RoutesSiem destination
/siem-destination
Configure SIEM streaming. The signing secret is returned once and cannot be retrieved later
AuthorizationBearer <token>
In: header
Request Body
application/json
name?string
Display name of the destination
Length
1 <= length <= 100url*string
HTTPS endpoint that receives the NDJSON batches. Must resolve to a public address.
Format
uriLength
length <= 2048authHeaderName?string
Name of a custom auth header, e.g. Authorization for a Splunk HEC token
Match
^[A-Za-z0-9-]+$Length
1 <= length <= 200authHeaderValue?string
Stored encrypted and never returned
Length
1 <= length <= 4096exportAuditLogs?boolean
Whether to stream audit log events. Default is true
exportCredentialAuditLogs?boolean
Whether to stream credential audit log events. Default is true
Response Body
application/json
curl -X POST "https://YOUR_ORG_ID.gatana.ai/api/v1/siem-destination" \ -H "Content-Type: application/json" \ -d '{ "url": "http://example.com" }'{
"destination": {
"id": "string",
"name": "string",
"url": "string",
"authHeaderName": "string",
"hasAuthHeaderValue": true,
"isEnabled": true,
"status": "active",
"exportAuditLogs": true,
"exportCredentialAuditLogs": true,
"consecutiveFailures": 0,
"failingSince": "string",
"nextAttemptAt": "string",
"lastAttemptAt": "string",
"lastSuccessAt": "string",
"lastError": "string",
"createdAt": "string",
"updatedAt": "string"
},
"signingSecret": "string"
}