Logsign SIEM API Documentation

All endpoints require authentication via the api_key query parameter.
Base URL: https://<LOGSIGN_HOST>

Table of Contents

1. Test API

Tests the API connection and validates the API key.

GET /test_api 10/min

Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key

Example Request

GET /test_api?api_key=YOUR_API_KEY

Example Response

{
  "success": true
}

2. Get Version

Returns the current Logsign SIEM version.

GET /get_version 10/min

Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key

Example Request

GET /get_version?api_key=YOUR_API_KEY

Example Response

{
  "success": true,
  "version": "6.4.1"
}

3. Feed List (GET)

Returns all entries from the specified feed list.

GET /feed_list 10/min

Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key
list_namestringYesName of the feed list
formatstringNoSet to txt to return the response as plain text

Example Request

GET /feed_list?api_key=YOUR_API_KEY&list_name=blocked_ips

4. Feed List (POST)

Adds a new entry to the specified feed list.

POST /feed_list 30/min

Query Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key
list_namestringYesName of the feed list

Body Parameters

ParameterTypeRequiredDescription
valuestringYesThe value to add
expire_timeintNoExpiration time in seconds (default: 0 = no expiry)

Example Request

POST /feed_list?api_key=YOUR_API_KEY&list_name=blocked_ips
Content-Type: application/json

{
  "value": "192.168.1.100",
  "expire_time": 3600
}

5. Get Count

Returns a single number calculated on the grouped_column field of the events that match the query in the given time frame. The criteria parameter selects how that number is calculated.

GET /get_count 30/min

Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key
querystringYesSearch query. Use * to match all events.
grouped_columnstringYesLogsign field the number is calculated on, for example Source.IP
criteriastringYesunique returns the number of distinct values of grouped_column. value returns the number of events in which grouped_column has a value. No other values are supported.
time_framestringYesTime window in the format <number> <unit>, for example 1 hour. See the note below.

time_frame format

A number and a unit separated by a space, for example 10 min, 24 hour or 7 day. Encode the space as %20 in the URL. Values such as last_1_hour are not accepted. Since version 6.4.115 an invalid time_frame is rejected with HTTP 403 and an explanatory message; older versions return HTTP 500. The same format applies to Get Events and Get Columns.

UnitMeaningUpper bound
minMinutes1440 (24 hours)
hourHours168 (7 days)
dayDays7

The maximum window is 7 days. A larger value is not rejected; it is reduced to the upper bound of its unit (for example 30 day is treated as 7 day).

Example Request

GET /get_count?api_key=YOUR_API_KEY&query=*&grouped_column=Source.IP&criteria=unique&time_frame=1%20hour

Example Response

{
  "success": true,
  "count": 42
}

success is false when the calculated number is 0.

6. Get Events

Returns events matching the given query with pagination support. Results are sorted by Time.Generated, newest first.

GET /get_events 30/min

Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key
querystringYesSearch query using Logsign field names, for example Source.IP:10.0.0.1. Use * to match all events.
time_framestringYesTime window in the format <number> <unit>, for example 1 hour. See the time_frame format note under Get Count.
pageintNoPage number (default: 1)
sizeintNoResults per page (default: 100, max: 1000)

Example Request

GET /get_events?api_key=YOUR_API_KEY&query=Source.IP:10.0.0.1&time_frame=1%20hour&page=1&size=50

Example Response

{
  "success": true,
  "events": [
    {
      "Time": { "Generated": "..." },
      "Source": { "IP": "10.0.0.1" },
      "...": "..."
    }
  ],
  "total_count": 1342,
  "size": 50
}

Use total_count to calculate the number of pages: ceil(total_count / size).

7. Get Columns

Returns the distinct values of grouped_column across the events that match the query in the given time frame. Up to 1000 values are returned.

GET /get_columns 30/min

Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key
querystringYesSearch query. Use * to match all events.
grouped_columnstringYesLogsign field whose values are returned, for example Source.IP
time_framestringYesTime window in the format <number> <unit>, for example 24 hour. See the time_frame format note under Get Count.

Example Request

GET /get_columns?api_key=YOUR_API_KEY&query=*&grouped_column=Source.IP&time_frame=24%20hour

Example Response

{
  "success": true,
  "columns": ["10.0.0.1", "10.0.0.2"]
}

8. Get Incidents

Returns incidents created after the specified timestamp.

GET /get_incidents 30/min

Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key
last_runstringYesTimestamp; returns incidents created after this time
querystringNoFilter query

Example Request

GET /get_incidents?api_key=YOUR_API_KEY&last_run=2026-04-17T00:00:00&query=severity:high

9. Set Incident Status

Updates the status of an incident.

POST /set_incident_status 30/min

Query Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key
incident_idstringYesIncident ID

Body

JSON object containing the status update data.

Example Request

POST /set_incident_status?api_key=YOUR_API_KEY&incident_id=INC-001
Content-Type: application/json

{
  "status": "closed"
}

10. Incident Comment

Adds a comment to an incident.

POST /incident_comment 30/min

Query Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key

Body Parameters

ParameterTypeRequiredDescription
incident_idstringYesIncident ID
messagestringYesComment text

Example Request

POST /incident_comment?api_key=YOUR_API_KEY
Content-Type: application/json

{
  "incident_id": "INC-001",
  "message": "Incident reviewed and closed as false positive."
}

11. Get Alert Configs

Returns all alert configurations grouped by alert blocks.

GET /get_alert_configs 1/min

Parameters

ParameterTypeRequiredDescription
api_keystringYesAPI key

Example Request

GET /get_alert_configs?api_key=YOUR_API_KEY

Example Response

[
  {
    "uid": "block-001",
    "name": "Network Alerts",
    "alerts": [
      {
        "uid": "alert-001",
        "name": "High Traffic Alert",
        "disabled": false,
        "block_uid": "block-001"
      }
    ]
  }
]

Error Responses

HTTP CodeDescription
403Invalid API key, missing required parameter, or invalid time_frame value (since 6.4.115)
500On versions before 6.4.115, an invalid time_frame (for example last_1_hour) returns HTTP 500. In Get Count, a criteria value other than unique or value is not supported and can also result in HTTP 500.
400Invalid request body (JSON parse error)
429Rate limit exceeded