REST API

REST endpoints for event ingestion and saved searches.

This reference is generated from the OpenAPI schema that python manage.py spectacular produces. It documents the shape of each endpoint; it is not a live API console. SIEMatic is self-hosted, so replace <your-siematic-host> below with the base URL of your own deployment.

The raw schema is available at openapi.yaml.

POST /api-token-auth/

Authentication: basicAuth, cookieAuth, tokenAuth

Request body

Field Type Required Description
username string yes —
password string yes —

Response 200

Field Type Required Description
token string yes —

GET /api/events/

ViewSet for Event model operations.

Provides CRUD operations for events with filtering, searching, and bulk creation support.

Authentication: basicAuth, cookieAuth, tokenAuth

Parameter Location Type Required Description
created query string (date-time) no —
host query string no —
index query string no —
search query string no A search term.
source query string no —
sourcetype query string no —
updated query string (date-time) no —

Response 200

Array of:

Field Type Required Description
id integer yes —
index string no —
sourcetype string no —
source string no —
host string no —
data string yes —
created string (date-time) yes —
updated string (date-time) yes —
extracted_fields any no —

POST /api/events/

Create one or more events.

Handles both single and bulk event creation.

Args: request: The HTTP request.

Returns: Response with created event data.

Authentication: basicAuth, cookieAuth, tokenAuth

Request body

Field Type Required Description
index string no —
sourcetype string no —
source string no —
host string no —
data string yes —
extracted_fields any no —

Response 201

Field Type Required Description
id integer yes —
index string no —
sourcetype string no —
source string no —
host string no —
data string yes —
created string (date-time) yes —
updated string (date-time) yes —
extracted_fields any no —

GET /api/events/{id}/

ViewSet for Event model operations.

Provides CRUD operations for events with filtering, searching, and bulk creation support.

Authentication: basicAuth, cookieAuth, tokenAuth

Parameter Location Type Required Description
id path integer yes A unique integer value identifying this event.

Response 200

Field Type Required Description
id integer yes —
index string no —
sourcetype string no —
source string no —
host string no —
data string yes —
created string (date-time) yes —
updated string (date-time) yes —
extracted_fields any no —

PUT /api/events/{id}/

ViewSet for Event model operations.

Provides CRUD operations for events with filtering, searching, and bulk creation support.

Authentication: basicAuth, cookieAuth, tokenAuth

Parameter Location Type Required Description
id path integer yes A unique integer value identifying this event.

Request body

Field Type Required Description
index string no —
sourcetype string no —
source string no —
host string no —
data string yes —
extracted_fields any no —

Response 200

Field Type Required Description
id integer yes —
index string no —
sourcetype string no —
source string no —
host string no —
data string yes —
created string (date-time) yes —
updated string (date-time) yes —
extracted_fields any no —

PATCH /api/events/{id}/

ViewSet for Event model operations.

Provides CRUD operations for events with filtering, searching, and bulk creation support.

Authentication: basicAuth, cookieAuth, tokenAuth

Parameter Location Type Required Description
id path integer yes A unique integer value identifying this event.

Request body

Field Type Required Description
index string no —
sourcetype string no —
source string no —
host string no —
data string no —
extracted_fields any no —

Response 200

Field Type Required Description
id integer yes —
index string no —
sourcetype string no —
source string no —
host string no —
data string yes —
created string (date-time) yes —
updated string (date-time) yes —
extracted_fields any no —

DELETE /api/events/{id}/

ViewSet for Event model operations.

Provides CRUD operations for events with filtering, searching, and bulk creation support.

Authentication: basicAuth, cookieAuth, tokenAuth

Parameter Location Type Required Description
id path integer yes A unique integer value identifying this event.

Response 204

No response body.

GET /api/savedsearches/

Authentication: basicAuth, cookieAuth, tokenAuth

Parameter Location Type Required Description
search query string no A search term.

Response 200

Array of:

Field Type Required Description
id integer yes —
name string yes —
query string yes —
shared_with array of integer no —
is_public boolean no —
created_at string (date-time) yes —
updated_at string (date-time) yes —

POST /api/savedsearches/

Authentication: basicAuth, cookieAuth, tokenAuth

Request body

Field Type Required Description
name string yes —
query string yes —
shared_with array of integer no —
is_public boolean no —

Response 201

Field Type Required Description
id integer yes —
name string yes —
query string yes —
shared_with array of integer no —
is_public boolean no —
created_at string (date-time) yes —
updated_at string (date-time) yes —

GET /api/savedsearches/{id}/

Authentication: basicAuth, cookieAuth, tokenAuth

Parameter Location Type Required Description
id path integer yes A unique integer value identifying this saved search.

Response 200

Field Type Required Description
id integer yes —
name string yes —
query string yes —
shared_with array of integer no —
is_public boolean no —
created_at string (date-time) yes —
updated_at string (date-time) yes —

PUT /api/savedsearches/{id}/

Authentication: basicAuth, cookieAuth, tokenAuth

Parameter Location Type Required Description
id path integer yes A unique integer value identifying this saved search.

Request body

Field Type Required Description
name string yes —
query string yes —
shared_with array of integer no —
is_public boolean no —

Response 200

Field Type Required Description
id integer yes —
name string yes —
query string yes —
shared_with array of integer no —
is_public boolean no —
created_at string (date-time) yes —
updated_at string (date-time) yes —

PATCH /api/savedsearches/{id}/

Authentication: basicAuth, cookieAuth, tokenAuth

Parameter Location Type Required Description
id path integer yes A unique integer value identifying this saved search.

Request body

Field Type Required Description
name string no —
query string no —
shared_with array of integer no —
is_public boolean no —

Response 200

Field Type Required Description
id integer yes —
name string yes —
query string yes —
shared_with array of integer no —
is_public boolean no —
created_at string (date-time) yes —
updated_at string (date-time) yes —

DELETE /api/savedsearches/{id}/

Authentication: basicAuth, cookieAuth, tokenAuth

Parameter Location Type Required Description
id path integer yes A unique integer value identifying this saved search.

Response 204

No response body.

POST /search2/api/run/

Authentication: basicAuth, cookieAuth, tokenAuth

Request body

Field Type Required Description
query string yes —

Response 200

Field Type Required Description
rows array of object yes —
meta SearchRunMeta yes —

Response 400

Field Type Required Description
error string yes —