Jump to Content
Home
Guides
API Reference
Changelog
💬 Discussions
v1.0
Log In
API Reference
Log In
v1.0
Home
Guides
API Reference
Changelog
💬 Discussions
Get TTL details
Search
All
Pages
Start typing to search…
JUMP TO
LogRhythm Admin Service API
lists
Get List Details
get
Create or Update List Summary
post
Get List Details and Items
get
Add Items to List
post
Remove Items From List
del
identities
Get Identities
get
Update Identities
put
Get Identity Display Names *
get
Get Identity Identifiers *
get
Update or Create Bulk Identities
post
Search Identities *
post
Search Identity Summaries *
post
Get Identity
get
Update Identity
put
Update Identity Status
put
Update Identifier Status
put
Add Identifier to Identity
post
Merge Two Identities
post
Get Identity Photo
get
Get Merged Identities
get
identity lists
Get Identity From List
get
entities
List Entities
get
Update Entity
post
Create Entities From File
post
Get Entity Details
get
Create Hosts From File
post
Create Networks From File
post
hosts
Fetch Hosts Details
get
Create Host Record
post
Batch Update Hosts
put
Fetch Hosts
get
Change Status of Host
put
Add Host Role and User
post
Delete Host Role or User
del
Get Host Details
get
Update Host
put
Update Host Id
post
Remove Host Identifiers
del
networks
List Networks
get
Create Network
post
Batch Update Networks
put
Get Network Details
get
Update Network
put
users
Get User Permissions
get
List User Records
get
Create New User
post
List All User Logins
get
List User Privileges
get
Get User Login Details
get
Create User Login
post
Get User Details
get
Create User Profile
post
Get User Profile Details
get
Get User Profile Summary
get
Clone User Profile
post
Get User Profile Details by Id
get
Delete User Profile
del
Get User Profile Privileges
get
Get User Profile Log Sources
get
knowledgebase
List Message Source Types
get
Create Message Source Type
post
Get Message Source Type Details
get
Update Message Source Type Details
put
Delete Message Source Type
del
List MPE Policies
get
List MPE Policies summary.
get
List Log Source Virtualization Templates
get
Create a new log source virtualization template.
post
Edit a log source virtualization template.
put
Associate virtual log source with a log source virtualization template.
patch
Get Log Source Virtualization Template Detail
get
Dissociate LSV items from an LSV template.
del
Get Log Source Virtualization Template Details
get
Create log source virtualization template item.
post
Delete log source virtualization template items.
del
Edit log source virtualization template item.
put
Get Log Source Virtualization Template Detail
get
List Privileges
get
notification groups
List Notification Groups
get
Create Notification Group
post
Update Notification Group
put
Delete Notification Group
del
List Users in Notification Group
get
Add Users to Notification Group
post
Remove Users From Notification Group
del
logsources
List Accepted Log Sources
get
Create Log Source
post
Get Log Source Details
get
Update Log Source
put
Change Status of logsources
put
Update existing Logsource to enable virtualization.
put
List Pending Log Sources
get
Create Pending Log Source
post
Delete Pending LogSource
del
Reject multiple pending logsources in batch.
put
Accept multiple pending logsources in batch.
put
Get Pending Log Source Details
get
Get matching logsources for a pending log source to associate
get
Accept pending LogSource by ID
put
Rejects a Pending Log Source.
put
Associate a pending Log Source.
put
Patch Log Source
patch
agents
List Accepted Agents
get
Create Agent Record
post
Update Agent Record
put
List Summary of Accepted Agents
get
Patch Agent Record
patch
Get Agent By Id
get
List Agent Log Sources
get
List Pending Agent Requests
get
Delete Pending Agents
del
Associate pending agent
put
Accept pending agent
put
Get Pending Agent
get
Reject Pending Agent
put
licenses
Get Licensed Entitlements *
get
List licenses
get
mperules
Fetch MPE Rule based on the provided MPE Rule Id
get
Retire/Activate MPE Rule based on the provided MPE Rule Id
patch
Fetch MPE Rules based on the provided query parameters
get
Create MPE Rule
post
Edit MPE Rule
put
beats
Get beat detail by beat Id available in the system
get
Update beat details of a beat available in the system
put
Get all beats details available in the system.
get
Create a new beat.
post
Fetch Beats Template
get
Fetch Beat Types
get
Updates heartbeat of beats
patch
Update status of beats based on beat IDs available in the system.
patch
openCollectors
Get all beats details available in the system associated to the given open collector id.
get
Updates Open Collector Heartbeat
patch
Creates a new open collector.
post
List all permissible open collector
get
Update status of one or multiple open collectors in the available in the system based on open collector Id.
patch
Get open collector by open collector id.
get
Updates an existing open collector.
put
locations
Provides all available locations.
get
Provides location details by location ID.
