Gatana logoGatana Docs
RoutesSiem destination

/siem-destination

Update the SIEM streaming destination

PATCH
/siem-destination
AuthorizationBearer <token>

In: header

Request Body

application/json

name?string

Display name of the destination

Length1 <= length <= 100
url?string

HTTPS endpoint that receives the NDJSON batches. Must resolve to a public address.

Formaturi
Lengthlength <= 2048
authHeaderName?string

Name of a custom auth header, e.g. Authorization for a Splunk HEC token

Match^[A-Za-z0-9-]+$
Length1 <= length <= 200
authHeaderValue?string

Stored encrypted and never returned

Length1 <= length <= 4096
exportAuditLogs?boolean

Whether to stream audit log events. Default is true

exportCredentialAuditLogs?boolean

Whether to stream credential audit log events. Default is true

isEnabled?boolean

Whether the destination is enabled

removeAuthHeader?boolean

Whether to clear an existing custom auth header

reactivate?boolean

Whether to clear the failure state of a destination that was disabled automatically. Cursors are kept, so delivery resumes where it stopped rather than skipping what was missed

Response Body

application/json

curl -X PATCH "https://YOUR_ORG_ID.gatana.ai/api/v1/siem-destination" \  -H "Content-Type: application/json" \  -d '{}'
{
  "id": "string",
  "name": "string",
  "url": "string",
  "authHeaderName": "string",
  "hasAuthHeaderValue": true,
  "isEnabled": true,
  "status": "active",
  "exportAuditLogs": true,
  "exportCredentialAuditLogs": true,
  "consecutiveFailures": 0,
  "failingSince": "string",
  "nextAttemptAt": "string",
  "lastAttemptAt": "string",
  "lastSuccessAt": "string",
  "lastError": "string",
  "createdAt": "string",
  "updatedAt": "string"
}