SIEM HTTP Destinations
A SIEM HTTP Destination defines where Files.com sends the log types you select. For HTTP destinations, Files.com sends JSON to the configured endpoint. For file destinations, Files.com writes JSON or CSV files to the configured folder.
List SIEM HTTP Destinations
Command
files-cli siem-http-destinations list
Output
Outputs a list of SiemHttpDestination objects according to the output format.
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator.
Additional Arguments
Show SIEM HTTP Destination
Command
files-cli siem-http-destinations find
Output
Outputs a SiemHttpDestination object according to the output format.
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator.
Flags
| Flag | Description |
|---|---|
| --id= int64 Required | Siem Http Destination ID. |
Create SIEM HTTP Destination
Command
files-cli siem-http-destinations create
Output
Outputs a SiemHttpDestination object according to the output format.
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator.
Flags
| Flag | Default | Description |
|---|---|---|
| --name= string | Name for this Destination | |
| --additional-headers= object | Additional HTTP Headers included in calls to the destination URL | |
| --sending-active boolean | true | Whether this SIEM HTTP Destination is currently being sent to or not |
| --generic-payload-type= string | Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. Possible values: json_newline, json_array | |
| --file-destination-path= string | Applicable only for destination type: file. Destination folder path on Files.com. | |
| --file-format= string | Applicable only for destination type: file. Generated file format. Possible values: json, csv | |
| --file-interval-minutes= int64 | Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360. | |
| --splunk-token= string | Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination. | |
| --crowdstrike-token= string | Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike. | |
| --azure-dcr-immutable-id= string | Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule. | |
| --azure-stream-name= string | Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table. | |
| --azure-oauth-client-credentials-tenant-id= string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID. | |
| --azure-oauth-client-credentials-client-id= string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID. | |
| --azure-oauth-client-credentials-client-secret= string | Applicable only for destination type: azure. Client Credentials OAuth Client Secret. | |
| --qradar-username= string | Applicable only for destination type: qradar. Basic auth username provided by QRadar. | |
| --qradar-password= string | Applicable only for destination type: qradar. Basic auth password provided by QRadar. | |
| --solar-winds-token= string | Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds. | |
| --new-relic-api-key= string | Applicable only for destination type: new_relic. API key provided by New Relic. | |
| --datadog-api-key= string | Applicable only for destination type: datadog. API key provided by Datadog. | |
| --action-send-enabled boolean | false | Whether or not sending is enabled for action logs. |
| --sftp-action-send-enabled boolean | false | Whether or not sending is enabled for sftp_action logs. |
| --ftp-action-send-enabled boolean | false | Whether or not sending is enabled for ftp_action logs. |
| --web-dav-action-send-enabled boolean | false | Whether or not sending is enabled for web_dav_action logs. |
| --sync-send-enabled boolean | false | Whether or not sending is enabled for sync logs. |
| --outbound-connection-send-enabled boolean | false | Whether or not sending is enabled for outbound_connection logs. |
| --automation-send-enabled boolean | false | Whether or not sending is enabled for automation logs. |
| --api-request-send-enabled boolean | false | Whether or not sending is enabled for api_request logs. |
| --public-hosting-request-send-enabled boolean | false | Whether or not sending is enabled for public_hosting_request logs. |
| --email-send-enabled boolean | false | Whether or not sending is enabled for email logs. |
| --exavault-api-request-send-enabled boolean | false | Whether or not sending is enabled for exavault_api_request logs. |
| --settings-change-send-enabled boolean | false | Whether or not sending is enabled for settings_change logs. |
| --destination-type= string Required | Destination Type Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible | |
| --destination-url= string | Destination Url |
send_test_entry SIEM HTTP Destination
Command
files-cli siem-http-destinations send-test-entry
Output
No output is returned.
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator.
