Skip to content

Replace Global Log Receiver.

PUT
/api/config/namespaces/{metadata.namespace}/global_log_receivers/{metadata.name}
curl --request PUT \
--url https://example-corp.console.ves.volterra.io/api/v1/api/production/us-east-1/namespaces/default/api/config/namespaces/example/global_log_receivers/example \
--header 'Authorization: <Authorization>' \
--header 'Content-Type: application/json' \
--data '{ "metadata": { "annotations": {}, "description": "example", "disable": true, "labels": {}, "name": "example", "namespace": "example" }, "spec": { "audit_logs": {}, "aws_cloud_watch_receiver": { "aws_cred": { "name": "example", "namespace": "example" }, "aws_region": "example", "batch": { "max_bytes": 1, "max_bytes_disabled": {}, "max_events": 1, "max_events_disabled": {}, "timeout_seconds": "example", "timeout_seconds_default": {} }, "compression": { "compression_default": {}, "compression_gzip": {}, "compression_none": {} }, "group_name": "example", "stream_name": "example" }, "azure_event_hubs_receiver": { "connection_string": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } }, "instance": "example", "namespace": "example" }, "azure_receiver": { "batch": { "max_bytes": 1, "max_bytes_disabled": {}, "max_events": 1, "max_events_disabled": {}, "timeout_seconds": "example", "timeout_seconds_default": {} }, "compression": { "compression_default": {}, "compression_gzip": {}, "compression_none": {} }, "connection_string": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } }, "container_name": "example", "filename_options": { "custom_folder": "example", "log_type_folder": {}, "no_folder": {} } }, "datadog_receiver": { "batch": { "max_bytes": 1, "max_bytes_disabled": {}, "max_events": 1, "max_events_disabled": {}, "timeout_seconds": "example", "timeout_seconds_default": {} }, "compression": { "compression_default": {}, "compression_gzip": {}, "compression_none": {} }, "datadog_api_key": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } }, "endpoint": "example", "no_tls": {}, "site": "example", "use_tls": { "disable_verify_certificate": {}, "disable_verify_hostname": {}, "enable_verify_certificate": {}, "enable_verify_hostname": {}, "mtls_disabled": {}, "mtls_enable": { "certificate": "example", "key_url": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } } }, "no_ca": {}, "trusted_ca_url": "example" } }, "dns_logs": {}, "gcp_bucket_receiver": { "batch": { "max_bytes": 1, "max_bytes_disabled": {}, "max_events": 1, "max_events_disabled": {}, "timeout_seconds": "example", "timeout_seconds_default": {} }, "bucket": "example", "compression": { "compression_default": {}, "compression_gzip": {}, "compression_none": {} }, "filename_options": { "custom_folder": "example", "log_type_folder": {}, "no_folder": {} }, "gcp_cred": { "name": "example", "namespace": "example" } }, "http_receiver": { "auth_basic": { "password": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } }, "user_name": "example" }, "auth_none": {}, "auth_token": { "token": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } } }, "batch": { "max_bytes": 1, "max_bytes_disabled": {}, "max_events": 1, "max_events_disabled": {}, "timeout_seconds": "example", "timeout_seconds_default": {} }, "compression": { "compression_default": {}, "compression_gzip": {}, "compression_none": {} }, "no_tls": {}, "uri": "example", "use_tls": { "disable_verify_certificate": {}, "disable_verify_hostname": {}, "enable_verify_certificate": {}, "enable_verify_hostname": {}, "mtls_disabled": {}, "mtls_enable": { "certificate": "example", "key_url": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } } }, "no_ca": {}, "trusted_ca_url": "example" } }, "kafka_receiver": { "batch": { "max_bytes": 1, "max_bytes_disabled": {}, "max_events": 1, "max_events_disabled": {}, "timeout_seconds": "example", "timeout_seconds_default": {} }, "bootstrap_servers": [ "example" ], "compression": { "compression_default": {}, "compression_gzip": {}, "compression_none": {} }, "kafka_topic": "example", "no_tls": {}, "use_tls": { "disable_verify_certificate": {}, "disable_verify_hostname": {}, "enable_verify_certificate": {}, "enable_verify_hostname": {}, "mtls_disabled": {}, "mtls_enable": { "certificate": "example", "key_url": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } } }, "no_ca": {}, "trusted_ca_url": "example" } }, "new_relic_receiver": { "api_key": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } }, "eu": {}, "us": {} }, "ns_all": {}, "ns_current": {}, "ns_list": { "namespaces": [ "example" ] }, "qradar_receiver": { "batch": { "max_bytes": 1, "max_bytes_disabled": {}, "max_events": 1, "max_events_disabled": {}, "timeout_seconds": "example", "timeout_seconds_default": {} }, "compression": { "compression_default": {}, "compression_gzip": {}, "compression_none": {} }, "no_tls": {}, "uri": "example", "use_tls": { "disable_verify_certificate": {}, "disable_verify_hostname": {}, "enable_verify_certificate": {}, "enable_verify_hostname": {}, "mtls_disabled": {}, "mtls_enable": { "certificate": "example", "key_url": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } } }, "no_ca": {}, "trusted_ca_url": "example" } }, "request_logs": {}, "s3_receiver": { "aws_cred": { "name": "example", "namespace": "example" }, "aws_region": "example", "batch": { "max_bytes": 1, "max_bytes_disabled": {}, "max_events": 1, "max_events_disabled": {}, "timeout_seconds": "example", "timeout_seconds_default": {} }, "bucket": "example", "compression": { "compression_default": {}, "compression_gzip": {}, "compression_none": {} }, "filename_options": { "custom_folder": "example", "log_type_folder": {}, "no_folder": {} } }, "security_events": {}, "splunk_receiver": { "batch": { "max_bytes": 1, "max_bytes_disabled": {}, "max_events": 1, "max_events_disabled": {}, "timeout_seconds": "example", "timeout_seconds_default": {} }, "compression": { "compression_default": {}, "compression_gzip": {}, "compression_none": {} }, "endpoint": "example", "no_tls": {}, "splunk_hec_token": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } }, "use_tls": { "disable_verify_certificate": {}, "disable_verify_hostname": {}, "enable_verify_certificate": {}, "enable_verify_hostname": {}, "mtls_disabled": {}, "mtls_enable": { "certificate": "example", "key_url": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } } }, "no_ca": {}, "trusted_ca_url": "example" } }, "sumo_logic_receiver": { "url": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } } } } }'

