SIEM HTTP Destinations

List SIEM HTTP Destinations

SDK Method

SiemHttpDestination.list()

Return Object

SiemHttpDestination[]

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Additional Arguments

Example Request

import SiemHttpDestination from 'files.com/lib/models/SiemHttpDestination';
import * as FilesErrors from 'files.com/lib/Errors';

try {
  const siemHttpDestinations = await SiemHttpDestination.list();
  for (const siemHttpDestination of siemHttpDestinations) {
    // Operate on siemHttpDestination
  }
} catch (err) {
  if (err instanceof FilesErrors.NotAuthenticatedError) {
    console.error(`Authentication Error Occurred (${err.constructor.name}): ${err.error}`);
  } else if (err instanceof FilesErrors.FilesError) {
    console.error(`Unknown Error Occurred (${err.constructor.name}): ${err.error}`);
  } else {
    throw err;
  }
}

Show SIEM HTTP Destination

SDK Method

SiemHttpDestination.find()

Return Object

SiemHttpDestination

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Method Arguments

ArgumentDescription
id
int64
Required
Siem Http Destination ID.

Example Request

import SiemHttpDestination from 'files.com/lib/models/SiemHttpDestination';
import * as FilesErrors from 'files.com/lib/Errors';

try {
  const siemHttpDestination = await SiemHttpDestination.find(id);
  // Operate on siemHttpDestination
} catch (err) {
  if (err instanceof FilesErrors.NotAuthenticatedError) {
    console.error(`Authentication Error Occurred (${err.constructor.name}): ${err.error}`);
  } else if (err instanceof FilesErrors.FilesError) {
    console.error(`Unknown Error Occurred (${err.constructor.name}): ${err.error}`);
  } else {
    throw err;
  }
}

Create SIEM HTTP Destination

SDK Method

SiemHttpDestination.create()

Return Object

SiemHttpDestination

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Method Arguments

ArgumentDefaultDescription
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
trueWhether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
falseWhether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
falseWhether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
falseWhether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
falseWhether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
falseWhether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
falseWhether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
falseWhether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
falseWhether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
falseWhether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
falseWhether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
falseWhether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
falseWhether or not sending is enabled for settings_change logs.
destination_type
string
Required
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url

Example Request

import SiemHttpDestination from 'files.com/lib/models/SiemHttpDestination';
import * as FilesErrors from 'files.com/lib/Errors';

try {
  const siemHttpDestination = await SiemHttpDestination.create({
    destination_type: "example",
  });
  // Operate on siemHttpDestination
} catch (err) {
  if (err instanceof FilesErrors.NotAuthenticatedError) {
    console.error(`Authentication Error Occurred (${err.constructor.name}): ${err.error}`);
  } else if (err instanceof FilesErrors.FilesError) {
    console.error(`Unknown Error Occurred (${err.constructor.name}): ${err.error}`);
  } else {
    throw err;
  }
}

send_test_entry SIEM HTTP Destination

SDK Method

SiemHttpDestination.sendTestEntry()

Return Object

No return value.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Method Arguments

ArgumentDescription
siem_http_destination_id
int64
SIEM HTTP Destination ID
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.

Example Request

import SiemHttpDestination from 'files.com/lib/models/SiemHttpDestination';
import * as FilesErrors from 'files.com/lib/Errors';

try {
  await SiemHttpDestination.sendTestEntry({
    siem_http_destination_id: 1,
  });
} catch (err) {
  if (err instanceof FilesErrors.NotAuthenticatedError) {
    console.error(`Authentication Error Occurred (${err.constructor.name}): ${err.error}`);
  } else if (err instanceof FilesErrors.FilesError) {
    console.error(`Unknown Error Occurred (${err.constructor.name}): ${err.error}`);
  } else {
    throw err;
  }
}

Update SIEM HTTP Destination

SDK Method

siemHttpDestination.update()

Return Object

SiemHttpDestination

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Method Arguments

ArgumentDescription
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url

Example Request

import SiemHttpDestination from 'files.com/lib/models/SiemHttpDestination';
import * as FilesErrors from 'files.com/lib/Errors';

try {
  // Find the siemHttpDestination object by its id.
  const siemHttpDestination = await SiemHttpDestination.find(id);
  await siemHttpDestination.update({
    name: "example",
  });
} catch (err) {
  if (err instanceof FilesErrors.NotAuthenticatedError) {
    console.error(`Authentication Error Occurred (${err.constructor.name}): ${err.error}`);
  } else if (err instanceof FilesErrors.FilesError) {
    console.error(`Unknown Error Occurred (${err.constructor.name}): ${err.error}`);
  } else {
    throw err;
  }
}

Delete SIEM HTTP Destination

SDK Method

siemHttpDestination.delete()

Return Object

No return value.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Example Request

import SiemHttpDestination from 'files.com/lib/models/SiemHttpDestination';
import * as FilesErrors from 'files.com/lib/Errors';

try {
  // Find the siemHttpDestination object by its id.
  const siemHttpDestination = await SiemHttpDestination.find(id);
  await siemHttpDestination.delete();
} catch (err) {
  if (err instanceof FilesErrors.NotAuthenticatedError) {
    console.error(`Authentication Error Occurred (${err.constructor.name}): ${err.error}`);
  } else if (err instanceof FilesErrors.FilesError) {
    console.error(`Unknown Error Occurred (${err.constructor.name}): ${err.error}`);
  } else {
    throw err;
  }
}

The SiemHttpDestination Object

Some of the methods above return a SiemHttpDestination object. The attributes of this object are listed below.

AttributeDescription
id
int64
SIEM HTTP Destination ID
name
string
Name for this Destination
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries.
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
splunk_token_masked
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token_masked
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret_masked
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password_masked
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token_masked
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key_masked
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key_masked
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
sftp_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
ftp_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
web_dav_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
sync_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
outbound_connection_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
automation_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
api_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
public_hosting_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
email_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
exavault_api_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.
settings_change_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
last_http_call_target_type
string
Type of URL that was last called. Can be destination_url or azure_oauth_client_credentials_url
Possible values: destination_url, azure_oauth_client_credentials_url, file_destination
last_http_call_success
boolean
Was the last HTTP call made successful?
last_http_call_response_code
int64
Last HTTP Call Response Code
last_http_call_response_body
string
Last HTTP Call Response Body. Large responses are truncated.
last_http_call_error_message
string
Last HTTP Call Error Message if applicable
last_http_call_time
string
Time of Last HTTP Call
last_http_call_duration_ms
int64
Duration of the last HTTP Call in milliseconds
most_recent_http_call_success_time
string
Time of Most Recent Successful HTTP Call
connection_test_entry
string
Connection Test Entry