SIEM Connector: Accessed Provider APIs

The following APIs are accessed by the SIEM connector.

Microsoft Sentinel

Synqly APIProvider API
GET /v1/siem/eventsPOST /v1/workspaces/{item}/query
GET /v1/siem/investigationsGET /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/providers/Microsoft.SecurityInsights/incidents
GET /v1/siem/investigations/{id}GET /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/providers/Microsoft.SecurityInsights/incidents/{item}
GET /v1/siem/log-providersGET /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/tables
PATCH /v1/siem/investigations/{id}GET /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/providers/Microsoft.SecurityInsights/incidents/{item}
PUT /subscriptions/{item}/resourceGroups/{item}/providers/Microsoft.OperationalInsights/workspaces/sentinel-e2e/providers/Microsoft.SecurityInsights/incidents/{item}

Sumo Logic Cloud SIEM

Synqly APIProvider API
GET /v1/siem/eventsPOST /api/v1/search/jobs
GET /api/v1/search/jobs/{item}
GET /api/v1/search/jobs/{item}/messages
GET /api/v1/search/jobs/{item}/records
GET /v1/siem/investigationsGET /api/sec/v1/insights
GET /v1/siem/investigations/{id}GET /api/sec/v1/insights/{item}
GET /v1/siem/investigations/{id}/evidenceGET /api/sec/v1/insights/{item}
GET /v1/siem/log-providersPOST /api/v1/search/jobs
GET /api/v1/search/jobs/{item}
GET /api/v1/search/jobs/{item}/records
POST /v1/siem/eventsPOST /receiver/v1/http/{item}

IBM QRadar

Synqly APIProvider API
GET /v1/siem/eventsPOST /api/ariel/searches
GET /api/ariel/searches/{item}
GET /api/ariel/searches/{item}/results
GET /v1/siem/investigationsGET /api/siem/offenses
GET /v1/siem/investigations/{id}GET /api/siem/offenses/{item}
GET /v1/siem/log-providersGET /api/config/{item}/{item}/{item}
POST /v1/siem/eventsPOST/

Splunk

Synqly APIProvider API
GET /v1/siem/eventsPOST /services/search/jobs
GET /services/search/jobs/{item}
GET /services/search/jobs/{item}/results
GET /v1/siem/log-providersPOST /services/search/jobs
GET /services/search/jobs/{item}
GET /services/search/jobs/{item}/results
POST /v1/siem/eventsPOST /services/collector/event

Elasticsearch

Synqly APIProvider API
GET /v1/siem/eventsPOST /logs-/{item}
POST /
/{item}
POST /synqly-data/{item}
GET /v1/siem/log-providersGET /*
POST /v1/siem/eventsPOST /logs-synqly-default/_bulk
POST /synqly-data/_bulk

CrowdStrike SIEM

Synqly APIProvider API
GET /v1/siem/eventsPOST /humio/api/v1/repositories/search-all/queryjobs
GET /humio/api/v1/repositories/search-all/queryjobs/{item}
POST /humio/api/v1/repositories/{item}/queryjobs

Google Security Operations

Synqly APIProvider API
GET /v1/siem/eventsGET /v1/events:udmSearch
GET /v1/siem/investigationsGET /v2/detect/rules/-/detections
GET /v1/siem/investigations/{id}GET /v2/detect/rules/{item}/detections/{item}
GET /v1/siem/investigations/{id}/evidenceGET /v2/detect/rules/{item}/detections/{item}
GET /v1/siem/log-providersGET /v2/logtypes

Rapid7 InsightIDR

Synqly APIProvider API
GET /v1/siem/eventsGET /query/logsets
GET /log_search/query/{item}
GET /management/logsets
GET /log_search/query/logs/{item}
GET /v1/siem/investigationsPOST /idr/v2/investigations/_search
GET /v1/siem/investigations/{id}GET /idr/v2/investigations/{item}
GET /v1/siem/investigations/{id}/evidenceGET /idr/v1/restricted/investigations/{item}/evidence
GET /v1/siem/log-providersGET /management/logsets
PATCH /v1/siem/investigations/{id}GET /idr/v2/investigations/{item}
PATCH /idr/v2/investigations/{item}