Replaces the content of an Global Log Receiver object.

Examples of this operation.

metadata.namespace
required
string

Namespace This defines the workspace within which each the configuration object is to be created. Must be a DNS_LABEL format. For a namespace object itself, namespace value will be ""

metadata.name
required
string

Name The configuration object to be replaced will be looked up by name.

Media typeapplication/json
ReplaceRequest is used to replace contents of a global_log_receiver

This is the input message of the ‘Replace’ RPC.

object
metadata
object
annotations
annotations

Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects.

object
description
description

Human readable description for the object.

string
>= 21 characters <= 1200 characters
disable
disable

A value of true will administratively disable the object.

boolean format: boolean
labels
labels

Map of string keys and values that can be used to organize and categorize (scope and select) objects as chosen by the user. Values specified here will be used by selector expression.

object
name
name

This is the name of configuration object. It has to be unique within the namespace. It can only be specified during create API and cannot be changed during replace API. The value of name has to follow DNS-1035 format. Required: YES.

string
>= 6 characters <= 1024 characters
namespace
namespace

This defines the workspace within which each the configuration object is to be created. Must be a DNS_LABEL format. For a namespace object itself, namespace value will be ""

string
>= 6 characters <= 1024 characters
spec
object
audit_logs
object
aws_cloud_watch_receiver
object
aws_cred
object
name
name

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name. Required: YES.

string
>= 1 characters <= 128 characters
namespace
namespace

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace.

string
>= 6 characters <= 64 characters
tenant
tenant

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant.

string
>= 6 characters <= 64 characters
aws_region
AWS Region

AWS Region Name Required: YES.

string
<= 1024 characters
batch
object
max_bytes
Max Bytes

Exclusive with [max_bytes_disabled] Send batch to endpoint after the batch is equal to or larger than this many bytes.

integer format: int64
max_bytes_disabled
object
max_events
Max Events

Exclusive with [max_events_disabled] Send batch to endpoint after this many log messages are in the batch.

