SIEM HTTP Destinations

List SIEM HTTP Destinations

Endpoint

GET/siem_http_destinations

Return Object

SiemHttpDestination[]

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Additional Arguments

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations.json \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

Example Response

[
  {
    "id": 1,
    "name": "example",
    "destination_type": "example",
    "destination_url": "example",
    "file_destination_path": "example",
    "file_format": "example",
    "file_interval_minutes": 1,
    "additional_headers": {
      "key": "example value"
    },
    "sending_active": true,
    "generic_payload_type": "example",
    "splunk_token_masked": "example",
    "crowdstrike_token_masked": "example",
    "azure_dcr_immutable_id": "example",
    "azure_stream_name": "example",
    "azure_oauth_client_credentials_tenant_id": "example",
    "azure_oauth_client_credentials_client_id": "example",
    "azure_oauth_client_credentials_client_secret_masked": "example",
    "qradar_username": "example",
    "qradar_password_masked": "example",
    "solar_winds_token_masked": "example",
    "new_relic_api_key_masked": "example",
    "datadog_api_key_masked": "example",
    "action_send_enabled": true,
    "action_entries_sent": 1,
    "sftp_action_send_enabled": true,
    "sftp_action_entries_sent": 1,
    "ftp_action_send_enabled": true,
    "ftp_action_entries_sent": 1,
    "web_dav_action_send_enabled": true,
    "web_dav_action_entries_sent": 1,
    "sync_send_enabled": true,
    "sync_entries_sent": 1,
    "outbound_connection_send_enabled": true,
    "outbound_connection_entries_sent": 1,
    "automation_send_enabled": true,
    "automation_entries_sent": 1,
    "api_request_send_enabled": true,
    "api_request_entries_sent": 1,
    "public_hosting_request_send_enabled": true,
    "public_hosting_request_entries_sent": 1,
    "email_send_enabled": true,
    "email_entries_sent": 1,
    "exavault_api_request_send_enabled": true,
    "exavault_api_request_entries_sent": 1,
    "settings_change_send_enabled": true,
    "settings_change_entries_sent": 1,
    "last_http_call_target_type": "destination_url",
    "last_http_call_success": true,
    "last_http_call_response_code": 1,
    "last_http_call_response_body": "example",
    "last_http_call_error_message": "example",
    "last_http_call_time": "example",
    "last_http_call_duration_ms": 1,
    "most_recent_http_call_success_time": "example",
    "connection_test_entry": "example"
  }
]

Show SIEM HTTP Destination

Endpoint

GET/siem_http_destinations/{id}

Return Object

SiemHttpDestination

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Request Parameters

ParameterDescription
id
int64
Required
Siem Http Destination ID.

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations/{id}.json \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

Example Response

{
  "id": 1,
  "name": "example",
  "destination_type": "example",
  "destination_url": "example",
  "file_destination_path": "example",
  "file_format": "example",
  "file_interval_minutes": 1,
  "additional_headers": {
    "key": "example value"
  },
  "sending_active": true,
  "generic_payload_type": "example",
  "splunk_token_masked": "example",
  "crowdstrike_token_masked": "example",
  "azure_dcr_immutable_id": "example",
  "azure_stream_name": "example",
  "azure_oauth_client_credentials_tenant_id": "example",
  "azure_oauth_client_credentials_client_id": "example",
  "azure_oauth_client_credentials_client_secret_masked": "example",
  "qradar_username": "example",
  "qradar_password_masked": "example",
  "solar_winds_token_masked": "example",
  "new_relic_api_key_masked": "example",
  "datadog_api_key_masked": "example",
  "action_send_enabled": true,
  "action_entries_sent": 1,
  "sftp_action_send_enabled": true,
  "sftp_action_entries_sent": 1,
  "ftp_action_send_enabled": true,
  "ftp_action_entries_sent": 1,
  "web_dav_action_send_enabled": true,
  "web_dav_action_entries_sent": 1,
  "sync_send_enabled": true,
  "sync_entries_sent": 1,
  "outbound_connection_send_enabled": true,
  "outbound_connection_entries_sent": 1,
  "automation_send_enabled": true,
  "automation_entries_sent": 1,
  "api_request_send_enabled": true,
  "api_request_entries_sent": 1,
  "public_hosting_request_send_enabled": true,
  "public_hosting_request_entries_sent": 1,
  "email_send_enabled": true,
  "email_entries_sent": 1,
  "exavault_api_request_send_enabled": true,
  "exavault_api_request_entries_sent": 1,
  "settings_change_send_enabled": true,
  "settings_change_entries_sent": 1,
  "last_http_call_target_type": "destination_url",
  "last_http_call_success": true,
  "last_http_call_response_code": 1,
  "last_http_call_response_body": "example",
  "last_http_call_error_message": "example",
  "last_http_call_time": "example",
  "last_http_call_duration_ms": 1,
  "most_recent_http_call_success_time": "example",
  "connection_test_entry": "example"
}

