---
title: "Create SIEM HTTP Destination"
method: POST
path: "/siem_http_destinations"
tags: ["siem_http_destinations", "SIEM HTTP Destinations"]
---

# Create SIEM HTTP Destination

`POST /siem_http_destinations`

Create SIEM HTTP Destination

## Response `201`

The SiemHttpDestinations object.

- SiemHttpDestinationEntity — SiemHttpDestinationEntity model
  - `id` integer — SIEM HTTP Destination ID
  - `name` string — Name for this Destination
  - `destination_type` 'generic' | 'splunk' | 'azure_legacy' | 'qradar' | 'sumo' | 'rapid7' | 'solar_winds' | 'new_relic' | 'datadog' | 'azure' | 'file' | 'crowdstrike' | 'splunk_compatible' — Destination Type
  - `destination_url` string — Destination Url
  - `file_destination_path` string — Applicable only for destination type: file. Destination folder path on Files.com.
  - `file_format` 'json' | 'csv' — Applicable only for destination type: file. Generated file format.
  - `file_interval_minutes` integer — Applicable only for destination type: file. Interval, in minutes, between file deliveries.
  - `additional_headers` object — Additional HTTP Headers included in calls to the destination URL
  - `sending_active` boolean — Whether this SIEM HTTP Destination is currently being sent to or not
  - `generic_payload_type` 'json_newline' | 'json_array' — Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
  - `splunk_token_masked` string — Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
  - `crowdstrike_token_masked` string — Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
  - `azure_dcr_immutable_id` string — Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
  - `azure_stream_name` string — Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
  - `azure_oauth_client_credentials_tenant_id` string — Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
  - `azure_oauth_client_credentials_client_id` string — Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
  - `azure_oauth_client_credentials_client_secret_masked` string — Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client Secret.
  - `qradar_username` string — Applicable only for destination type: qradar. Basic auth username provided by QRadar.
  - `qradar_password_masked` string — Applicable only for destination type: qradar. Basic auth password provided by QRadar.
  - `solar_winds_token_masked` string — Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
  - `new_relic_api_key_masked` string — Applicable only for destination type: new_relic. API key provided by New Relic.
  - `datadog_api_key_masked` string — Applicable only for destination type: datadog. API key provided by Datadog.
  - `action_send_enabled` boolean — Whether or not sending is enabled for action logs.
  - `action_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `sftp_action_send_enabled` boolean — Whether or not sending is enabled for sftp_action logs.
  - `sftp_action_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `ftp_action_send_enabled` boolean — Whether or not sending is enabled for ftp_action logs.
  - `ftp_action_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `web_dav_action_send_enabled` boolean — Whether or not sending is enabled for web_dav_action logs.
  - `web_dav_action_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `sync_send_enabled` boolean — Whether or not sending is enabled for sync logs.
  - `sync_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `outbound_connection_send_enabled` boolean — Whether or not sending is enabled for outbound_connection logs.
  - `outbound_connection_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `automation_send_enabled` boolean — Whether or not sending is enabled for automation logs.
  - `automation_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `api_request_send_enabled` boolean — Whether or not sending is enabled for api_request logs.
  - `api_request_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `public_hosting_request_send_enabled` boolean — Whether or not sending is enabled for public_hosting_request logs.
  - `public_hosting_request_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `email_send_enabled` boolean — Whether or not sending is enabled for email logs.
  - `email_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `exavault_api_request_send_enabled` boolean — Whether or not sending is enabled for exavault_api_request logs.
  - `exavault_api_request_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `settings_change_send_enabled` boolean — Whether or not sending is enabled for settings_change logs.
  - `settings_change_entries_sent` integer — Number of log entries sent for the lifetime of this destination.
  - `last_http_call_target_type` 'destination_url' | 'azure_oauth_client_credentials_url' | 'file_destination' — Type of URL that was last called. Can be `destination_url` or `azure_oauth_client_credentials_url`
  - `last_http_call_success` boolean — Was the last HTTP call made successful?
  - `last_http_call_response_code` integer — Last HTTP Call Response Code
  - `last_http_call_response_body` string — Last HTTP Call Response Body. Large responses are truncated.
  - `last_http_call_error_message` string — Last HTTP Call Error Message if applicable
  - `last_http_call_time` string — Time of Last HTTP Call
  - `last_http_call_duration_ms` integer — Duration of the last HTTP Call in milliseconds
  - `most_recent_http_call_success_time` string — Time of Most Recent Successful HTTP Call
  - `connection_test_entry` string — Connection Test Entry

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `405` — Method Not Allowed
- `409` — Conflict
- `412` — Precondition Failed
- `422` — Unprocessable Entity
- `423` — Locked
- `429` — Too Many Requests

---

[API](https://skmtc.net/files/apis/files-com-api.md) · [All operations](https://skmtc.net/files/apis/files-com-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/files/files-com-api/versions/c80c746637fd/schema)
