- play_arrow What's New in REST API Version 17.0
- play_arrow Access Endpoints
- play_arrow Access Endpoints
- play_arrow Analytics Endpoints
- play_arrow Analytics Endpoints
- GET /analytics/ade_rules
- GET /analytics/ade_rules/ade_rule_delete_tasks/{task_id}
- GET /analytics/ade_rules/ade_rule_dependent_tasks/{task_id}
- POST /analytics/ade_rules/ade_rule_dependent_tasks/{task_id}
- GET /analytics/ade_rules/ade_rule_dependent_tasks/{task_id}/results
- DELETE /analytics/ade_rules/{id}
- GET /analytics/ade_rules/{id}
- POST /analytics/ade_rules/{id}
- GET /analytics/ade_rules/{id}/dependents
- GET /analytics/building_blocks
- GET /analytics/building_blocks/building_block_delete_tasks/{task_id}
- GET /analytics/building_blocks/building_block_dependent_tasks/{task_id}
- POST /analytics/building_blocks/building_block_dependent_tasks/{task_id}
- GET /analytics/building_blocks/building_block_dependent_tasks/{task_id}/results
- DELETE /analytics/building_blocks/{id}
- GET /analytics/building_blocks/{id}
- POST /analytics/building_blocks/{id}
- GET /analytics/building_blocks/{id}/dependents
- GET /analytics/custom_actions/actions
- POST /analytics/custom_actions/actions
- DELETE /analytics/custom_actions/actions/{action_id}
- GET /analytics/custom_actions/actions/{action_id}
- POST /analytics/custom_actions/actions/{action_id}
- GET /analytics/custom_actions/interpreters
- GET /analytics/custom_actions/interpreters/{interpreter_id}
- GET /analytics/custom_actions/scripts
- POST /analytics/custom_actions/scripts
- DELETE /analytics/custom_actions/scripts/{script_id}
- GET /analytics/custom_actions/scripts/{script_id}
- POST /analytics/custom_actions/scripts/{script_id}
- GET /analytics/rule_groups
- DELETE /analytics/rule_groups/{group_id}
- GET /analytics/rule_groups/{group_id}
- POST /analytics/rule_groups/{group_id}
- GET /analytics/rules
- DELETE /analytics/rules/{id}
- GET /analytics/rules/{id}
- POST /analytics/rules/{id}
- GET /analytics/rules/{id}/dependents
- GET /analytics/rules/rule_delete_tasks/{task_id}
- GET /analytics/rules/rule_dependent_tasks/{task_id}
- POST /analytics/rules/rule_dependent_tasks/{task_id}
- GET /analytics/rules/rule_dependent_tasks/{task_id}/results
- GET /analytics/rules_offense_contributions
- play_arrow Ariel Endpoints
- play_arrow Ariel Endpoints
- GET /ariel/databases
- GET /ariel/databases/{database_name}
- GET /ariel/event_saved_search_groups
- DELETE /ariel/event_saved_search_groups/{group_id}
- GET /ariel/event_saved_search_groups/{group_id}
- POST /ariel/event_saved_search_groups/{group_id}
- GET /ariel/flow_saved_search_groups
- DELETE /ariel/flow_saved_search_groups/{group_id}
- GET /ariel/flow_saved_search_groups/{group_id}
- POST /ariel/flow_saved_search_groups/{group_id}
- GET /ariel/flow_vlans
- POST /ariel/flow_vlans
- DELETE /ariel/flow_vlans/{id}
- GET /ariel/flow_vlans/{id}
- GET /ariel/functions
- GET /ariel/functions/{function_name}
- GET /ariel/lookups
- POST /ariel/lookups
- DELETE /ariel/lookups/{name}
- GET /ariel/lookups/{name}
- POST /ariel/lookups/{name}
- GET /ariel/parser_keywords
- POST /ariel/processors/aql_metadata
- GET /ariel/saved_search_delete_tasks/{task_id}
- GET /ariel/saved_search_dependent_tasks/{task_id}
- POST /ariel/saved_search_dependent_tasks/{task_id}
- GET /ariel/saved_search_dependent_tasks/{task_id}/results
- GET /ariel/saved_searches
- DELETE /ariel/saved_searches/{id}
- GET /ariel/saved_searches/{id}
- POST /ariel/saved_searches/{id}
- GET /ariel/saved_searches/{id}/dependents
- GET /ariel/searches
- POST /ariel/searches
- DELETE /ariel/searches/{search_id}
- GET /ariel/searches/{search_id}
- POST /ariel/searches/{search_id}
- GET /ariel/searches/{search_id}/metadata
