Skip to content

CrowdStrike Falcon® Next-Gen SIEM

OperationProvider Endpoints
Post EventsPOST /services/collector
Query AlertsPOST /alerts/combined/alerts/v1
Query EventsGET /humio/api/v1/repositories/search-all/queryjobs/{jobId}
POST /humio/api/v1/repositories/investigate_view/queryjobs
POST /humio/api/v1/repositories/search-all/queryjobs

Google Security Operations (Chronicle Compatibility)

OperationProvider Endpoints
Get EvidenceGET /v2/detect/rules/{ruleId}
Get InvestigationGET /v2/detect/rules/{ruleId}
Post EventsPOST /v2/udmevents:batchCreate
Query AlertsGET /v2/detect/rules/-/detections
GET /v2/detect/rules/{ruleId}
Query EventsGET /v1/events:udmSearch
Query InvestigationsGET /v2/detect/rules/-/detections
Query Log ProvidersGET /v2/logtypes

Google Security Operations

OperationProvider Endpoints
Post EventsPOST /v1alpha/projects/synqly/locations/us/instances/{customerId}/events:import
Query EventsGET /v1alpha/projects/synqly/locations/us/instances/{customerId}:udmSearch
Query Log ProvidersGET /v1alpha/projects/synqly/locations/us/instances/{customerId}/logTypes

OpenSearch SIEM

OperationProvider Endpoints
Post EventsPOST /{index}/_bulk
Query EventsPOST /{index}/_plugins/_asynchronous_search
Query Log ProvidersGET /{index}

Panther SIEM

OperationProvider Endpoints
Get AlertPOST /public/graphql
Post EventsPOST /http/{logSourceId}
Query AlertsPOST /public/graphql
Query EventsPOST /public/graphql
Query Log ProvidersPOST /public/graphql

Rapid7 InsightIDR

OperationProvider Endpoints
Get AlertGET /idr/at/alerts/{id}
GET /idr/at/alerts/{id}/actors
GET /idr/at/alerts/{id}/evidences
Get EvidenceGET /idr/v1/restricted/investigations/{id}/evidence
Get InvestigationGET /idr/v2/investigations/{id}
GET /idr/v2/investigations/{id}/rapid7-product-alerts
Patch InvestigationGET /idr/v2/investigations/{id}
PATCH /idr/v2/investigations/{id}
Query AlertsPOST /idr/at/alerts/ops/search
Query EventsGET /log_search/query/logs/{logId}
GET /log_search/query/{logId}
GET /management/logsets
GET /query/logsets
Query InvestigationsPOST /idr/v2/investigations/_search
Query Log ProvidersGET /management/logsets

Splunk Enterprise Security

OperationProvider Endpoints
Get AlertGET /services/alerts/fired_alerts/{id}
GET /servicesNS/-/-/saved/searches/Test Alert
Post EventsPOST
POST /services/collector/event
Query AlertsGET /services/alerts/fired_alerts/{id}
Query EventsGET /services/search/jobs/{jobId}
GET /services/search/jobs/{jobId}/results POST /services/search/jobs
Query Log ProvidersGET /services/search/jobs/{jobId}
GET /services/search/jobs/{jobId}/results
POST /services/search/jobs