SIEM HTTP Destinations

A SIEM HTTP Destination defines where Files.com sends the log types you select. For HTTP destinations, Files.com sends JSON to the configured endpoint. For file destinations, Files.com writes JSON or CSV files to the configured folder.

List SIEM HTTP Destinations

Endpoint

GET/siem_http_destinations

Return Object

SiemHttpDestination[]

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator.

Additional Arguments

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations.json \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

Example Response

[
  {
    "id": 1,
    "name": "example",
    "destination_type": "example",
    "destination_url": "example",
    "file_destination_path": "example",
    "file_format": "example",
    "file_interval_minutes": 1,
    "additional_headers": {
      "Authorization": "Bearer YOUR_TOKEN"
    },
    "sending_active": true,
    "generic_payload_type": "example",
    "splunk_token_masked": "example",
    "crowdstrike_token_masked": "example",
    "azure_dcr_immutable_id": "example",
    "azure_stream_name": "example",
    "azure_oauth_client_credentials_tenant_id": "example",
    "azure_oauth_client_credentials_client_id": "example",
    "azure_oauth_client_credentials_client_secret_masked": "example",
    "qradar_username": "example",
    "qradar_password_masked": "example",
    "solar_winds_token_masked": "example",
    "new_relic_api_key_masked": "example",
    "datadog_api_key_masked": "example",
    "action_send_enabled": true,
    "action_entries_sent": 1,
    "sftp_action_send_enabled": true,
    "sftp_action_entries_sent": 1,
    "ftp_action_send_enabled": true,
    "ftp_action_entries_sent": 1,
    "web_dav_action_send_enabled": true,
    "web_dav_action_entries_sent": 1,
    "sync_send_enabled": true,
    "sync_entries_sent": 1,
    "outbound_connection_send_enabled": true,
    "outbound_connection_entries_sent": 1,
    "automation_send_enabled": true,
    "automation_entries_sent": 1,
    "api_request_send_enabled": true,
    "api_request_entries_sent": 1,
    "public_hosting_request_send_enabled": true,
    "public_hosting_request_entries_sent": 1,
    "email_send_enabled": true,
    "email_entries_sent": 1,
    "exavault_api_request_send_enabled": true,
    "exavault_api_request_entries_sent": 1,
    "settings_change_send_enabled": true,
    "settings_change_entries_sent": 1,
    "last_http_call_target_type": "destination_url",
    "last_http_call_success": true,
    "last_http_call_response_code": 1,
    "last_http_call_response_body": "example",
    "last_http_call_error_message": "example",
    "last_http_call_time": "example",
    "last_http_call_duration_ms": 1,
    "most_recent_http_call_success_time": "example",
    "connection_test_entry": "example"
  }
]

Show SIEM HTTP Destination

Endpoint

GET/siem_http_destinations/{id}

Return Object

SiemHttpDestination

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator.

Request Parameters

ParameterDescription
id
int64
Required
Siem Http Destination ID.

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations/{id}.json \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

Example Response

{
  "id": 1,
  "name": "example",
  "destination_type": "example",
  "destination_url": "example",
  "file_destination_path": "example",
  "file_format": "example",
  "file_interval_minutes": 1,
  "additional_headers": {
    "Authorization": "Bearer YOUR_TOKEN"
  },
  "sending_active": true,
  "generic_payload_type": "example",
  "splunk_token_masked": "example",
  "crowdstrike_token_masked": "example",
  "azure_dcr_immutable_id": "example",
  "azure_stream_name": "example",
  "azure_oauth_client_credentials_tenant_id": "example",
  "azure_oauth_client_credentials_client_id": "example",
  "azure_oauth_client_credentials_client_secret_masked": "example",
  "qradar_username": "example",
  "qradar_password_masked": "example",
  "solar_winds_token_masked": "example",
  "new_relic_api_key_masked": "example",
  "datadog_api_key_masked": "example",
  "action_send_enabled": true,
  "action_entries_sent": 1,
  "sftp_action_send_enabled": true,
  "sftp_action_entries_sent": 1,
  "ftp_action_send_enabled": true,
  "ftp_action_entries_sent": 1,
  "web_dav_action_send_enabled": true,
  "web_dav_action_entries_sent": 1,
  "sync_send_enabled": true,
  "sync_entries_sent": 1,
  "outbound_connection_send_enabled": true,
  "outbound_connection_entries_sent": 1,
  "automation_send_enabled": true,
  "automation_entries_sent": 1,
  "api_request_send_enabled": true,
  "api_request_entries_sent": 1,
  "public_hosting_request_send_enabled": true,
  "public_hosting_request_entries_sent": 1,
  "email_send_enabled": true,
  "email_entries_sent": 1,
  "exavault_api_request_send_enabled": true,
  "exavault_api_request_entries_sent": 1,
  "settings_change_send_enabled": true,
  "settings_change_entries_sent": 1,
  "last_http_call_target_type": "destination_url",
  "last_http_call_success": true,
  "last_http_call_response_code": 1,
  "last_http_call_response_body": "example",
  "last_http_call_error_message": "example",
  "last_http_call_time": "example",
  "last_http_call_duration_ms": 1,
  "most_recent_http_call_success_time": "example",
  "connection_test_entry": "example"
}