- GET /ariel/searches/{search_id}/results
- GET /ariel/taggedfieldcategories
- POST /ariel/taggedfieldcategories
- DELETE /ariel/taggedfieldcategories/{id}
- GET /ariel/taggedfieldcategories/{id}
- POST /ariel/taggedfieldcategories/{id}
- GET /ariel/taggedfields
- POST /ariel/taggedfields
- DELETE /ariel/taggedfields/{id}
- GET /ariel/taggedfields/{id}
- POST /ariel/taggedfields/{id}
- POST /ariel/validators/aql
- play_arrow Asset_model Endpoints
- play_arrow Asset_model Endpoints
- GET /asset_model/assets
- POST /asset_model/assets/{asset_id}
- GET /asset_model/configuration
- POST /asset_model/configuration
- GET /asset_model/properties
- GET /asset_model/saved_search_groups
- DELETE /asset_model/saved_search_groups/{group_id}
- GET /asset_model/saved_search_groups/{group_id}
- POST /asset_model/saved_search_groups/{group_id}
- GET /asset_model/saved_searches
- DELETE /asset_model/saved_searches/{saved_search_id}
- GET /asset_model/saved_searches/{saved_search_id}
- POST /asset_model/saved_searches/{saved_search_id}
- GET /asset_model/saved_searches/{saved_search_id}/results
- play_arrow Auth Endpoints
- play_arrow Auth Endpoints
- play_arrow Backup_and_restore Endpoints
- play_arrow Backup_and_restore Endpoints
- GET /backup_and_restore/backups
- POST /backup_and_restore/backups
- DELETE /backup_and_restore/backups/{id}
- GET /backup_and_restore/backups/{id}
- POST /backup_and_restore/backups/{id}
- GET /backup_and_restore/restores
- POST /backup_and_restore/restores
- DELETE /backup_and_restore/restores/{id}
- GET /backup_and_restore/restores/{id}
- POST /backup_and_restore/restores/{id}
- play_arrow Bandwidth_manager Endpoints
- play_arrow Bandwidth_manager Endpoints
- GET /bandwidth_manager/configurations
- POST /bandwidth_manager/configurations
- DELETE /bandwidth_manager/configurations/{id}
- GET /bandwidth_manager/configurations/{id}
- POST /bandwidth_manager/configurations/{id}
- GET /bandwidth_manager/filters
- POST /bandwidth_manager/filters
- DELETE /bandwidth_manager/filters/{id}
- GET /bandwidth_manager/filters/{id}
- POST /bandwidth_manager/filters/{id}
- play_arrow Data_classification Endpoints
- play_arrow Data_classification Endpoints
- GET /data_classification/dsm_event_mappings
- POST /data_classification/dsm_event_mappings
- GET /data_classification/dsm_event_mappings/{dsm_event_mapping_id}
- POST /data_classification/dsm_event_mappings/{dsm_event_mapping_id}
- GET /data_classification/high_level_categories
- GET /data_classification/high_level_categories/{high_level_category_id}
- GET /data_classification/low_level_categories
- GET /data_classification/low_level_categories/{low_level_category_id}
- GET /data_classification/qid_records
- POST /data_classification/qid_records
- GET /data_classification/qid_records/{qid_record_id}
- POST /data_classification/qid_records/{qid_record_id}
- play_arrow Disaster_recovery Endpoints
- play_arrow Dynamic_search Endpoints
- play_arrow Dynamic_search Endpoints
- GET /dynamic_search/saved_queries
- POST /dynamic_search/saved_queries
- DELETE /dynamic_search/saved_queries/{id}
- GET /dynamic_search/saved_queries/{id}
- GET /dynamic_search/schemas
- GET /dynamic_search/schemas/{name}
- GET /dynamic_search/schemas/{name}/fields
- GET /dynamic_search/schemas/{name}/functions
- GET /dynamic_search/schemas/{name}/operators
- GET /dynamic_search/searches
- POST /dynamic_search/searches
- DELETE /dynamic_search/searches/{handle}
- GET /dynamic_search/searches/{handle}
- GET /dynamic_search/searches/{handle}/results
- play_arrow GUI_app_framework Endpoints
- play_arrow GUI_app_framework Endpoints
- GET /gui_app_framework/application_creation_task
- POST /gui_app_framework/application_creation_task
