SIEM HTTP Destinations
List SIEM HTTP Destinations
SDK Method
files_sdk.siem_http_destination.list()
Return Object
ListObj[SiemHttpDestination]
Authorization Requirement
Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.
Additional Arguments
Show SIEM HTTP Destination
SDK Method
files_sdk.siem_http_destination.find()
Return Object
SiemHttpDestination
Authorization Requirement
Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.
Method Arguments
| Argument | Description |
|---|---|
| id int64 Required | Siem Http Destination ID. |
Create SIEM HTTP Destination
SDK Method
files_sdk.siem_http_destination.create()
Return Object
SiemHttpDestination
Authorization Requirement
Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.
Method Arguments
| Argument | Default | Description |
|---|---|---|
| name string | Name for this Destination | |
| additional_headers object | Additional HTTP Headers included in calls to the destination URL | |
| sending_active boolean | true | Whether this SIEM HTTP Destination is currently being sent to or not |
| generic_payload_type string | Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. Possible values: json_newline, json_array | |
| file_destination_path string | Applicable only for destination type: file. Destination folder path on Files.com. | |
| file_format string | Applicable only for destination type: file. Generated file format. Possible values: json, csv | |
| file_interval_minutes int64 | Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360. | |
| splunk_token string | Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination. | |
| crowdstrike_token string | Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike. | |
| azure_dcr_immutable_id string | Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule. | |
| azure_stream_name string | Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table. | |
| azure_oauth_client_credentials_tenant_id string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID. | |
| azure_oauth_client_credentials_client_id string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID. | |
| azure_oauth_client_credentials_client_secret string | Applicable only for destination type: azure. Client Credentials OAuth Client Secret. | |
| qradar_username string | Applicable only for destination type: qradar. Basic auth username provided by QRadar. | |
| qradar_password string | Applicable only for destination type: qradar. Basic auth password provided by QRadar. | |
| solar_winds_token string | Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds. | |
| new_relic_api_key string | Applicable only for destination type: new_relic. API key provided by New Relic. | |
| datadog_api_key string | Applicable only for destination type: datadog. API key provided by Datadog. | |
| action_send_enabled boolean | false | Whether or not sending is enabled for action logs. |
| sftp_action_send_enabled boolean | false | Whether or not sending is enabled for sftp_action logs. |
| ftp_action_send_enabled boolean | false | Whether or not sending is enabled for ftp_action logs. |
| web_dav_action_send_enabled boolean | false | Whether or not sending is enabled for web_dav_action logs. |
| sync_send_enabled boolean | false | Whether or not sending is enabled for sync logs. |
| outbound_connection_send_enabled boolean | false | Whether or not sending is enabled for outbound_connection logs. |
| automation_send_enabled boolean | false | Whether or not sending is enabled for automation logs. |
| api_request_send_enabled boolean | false | Whether or not sending is enabled for api_request logs. |
| public_hosting_request_send_enabled boolean | false | Whether or not sending is enabled for public_hosting_request logs. |
| email_send_enabled boolean | false | Whether or not sending is enabled for email logs. |
| exavault_api_request_send_enabled boolean | false | Whether or not sending is enabled for exavault_api_request logs. |
| settings_change_send_enabled boolean | false | Whether or not sending is enabled for settings_change logs. |
| destination_type string Required | Destination Type Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible | |
| destination_url string | Destination Url |
send_test_entry SIEM HTTP Destination
SDK Method
files_sdk.siem_http_destination.send_test_entry()
Return Object
No return value.
Authorization Requirement
Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.
