Skip to content

CrowdStrike Falcon® Next-Gen SIEM

OperationProvider Endpoints
Post EventsPOST /services/collector
Query AlertsGET /incidents/queries/incidents/v1
Query EventsGET /humio/api/v1/repositories/search-all/queryjobs/{jobId}
POST /humio/api/v1/repositories/investigate_view/queryjobs
POST /humio/api/v1/repositories/search-all/queryjobs

Elastic SIEM

OperationProvider Endpoints
Post EventsPOST /{index}/_bulk
Query AlertsPOST /api/detection_engine/signals/search
Query EventsPOST /{index}/_async_search
Query Log ProvidersGET /{index}

OpenSearch SIEM

OperationProvider Endpoints
Post EventsPOST /{index}/_bulk
Query EventsPOST /{index}/_plugins/_asynchronous_search
Query Log ProvidersGET /{index}

IBM QRadar SIEM

OperationProvider Endpoints
Get InvestigationGET /api/siem/offenses/{id}
Post EventsPOST
Query EventsGET /api/ariel/searches/{searchId}
GET /api/ariel/searches/{searchId}/results
POST /api/ariel/searches
Query InvestigationsGET /api/siem/offenses
Query Log ProvidersGET /api/config/event_sources/log_source_management/log_sources

Rapid7 InsightIDR

OperationProvider Endpoints
Get EvidenceGET /idr/v1/restricted/investigations/{id}/evidence
Get InvestigationGET /idr/v2/investigations/{id}
Patch InvestigationGET /idr/v2/investigations/{id}
PATCH /idr/v2/investigations/{id}
Query EventsGET /log_search/query/logs/{logId}
GET /log_search/query/{logId}
GET /management/logsets
GET /query/logsets
Query InvestigationsPOST /idr/v2/investigations/_search
Query Log ProvidersGET /management/logsets

Microsoft Sentinel

OperationProvider Endpoints
Get InvestigationGET /subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/incidents/{id}
Patch InvestigationGET /subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/incidents/{id}
PUT /subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/incidents/{id}
Post EventsPOST /dataCollectionRules/{ruleId}/streams/{streamName}
Query AlertsGET /subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/alertRules
Query EventsPOST /v1/workspaces/{workspaceId}/query
Query InvestigationsGET /subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/providers/Microsoft.SecurityInsights/incidents
Query Log ProvidersGET /subscriptions/{subscriptionId}/resourceGroups/{resourceGroup}/providers/Microsoft.OperationalInsights/workspaces/{workspaceName}/tables

Splunk Enterprise Security

OperationProvider Endpoints
Post EventsPOST
POST /services/collector/event
Query AlertsGET /servicesNS/-/-/saved/searches
Query EventsGET /services/search/jobs/{jobId}
GET /services/search/jobs/{jobId}/results
POST /services/search/jobs
Query Log ProvidersGET /services/search/jobs/{jobId}
GET /services/search/jobs/{jobId}/results
POST /services/search/jobs

Sumo Logic Cloud SIEM

OperationProvider Endpoints
Get EvidenceGET /api/sec/v1/insights/{id}
Get InvestigationGET /api/sec/v1/insights/{id}
Post EventsPOST /receiver/v1/http/{httpCollectorCode}
Query EventsGET /api/v1/search/jobs/{jobId}
GET /api/v1/search/jobs/{jobId}/messages
GET /api/v1/search/jobs/{jobId}/records
POST /api/v1/search/jobs
Query InvestigationsGET /api/sec/v1/insights
Query Log ProvidersGET /api/v1/search/jobs/{jobId}
GET /api/v1/search/jobs/{jobId}/records
POST /api/v1/search/jobs