- GET /gui_app_framework/application_creation_task/{application_id}
- POST /gui_app_framework/application_creation_task/{application_id}
- GET /gui_app_framework/application_creation_task/{application_id}/auth
- POST /gui_app_framework/application_creation_task/{application_id}/auth
- GET /gui_app_framework/application_definitions
- POST /gui_app_framework/application_definitions
- DELETE /gui_app_framework/application_definitions/{application_definition_id}
- GET /gui_app_framework/application_definitions/{application_definition_id}
- POST /gui_app_framework/application_definitions/{application_definition_id}
- PUT /gui_app_framework/application_definitions/{application_definition_id}
- GET /gui_app_framework/application_definitions/{application_definition_id}/user_role_id
- DELETE /gui_app_framework/application_definitions/{application_definition_id}/user_role_id/{user_role_id}
- POST /gui_app_framework/application_definitions/{application_definition_id}/user_role_id/{user_role_id}
- GET /gui_app_framework/applications
- POST /gui_app_framework/applications
- DELETE /gui_app_framework/applications/{application_id}
- GET /gui_app_framework/applications/{application_id}
- POST /gui_app_framework/applications/{application_id}
- PUT /gui_app_framework/applications/{application_id}
- GET /gui_app_framework/applications/{application_id}/host_type
- GET /gui_app_framework/named_services
- GET /gui_app_framework/named_services/{uuid}
- play_arrow Health Endpoints
- play_arrow Health Endpoints
- GET /health/metrics/qradar_metrics
- GET /health/metrics/qradar_metrics/{id}
- POST /health/metrics/qradar_metrics/{id}
- POST /health/metrics/qradar_metrics_global_config
- GET /health/metrics/system_metrics
- GET /health/metrics/system_metrics/{id}
- POST /health/metrics/system_metrics/{id}
- POST /health/metrics/system_metrics_global_config
- play_arrow Health_data Endpoints
- play_arrow Help Endpoints
- play_arrow QNI Endpoints
- play_arrow JSA Risk Manager Endpoints
- play_arrow JSA Risk Manager Endpoints
- GET /qrm/model_groups
- DELETE /qrm/model_groups/{group_id}
- GET /qrm/model_groups/{group_id}
- POST /qrm/model_groups/{group_id}
- GET /qrm/qrm_saved_search_groups
- DELETE /qrm/qrm_saved_search_groups/{group_id}
- GET /qrm/qrm_saved_search_groups/{group_id}
- POST /qrm/qrm_saved_search_groups/{group_id}
- GET /qrm/question_groups
- DELETE /qrm/question_groups/{group_id}
- GET /qrm/question_groups/{group_id}
- POST /qrm/question_groups/{group_id}
- GET /qrm/simulation_groups
- DELETE /qrm/simulation_groups/{group_id}
- GET /qrm/simulation_groups/{group_id}
- POST /qrm/simulation_groups/{group_id}
- GET /qrm/topology_saved_search_groups
- DELETE /qrm/topology_saved_search_groups/{group_id}
- GET /qrm/topology_saved_search_groups/{group_id}
- POST /qrm/topology_saved_search_groups/{group_id}
- play_arrow JSA Vulnerability Manager Endpoints
- play_arrow JSA Vulnerability Manager Endpoints
- GET /qvm/assets
- GET /qvm/filters
- GET /qvm/network
- GET /qvm/openservices
- GET /qvm/saved_search_groups
- DELETE /qvm/saved_search_groups/{group_id}
- GET /qvm/saved_search_groups/{group_id}
- POST /qvm/saved_search_groups/{group_id}
- GET /qvm/saved_searches
- DELETE /qvm/saved_searches/{saved_search_id}
- GET /qvm/saved_searches/{saved_search_id}
- POST /qvm/saved_searches/{saved_search_id}
- GET /qvm/saved_searches/{saved_search_id}/vuln_instances
- GET /qvm/saved_searches/vuln_instances/{task_id}/results/assets
- GET /qvm/saved_searches/vuln_instances/{task_id}/results/vuln_instances
- GET /qvm/saved_searches/vuln_instances/{task_id}/results/vulnerabilities
- GET /qvm/saved_searches/vuln_instances/{task_id}/status
- POST /qvm/saved_searches/vuln_instances/{task_id}/status