integer format: int64
max_events_disabled
object
timeout_seconds
Timeout Seconds

Exclusive with [timeout_seconds_default] Send batch to the endpoint after this many seconds.

string format: uint64
<= 1024 characters
timeout_seconds_default
object
compression
object
compression_default
object
compression_gzip
object
compression_none
object
group_name
Group Name

The group name of the target Cloudwatch Logs stream Required: YES.

string
>= 3 characters <= 512 characters
stream_name
Stream Name

The stream name of the target Cloudwatch Logs stream. Note that there can only be one writer to a log stream at a time Required: YES.

string
>= 3 characters <= 512 characters
azure_event_hubs_receiver
object
connection_string
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
instance
Event Hubs Instance

Event Hubs Instance name into which logs should be stored Required: YES.

string
>= 3 characters <= 63 characters
namespace
Event Hubs Namespace

Event Hubs Namespace is namespace with instance into which logs should be stored Required: YES.

string
>= 3 characters <= 63 characters
azure_receiver
object
batch
object
max_bytes
Max Bytes

Exclusive with [max_bytes_disabled] Send batch to endpoint after the batch is equal to or larger than this many bytes.

integer format: int64
max_bytes_disabled
object
max_events
Max Events

Exclusive with [max_events_disabled] Send batch to endpoint after this many log messages are in the batch.

integer format: int64
max_events_disabled
object
timeout_seconds
Timeout Seconds

Exclusive with [timeout_seconds_default] Send batch to the endpoint after this many seconds.

string format: uint64
<= 1024 characters
timeout_seconds_default
object
compression
object
compression_default
object
compression_gzip
object
compression_none
object
connection_string
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
container_name
Container Name

Container Name is the name of the container into which logs should be stored Required: YES.

string
>= 3 characters <= 63 characters
filename_options
object
custom_folder
Custom Folder

Exclusive with [log_type_folder no_folder] Use your own folder name as the name of the folder in the endpoint bucket or file The folder name must match /^[a-z_][a-z0-9\\-\\._]*$/i

string
<= 1024 characters
log_type_folder
object
no_folder
object
datadog_receiver
object
batch
object
max_bytes
Max Bytes

Exclusive with [max_bytes_disabled] Send batch to endpoint after the batch is equal to or larger than this many bytes.

integer format: int64
max_bytes_disabled
object
max_events
Max Events

Exclusive with [max_events_disabled] Send batch to endpoint after this many log messages are in the batch.

integer format: int64
max_events_disabled
object
timeout_seconds
Timeout Seconds

Exclusive with [timeout_seconds_default] Send batch to the endpoint after this many seconds.

string format: uint64
<= 1024 characters
timeout_seconds_default
object
compression
object
compression_default
object
compression_gzip
object
compression_none
object
datadog_api_key
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
endpoint
Datadog Endpoint

Exclusive with [site] Datadog Endpoint,.

string
<= 1024 characters
no_tls
object
site
Datadog Site

Exclusive with [endpoint] Datadog Site,.

string
<= 1024 characters
use_tls
object
disable_verify_certificate
object
disable_verify_hostname
object
enable_verify_certificate
object
enable_verify_hostname
object
mtls_disabled
object
mtls_enable
object
certificate

Client certificate is PEM-encoded certificate or certificate-chain.

string
<= 131072 characters
key_url
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
no_ca
object
trusted_ca_url
Server CA certificates

Exclusive with [no_ca] The URL or value for trusted Server CA certificate or certificate chain Certificates in PEM format including the PEM headers.

string
<= 131072 characters
dns_logs
object
gcp_bucket_receiver
object
batch
object
max_bytes
Max Bytes

Exclusive with [max_bytes_disabled] Send batch to endpoint after the batch is equal to or larger than this many bytes.

integer format: int64
max_bytes_disabled
object
max_events
Max Events

Exclusive with [max_events_disabled] Send batch to endpoint after this many log messages are in the batch.

integer format: int64
max_events_disabled
object
timeout_seconds
Timeout Seconds

Exclusive with [timeout_seconds_default] Send batch to the endpoint after this many seconds.

string format: uint64
<= 1024 characters
timeout_seconds_default
object
bucket
GCP Bucket Name

GCP Bucket Name Required: YES.

