SIEM HTTP Destinations

List SIEM HTTP Destinations

Command

files-cli siem-http-destinations list

Output

Outputs a list of SiemHttpDestination objects according to the output format.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Additional Arguments

Example Request

files-cli siem-http-destinations list

Show SIEM HTTP Destination

Command

files-cli siem-http-destinations find

Output

Outputs a SiemHttpDestination object according to the output format.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Flags

FlagDescription
--id=
int64
Required
Siem Http Destination ID.

Example Request

files-cli siem-http-destinations find \
  --id=1

Create SIEM HTTP Destination

Command

files-cli siem-http-destinations create

Output

Outputs a SiemHttpDestination object according to the output format.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Flags

FlagDefaultDescription
--name=
string
Name for this Destination
--additional-headers=
object
Additional HTTP Headers included in calls to the destination URL
--sending-active
boolean
trueWhether this SIEM HTTP Destination is currently being sent to or not
--generic-payload-type=
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
--file-destination-path=
string
Applicable only for destination type: file. Destination folder path on Files.com.
--file-format=
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
--file-interval-minutes=
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
--splunk-token=
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
--crowdstrike-token=
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
--azure-dcr-immutable-id=
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
--azure-stream-name=
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
--azure-oauth-client-credentials-tenant-id=
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
--azure-oauth-client-credentials-client-id=
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
--azure-oauth-client-credentials-client-secret=
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
--qradar-username=
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
--qradar-password=
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
--solar-winds-token=
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
--new-relic-api-key=
string
Applicable only for destination type: new_relic. API key provided by New Relic.
--datadog-api-key=
string
Applicable only for destination type: datadog. API key provided by Datadog.
--action-send-enabled
boolean
falseWhether or not sending is enabled for action logs.
--sftp-action-send-enabled
boolean
falseWhether or not sending is enabled for sftp_action logs.
--ftp-action-send-enabled
boolean
falseWhether or not sending is enabled for ftp_action logs.
--web-dav-action-send-enabled
boolean
falseWhether or not sending is enabled for web_dav_action logs.
--sync-send-enabled
boolean
falseWhether or not sending is enabled for sync logs.
--outbound-connection-send-enabled
boolean
falseWhether or not sending is enabled for outbound_connection logs.
--automation-send-enabled
boolean
falseWhether or not sending is enabled for automation logs.
--api-request-send-enabled
boolean
falseWhether or not sending is enabled for api_request logs.
--public-hosting-request-send-enabled
boolean
falseWhether or not sending is enabled for public_hosting_request logs.
--email-send-enabled
boolean
falseWhether or not sending is enabled for email logs.
--exavault-api-request-send-enabled
boolean
falseWhether or not sending is enabled for exavault_api_request logs.
--settings-change-send-enabled
boolean
falseWhether or not sending is enabled for settings_change logs.
--destination-type=
string
Required
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
--destination-url=
string
Destination Url

Example Request

files-cli siem-http-destinations create \
  --destination-type="example"

send_test_entry SIEM HTTP Destination

Command

files-cli siem-http-destinations send-test-entry

Output

No output is returned.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Flags

FlagDescription
--siem-http-destination-id=
int64
SIEM HTTP Destination ID
--destination-type=
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
--destination-url=
string
Destination Url
--name=
string
Name for this Destination
--additional-headers=
object
Additional HTTP Headers included in calls to the destination URL
--sending-active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
--generic-payload-type=
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
--file-destination-path=
string
Applicable only for destination type: file. Destination folder path on Files.com.
--file-format=
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
--file-interval-minutes=
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
--splunk-token=
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
--crowdstrike-token=
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
--azure-dcr-immutable-id=
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
--azure-stream-name=
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
--azure-oauth-client-credentials-tenant-id=
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
--azure-oauth-client-credentials-client-id=
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
--azure-oauth-client-credentials-client-secret=
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
--qradar-username=
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
--qradar-password=
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
--solar-winds-token=
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
--new-relic-api-key=
string
Applicable only for destination type: new_relic. API key provided by New Relic.
--datadog-api-key=
string
Applicable only for destination type: datadog. API key provided by Datadog.
--action-send-enabled
boolean
Whether or not sending is enabled for action logs.
--sftp-action-send-enabled
boolean
Whether or not sending is enabled for sftp_action logs.
--ftp-action-send-enabled
boolean
Whether or not sending is enabled for ftp_action logs.
--web-dav-action-send-enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
--sync-send-enabled
boolean
Whether or not sending is enabled for sync logs.
--outbound-connection-send-enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
--automation-send-enabled
boolean
Whether or not sending is enabled for automation logs.
--api-request-send-enabled
boolean
Whether or not sending is enabled for api_request logs.
--public-hosting-request-send-enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
--email-send-enabled
boolean
Whether or not sending is enabled for email logs.
--exavault-api-request-send-enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
--settings-change-send-enabled
boolean
Whether or not sending is enabled for settings_change logs.