- POST /qvm/tickets/assign
- GET /qvm/vulns
- play_arrow Reference_data Endpoints
- play_arrow Reference_data Endpoints
- GET /reference_data/map_delete_tasks/{task_id}
- GET /reference_data/map_dependent_tasks/{task_id}
- POST /reference_data/map_dependent_tasks/{task_id}
- GET /reference_data/map_dependent_tasks/{task_id}/results
- GET /reference_data/map_of_sets
- POST /reference_data/map_of_sets
- POST /reference_data/map_of_sets/bulk_load/{name}
- POST /reference_data/map_of_sets/bulk_load/{namespace}/{name}/{domain_id}
- DELETE /reference_data/map_of_sets/{name}
- GET /reference_data/map_of_sets/{name}
- POST /reference_data/map_of_sets/{name}
- GET /reference_data/map_of_sets/{name}/dependents
- DELETE /reference_data/map_of_sets/{name}/{key}
- GET /reference_data/map_of_sets_delete_tasks/{task_id}
- GET /reference_data/map_of_sets_dependent_tasks/{task_id}
- POST /reference_data/map_of_sets_dependent_tasks/{task_id}
- GET /reference_data/map_of_sets_dependent_tasks/{task_id}/results
- GET /reference_data/maps
- POST /reference_data/maps
- POST /reference_data/maps/bulk_load/{name}
- POST /reference_data/maps/bulk_load/{namespace}/{name}/{domain_id}
- DELETE /reference_data/maps/{name}
- GET /reference_data/maps/{name}
- POST /reference_data/maps/{name}
- GET /reference_data/maps/{name}/dependents
- DELETE /reference_data/maps/{name}/{key}
- GET /reference_data/sets
- POST /reference_data/sets
- POST /reference_data/sets/bulk_load/{namespace}/{name}/{domain_id}
- DELETE /reference_data/sets/{name}
- GET /reference_data/sets/{name}
- POST /reference_data/sets/{name}
- DELETE /reference_data/sets/{name}/{value}
- GET /reference_data/tables
- POST /reference_data/tables
- POST /reference_data/tables/bulk_load/{name}
- POST /reference_data/tables/bulk_load/{namespace}/{name}/{domain_id}
- DELETE /reference_data/tables/{name}
- GET /reference_data/tables/{name}
- POST /reference_data/tables/{name}
- GET /reference_data/tables/{name}/dependents
- DELETE /reference_data/tables/{name}/{outer_key}/{inner_key}
- GET /reference_data/tables_delete_tasks/{task_id}
- GET /reference_data/tables_dependent_tasks/{task_id}
- POST /reference_data/tables_dependent_tasks/{task_id}
- GET /reference_data/tables_dependent_tasks/{task_id}/results
- play_arrow Reference_data_collections Endpoints
- play_arrow Reference_data_collections Endpoints
- GET /reference_data_collections/set_bulk_update_tasks/{task_status_id}
- GET /reference_data_collections/set_bulk_update_tasks/{task_status_id}/results
- GET /reference_data_collections/set_delete_tasks/{task_status_id}
- GET /reference_data_collections/set_dependents_tasks/{task_status_id}
- POST /reference_data_collections/set_dependents_tasks/{task_status_id}
- GET /reference_data_collections/set_dependents_tasks/{task_status_id}/results
- GET /reference_data_collections/set_entries
- PATCH /reference_data_collections/set_entries
- POST /reference_data_collections/set_entries
- DELETE /reference_data_collections/set_entries/{id}
- GET /reference_data_collections/set_entries/{id}
- POST /reference_data_collections/set_entries/{id}
- GET /reference_data_collections/sets
- POST /reference_data_collections/sets
- DELETE /reference_data_collections/sets/{id}
- GET /reference_data_collections/sets/{id}
- POST /reference_data_collections/sets/{id}
- GET /reference_data_collections/sets/{id}/dependents
- play_arrow Scanner Endpoints
- play_arrow Scanner Endpoints
- GET /scanner/profiles
- POST /scanner/profiles/create
- POST /scanner/profiles/start
- GET /scanner/scanprofiles
- POST /scanner/scanprofiles
- DELETE /scanner/scanprofiles/{profileid}
- GET /scanner/scanprofiles/{profileid}
- POST /scanner/scanprofiles/{profileid}
