All endpoints require authentication via the api_key query parameter.
Base URL: https://<LOGSIGN_HOST>
Tests the API connection and validates the API key.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
GET /test_api?api_key=YOUR_API_KEY
{
"success": true
}
Returns the current Logsign SIEM version.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
GET /get_version?api_key=YOUR_API_KEY
{
"success": true,
"version": "6.4.1"
}
Returns all entries from the specified feed list.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
| list_name | string | Yes | Name of the feed list |
| format | string | No | Set to txt to return the response as plain text |
GET /feed_list?api_key=YOUR_API_KEY&list_name=blocked_ips
Adds a new entry to the specified feed list.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
| list_name | string | Yes | Name of the feed list |
| Parameter | Type | Required | Description |
|---|---|---|---|
| value | string | Yes | The value to add |
| expire_time | int | No | Expiration time in seconds (default: 0 = no expiry) |
POST /feed_list?api_key=YOUR_API_KEY&list_name=blocked_ips
Content-Type: application/json
{
"value": "192.168.1.100",
"expire_time": 3600
}
Returns a single number calculated on the grouped_column field of the events that match the query in the given time frame. The criteria parameter selects how that number is calculated.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
| query | string | Yes | Search query. Use * to match all events. |
| grouped_column | string | Yes | Logsign field the number is calculated on, for example Source.IP |
| criteria | string | Yes | unique returns the number of distinct values of grouped_column. value returns the number of events in which grouped_column has a value. No other values are supported. |
| time_frame | string | Yes | Time window in the format <number> <unit>, for example 1 hour. See the note below. |
A number and a unit separated by a space, for example 10 min, 24 hour or 7 day. Encode the space as %20 in the URL. Values such as last_1_hour are not accepted. Since version 6.4.115 an invalid time_frame is rejected with HTTP 403 and an explanatory message; older versions return HTTP 500. The same format applies to Get Events and Get Columns.
| Unit | Meaning | Upper bound |
|---|---|---|
| min | Minutes | 1440 (24 hours) |
| hour | Hours | 168 (7 days) |
| day | Days | 7 |
The maximum window is 7 days. A larger value is not rejected; it is reduced to the upper bound of its unit (for example 30 day is treated as 7 day).
GET /get_count?api_key=YOUR_API_KEY&query=*&grouped_column=Source.IP&criteria=unique&time_frame=1%20hour
{
"success": true,
"count": 42
}
success is false when the calculated number is 0.
Returns events matching the given query with pagination support. Results are sorted by Time.Generated, newest first.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
| query | string | Yes | Search query using Logsign field names, for example Source.IP:10.0.0.1. Use * to match all events. |
| time_frame | string | Yes | Time window in the format <number> <unit>, for example 1 hour. See the time_frame format note under Get Count. |
| page | int | No | Page number (default: 1) |
| size | int | No | Results per page (default: 100, max: 1000) |
GET /get_events?api_key=YOUR_API_KEY&query=Source.IP:10.0.0.1&time_frame=1%20hour&page=1&size=50
{
"success": true,
"events": [
{
"Time": { "Generated": "..." },
"Source": { "IP": "10.0.0.1" },
"...": "..."
}
],
"total_count": 1342,
"size": 50
}
Use total_count to calculate the number of pages: ceil(total_count / size).
Returns the distinct values of grouped_column across the events that match the query in the given time frame. Up to 1000 values are returned.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
| query | string | Yes | Search query. Use * to match all events. |
| grouped_column | string | Yes | Logsign field whose values are returned, for example Source.IP |
| time_frame | string | Yes | Time window in the format <number> <unit>, for example 24 hour. See the time_frame format note under Get Count. |
GET /get_columns?api_key=YOUR_API_KEY&query=*&grouped_column=Source.IP&time_frame=24%20hour
{
"success": true,
"columns": ["10.0.0.1", "10.0.0.2"]
}
Returns incidents created after the specified timestamp.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
| last_run | string | Yes | Timestamp; returns incidents created after this time |
| query | string | No | Filter query |
GET /get_incidents?api_key=YOUR_API_KEY&last_run=2026-04-17T00:00:00&query=severity:high
Updates the status of an incident.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
| incident_id | string | Yes | Incident ID |
JSON object containing the status update data.
POST /set_incident_status?api_key=YOUR_API_KEY&incident_id=INC-001
Content-Type: application/json
{
"status": "closed"
}
Adds a comment to an incident.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
| Parameter | Type | Required | Description |
|---|---|---|---|
| incident_id | string | Yes | Incident ID |
| message | string | Yes | Comment text |
POST /incident_comment?api_key=YOUR_API_KEY
Content-Type: application/json
{
"incident_id": "INC-001",
"message": "Incident reviewed and closed as false positive."
}
Returns all alert configurations grouped by alert blocks.
| Parameter | Type | Required | Description |
|---|---|---|---|
| api_key | string | Yes | API key |
GET /get_alert_configs?api_key=YOUR_API_KEY
[
{
"uid": "block-001",
"name": "Network Alerts",
"alerts": [
{
"uid": "alert-001",
"name": "High Traffic Alert",
"disabled": false,
"block_uid": "block-001"
}
]
}
]
| HTTP Code | Description |
|---|---|
| 403 | Invalid API key, missing required parameter, or invalid time_frame value (since 6.4.115) |
| 500 | On versions before 6.4.115, an invalid time_frame (for example last_1_hour) returns HTTP 500. In Get Count, a criteria value other than unique or value is not supported and can also result in HTTP 500. |
| 400 | Invalid request body (JSON parse error) |
| 429 | Rate limit exceeded |