Gatana logoGatana Docs
RoutesSiem destination

/siem-destination

Configure SIEM streaming. The signing secret is returned once and cannot be retrieved later

POST
/siem-destination
AuthorizationBearer <token>

In: header

Request Body

application/json

name?string

Display name of the destination

Length1 <= length <= 100
url*string

HTTPS endpoint that receives the NDJSON batches. Must resolve to a public address.

Formaturi
Lengthlength <= 2048
authHeaderName?string

Name of a custom auth header, e.g. Authorization for a Splunk HEC token

Match^[A-Za-z0-9-]+$
Length1 <= length <= 200
authHeaderValue?string

Stored encrypted and never returned

Length1 <= length <= 4096
exportAuditLogs?boolean

Whether to stream audit log events. Default is true

exportCredentialAuditLogs?boolean

Whether to stream credential audit log events. Default is true

Response Body

application/json

curl -X POST "https://YOUR_ORG_ID.gatana.ai/api/v1/siem-destination" \  -H "Content-Type: application/json" \  -d '{    "url": "http://example.com"  }'
{
  "destination": {
    "id": "string",
    "name": "string",
    "url": "string",
    "authHeaderName": "string",
    "hasAuthHeaderValue": true,
    "isEnabled": true,
    "status": "active",
    "exportAuditLogs": true,
    "exportCredentialAuditLogs": true,
    "consecutiveFailures": 0,
    "failingSince": "string",
    "nextAttemptAt": "string",
    "lastAttemptAt": "string",
    "lastSuccessAt": "string",
    "lastError": "string",
    "createdAt": "string",
    "updatedAt": "string"
  },
  "signingSecret": "string"
}