- GET /scanner/scanprofiles/{profileid}/runs
- GET /scanner/scanprofiles/{profileid}/runs/{run_id}
- GET /scanner/scanprofiles/{profileid}/runs/{run_id}/results
- POST /scanner/scanprofiles/{profileid}/start
- play_arrow Services Endpoints
- play_arrow Services Endpoints
- POST /services/dig_lookups
- GET /services/dig_lookups/{dig_lookup_id}
- POST /services/dns_lookups
- GET /services/dns_lookups/{dns_lookup_id}
- GET /services/geolocations
- POST /services/port_scans
- GET /services/port_scans/{port_scan_id}
- POST /services/whois_lookups
- GET /services/whois_lookups/{whois_lookup_id}
- play_arrow SIEM Endpoints
- play_arrow SIEM Endpoints
- GET /siem/local_destination_addresses
- GET /siem/local_destination_addresses/{local_destination_address_id}
- GET /siem/offense_closing_reasons
- POST /siem/offense_closing_reasons
- GET /siem/offense_closing_reasons/{closing_reason_id}
- GET /siem/offense_saved_search_delete_tasks/{task_id}
- GET /siem/offense_saved_search_dependent_tasks/{task_id}
- POST /siem/offense_saved_search_dependent_tasks/{task_id}
- GET /siem/offense_saved_search_dependent_tasks/{task_id}/results
- GET /siem/offense_saved_search_groups
- DELETE /siem/offense_saved_search_groups/{group_id}
- GET /siem/offense_saved_search_groups/{group_id}
- POST /siem/offense_saved_search_groups/{group_id}
- GET /siem/offense_saved_searches
- DELETE /siem/offense_saved_searches/{id}
- GET /siem/offense_saved_searches/{id}
- POST /siem/offense_saved_searches/{id}
- GET /siem/offense_saved_searches/{id}/dependents
- GET /siem/offense_types
- GET /siem/offense_types/{offense_type_id}
- GET /siem/offenses
- GET /siem/offenses/{offense_id}
- POST /siem/offenses/{offense_id}
- GET /siem/offenses/{offense_id}/assignable_actors
- GET /siem/offenses/{offense_id}/notes
- POST /siem/offenses/{offense_id}/notes
- GET /siem/offenses/{offense_id}/notes/{note_id}
- GET /siem/source_addresses
- GET /siem/source_addresses/{source_address_id}
- play_arrow Staged_config Endpoints
- play_arrow Staged_config Endpoints
- GET /staged_config/access/security_profiles
- GET /staged_config/access/security_profiles/{id}
- GET /staged_config/access/user_delete_tasks/{task_id}
- GET /staged_config/access/user_roles
- GET /staged_config/access/user_roles/{id}
- GET /staged_config/access/users
- POST /staged_config/access/users
- DELETE /staged_config/access/users/{id}
- GET /staged_config/access/users/{id}
- POST /staged_config/access/users/{id}
- GET /staged_config/backup_and_restore/scheduled_backup_configurations
- GET /staged_config/backup_and_restore/scheduled_backup_configurations/{id}
- POST /staged_config/backup_and_restore/scheduled_backup_configurations/{id}
- GET /staged_config/certificates/certificate_signing_request
- POST /staged_config/certificates/certificate_signing_request
- DELETE /staged_config/certificates/certificate_signing_request/{id}
- GET /staged_config/certificates/certificate_signing_request/{id}
- GET /staged_config/certificates/end_certificates
- POST /staged_config/certificates/end_certificates
- DELETE /staged_config/certificates/end_certificates/{id}
- GET /staged_config/certificates/end_certificates/{id}
- POST /staged_config/certificates/end_certificates/{id}
- GET /staged_config/certificates/root_certificates
- POST /staged_config/certificates/root_certificates
- DELETE /staged_config/certificates/root_certificates/{id}
- GET /staged_config/certificates/root_certificates/{id}
- GET /staged_config/deploy_status
- POST /staged_config/deploy_status
- GET /staged_config/deployment/hosts
- GET /staged_config/deployment/hosts/{id}
- GET /staged_config/deployment/hosts/{id}/tunnels
- POST /staged_config/deployment/hosts/{id}/tunnels/{name}
