SIEM HTTP Destinations

List SIEM HTTP Destinations

SDK Method

SiemHttpDestination.List();

Return Object

FilesList<SiemHttpDestination>

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Additional Arguments

Example Request

using FilesCom.Models;

try
{
    var siemHttpDestinationIterator = SiemHttpDestination.List();
    foreach (SiemHttpDestination siemHttpDestination in siemHttpDestinationIterator.ListAutoPaging()) {
        // Operate on siemHttpDestination
    }
}
catch (FilesCom.NotAuthenticatedException e)
{
    Console.WriteLine($"Authentication Error Occurred ({e.GetType().Name}): " + e.Message);
}
catch (FilesCom.SdkException e)
{
    Console.WriteLine($"Unknown Error Occurred ({e.GetType().Name}): " + e.Message);
}

Show SIEM HTTP Destination

SDK Method

SiemHttpDestination.Find();

Return Object

SiemHttpDestination

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Method Arguments

ArgumentDescription
id
int64
Required
Siem Http Destination ID.

Example Request

using FilesCom.Models;

try
{
    var siemHttpDestination = await SiemHttpDestination.Find(id);
    // Operate on siemHttpDestination
}
catch (FilesCom.NotAuthenticatedException e)
{
    Console.WriteLine($"Authentication Error Occurred ({e.GetType().Name}): " + e.Message);
}
catch (FilesCom.SdkException e)
{
    Console.WriteLine($"Unknown Error Occurred ({e.GetType().Name}): " + e.Message);
}

Create SIEM HTTP Destination

SDK Method

SiemHttpDestination.Create();

Return Object

SiemHttpDestination

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Method Arguments

ArgumentDefaultDescription
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
trueWhether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
falseWhether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
falseWhether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
falseWhether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
falseWhether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
falseWhether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
falseWhether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
falseWhether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
falseWhether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
falseWhether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
falseWhether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
falseWhether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
falseWhether or not sending is enabled for settings_change logs.
destination_type
string
Required
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url

Example Request

using FilesCom.Models;

var parameters = new Dictionary<string, object>();
parameters.Add("destination_type", "example");

try
{
    var siemHttpDestination = await SiemHttpDestination.Create(parameters);
    // Operate on siemHttpDestination
}
catch (FilesCom.NotAuthenticatedException e)
{
    Console.WriteLine($"Authentication Error Occurred ({e.GetType().Name}): " + e.Message);
}
catch (FilesCom.SdkException e)
{
    Console.WriteLine($"Unknown Error Occurred ({e.GetType().Name}): " + e.Message);
}

send_test_entry SIEM HTTP Destination

SDK Method

SiemHttpDestination.SendTestEntry();

Return Object

No return value.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Method Arguments

ArgumentDescription
siem_http_destination_id
int64
SIEM HTTP Destination ID
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.

Example Request

using FilesCom.Models;

var parameters = new Dictionary<string, object>();
parameters.Add("siem_http_destination_id", (Int64?) 1);

try
{
    await SiemHttpDestination.SendTestEntry(parameters);
}
catch (FilesCom.NotAuthenticatedException e)
{
    Console.WriteLine($"Authentication Error Occurred ({e.GetType().Name}): " + e.Message);
}
catch (FilesCom.SdkException e)
{
    Console.WriteLine($"Unknown Error Occurred ({e.GetType().Name}): " + e.Message);
}

Update SIEM HTTP Destination

SDK Method

siemHttpDestination.Update();

Return Object

SiemHttpDestination

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Method Arguments

ArgumentDescription
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url

Example Request

using FilesCom.Models;

var parameters = new Dictionary<string, object>();
parameters.Add("name", "example");

try
{
    // Find the siemHttpDestination object by its id.
    var siemHttpDestination = await SiemHttpDestination.Find(id);
    await siemHttpDestination.Update(parameters);
}
catch (FilesCom.NotAuthenticatedException e)
{
    Console.WriteLine($"Authentication Error Occurred ({e.GetType().Name}): " + e.Message);
}
catch (FilesCom.SdkException e)
{
    Console.WriteLine($"Unknown Error Occurred ({e.GetType().Name}): " + e.Message);
}

Delete SIEM HTTP Destination

SDK Method

siemHttpDestination.Delete();

Return Object

No return value.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Example Request

using FilesCom.Models;

try
{
    // Find the siemHttpDestination object by its id.
    var siemHttpDestination = await SiemHttpDestination.Find(id);
    await siemHttpDestination.Delete();
}
catch (FilesCom.NotAuthenticatedException e)
{
    Console.WriteLine($"Authentication Error Occurred ({e.GetType().Name}): " + e.Message);
}
catch (FilesCom.SdkException e)
{
    Console.WriteLine($"Unknown Error Occurred ({e.GetType().Name}): " + e.Message);
}

The SiemHttpDestination Object

Some of the methods above return a SiemHttpDestination object. The attributes of this object are listed below.

AttributeDescription
id
int64
SIEM HTTP Destination ID
name
string
Name for this Destination
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries.
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
splunk_token_masked
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token_masked
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret_masked
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password_masked
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token_masked
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key_masked
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key_masked
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
sftp_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
ftp_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
web_dav_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
sync_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
outbound_connection_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
automation_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
api_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
public_hosting_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
email_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
exavault_api_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.
settings_change_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
last_http_call_target_type
string
Type of URL that was last called. Can be destination_url or azure_oauth_client_credentials_url
Possible values: destination_url, azure_oauth_client_credentials_url, file_destination
last_http_call_success
boolean
Was the last HTTP call made successful?
last_http_call_response_code
int64
Last HTTP Call Response Code
last_http_call_response_body
string
Last HTTP Call Response Body. Large responses are truncated.
last_http_call_error_message
string
Last HTTP Call Error Message if applicable
last_http_call_time
string
Time of Last HTTP Call
last_http_call_duration_ms
int64
Duration of the last HTTP Call in milliseconds
most_recent_http_call_success_time
string
Time of Most Recent Successful HTTP Call
connection_test_entry
string
Connection Test Entry