get
mpePolicies
Create a new MPE policy.
post
Delete MPE policies.
del
Returns the MPE Policy based on the Id.
get
Edit an MPE Policy.
put
Returns the list of MPE rules by MPE policy id.
get
Get an MPE Rule on the basis of MPE Policy Id and MPE Rule Id.
get
Update an MPE Rule on the basis of MPE Policy Id and MPE Rule Id.
put
messagesourcedateformats
List Date Formats
get
Get Message Source Date Format
get
LogRhythm AIE Drill Down API
/drilldown/{alarmID}
Get Drill-Down Logs and Summary
get
/drilldown/{alarmID}/summary
Get Drill-Down Summary
get
LogRhythm AI Engine API
Rules
Imports an AIE rule from the specified .airx file.
post
Updates the statuses of AIE rules in batch.
patch
Initiates restart request of the AIE service for the specified engine.
post
LogRhythm Alarm API
alarms
Get alarm details by ID
get
Update Alarm Status and RBP
patch
Update Alarm Comments
post
Get alarm history details by ID and filter criteria
get
Get alarm details using filter criteria
get
Get alarm summary by alarmId
get
Get events by alarmId
get
Get Alarm Url
get
LogRhythm Case API
Case Summary
List Cases
get
Create Case
post
Get Case
get
Update Case
put
Change Case Status *
put
Case Metrics
Get Case Metrics
get
Update Case Metrics
put
Case Evidence
List Evidence
get
Add File Evidence
post
Add Alarm Evidence
post
Add Log Evidence
post
Add User Event Evidence
post
Add Note Evidence
post
Get Evidence
get
Update Evidence
put
Delete Evidence
del
Get Evidence Progress
get
Download File Evidence
get
Get Evidence Logs Bytes
get
List User Events
get
Get Logs Index
get
Update Logs Index
put
Playbooks
List Playbooks
get
Create Playbook
post
Clone Playbook
post
Get Playbook
get
Update Playbook
put
Update Playbook (Partial)
patch
Delete Playbook
del
Playbook Procedures
List Procedures
get
Update Procedures
put
Get Procedure
get
Playbook Attachments
List Attachments
get
Get Attachment
get
Link Attachment
put
Unlink Attachment
del
Download Attachment
get
Playbook Import / Export
Import Playbook
post
Export Playbook
get
Files
Upload File
post
Get Whitelist
get
Get File Progress
get
Case Tags
Add Case Tags *
put
Remove Case Tags *
put
Case Collaborators
Get Case Collaborators
get
Update Case Collaborators
put
Add Case Collaborators *
put
Remove Case Collaborators *
put
Change Case Owner *
put
Associated Cases
List Associated Cases
get
Add Associated Cases
post
Remove Associated Cases
del
Case History
List Case History *
get
Case Playbooks
List Playbooks
get
Add Playbook
post
Get Playbook
get
Update Playbook
put
Remove Playbook
del
Case Playbook Procedures
List Procedures
get
Get Procedure
get
Update Procedure
put
List Procedures (All Cases)
get
Case Playbook Attachments
List Attachments
get
Get Attachment
get
Download Attachment
get
Global History
List Global History *
get
Logs Indexes
List Logs Indexes (All Cases)
get
Tags
List Tags
get
Create Tag
post
Get Tag
get
Delete Tag
del
Capabilities
Get Capabilities
get
Users
List People *
get
Get Person *
get
List Collaborators *
get
List Owners *
get
Feature Flags
Get Feature Flags *
get
Maintenance
Run Log Evidence Maintenance *
post
LogRhythm Metrics API
Log Volume
Get Log Volume Details
post
TTL
Get TTL details
get
LogRhythm Network Monitor API
/applications
Returns the list of applications classified by Network Monitor.
get
/configuration/ntp
Returns the primary and secondary NTP server configuration.
get
Sets the primary and secondary NTP server configuration.
put
/dpaRules/actions/upload
Uploads a DPA Rule in lrl format.
post
/dpaRules/custom
Remove all Custom DPA Rules. This operation cannot be undone.
del
Retrieve metadata for all Custom DPA Rules.
get
Create or update one or more Custom DPA Rules.
post
/dpaRules/custom/bulk
Delete one or more Custom DPA Rules. This operation cannot be undone.
del
/dpaRules/custom/{ruleName}
Delete the Custom DPA Rule with the given rule name. This operation cannot be undone.
del
/dpaRules/reload
Reload DPA Rules.
put
/dpaRules/{ruleName}/actions/download
Download the LRL file associated with this DPA rule.
get
/dpaRules/system
Retrieve metadata for all System DPA Rules.
get
Enable or disable a System DPA Rule.
post
/eula/actions/download
Download the Network Monitor End User License Agreement.
get
/indices/metadata
Returns all metadata indices for Network Monitor.