Flags
| Flag | Description |
|---|---|
| --siem-http-destination-id= int64 | SIEM HTTP Destination ID |
| --destination-type= string | Destination Type Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible |
| --destination-url= string | Destination Url |
| --name= string | Name for this Destination |
| --additional-headers= object | Additional HTTP Headers included in calls to the destination URL |
| --sending-active boolean | Whether this SIEM HTTP Destination is currently being sent to or not |
| --generic-payload-type= string | Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. Possible values: json_newline, json_array |
| --file-destination-path= string | Applicable only for destination type: file. Destination folder path on Files.com. |
| --file-format= string | Applicable only for destination type: file. Generated file format. Possible values: json, csv |
| --file-interval-minutes= int64 | Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360. |
| --splunk-token= string | Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination. |
| --crowdstrike-token= string | Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike. |
| --azure-dcr-immutable-id= string | Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule. |
| --azure-stream-name= string | Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table. |
| --azure-oauth-client-credentials-tenant-id= string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID. |
| --azure-oauth-client-credentials-client-id= string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID. |
| --azure-oauth-client-credentials-client-secret= string | Applicable only for destination type: azure. Client Credentials OAuth Client Secret. |
| --qradar-username= string | Applicable only for destination type: qradar. Basic auth username provided by QRadar. |
| --qradar-password= string | Applicable only for destination type: qradar. Basic auth password provided by QRadar. |
| --solar-winds-token= string | Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds. |
| --new-relic-api-key= string | Applicable only for destination type: new_relic. API key provided by New Relic. |
| --datadog-api-key= string | Applicable only for destination type: datadog. API key provided by Datadog. |
| --action-send-enabled boolean | Whether or not sending is enabled for action logs. |
| --sftp-action-send-enabled boolean | Whether or not sending is enabled for sftp_action logs. |
| --ftp-action-send-enabled boolean | Whether or not sending is enabled for ftp_action logs. |
| --web-dav-action-send-enabled boolean | Whether or not sending is enabled for web_dav_action logs. |
| --sync-send-enabled boolean | Whether or not sending is enabled for sync logs. |
| --outbound-connection-send-enabled boolean | Whether or not sending is enabled for outbound_connection logs. |
| --automation-send-enabled boolean | Whether or not sending is enabled for automation logs. |
| --api-request-send-enabled boolean | Whether or not sending is enabled for api_request logs. |
| --public-hosting-request-send-enabled boolean | Whether or not sending is enabled for public_hosting_request logs. |
| --email-send-enabled boolean | Whether or not sending is enabled for email logs. |
| --exavault-api-request-send-enabled boolean | Whether or not sending is enabled for exavault_api_request logs. |
| --settings-change-send-enabled boolean | Whether or not sending is enabled for settings_change logs. |
Update SIEM HTTP Destination
Command
files-cli siem-http-destinations update
Output
Outputs a SiemHttpDestination object according to the output format.
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator.
Flags
| Flag | Description |
|---|---|
| --id= int64 Required | Siem Http Destination ID. |
| --name= string | Name for this Destination |
| --additional-headers= object | Additional HTTP Headers included in calls to the destination URL |
| --sending-active boolean | Whether this SIEM HTTP Destination is currently being sent to or not |
| --generic-payload-type= string | Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. Possible values: json_newline, json_array |
| --file-destination-path= string | Applicable only for destination type: file. Destination folder path on Files.com. |
| --file-format= string | Applicable only for destination type: file. Generated file format. Possible values: json, csv |
| --file-interval-minutes= int64 | Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360. |
| --splunk-token= string | Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination. |
| --crowdstrike-token= string | Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike. |
| --azure-dcr-immutable-id= string | Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule. |
| --azure-stream-name= string | Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table. |
| --azure-oauth-client-credentials-tenant-id= string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID. |
| --azure-oauth-client-credentials-client-id= string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID. |
| --azure-oauth-client-credentials-client-secret= string | Applicable only for destination type: azure. Client Credentials OAuth Client Secret. |
| --qradar-username= string | Applicable only for destination type: qradar. Basic auth username provided by QRadar. |
| --qradar-password= string | Applicable only for destination type: qradar. Basic auth password provided by QRadar. |
| --solar-winds-token= string | Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds. |
| --new-relic-api-key= string | Applicable only for destination type: new_relic. API key provided by New Relic. |
| --datadog-api-key= string | Applicable only for destination type: datadog. API key provided by Datadog. |
| --action-send-enabled boolean | Whether or not sending is enabled for action logs. |
| --sftp-action-send-enabled boolean | Whether or not sending is enabled for sftp_action logs. |
| --ftp-action-send-enabled boolean | Whether or not sending is enabled for ftp_action logs. |
| --web-dav-action-send-enabled boolean | Whether or not sending is enabled for web_dav_action logs. |
| --sync-send-enabled boolean | Whether or not sending is enabled for sync logs. |
| --outbound-connection-send-enabled boolean | Whether or not sending is enabled for outbound_connection logs. |
| --automation-send-enabled boolean | Whether or not sending is enabled for automation logs. |
| --api-request-send-enabled boolean | Whether or not sending is enabled for api_request logs. |
| --public-hosting-request-send-enabled boolean | Whether or not sending is enabled for public_hosting_request logs. |
| --email-send-enabled boolean | Whether or not sending is enabled for email logs. |
| --exavault-api-request-send-enabled boolean | Whether or not sending is enabled for exavault_api_request logs. |
| --settings-change-send-enabled boolean | Whether or not sending is enabled for settings_change logs. |
| --destination-type= string | Destination Type Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible |
| --destination-url= string | Destination Url |
Delete SIEM HTTP Destination
Command
files-cli siem-http-destinations delete
Output
No output is returned.
