Skip to content

Firewall Logs Aggregation Query.

POST
/api/data/namespaces/{namespace}/firewall_logs/aggregation
curl --request POST \
--url https://example-corp.console.ves.volterra.io/api/v1/api/production/us-east-1/namespaces/default/api/data/namespaces/example/firewall_logs/aggregation \
--header 'Authorization: <Authorization>' \
--header 'Content-Type: application/json' \
--data '{ "aggs": {}, "end_time": "example", "namespace": "example", "query": "example", "start_time": "example" }'

Request to GET summary/analytics data for the firewall logs that matches the query in request for a given namespace.

Examples of this operation.

namespace
required
string

Namespace GET aggregation data for a given namespace.

Media typeapplication/json
FirewallLogAggregationRequest

Request to GET only aggregation data for Firewall logs.

object
aggs
aggregations

Aggregations provide summary/analytics data over the log response. If the number of logs that matched the query is large and cannot be returned in a single response message, user can GET helpful insights/summary using aggregations. The aggregations are key’ed by user-defined aggregation name. The response will be key’ed with the same name. Optional.

object
end_time
end time

Fetch Firewall logs whose timestamp <= end_time format: unix_timestamp|RFC 3339

Optional: If not specified, then the end_time will be evaluated to start_time+10m If start_time is not specified, then the end_time will be evaluated to

string
<= 1024 characters
namespace
namespace

GET aggregation data for a given namespace.

string
>= 6 characters <= 1024 characters
query
query

Query is used to specify the list of matchers syntax for query := {[]} := <field_name>"" <field_name> := string One or more of following fields in Firewall log may be specified in the query. Site - Name of the site src_ip - Source IP Address dst_ip - Destination IP Address policy_hits.policy - Policy Name policy_hits.policy_rule - Policy Rule Name policy_hits.result - allow|deny|default_deny := string := [”=”|”!=”|”=”|”!”] = : equal to != : not equal to =~ : regex match !~ : not regex match When more than one matcher is specified in the query, then Firewall logs matching ALL the matchers will be returned in the response.

Optional: If not specified, all the Firewall logs matching the given tenant, namespace will be returned in the response.

string
<= 1024 characters
start_time
start time

Fetch Firewall logs whose timestamp >= start_time format: unix_timestamp|RFC 3339

Optional: If not specified, then the start_time will be evaluated to end_time-10m If end_time is not specified, then the start_time will be evaluated to -10m.

string
<= 1024 characters
Examplegenerated
{
"aggs": {},
"end_time": "example",
"namespace": "example",
"query": "example",
"start_time": "example"
}

A successful response.

Media typeapplication/json
LogAggregationResponse

Response message for AuditLogAggregationRequest/AccessLogAggregationRequest.

object
aggs
aggregations

Aggregations provide summary/analytics data over the log response. If the number of logs that matched the query is large and cannot be returned in a single response message, user can GET helpful insights/summary using aggregations. The aggregation data is key’ed with the aggregation name specified in the request.

object
total_hits
total hits

Total number of log messages that matched the query.

string format: uint64
<= 1024 characters
Examplegenerated
{
"aggs": {},
"total_hits": "example"
}

Returned when operation is not authorized.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when there is no permission to access resource.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when resource is not found.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when operation on resource is conflicting with current value.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when operation has been rejected as it is happening too frequently.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when server encountered an error in processing API.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when service is unavailable temporarily.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when server timed out processing request.

Media typeapplication/json
string format: string
Examplegenerated
example