Create SIEM HTTP Destination

Endpoint

POST/siem_http_destinations

Return Object

SiemHttpDestination

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator.

Request Parameters

ParameterDefaultDescription
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
trueWhether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
falseWhether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
falseWhether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
falseWhether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
falseWhether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
falseWhether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
falseWhether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
falseWhether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
falseWhether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
falseWhether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
falseWhether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
falseWhether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
falseWhether or not sending is enabled for settings_change logs.
destination_type
string
Required
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations.json \
  -X POST \
  -H 'Content-Type: application/json' \
  -d '{"name":"example","additional_headers":{"Authorization":"Bearer YOUR_TOKEN"},"sending_active":true,"generic_payload_type":"example","file_destination_path":"example","file_format":"example","file_interval_minutes":1,"azure_dcr_immutable_id":"example","azure_stream_name":"example","azure_oauth_client_credentials_tenant_id":"example","azure_oauth_client_credentials_client_id":"example","qradar_username":"example","action_send_enabled":true,"sftp_action_send_enabled":true,"ftp_action_send_enabled":true,"web_dav_action_send_enabled":true,"sync_send_enabled":true,"outbound_connection_send_enabled":true,"automation_send_enabled":true,"api_request_send_enabled":true,"public_hosting_request_send_enabled":true,"email_send_enabled":true,"exavault_api_request_send_enabled":true,"settings_change_send_enabled":true,"destination_type":"example","destination_url":"example"}' \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

Example Response

{
  "id": 1,
  "name": "example",
  "destination_type": "example",
  "destination_url": "example",
  "file_destination_path": "example",
  "file_format": "example",
  "file_interval_minutes": 1,
  "additional_headers": {
    "Authorization": "Bearer YOUR_TOKEN"
  },
  "sending_active": true,
  "generic_payload_type": "example",
  "splunk_token_masked": "example",
  "crowdstrike_token_masked": "example",
  "azure_dcr_immutable_id": "example",
  "azure_stream_name": "example",
  "azure_oauth_client_credentials_tenant_id": "example",
  "azure_oauth_client_credentials_client_id": "example",
  "azure_oauth_client_credentials_client_secret_masked": "example",
  "qradar_username": "example",
  "qradar_password_masked": "example",
  "solar_winds_token_masked": "example",
  "new_relic_api_key_masked": "example",
  "datadog_api_key_masked": "example",
  "action_send_enabled": true,
  "action_entries_sent": 1,
  "sftp_action_send_enabled": true,
  "sftp_action_entries_sent": 1,
  "ftp_action_send_enabled": true,
  "ftp_action_entries_sent": 1,
  "web_dav_action_send_enabled": true,
  "web_dav_action_entries_sent": 1,
  "sync_send_enabled": true,
  "sync_entries_sent": 1,
  "outbound_connection_send_enabled": true,
  "outbound_connection_entries_sent": 1,
  "automation_send_enabled": true,
  "automation_entries_sent": 1,
  "api_request_send_enabled": true,
  "api_request_entries_sent": 1,
  "public_hosting_request_send_enabled": true,
  "public_hosting_request_entries_sent": 1,
  "email_send_enabled": true,
  "email_entries_sent": 1,
  "exavault_api_request_send_enabled": true,
  "exavault_api_request_entries_sent": 1,
  "settings_change_send_enabled": true,
  "settings_change_entries_sent": 1,
  "last_http_call_target_type": "destination_url",
  "last_http_call_success": true,
  "last_http_call_response_code": 1,
  "last_http_call_response_body": "example",
  "last_http_call_error_message": "example",
  "last_http_call_time": "example",
  "last_http_call_duration_ms": 1,
  "most_recent_http_call_success_time": "example",
  "connection_test_entry": "example"
}