- GET /staged_config/flow/applications/active_applications
- POST /staged_config/flow/applications/active_applications
- DELETE /staged_config/flow/applications/active_applications/{id}
- GET /staged_config/flow/applications/active_applications/{id}
- POST /staged_config/flow/applications/active_applications/{id}
- GET /staged_config/remote_networks
- POST /staged_config/remote_networks
- DELETE /staged_config/remote_networks/{network_id}
- GET /staged_config/remote_networks/{network_id}
- POST /staged_config/remote_networks/{network_id}
- GET /staged_config/remote_services
- POST /staged_config/remote_services
- DELETE /staged_config/remote_services/{service_id}
- GET /staged_config/remote_services/{service_id}
- POST /staged_config/remote_services/{service_id}
- DELETE /staged_config/yara_rules
- PUT /staged_config/yara_rules
- play_arrow System Endpoints
- play_arrow System Endpoints
- GET /system/about
- GET /system/authorization/password_policies
- GET /system/authorization/password_policies/{id}
- POST /system/authorization/password_policies/{id}
- POST /system/authorization/password_validators
- GET /system/authorization/settings
- POST /system/authorization/settings
- GET /system/email_servers
- POST /system/email_servers
- DELETE /system/email_servers/{email_server_id}
- GET /system/email_servers/{email_server_id}
- POST /system/email_servers/{email_server_id}
- GET /system/eula_acceptances
- GET /system/eula_acceptances/{id}
- POST /system/eula_acceptances/{id}
- GET /system/eulas
- GET /system/information/encodings
- GET /system/information/locales
- POST /system/server_connection_validator
- GET /system/servers
- GET /system/servers/{server_id}
- POST /system/servers/{server_id}
- GET /system/servers/{server_id}/firewall_rules
- PUT /system/servers/{server_id}/firewall_rules
- GET /system/servers/{server_id}/network_interfaces/bonded
- POST /system/servers/{server_id}/network_interfaces/bonded
- DELETE /system/servers/{server_id}/network_interfaces/bonded/{device_name}
- POST /system/servers/{server_id}/network_interfaces/bonded/{device_name}
- GET /system/servers/{server_id}/network_interfaces/ethernet
- POST /system/servers/{server_id}/network_interfaces/ethernet/{device_name}
- GET /system/servers/{server_id}/system_time_settings
- POST /system/servers/{server_id}/system_time_settings
- GET /system/servers/{server_id}/timezones
ON THIS PAGE
POST /config/event_sources/generated_regexes
SUMMARY Retrieves a regex pattern
MIME Type |
---|
application/json |
Parameter | Type | Optionality | Data Type | MIME Type | Description |
---|---|---|---|---|---|
fields | header | Optional | String | text/plain | Optional - Use this parameter to specify which fields you would like to get back in the response. Fields that are not named are excluded. Specify subfields in brackets and multiple fields in the same object are separated by commas. |
Parameter | Data Type | MIME Type | Description | Sample |
---|---|---|---|---|
payload | Object | application/json | An event sample containing the data which you want the generated regular expression to capture, a leading anchor and trailing anchor. | { "payload_data": [ { "capture_groups": [ { "begin_index": 42, "end_index": 42 } ], "event_sample": "String" } ], "regex": "String" } |
HTTP Response Code | Unique Code | Description |
---|---|---|
200 | The requested regex pattern was generated and returned successfully. | |
422 | 10025 | The system was unable to create a regular expression because of invalid indices. |
422 | 10026 | The system was unable to create a regular expression because of an invalid beginning index. |
422 | 10027 | null |
500 | 1020 | The system was unable to confidently create a regular expression. |