Create SIEM HTTP Destination

Endpoint

POST/siem_http_destinations

Return Object

SiemHttpDestination

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Request Parameters

ParameterDefaultDescription
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
trueWhether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
falseWhether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
falseWhether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
falseWhether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
falseWhether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
falseWhether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
falseWhether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
falseWhether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
falseWhether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
falseWhether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
falseWhether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
falseWhether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
falseWhether or not sending is enabled for settings_change logs.
destination_type
string
Required
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations.json \
  -X POST \
  -H 'Content-Type: application/json' \
  -d '{"name":"example","additional_headers":{"key":"example value"},"sending_active":true,"generic_payload_type":"example","file_destination_path":"example","file_format":"example","file_interval_minutes":1,"azure_dcr_immutable_id":"example","azure_stream_name":"example","azure_oauth_client_credentials_tenant_id":"example","azure_oauth_client_credentials_client_id":"example","qradar_username":"example","action_send_enabled":true,"sftp_action_send_enabled":true,"ftp_action_send_enabled":true,"web_dav_action_send_enabled":true,"sync_send_enabled":true,"outbound_connection_send_enabled":true,"automation_send_enabled":true,"api_request_send_enabled":true,"public_hosting_request_send_enabled":true,"email_send_enabled":true,"exavault_api_request_send_enabled":true,"settings_change_send_enabled":true,"destination_type":"example","destination_url":"example"}' \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

Example Response

{
  "id": 1,
  "name": "example",
  "destination_type": "example",
  "destination_url": "example",
  "file_destination_path": "example",
  "file_format": "example",
  "file_interval_minutes": 1,
  "additional_headers": {
    "key": "example value"
  },
  "sending_active": true,
  "generic_payload_type": "example",
  "splunk_token_masked": "example",
  "crowdstrike_token_masked": "example",
  "azure_dcr_immutable_id": "example",
  "azure_stream_name": "example",
  "azure_oauth_client_credentials_tenant_id": "example",
  "azure_oauth_client_credentials_client_id": "example",
  "azure_oauth_client_credentials_client_secret_masked": "example",
  "qradar_username": "example",
  "qradar_password_masked": "example",
  "solar_winds_token_masked": "example",
  "new_relic_api_key_masked": "example",
  "datadog_api_key_masked": "example",
  "action_send_enabled": true,
  "action_entries_sent": 1,
  "sftp_action_send_enabled": true,
  "sftp_action_entries_sent": 1,
  "ftp_action_send_enabled": true,
  "ftp_action_entries_sent": 1,
  "web_dav_action_send_enabled": true,
  "web_dav_action_entries_sent": 1,
  "sync_send_enabled": true,
  "sync_entries_sent": 1,
  "outbound_connection_send_enabled": true,
  "outbound_connection_entries_sent": 1,
  "automation_send_enabled": true,
  "automation_entries_sent": 1,
  "api_request_send_enabled": true,
  "api_request_entries_sent": 1,
  "public_hosting_request_send_enabled": true,
  "public_hosting_request_entries_sent": 1,
  "email_send_enabled": true,
  "email_entries_sent": 1,
  "exavault_api_request_send_enabled": true,
  "exavault_api_request_entries_sent": 1,
  "settings_change_send_enabled": true,
  "settings_change_entries_sent": 1,
  "last_http_call_target_type": "destination_url",
  "last_http_call_success": true,
  "last_http_call_response_code": 1,
  "last_http_call_response_body": "example",
  "last_http_call_error_message": "example",
  "last_http_call_time": "example",
  "last_http_call_duration_ms": 1,
  "most_recent_http_call_success_time": "example",
  "connection_test_entry": "example"
}

send_test_entry SIEM HTTP Destination

Endpoint

POST/siem_http_destinations/send_test_entry

Return Object

No return value.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Request Parameters