string
>= 3 characters <= 128 characters
compression
object
compression_default
object
compression_gzip
object
compression_none
object
filename_options
object
custom_folder
Custom Folder

Exclusive with [log_type_folder no_folder] Use your own folder name as the name of the folder in the endpoint bucket or file The folder name must match /^[a-z_][a-z0-9\\-\\._]*$/i

string
<= 1024 characters
log_type_folder
object
no_folder
object
gcp_cred
object
name
name

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name. Required: YES.

string
>= 1 characters <= 128 characters
namespace
namespace

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace.

string
>= 6 characters <= 64 characters
tenant
tenant

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant.

string
>= 6 characters <= 64 characters
http_receiver
object
auth_basic
object
password
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
user_name
username

HTTP Basic Auth User Name.

string
<= 64 characters
auth_none
object
auth_token
object
token
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
batch
object
max_bytes
Max Bytes

Exclusive with [max_bytes_disabled] Send batch to endpoint after the batch is equal to or larger than this many bytes.

integer format: int64
max_bytes_disabled
object
max_events
Max Events

Exclusive with [max_events_disabled] Send batch to endpoint after this many log messages are in the batch.

integer format: int64
max_events_disabled
object
timeout_seconds
Timeout Seconds

Exclusive with [timeout_seconds_default] Send batch to the endpoint after this many seconds.

string format: uint64
<= 1024 characters
timeout_seconds_default
object
compression
object
compression_default
object
compression_gzip
object
compression_none
object
no_tls
object
uri
HTTP Uri

HTTP URI is the URI of the HTTP endpoint to send logs to, Required: YES.

string
<= 1024 characters
use_tls
object
disable_verify_certificate
object
disable_verify_hostname
object
enable_verify_certificate
object
enable_verify_hostname
object
mtls_disabled
object
mtls_enable
object
certificate

Client certificate is PEM-encoded certificate or certificate-chain.

string
<= 131072 characters
key_url
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
no_ca
object
trusted_ca_url
Server CA certificates

Exclusive with [no_ca] The URL or value for trusted Server CA certificate or certificate chain Certificates in PEM format including the PEM headers.

string
<= 131072 characters
kafka_receiver
object
batch
object
max_bytes
Max Bytes

Exclusive with [max_bytes_disabled] Send batch to endpoint after the batch is equal to or larger than this many bytes.

integer format: int64
max_bytes_disabled
object
max_events
Max Events

Exclusive with [max_events_disabled] Send batch to endpoint after this many log messages are in the batch.

integer format: int64
max_events_disabled
object
timeout_seconds
Timeout Seconds

Exclusive with [timeout_seconds_default] Send batch to the endpoint after this many seconds.

string format: uint64
<= 1024 characters
timeout_seconds_default
object
bootstrap_servers
Kafka Bootstrap Servers List

List of host:port pairs of the Kafka brokers Required: YES.

Array<string>
>= 1 items <= 8 items
compression
object
compression_default
object
compression_gzip
object
compression_none
object
kafka_topic
Kafka Topic

The Kafka topic name to write events to Required: YES.

string
>= 3 characters <= 255 characters
no_tls
object
use_tls
object
disable_verify_certificate
object
disable_verify_hostname
object
enable_verify_certificate
object
enable_verify_hostname
object
mtls_disabled
object
mtls_enable
object
certificate

Client certificate is PEM-encoded certificate or certificate-chain.

string
<= 131072 characters
key_url
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
no_ca
object
trusted_ca_url
Server CA certificates

Exclusive with [no_ca] The URL or value for trusted Server CA certificate or certificate chain Certificates in PEM format including the PEM headers.

string
<= 131072 characters
new_relic_receiver
object
api_key
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
eu
object
us
object
ns_all
object
ns_current
object
ns_list
object
namespaces
Namespaces

List of namespaces to stream logs for Required: YES.