get
/indices/metadata/{index}
Deletes the metadata index using the provided index. This operation cannot be undone. This route is admin-only.
del
/indices/upgrade
Returns all indices for Network Monitor's upgrade history.
get
/licenses
Returns Network Monitor license information.
get
Uploads and installs an enterprise or Freemium license. Reboot required.
post
/login
Validate Login Credentials.
post
/logs/{logName}/actions/download
Download the specified Network Monitor log.
get
/me
Retrieves details for the current user.
get
Updates details for the current user.
put
/me/actions/changePassword
Change Current User's Password
post
/me/actions/resetApiToken
Resets the current user's API token.
post
/network/hostname
Returns the hostname of the Network Monitor appliance.
get
Sets the hostname of the Network Monitor appliance. Returns the new hostname if successful.
put
/pcap/actions/download
Download multiple PCAPs at one time.
post
/pcap/actions/upload
Uploads a PCAP for replay.
post
/queryRules
Returns the list of Query Rules.
get
Set Query Rules.
put
Removes all Query Rules.
del
/queryRules/{queryRuleId}
Returns the specified Query Rule.
get
Add a single Query Rule.
put
Removes the specified Query Rule.
del
/search
Allows direct queries into ElasticSearch.
post
/services
Returns current status of all Network Monitor services.
get
/services/actions/restart
Restart Network Monitor services. This route is admin-only.
put
/services/capture
Returns the current Capture configuration.
get
Configures Capture settings.
put
/services/capture/actions/addCapturedApplications
Appends applications to an existing list of captured applications.
put
/services/capture/actions/addExcludedApplications
Appends applications to an existing list of excluded applications.
put
/services/capture/actions/removeCapturedApplications
Removes applications from an existing list of captured applications.
put
/services/capture/actions/removeExcludedApplications
Removes applications from an existing list of excluded applications.
put
/services/filters/application/blacklist
Retreives the list of all blacklisted applications. This route is admin-only.
get
Removes all applications from the application blacklist. This route is admin-only.
del
Adds one or more applications to the application blacklist. This route is admin-only.
post
Sets the application blacklist. This route is admin-only.
put
/services/filters/application/blacklist/{application}
Removes the specified application from the application blacklist. This route is admin-only.
del
/services/filters/ip/blacklist
Gets the IP filter blacklist. This route is admin-only.
get
Deletes the entire IP filter blacklist. This route is admin-only.
del
Adds or updates one or more IP filters to the blacklist. This route is admin-only.
post
Sets the IP filter blacklist. This route is admin-only.
put
/services/filters/ip/blacklist/{filter}
Deletes an individual filter from the IP filter blacklist. This route is admin-only.
del
/services/filters/ip/mode
Gets the IP filter mode. This route is admin-only.
get
Updates the IP filter mode. This route is admin-only.
put
/services/filters/ip/whitelist
Gets the IP filter whitelist. This route is admin-only.
get
Deletes the entire IP filter whitelist. This route is admin-only.
del
Adds or updates one or more IP filters to the whitelist. This route is admin-only.
post
Sets the IP filter whitelist. This route is admin-only.
put
/services/filters/ip/whitelist/{filter}
Deletes an individual filter from the IP filter whitelist. This route is admin-only.
del
/session/{id}
Get session metadata, such as the application, if it is captured, total bytes, etc.
get
/session/{id}/csv
Get session metadata downloaded into a csv file
get
/session/{id}/files
Download reconstructed files contained in the session.
get
/session/{id}/pcap
Reconstruct and download the pcap associated with a session ID.
get
/session/replayed
Get replayed session information.
get
/system/actions/reboot
Reboot Network Monitor. This route is admin-only.
post
/system/actions/shutdown
Shutdown Network Monitor. This route is admin-only.
post
/system/actions/upgrade
Upgrades Network Monitor. Reboot required. This route is admin-only.
post
/systemInfo
Network Monitor System Information.
get
/system/storage/filesystems
Returns filesystem configurations for Network Monitor.
get
/system/time
Returns the current system time in milliseconds.
get
/users
Returns a list of all users. This route is admin-only.
get
Update or add multiple users at once. This route is admin-only.
put
/users/{username}
Retrieves a user from the provided username. This route is admin-only.
get
Updates a user if it already exists, and creates a user if it does not. This route is admin-only.
put
Deletes the user using the provided username. This operation cannot be undone. This route is admin-only.
del
/users/{username}/actions/resetPassword
Reset A User's Password. This route is admin-only.
post
LogRhythm Search API
Search API
Initiate Search
post
Search Result
post
Powered by
Get TTL details
get
http://localhost:8505/lr-metrics-api/ttl
Fetch cluster-wise TTL detail.
Language
Shell
Node
Ruby
PHP
Python
Response
Click
Try It!
to start a request and see the response here!