send_test_entry SIEM HTTP Destination

Endpoint

POST/siem_http_destinations/send_test_entry

Return Object

No return value.

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator.

Request Parameters

ParameterDescription
siem_http_destination_id
int64
SIEM HTTP Destination ID
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations/send_test_entry.json \
  -X POST \
  -H 'Content-Type: application/json' \
  -d '{"siem_http_destination_id":1,"destination_type":"example","destination_url":"example","name":"example","additional_headers":{"Authorization":"Bearer YOUR_TOKEN"},"sending_active":true,"generic_payload_type":"example","file_destination_path":"example","file_format":"example","file_interval_minutes":1,"azure_dcr_immutable_id":"example","azure_stream_name":"example","azure_oauth_client_credentials_tenant_id":"example","azure_oauth_client_credentials_client_id":"example","qradar_username":"example","action_send_enabled":true,"sftp_action_send_enabled":true,"ftp_action_send_enabled":true,"web_dav_action_send_enabled":true,"sync_send_enabled":true,"outbound_connection_send_enabled":true,"automation_send_enabled":true,"api_request_send_enabled":true,"public_hosting_request_send_enabled":true,"email_send_enabled":true,"exavault_api_request_send_enabled":true,"settings_change_send_enabled":true}' \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

Update SIEM HTTP Destination

Endpoint

PATCH/siem_http_destinations/{id}

Return Object

SiemHttpDestination

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator.

Request Parameters

ParameterDescription
id
int64
Required
Siem Http Destination ID.
name
string
Name for this Destination
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
splunk_token
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret
string
Applicable only for destination type: azure. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations/{id}.json \
  -X PATCH \
  -H 'Content-Type: application/json' \
  -d '{"name":"example","additional_headers":{"Authorization":"Bearer YOUR_TOKEN"},"sending_active":true,"generic_payload_type":"example","file_destination_path":"example","file_format":"example","file_interval_minutes":1,"azure_dcr_immutable_id":"example","azure_stream_name":"example","azure_oauth_client_credentials_tenant_id":"example","azure_oauth_client_credentials_client_id":"example","qradar_username":"example","action_send_enabled":true,"sftp_action_send_enabled":true,"ftp_action_send_enabled":true,"web_dav_action_send_enabled":true,"sync_send_enabled":true,"outbound_connection_send_enabled":true,"automation_send_enabled":true,"api_request_send_enabled":true,"public_hosting_request_send_enabled":true,"email_send_enabled":true,"exavault_api_request_send_enabled":true,"settings_change_send_enabled":true,"destination_type":"example","destination_url":"example"}' \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