Array<string>
<= 16 items
qradar_receiver
object
batch
object
max_bytes
Max Bytes

Exclusive with [max_bytes_disabled] Send batch to endpoint after the batch is equal to or larger than this many bytes.

integer format: int64
max_bytes_disabled
object
max_events
Max Events

Exclusive with [max_events_disabled] Send batch to endpoint after this many log messages are in the batch.

integer format: int64
max_events_disabled
object
timeout_seconds
Timeout Seconds

Exclusive with [timeout_seconds_default] Send batch to the endpoint after this many seconds.

string format: uint64
<= 1024 characters
timeout_seconds_default
object
compression
object
compression_default
object
compression_gzip
object
compression_none
object
no_tls
object
uri
Log Source Collector URL

Log Source Collector URL is the URL of the IBM QRadar Log Source Collector to send logs to, Required: YES.

string
<= 1024 characters
use_tls
object
disable_verify_certificate
object
disable_verify_hostname
object
enable_verify_certificate
object
enable_verify_hostname
object
mtls_disabled
object
mtls_enable
object
certificate

Client certificate is PEM-encoded certificate or certificate-chain.

string
<= 131072 characters
key_url
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
no_ca
object
trusted_ca_url
Server CA certificates

Exclusive with [no_ca] The URL or value for trusted Server CA certificate or certificate chain Certificates in PEM format including the PEM headers.

string
<= 131072 characters
request_logs
object
s3_receiver
object
aws_cred
object
name
name

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name. Required: YES.

string
>= 1 characters <= 128 characters
namespace
namespace

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace.

string
>= 6 characters <= 64 characters
tenant
tenant

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant.

string
>= 6 characters <= 64 characters
aws_region
AWS Region

AWS Region Name Required: YES.

string
<= 1024 characters
batch
object
max_bytes
Max Bytes

Exclusive with [max_bytes_disabled] Send batch to endpoint after the batch is equal to or larger than this many bytes.

integer format: int64
max_bytes_disabled
object
max_events
Max Events

Exclusive with [max_events_disabled] Send batch to endpoint after this many log messages are in the batch.

integer format: int64
max_events_disabled
object
timeout_seconds
Timeout Seconds

Exclusive with [timeout_seconds_default] Send batch to the endpoint after this many seconds.

string format: uint64
<= 1024 characters
timeout_seconds_default
object
bucket
S3 Bucket Name

S3 Bucket Name Required: YES.

string
>= 3 characters <= 128 characters
compression
object
compression_default
object
compression_gzip
object
compression_none
object
filename_options
object
custom_folder
Custom Folder

Exclusive with [log_type_folder no_folder] Use your own folder name as the name of the folder in the endpoint bucket or file The folder name must match /^[a-z_][a-z0-9\\-\\._]*$/i

string
<= 1024 characters
log_type_folder
object
no_folder
object
security_events
object
splunk_receiver
object
batch
object
max_bytes
Max Bytes

Exclusive with [max_bytes_disabled] Send batch to endpoint after the batch is equal to or larger than this many bytes.

integer format: int64
max_bytes_disabled
object
max_events
Max Events

Exclusive with [max_events_disabled] Send batch to endpoint after this many log messages are in the batch.

integer format: int64
max_events_disabled
object
timeout_seconds
Timeout Seconds

Exclusive with [timeout_seconds_default] Send batch to the endpoint after this many seconds.

string format: uint64
<= 1024 characters
timeout_seconds_default
object
compression
object
compression_default
object
compression_gzip
object
compression_none
object
endpoint
Splunk HEC Logs Endpoint

Splunk HEC Logs Endpoint, (Note: must not contain /services/collector) Required: YES.

string
<= 1024 characters
no_tls
object
splunk_hec_token
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
use_tls
object
disable_verify_certificate
object
disable_verify_hostname
object
enable_verify_certificate
object
enable_verify_hostname
object
mtls_disabled
object
mtls_enable
object
certificate

Client certificate is PEM-encoded certificate or certificate-chain.

string
<= 131072 characters
key_url
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
no_ca
object
trusted_ca_url
Server CA certificates

Exclusive with [no_ca] The URL or value for trusted Server CA certificate or certificate chain Certificates in PEM format including the PEM headers.

string
<= 131072 characters
sumo_logic_receiver
object
url
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters

A successful response.

Media typeapplication/json
object
Examplegenerated
{}

Returned when operation is not authorized.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when there is no permission to access resource.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when resource is not found.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when operation on resource is conflicting with current value.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when operation has been rejected as it is happening too frequently.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when server encountered an error in processing API.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when service is unavailable temporarily.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when server timed out processing request.

Media typeapplication/json
string format: string
Examplegenerated
example