Method Arguments
| Argument | Description |
|---|---|
| siem_http_destination_id int64 | SIEM HTTP Destination ID |
| destination_type string | Destination Type Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible |
| destination_url string | Destination Url |
| name string | Name for this Destination |
| additional_headers object | Additional HTTP Headers included in calls to the destination URL |
| sending_active boolean | Whether this SIEM HTTP Destination is currently being sent to or not |
| generic_payload_type string | Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. Possible values: json_newline, json_array |
| file_destination_path string | Applicable only for destination type: file. Destination folder path on Files.com. |
| file_format string | Applicable only for destination type: file. Generated file format. Possible values: json, csv |
| file_interval_minutes int64 | Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360. |
| splunk_token string | Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination. |
| crowdstrike_token string | Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike. |
| azure_dcr_immutable_id string | Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule. |
| azure_stream_name string | Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table. |
| azure_oauth_client_credentials_tenant_id string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID. |
| azure_oauth_client_credentials_client_id string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID. |
| azure_oauth_client_credentials_client_secret string | Applicable only for destination type: azure. Client Credentials OAuth Client Secret. |
| qradar_username string | Applicable only for destination type: qradar. Basic auth username provided by QRadar. |
| qradar_password string | Applicable only for destination type: qradar. Basic auth password provided by QRadar. |
| solar_winds_token string | Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds. |
| new_relic_api_key string | Applicable only for destination type: new_relic. API key provided by New Relic. |
| datadog_api_key string | Applicable only for destination type: datadog. API key provided by Datadog. |
| action_send_enabled boolean | Whether or not sending is enabled for action logs. |
| sftp_action_send_enabled boolean | Whether or not sending is enabled for sftp_action logs. |
| ftp_action_send_enabled boolean | Whether or not sending is enabled for ftp_action logs. |
| web_dav_action_send_enabled boolean | Whether or not sending is enabled for web_dav_action logs. |
| sync_send_enabled boolean | Whether or not sending is enabled for sync logs. |
| outbound_connection_send_enabled boolean | Whether or not sending is enabled for outbound_connection logs. |
| automation_send_enabled boolean | Whether or not sending is enabled for automation logs. |
| api_request_send_enabled boolean | Whether or not sending is enabled for api_request logs. |
| public_hosting_request_send_enabled boolean | Whether or not sending is enabled for public_hosting_request logs. |
| email_send_enabled boolean | Whether or not sending is enabled for email logs. |
| exavault_api_request_send_enabled boolean | Whether or not sending is enabled for exavault_api_request logs. |
| settings_change_send_enabled boolean | Whether or not sending is enabled for settings_change logs. |
Update SIEM HTTP Destination
SDK Method
siem_http_destination.update()
Return Object
SiemHttpDestination
Authorization Requirement
Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.
Method Arguments
| Argument | Description |
|---|---|
| name string | Name for this Destination |
| additional_headers object | Additional HTTP Headers included in calls to the destination URL |
| sending_active boolean | Whether this SIEM HTTP Destination is currently being sent to or not |
| generic_payload_type string | Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. Possible values: json_newline, json_array |
| file_destination_path string | Applicable only for destination type: file. Destination folder path on Files.com. |
| file_format string | Applicable only for destination type: file. Generated file format. Possible values: json, csv |
| file_interval_minutes int64 | Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360. |
| splunk_token string | Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination. |
| crowdstrike_token string | Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike. |
| azure_dcr_immutable_id string | Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule. |
| azure_stream_name string | Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table. |
| azure_oauth_client_credentials_tenant_id string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID. |
| azure_oauth_client_credentials_client_id string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID. |
| azure_oauth_client_credentials_client_secret string | Applicable only for destination type: azure. Client Credentials OAuth Client Secret. |
| qradar_username string | Applicable only for destination type: qradar. Basic auth username provided by QRadar. |
| qradar_password string | Applicable only for destination type: qradar. Basic auth password provided by QRadar. |
| solar_winds_token string | Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds. |
| new_relic_api_key string | Applicable only for destination type: new_relic. API key provided by New Relic. |
| datadog_api_key string | Applicable only for destination type: datadog. API key provided by Datadog. |
| action_send_enabled boolean | Whether or not sending is enabled for action logs. |
| sftp_action_send_enabled boolean | Whether or not sending is enabled for sftp_action logs. |
| ftp_action_send_enabled boolean | Whether or not sending is enabled for ftp_action logs. |
| web_dav_action_send_enabled boolean | Whether or not sending is enabled for web_dav_action logs. |
| sync_send_enabled boolean | Whether or not sending is enabled for sync logs. |
| outbound_connection_send_enabled boolean | Whether or not sending is enabled for outbound_connection logs. |
| automation_send_enabled boolean | Whether or not sending is enabled for automation logs. |
| api_request_send_enabled boolean | Whether or not sending is enabled for api_request logs. |
| public_hosting_request_send_enabled boolean | Whether or not sending is enabled for public_hosting_request logs. |
| email_send_enabled boolean | Whether or not sending is enabled for email logs. |
| exavault_api_request_send_enabled boolean | Whether or not sending is enabled for exavault_api_request logs. |
| settings_change_send_enabled boolean | Whether or not sending is enabled for settings_change logs. |
| destination_type string | Destination Type Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible |
| destination_url string | Destination Url |
Delete SIEM HTTP Destination
SDK Method
siem_http_destination.delete()
Return Object
No return value.
