Skip to content

SIEM Connector: Accessed Provider APIs

The following APIs are accessed by the SIEM connector.

Rapid7 InsightIDR

Synqly APIProvider API
GET /v1/siem/eventsGET /management/logsets
GET /query/logsets
GET /log_search/query/{item}
GET /log_search/query/logs/{item}
GET /v1/siem/investigationsPOST /idr/v2/investigations/_search
GET /v1/siem/investigations/{id}GET /idr/v2/investigations/{item}
GET /v1/siem/investigations/{id}/evidenceGET /idr/v1/restricted/investigations/{item}/evidence
GET /v1/siem/log-providersGET /management/logsets
PATCH /v1/siem/investigations/{id}GET /idr/v2/investigations/{item}
PATCH /idr/v2/investigations/{item}

Sumo Logic Cloud SIEM

Synqly APIProvider API
GET /v1/siem/eventsPOST /api/v1/search/jobs
GET /api/v1/search/jobs/{item}
GET /api/v1/search/jobs/{item}/messages
GET /api/v1/search/jobs/{item}/records
GET /v1/siem/investigationsGET /api/sec/v1/insights
GET /v1/siem/investigations/{id}GET /api/sec/v1/insights/{item}
GET /v1/siem/investigations/{id}/evidenceGET /api/sec/v1/insights/{item}
GET /v1/siem/log-providersPOST /api/v1/search/jobs
GET /api/v1/search/jobs/{item}
GET /api/v1/search/jobs/{item}/records
POST /v1/siem/eventsPOST /receiver/v1/http/{item}

Splunk Enterprise Security

Synqly APIProvider API
GET /v1/siem/alertsGET /servicesNS/-/-/saved/searches
GET /v1/siem/eventsPOST /services/search/jobs
GET /services/search/jobs/{item}
GET /services/search/jobs/{item}/results
GET /v1/siem/log-providersPOST /services/search/jobs
GET /services/search/jobs/{item}
GET /services/search/jobs/{item}/results
POST /v1/siem/eventsPOST /services/collector/event

IBM QRadar SIEM

Synqly APIProvider API
GET /v1/siem/eventsPOST /api/ariel/searches
GET /api/ariel/searches/{item}
GET /api/ariel/searches/{item}/results
GET /v1/siem/investigationsGET /api/siem/offenses
GET /v1/siem/investigations/{id}GET /api/siem/offenses/{item}
GET /v1/siem/log-providersGET /api/config/{item}/{item}/{item}
POST /v1/siem/eventsPOST/

Microsoft Sentinel

Synqly APIProvider API
GET /v1/siem/alertsGET /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/providers/Microsoft.SecurityInsights/alertRules
GET /v1/siem/eventsPOST /v1/workspaces/{item}/query
GET /v1/siem/investigationsGET /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/providers/Microsoft.SecurityInsights/incidents
GET /v1/siem/investigations/{id}GET /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/providers/Microsoft.SecurityInsights/incidents/{item}
GET /v1/siem/log-providersGET /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/tables
PATCH /v1/siem/investigations/{id}GET /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/providers/Microsoft.SecurityInsights/incidents/{item}
PUT /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/providers/Microsoft.SecurityInsights/incidents/{item}
POST /v1/siem/eventsPOST /dataCollectionRules/{item}/streams/Custom-ASimEvent

Elastic SIEM

Synqly APIProvider API
GET /v1/siem/alertsPOST /api/{item}/signals/search
GET /v1/siem/eventsPOST /logs-/{item}
POST /
/{item}
POST /synqly-data/{item}
GET /v1/siem/log-providersGET /*
POST /v1/siem/eventsPOST /logs-synqly-default/_bulk
POST /synqly-data/_bulk

OpenSearch

Synqly APIProvider API
GET /v1/siem/eventsPOST /logs-/{item}/{item}
POST /
/{item}/{item}
POST /e2e/{item}/{item}
GET /v1/siem/log-providersGET /*
POST /v1/siem/eventsPOST /logs-synqly-default/_bulk
POST /e2e/_bulk