Example Response

{
  "id": 1,
  "name": "example",
  "destination_type": "example",
  "destination_url": "example",
  "file_destination_path": "example",
  "file_format": "example",
  "file_interval_minutes": 1,
  "additional_headers": {
    "Authorization": "Bearer YOUR_TOKEN"
  },
  "sending_active": true,
  "generic_payload_type": "example",
  "splunk_token_masked": "example",
  "crowdstrike_token_masked": "example",
  "azure_dcr_immutable_id": "example",
  "azure_stream_name": "example",
  "azure_oauth_client_credentials_tenant_id": "example",
  "azure_oauth_client_credentials_client_id": "example",
  "azure_oauth_client_credentials_client_secret_masked": "example",
  "qradar_username": "example",
  "qradar_password_masked": "example",
  "solar_winds_token_masked": "example",
  "new_relic_api_key_masked": "example",
  "datadog_api_key_masked": "example",
  "action_send_enabled": true,
  "action_entries_sent": 1,
  "sftp_action_send_enabled": true,
  "sftp_action_entries_sent": 1,
  "ftp_action_send_enabled": true,
  "ftp_action_entries_sent": 1,
  "web_dav_action_send_enabled": true,
  "web_dav_action_entries_sent": 1,
  "sync_send_enabled": true,
  "sync_entries_sent": 1,
  "outbound_connection_send_enabled": true,
  "outbound_connection_entries_sent": 1,
  "automation_send_enabled": true,
  "automation_entries_sent": 1,
  "api_request_send_enabled": true,
  "api_request_entries_sent": 1,
  "public_hosting_request_send_enabled": true,
  "public_hosting_request_entries_sent": 1,
  "email_send_enabled": true,
  "email_entries_sent": 1,
  "exavault_api_request_send_enabled": true,
  "exavault_api_request_entries_sent": 1,
  "settings_change_send_enabled": true,
  "settings_change_entries_sent": 1,
  "last_http_call_target_type": "destination_url",
  "last_http_call_success": true,
  "last_http_call_response_code": 1,
  "last_http_call_response_body": "example",
  "last_http_call_error_message": "example",
  "last_http_call_time": "example",
  "last_http_call_duration_ms": 1,
  "most_recent_http_call_success_time": "example",
  "connection_test_entry": "example"
}

Delete SIEM HTTP Destination

Endpoint

DELETE/siem_http_destinations/{id}

Return Object

No return value.

Authorization Requirement

Requires a Site-Wide API key, or a User API key or session from a Site Administrator.

Request Parameters

ParameterDescription
id
int64
Required
Siem Http Destination ID.

Example Request

curl https://app.files.com/api/rest/v1/siem_http_destinations/{id}.json \
  -X DELETE \
  -H 'X-FilesAPI-Key: YOUR_API_KEY'

The SiemHttpDestination Object

Some of the endpoints above return a SiemHttpDestination object. The attributes of this object are listed below.

AttributeDescription
id
int64
SIEM HTTP Destination ID
name
string
Name for this Destination
destination_type
string
Destination Type
Possible values: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible
destination_url
string
Destination Url
file_destination_path
string
Applicable only for destination type: file. Destination folder path on Files.com.
file_format
string
Applicable only for destination type: file. Generated file format.
Possible values: json, csv
file_interval_minutes
int64
Applicable only for destination type: file. Interval, in minutes, between file deliveries.
additional_headers
object
Additional HTTP Headers included in calls to the destination URL
sending_active
boolean
Whether this SIEM HTTP Destination is currently being sent to or not
generic_payload_type
string
Applicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON.
Possible values: json_newline, json_array
splunk_token_masked
string
Applicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
crowdstrike_token_masked
string
Applicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
azure_dcr_immutable_id
string
Applicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
azure_stream_name
string
Applicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
azure_oauth_client_credentials_tenant_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
azure_oauth_client_credentials_client_id
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
azure_oauth_client_credentials_client_secret_masked
string
Applicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client Secret.
qradar_username
string
Applicable only for destination type: qradar. Basic auth username provided by QRadar.
qradar_password_masked
string
Applicable only for destination type: qradar. Basic auth password provided by QRadar.
solar_winds_token_masked
string
Applicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
new_relic_api_key_masked
string
Applicable only for destination type: new_relic. API key provided by New Relic.
datadog_api_key_masked
string
Applicable only for destination type: datadog. API key provided by Datadog.
action_send_enabled
boolean
Whether or not sending is enabled for action logs.
action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
sftp_action_send_enabled
boolean
Whether or not sending is enabled for sftp_action logs.
sftp_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
ftp_action_send_enabled
boolean
Whether or not sending is enabled for ftp_action logs.
ftp_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
web_dav_action_send_enabled
boolean
Whether or not sending is enabled for web_dav_action logs.
web_dav_action_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
sync_send_enabled
boolean
Whether or not sending is enabled for sync logs.
sync_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
outbound_connection_send_enabled
boolean
Whether or not sending is enabled for outbound_connection logs.
outbound_connection_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
automation_send_enabled
boolean
Whether or not sending is enabled for automation logs.
automation_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
api_request_send_enabled
boolean
Whether or not sending is enabled for api_request logs.
api_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
public_hosting_request_send_enabled
boolean
Whether or not sending is enabled for public_hosting_request logs.
public_hosting_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
email_send_enabled
boolean
Whether or not sending is enabled for email logs.
email_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
exavault_api_request_send_enabled
boolean
Whether or not sending is enabled for exavault_api_request logs.
exavault_api_request_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
settings_change_send_enabled
boolean
Whether or not sending is enabled for settings_change logs.
settings_change_entries_sent
int64
Number of log entries sent for the lifetime of this destination.
last_http_call_target_type
string
Type of URL that was last called. Can be destination_url or azure_oauth_client_credentials_url
Possible values: destination_url, azure_oauth_client_credentials_url, file_destination
last_http_call_success
boolean
Was the last HTTP call made successful?
last_http_call_response_code
int64
Last HTTP Call Response Code
last_http_call_response_body
string
Last HTTP Call Response Body. Large responses are truncated.
last_http_call_error_message
string
Last HTTP Call Error Message if applicable
last_http_call_time
string
Time of Last HTTP Call
last_http_call_duration_ms
int64
Duration of the last HTTP Call in milliseconds
most_recent_http_call_success_time
string
Time of Most Recent Successful HTTP Call
connection_test_entry
string
Connection Test Entry