Authorization Requirement
Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.
The SiemHttpDestination Object
Some of the methods above return a SiemHttpDestination object. The attributes of this object are listed below.
| Attribute | Description |
|---|---|
| id int64 | SIEM HTTP Destination ID |
| name string | Name for this Destination |
| destination_type string | Destination Type Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible |
| destination_url string | Destination Url |
| file_destination_path string | Applicable only for destination type: file. Destination folder path on Files.com. |
| file_format string | Applicable only for destination type: file. Generated file format. Possible values: json, csv |
| file_interval_minutes int64 | Applicable only for destination type: file. Interval, in minutes, between file deliveries. |
| additional_headers object | Additional HTTP Headers included in calls to the destination URL |
| sending_active boolean | Whether this SIEM HTTP Destination is currently being sent to or not |
| generic_payload_type string | Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. Possible values: json_newline, json_array |
| splunk_token_masked string | Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination. |
| crowdstrike_token_masked string | Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike. |
| azure_dcr_immutable_id string | Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule. |
| azure_stream_name string | Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table. |
| azure_oauth_client_credentials_tenant_id string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID. |
| azure_oauth_client_credentials_client_id string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID. |
| azure_oauth_client_credentials_client_secret_masked string | Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client Secret. |
| qradar_username string | Applicable only for destination type: qradar. Basic auth username provided by QRadar. |
| qradar_password_masked string | Applicable only for destination type: qradar. Basic auth password provided by QRadar. |
| solar_winds_token_masked string | Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds. |
| new_relic_api_key_masked string | Applicable only for destination type: new_relic. API key provided by New Relic. |
| datadog_api_key_masked string | Applicable only for destination type: datadog. API key provided by Datadog. |
| action_send_enabled boolean | Whether or not sending is enabled for action logs. |
| action_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| sftp_action_send_enabled boolean | Whether or not sending is enabled for sftp_action logs. |
| sftp_action_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| ftp_action_send_enabled boolean | Whether or not sending is enabled for ftp_action logs. |
| ftp_action_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| web_dav_action_send_enabled boolean | Whether or not sending is enabled for web_dav_action logs. |
| web_dav_action_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| sync_send_enabled boolean | Whether or not sending is enabled for sync logs. |
| sync_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| outbound_connection_send_enabled boolean | Whether or not sending is enabled for outbound_connection logs. |
| outbound_connection_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| automation_send_enabled boolean | Whether or not sending is enabled for automation logs. |
| automation_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| api_request_send_enabled boolean | Whether or not sending is enabled for api_request logs. |
| api_request_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| public_hosting_request_send_enabled boolean | Whether or not sending is enabled for public_hosting_request logs. |
| public_hosting_request_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| email_send_enabled boolean | Whether or not sending is enabled for email logs. |
| email_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| exavault_api_request_send_enabled boolean | Whether or not sending is enabled for exavault_api_request logs. |
| exavault_api_request_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| settings_change_send_enabled boolean | Whether or not sending is enabled for settings_change logs. |
| settings_change_entries_sent int64 | Number of log entries sent for the lifetime of this destination. |
| last_http_call_target_type string | Type of URL that was last called. Can be destination_url or azure_oauth_client_credentials_urlPossible values: destination_url, azure_oauth_client_credentials_url, file_destination |
| last_http_call_success boolean | Was the last HTTP call made successful? |
| last_http_call_response_code int64 | Last HTTP Call Response Code |
| last_http_call_response_body string | Last HTTP Call Response Body. Large responses are truncated. |
| last_http_call_error_message string | Last HTTP Call Error Message if applicable |
| last_http_call_time string | Time of Last HTTP Call |
| last_http_call_duration_ms int64 | Duration of the last HTTP Call in milliseconds |
| most_recent_http_call_success_time string | Time of Most Recent Successful HTTP Call |
| connection_test_entry string | Connection Test Entry |