Authorization Requirement
Requires a Site-Wide API key, or a User API key or session from a Site Administrator.
Flags
| Flag | Description |
|---|---|
| --id= int64 Required | Siem Http Destination ID. |
The SiemHttpDestination Object
Some of the commands above return a SiemHttpDestination object. The attributes of this object are listed below.
| Attribute | Description |
|---|---|
| id int64 | SIEM HTTP Destination ID |
| name string | Name for this Destination |
| destination_type string | Destination Type Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible |
| destination_url string | Destination Url |
| file_destination_path string | Applicable only for destination type: file. Destination folder path on Files.com. |
| file_format string | Applicable only for destination type: file. Generated file format. Possible values: json, csv |
| file_interval_minutes int64 | Applicable only for destination type: file. Interval, in minutes, between file deliveries. |
| additional_headers object | Additional HTTP Headers included in calls to the destination URL |
| sending_active boolean | Whether this SIEM HTTP Destination is currently being sent to or not |
| generic_payload_type string | Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. Possible values: json_newline, json_array |
| splunk_token_masked string | Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination. |
| crowdstrike_token_masked string | Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike. |
| azure_dcr_immutable_id string | Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule. |
| azure_stream_name string | Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table. |
| azure_oauth_client_credentials_tenant_id string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID. |
| azure_oauth_client_credentials_client_id string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID. |
| azure_oauth_client_credentials_client_secret_masked string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client Secret. |
| qradar_username string | Applicable only for destination type: qradar. Basic auth username provided by QRadar. |
| qradar_password_masked string | Applicable only for destination type: qradar. Basic auth password provided by QRadar. |
| solar_winds_token_masked string | Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds. |
| new_relic_api_key_masked string | Applicable only for destination type: new_relic. API key provided by New Relic. |
| datadog_api_key_masked string | Applicable only for destination type: datadog. API key provided by Datadog. |
| action_send_enabled boolean | Whether or not sending is enabled for action logs. |
| action_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| sftp_action_send_enabled boolean | Whether or not sending is enabled for sftp_action logs. |
| sftp_action_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| ftp_action_send_enabled boolean | Whether or not sending is enabled for ftp_action logs. |
| ftp_action_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| web_dav_action_send_enabled boolean | Whether or not sending is enabled for web_dav_action logs. |
| web_dav_action_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| sync_send_enabled boolean | Whether or not sending is enabled for sync logs. |
| sync_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| outbound_connection_send_enabled boolean | Whether or not sending is enabled for outbound_connection logs. |
| outbound_connection_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| automation_send_enabled boolean | Whether or not sending is enabled for automation logs. |
| automation_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| api_request_send_enabled boolean | Whether or not sending is enabled for api_request logs. |
| api_request_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| public_hosting_request_send_enabled boolean | Whether or not sending is enabled for public_hosting_request logs. |
| public_hosting_request_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| email_send_enabled boolean | Whether or not sending is enabled for email logs. |
| email_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| exavault_api_request_send_enabled boolean | Whether or not sending is enabled for exavault_api_request logs. |
| exavault_api_request_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| settings_change_send_enabled boolean | Whether or not sending is enabled for settings_change logs. |
| settings_change_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| last_http_call_target_type string | Type of URL that was last called. Can be destination_url or azure_oauth_client_credentials_urlPossible values: destination_url, azure_oauth_client_credentials_url, file_destination |
| last_http_call_success boolean | Was the last HTTP call made successful? |
| last_http_call_response_code int64 | Last HTTP Call Response Code |
| last_http_call_response_body string | Last HTTP Call Response Body. Large responses are truncated. |
| last_http_call_error_message string | Last HTTP Call Error Message if applicable |
| last_http_call_time string | Time of Last HTTP Call |
| last_http_call_duration_ms int64 | Duration of the last HTTP Call in milliseconds |
| most_recent_http_call_success_time string | Time of Most Recent Successful HTTP Call |
| connection_test_entry string | Connection Test Entry |
additional_headers
Additional HTTP Headers included in calls to the destination URL
| Value type | Description |
|---|---|
| object of string values | Additional HTTP Headers included in calls to the destination URL |