Example SiemHttpDestination Object

{
  "id": 1,
  "name": "example",
  "destination_type": "example",
  "destination_url": "example",
  "file_destination_path": "example",
  "file_format": "example",
  "file_interval_minutes": 1,
  "additional_headers": {
    "Authorization": "Bearer YOUR_TOKEN"
  },
  "sending_active": true,
  "generic_payload_type": "example",
  "splunk_token_masked": "example",
  "crowdstrike_token_masked": "example",
  "azure_dcr_immutable_id": "example",
  "azure_stream_name": "example",
  "azure_oauth_client_credentials_tenant_id": "example",
  "azure_oauth_client_credentials_client_id": "example",
  "azure_oauth_client_credentials_client_secret_masked": "example",
  "qradar_username": "example",
  "qradar_password_masked": "example",
  "solar_winds_token_masked": "example",
  "new_relic_api_key_masked": "example",
  "datadog_api_key_masked": "example",
  "action_send_enabled": true,
  "action_entries_sent": 1,
  "sftp_action_send_enabled": true,
  "sftp_action_entries_sent": 1,
  "ftp_action_send_enabled": true,
  "ftp_action_entries_sent": 1,
  "web_dav_action_send_enabled": true,
  "web_dav_action_entries_sent": 1,
  "sync_send_enabled": true,
  "sync_entries_sent": 1,
  "outbound_connection_send_enabled": true,
  "outbound_connection_entries_sent": 1,
  "automation_send_enabled": true,
  "automation_entries_sent": 1,
  "api_request_send_enabled": true,
  "api_request_entries_sent": 1,
  "public_hosting_request_send_enabled": true,
  "public_hosting_request_entries_sent": 1,
  "email_send_enabled": true,
  "email_entries_sent": 1,
  "exavault_api_request_send_enabled": true,
  "exavault_api_request_entries_sent": 1,
  "settings_change_send_enabled": true,
  "settings_change_entries_sent": 1,
  "last_http_call_target_type": "destination_url",
  "last_http_call_success": true,
  "last_http_call_response_code": 1,
  "last_http_call_response_body": "example",
  "last_http_call_error_message": "example",
  "last_http_call_time": "example",
  "last_http_call_duration_ms": 1,
  "most_recent_http_call_success_time": "example",
  "connection_test_entry": "example"
}

additional_headers

Additional HTTP Headers included in calls to the destination URL

Value typeDescription
object of string valuesAdditional HTTP Headers included in calls to the destination URL

Example additional_headers

{
  "Authorization": "Bearer YOUR_TOKEN"
}