ParameterDescription
siem_http_destination_id
int64
SIEM HTTP Destination ID
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations/send_test_entry.json \
  -X POST \
  -H 'Content-Type: application/json' \
  -d '{"siem_http_destination_id":1,"destination_type":"example","destination_url":"example","name":"example","additional_headers":{"key":"example value"},"sending_active":true,"generic_payload_type":"example","file_destination_path":"example","file_format":"example","file_interval_minutes":1,"azure_dcr_immutable_id":"example","azure_stream_name":"example","azure_oauth_client_credentials_tenant_id":"example","azure_oauth_client_credentials_client_id":"example","qradar_username":"example","action_send_enabled":true,"sftp_action_send_enabled":true,"ftp_action_send_enabled":true,"web_dav_action_send_enabled":true,"sync_send_enabled":true,"outbound_connection_send_enabled":true,"automation_send_enabled":true,"api_request_send_enabled":true,"public_hosting_request_send_enabled":true,"email_send_enabled":true,"exavault_api_request_send_enabled":true,"settings_change_send_enabled":true}' \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

Update SIEM HTTP Destination

Endpoint

PATCH/siem_http_destinations/{id}

Return Object

SiemHttpDestination

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Request Parameters

ParameterDescription
id
int64
Required
Siem Http Destination ID.
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations/{id}.json \
  -X PATCH \
  -H 'Content-Type: application/json' \
  -d '{"name":"example","additional_headers":{"key":"example value"},"sending_active":true,"generic_payload_type":"example","file_destination_path":"example","file_format":"example","file_interval_minutes":1,"azure_dcr_immutable_id":"example","azure_stream_name":"example","azure_oauth_client_credentials_tenant_id":"example","azure_oauth_client_credentials_client_id":"example","qradar_username":"example","action_send_enabled":true,"sftp_action_send_enabled":true,"ftp_action_send_enabled":true,"web_dav_action_send_enabled":true,"sync_send_enabled":true,"outbound_connection_send_enabled":true,"automation_send_enabled":true,"api_request_send_enabled":true,"public_hosting_request_send_enabled":true,"email_send_enabled":true,"exavault_api_request_send_enabled":true,"settings_change_send_enabled":true,"destination_type":"example","destination_url":"example"}' \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

Example Response

{
  "id": 1,
  "name": "example",
  "destination_type": "example",
  "destination_url": "example",
  "file_destination_path": "example",
  "file_format": "example",
  "file_interval_minutes": 1,
  "additional_headers": {
    "key": "example value"
  },
  "sending_active": true,
  "generic_payload_type": "example",
  "splunk_token_masked": "example",
  "crowdstrike_token_masked": "example",
  "azure_dcr_immutable_id": "example",
  "azure_stream_name": "example",
  "azure_oauth_client_credentials_tenant_id": "example",
  "azure_oauth_client_credentials_client_id": "example",
  "azure_oauth_client_credentials_client_secret_masked": "example",
  "qradar_username": "example",
  "qradar_password_masked": "example",
  "solar_winds_token_masked": "example",
  "new_relic_api_key_masked": "example",
  "datadog_api_key_masked": "example",
  "action_send_enabled": true,
  "action_entries_sent": 1,
  "sftp_action_send_enabled": true,
  "sftp_action_entries_sent": 1,
  "ftp_action_send_enabled": true,
  "ftp_action_entries_sent": 1,
  "web_dav_action_send_enabled": true,
  "web_dav_action_entries_sent": 1,
  "sync_send_enabled": true,
  "sync_entries_sent": 1,
  "outbound_connection_send_enabled": true,
  "outbound_connection_entries_sent": 1,
  "automation_send_enabled": true,
  "automation_entries_sent": 1,
  "api_request_send_enabled": true,
  "api_request_entries_sent": 1,
  "public_hosting_request_send_enabled": true,
  "public_hosting_request_entries_sent": 1,
  "email_send_enabled": true,
  "email_entries_sent": 1,
  "exavault_api_request_send_enabled": true,
  "exavault_api_request_entries_sent": 1,
  "settings_change_send_enabled": true,
  "settings_change_entries_sent": 1,
  "last_http_call_target_type": "destination_url",
  "last_http_call_success": true,
  "last_http_call_response_code": 1,
  "last_http_call_response_body": "example",
  "last_http_call_error_message": "example",
  "last_http_call_time": "example",
  "last_http_call_duration_ms": 1,
  "most_recent_http_call_success_time": "example",
  "connection_test_entry": "example"
}

Delete SIEM HTTP Destination

Endpoint

DELETE/siem_http_destinations/{id}

Return Object

No return value.

