant_id": "example",
  "azure_oauth_client_credentials_client_id": "example",
  "azure_oauth_client_credentials_client_secret_masked": "example",
  "qradar_username": "example",
  "qradar_password_masked": "example",
  "solar_winds_token_masked": "example",
  "new_relic_api_key_masked": "example",
  "datadog_api_key_masked": "example",
  "action_send_enabled": true,
  "action_entries_sent": 1,
  "sftp_action_send_enabled": true,
  "sftp_action_entries_sent": 1,
  "ftp_action_send_enabled": true,
  "ftp_action_entries_sent": 1,
  "web_dav_action_send_enabled": true,
  "web_dav_action_entries_sent": 1,
  "sync_send_enabled": true,
  "sync_entries_sent": 1,
  "outbound_connection_send_enabled": true,
  "outbound_connection_entries_sent": 1,
  "automation_send_enabled": true,
  "automation_entries_sent": 1,
  "api_request_send_enabled": true,
  "api_request_entries_sent": 1,
  "public_hosting_request_send_enabled": true,
  "public_hosting_request_entries_sent": 1,
  "email_send_enabled": true,
  "email_entries_sent": 1,
  "exavault_api_request_send_enabled": true,
  "exavault_api_request_entries_sent": 1,
  "settings_change_send_enabled": true,
  "settings_change_entries_sent": 1,
  "last_http_call_target_type": "destination_url",
  "last_http_call_success": true,
  "last_http_call_response_code": 1,
  "last_http_call_response_body": "example",
  "last_http_call_error_message": "example",
  "last_http_call_time": "example",
  "last_http_call_duration_ms": 1,
  "most_recent_http_call_success_time": "example",
  "connection_test_entry": "example"
}