Example Request

files-cli siem-http-destinations send-test-entry \
  --siem-http-destination-id=1

Update SIEM HTTP Destination

Command

files-cli siem-http-destinations update

Output

Outputs a SiemHttpDestination object according to the output format.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Flags

FlagDescription
--id=
int64
Required
Siem Http Destination ID.
--name=
string
Name for this Destination
--additional-headers=
object
Additional HTTP Headers included in calls to the destination URL
--sending-active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
--generic-payload-type=
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
--file-destination-path=
string
Applicable only for destination type: file. Destination folder path on Files.com.
--file-format=
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
--file-interval-minutes=
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
--splunk-token=
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
--crowdstrike-token=
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
--azure-dcr-immutable-id=
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
--azure-stream-name=
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
--azure-oauth-client-credentials-tenant-id=
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
--azure-oauth-client-credentials-client-id=
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
--azure-oauth-client-credentials-client-secret=
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
--qradar-username=
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
--qradar-password=
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
--solar-winds-token=
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
--new-relic-api-key=
string
Applicable only for destination type: new_relic. API key provided by New Relic.
--datadog-api-key=
string
Applicable only for destination type: datadog. API key provided by Datadog.
--action-send-enabled
boolean
Whether or not sending is enabled for action logs.
--sftp-action-send-enabled
boolean
Whether or not sending is enabled for sftp_action logs.
--ftp-action-send-enabled
boolean
Whether or not sending is enabled for ftp_action logs.
--web-dav-action-send-enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
--sync-send-enabled
boolean
Whether or not sending is enabled for sync logs.
--outbound-connection-send-enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
--automation-send-enabled
boolean
Whether or not sending is enabled for automation logs.
--api-request-send-enabled
boolean
Whether or not sending is enabled for api_request logs.
--public-hosting-request-send-enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
--email-send-enabled
boolean
Whether or not sending is enabled for email logs.
--exavault-api-request-send-enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
--settings-change-send-enabled
boolean
Whether or not sending is enabled for settings_change logs.
--destination-type=
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
--destination-url=
string
Destination Url

Example Request

files-cli siem-http-destinations update \
  --id=1 \
  --name="example"

Delete SIEM HTTP Destination

Command

files-cli siem-http-destinations delete

Output

No output is returned.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Flags

FlagDescription
--id=
int64
Required
Siem Http Destination ID.

Example Request

files-cli siem-http-destinations delete \
  --id=1

The SiemHttpDestination Object

Some of the commands above return a SiemHttpDestination object. The attributes of this object are listed below.

AttributeDescription
id
int64
SIEM HTTP Destination ID
name
string
Name for this Destination
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries.
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
splunk_token_masked
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token_masked
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret_masked
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password_masked
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token_masked
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key_masked
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key_masked
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
sftp_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
ftp_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
web_dav_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
sync_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
outbound_connection_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
automation_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
api_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
public_hosting_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
email_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
exavault_api_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.
settings_change_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
last_http_call_target_type
string
Type of URL that was last called. Can be destination_url or azure_oauth_client_credentials_url
Possible values: destination_url, azure_oauth_client_credentials_url, file_destination
last_http_call_success
boolean
Was the last HTTP call made successful?
last_http_call_response_code
int64
Last HTTP Call Response Code
last_http_call_response_body
string
Last HTTP Call Response Body. Large responses are truncated.
last_http_call_error_message
string
Last HTTP Call Error Message if applicable
last_http_call_time
string
Time of Last HTTP Call
last_http_call_duration_ms
int64
Duration of the last HTTP Call in milliseconds
most_recent_http_call_success_time
string
Time of Most Recent Successful HTTP Call
connection_test_entry
string
Connection Test Entry