Authorization Requirement

Requires either a Site-Wide API key or User API key or session from a User with Site Admin permissions.

Request Parameters

ParameterDescription
id
int64
Required
Siem Http Destination ID.

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations/{id}.json \
  -X DELETE \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

The SiemHttpDestination Object

Some of the endpoints above return a SiemHttpDestination object. The attributes of this object are listed below.

AttributeDescription
id
int64
SIEM HTTP Destination ID
name
string
Name for this Destination
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries.
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
splunk_token_masked
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token_masked
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret_masked
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password_masked
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token_masked
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key_masked
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key_masked
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
sftp_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
ftp_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
web_dav_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
sync_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
outbound_connection_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
automation_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
api_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
public_hosting_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
email_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
exavault_api_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.
settings_change_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
last_http_call_target_type
string
Type of URL that was last called. Can be destination_url or azure_oauth_client_credentials_url
Possible values: destination_url, azure_oauth_client_credentials_url, file_destination
last_http_call_success
boolean
Was the last HTTP call made successful?
last_http_call_response_code
int64
Last HTTP Call Response Code
last_http_call_response_body
string
Last HTTP Call Response Body. Large responses are truncated.
last_http_call_error_message
string
Last HTTP Call Error Message if applicable
last_http_call_time
string
Time of Last HTTP Call
last_http_call_duration_ms
int64
Duration of the last HTTP Call in milliseconds
most_recent_http_call_success_time
string
Time of Most Recent Successful HTTP Call
connection_test_entry
string
Connection Test Entry

Example SiemHttpDestination Object

{
  "id": 1,
  "name": "example",
  "destination_type": "example",
  "destination_url": "example",
  "file_destination_path": "example",
  "file_format": "example",
  "file_interval_minutes": 1,
  "additional_headers": {
    "key": "example value"
  },
  "sending_active": true,
  "generic_payload_type": "example",
  "splunk_token_masked": "example",
  "crowdstrike_token_masked": "example",
  "azure_dcr_immutable_id": "example",
  "azure_stream_name": "example",
  "azure_oauth_client_credentials_tenant_id": "example",
  "azure_oauth_client_credentials_client_id": "example",
  "azure_oauth_client_credentials_client_secret_masked": "example",
  "qradar_username": "example",
  "qradar_password_masked": "example",
  "solar_winds_token_masked": "example",
  "new_relic_api_key_masked": "example",
  "datadog_api_key_masked": "example",
  "action_send_enabled": true,
  "action_entries_sent": 1,
  "sftp_action_send_enabled": true,
  "sftp_action_entries_sent": 1,
  "ftp_action_send_enabled": true,
  "ftp_action_entries_sent": 1,
  "web_dav_action_send_enabled": true,
  "web_dav_action_entries_sent": 1,
  "sync_send_enabled": true,
  "sync_entries_sent": 1,
  "outbound_connection_send_enabled": true,
  "outbound_connection_entries_sent": 1,
  "automation_send_enabled": true,
  "automation_entries_sent": 1,
  "api_request_send_enabled": true,
  "api_request_entries_sent": 1,
  "public_hosting_request_send_enabled": true,
  "public_hosting_request_entries_sent": 1,
  "email_send_enabled": true,
  "email_entries_sent": 1,
  "exavault_api_request_send_enabled": true,
  "exavault_api_request_entries_sent": 1,
  "settings_change_send_enabled": true,
  "settings_change_entries_sent": 1,
  "last_http_call_target_type": "destination_url",
  "last_http_call_success": true,
  "last_http_call_response_code": 1,
  "last_http_call_response_body": "example",
  "last_http_call_error_message": "example",
  "last_http_call_time": "example",
  "last_http_call_duration_ms": 1,
  "most_recent_http_call_success_time": "example",
  "connection_test_entry": "example"
}