RoutesSiem destination
/siem-destination
Update the SIEM streaming destination
AuthorizationBearer <token>
In: header
Request Body
application/json
name?string
Display name of the destination
Length
1 <= length <= 100url?string
HTTPS endpoint that receives the NDJSON batches. Must resolve to a public address.
Format
uriLength
length <= 2048authHeaderName?string
Name of a custom auth header, e.g. Authorization for a Splunk HEC token
Match
^[A-Za-z0-9-]+$Length
1 <= length <= 200authHeaderValue?string
Stored encrypted and never returned
Length
1 <= length <= 4096exportAuditLogs?boolean
Whether to stream audit log events. Default is true
exportCredentialAuditLogs?boolean
Whether to stream credential audit log events. Default is true
isEnabled?boolean
Whether the destination is enabled
removeAuthHeader?boolean
Whether to clear an existing custom auth header
reactivate?boolean
Whether to clear the failure state of a destination that was disabled automatically. Cursors are kept, so delivery resumes where it stopped rather than skipping what was missed
Response Body
application/json
curl -X PATCH "https://YOUR_ORG_ID.gatana.ai/api/v1/siem-destination" \ -H "Content-Type: application/json" \ -d '{}'{
"id": "string",
"name": "string",
"url": "string",
"authHeaderName": "string",
"hasAuthHeaderValue": true,
"isEnabled": true,
"status": "active",
"exportAuditLogs": true,
"exportCredentialAuditLogs": true,
"consecutiveFailures": 0,
"failingSince": "string",
"nextAttemptAt": "string",
"lastAttemptAt": "string",
"lastSuccessAt": "string",
"lastError": "string",
"createdAt": "string",
"updatedAt": "string"
}