Logsign SIEM API Documentation

All endpoints require authentication via the api_key query parameter.
Base URL: https://<LOGSIGN_HOST>

1. Test API

Tests the API connection and validates the API key.

GET/test_api10/min

Parameters

Parameter Type Required Description
api_key string Yes API key

Example Request

GET /test_api?api_key=YOUR_API_KEY

Example Response

{
  "success": true
}

 

2. Get Version

Returns the current Logsign SIEM version.

GET/get_version10/min

Parameters

Parameter Type Required Description
api_key string Yes API key

Example Request

GET /get_version?api_key=YOUR_API_KEY

Example Response

{
  "success": true,
  "version": "6.4.1"
}

 

3. Feed List (GET)

Returns all entries from the specified feed list.

GET/feed_list10/min

Parameters

Parameter Type Required Description
api_key string Yes API key
list_name string Yes Name of the feed list
format string No Set to txt to return the response as plain text

Example Request

GET /feed_list?api_key=YOUR_API_KEY&list_name=blocked_ips

 

4. Feed List (POST)

Adds a new entry to the specified feed list.

POST/feed_list30/min

Query Parameters

Parameter Type Required Description
api_key string Yes API key
list_name string Yes Name of the feed list

Body Parameters

Parameter Type Required Description
value string Yes The value to add
expire_time int No Expiration time in seconds (default: 0 = no expiry)

Example Request

POST /feed_list?api_key=YOUR_API_KEY&list_name=blocked_ips
Content-Type: application/json

{
  "value": "192.168.1.100",
  "expire_time": 3600
}

5. Get Count

Returns a single number calculated on the grouped_column field of the events that match the query in the given time frame. The criteria parameter selects how that number is calculated.

GET/get_count30/min

Parameters

Parameter Type Required Description
api_key string Yes API key
query string Yes Search query. Use * to match all events.
grouped_column string Yes Logsign field the number is calculated on, for example Source.IP
criteria string Yes unique returns the number of distinct values of grouped_column. value returns the number of events in which grouped_column has a value. No other values are supported.
time_frame string Yes Time window in the format <number> <unit>, for example 1 hour. See the note below.

time_frame format: a number and a unit separated by a space. The unit is min, hour or day (for example 10 min, 24 hour, 7 day), and the window is capped at 1440 min, 168 hour or 7 day. Encode the space as %20 in the URL. Values such as last_1_hour are not accepted. Since version 6.4.115 an invalid time_frame is rejected with HTTP 403 and an explanatory message; older versions return HTTP 500. The same format applies to Get Events, Get Columns, Get Incidents and Get System Events.

Example Request

GET /get_count?api_key=YOUR_API_KEY&query=*&grouped_column=Source.IP&criteria=unique&time_frame=1%20hour

Example Response

{
  "success": true,
  "count": 42
}

success is false when the calculated number is 0.

6. Get Events

Returns events matching the given query with pagination support. Results are sorted by Time.Generated, newest first.

GET/get_events30/min

Parameters

Parameter Type Required Description
api_key string Yes API key
query string Yes Search query using Logsign field names, for example Source.IP:10.0.0.1. Use * to match all events.
time_frame string Yes Time window in the format <number> <unit>, for example 1 hour. See the time_frame format note under Get Count.
page int No Page number (default: 1)
size int No Results per page (default: 100, max: 1000)

Example Request

GET /get_events?api_key=YOUR_API_KEY&query=Source.IP:10.0.0.1&time_frame=1%20hour&page=1&size=50

Example Response

{
  "success": true,
  "events": [
    {
      "Time": { "Generated": "..." },
      "Source": { "IP": "10.0.0.1" },
      "...": "..."
    }
  ],
  "total_count": 1342,
  "size": 50
}

Use total_count to calculate the number of pages: ceil(total_count / size).

7. Get Columns

Returns the distinct values of grouped_column across the events that match the query in the given time frame. Up to 1000 values are returned.

GET/get_columns30/min

Parameters

Parameter Type Required Description
api_key string Yes API key
query string Yes Search query. Use * to match all events.
grouped_column string Yes Logsign field whose values are returned, for example Source.IP
time_frame string Yes Time window in the format <number> <unit>, for example 24 hour. See the time_frame format note under Get Count.

Example Request

GET /get_columns?api_key=YOUR_API_KEY&query=*&grouped_column=Source.IP&time_frame=24%20hour

Example Response

{
  "success": true,
  "columns": ["10.0.0.1", "10.0.0.2"]
}

 

8. Get Incidents

By default this endpoint returns alert data (DataType:Alert) for backward compatibility. Since version 6.4.112, sending source=incident returns actual incident data instead, including incident status. This makes it possible to distinguish open and closed incidents. 

Returns incidents created after the specified timestamp.

GET/get_incidents30/min

Parameters

Parameter Type Required Description
api_key string Yes API key
last_run string Yes Timestamp; returns incidents created after this time
query string No Filter query
source string No

Data source to return. Set to incident to return incident data (with status). 

If omitted, alert data is returned (default).

 

Example Request

GET /get_incidents?api_key=YOUR_API_KEY&last_run=2026-04-17T00:00:00Z&query=severity:high
GET /get_incidents?api_key=YOUR_API_KEY&last_run=2026-04-17T00:00:00Z&source=incident

 

time_frame

curl --location 'https://YOUR_HOST/get_incidents?api_key=YOUR_API_KEY&time_frame=10%20min&query=*&source=incident'
curl --location 'https://YOUR_HOST/get_incidents?api_key=YOUR_API_KEY&time_frame=1%20hour&query=*&source=incident'

 

9. Set Incident Status

Closes an incident with the given reason and comment.

POST/set_incident_status30/min

Query Parameters

Parameter Type Required Description
api_key string Yes API key
incident_id string Yes

Incident ID. Either the Incident.ID column value or the DocID shown in the incident 

URL can be used; both work

Body Parameters

Parameter Type Required Description
reason_id int Yes Close reason. See the reason list below. 
comment string Yes Comment describing why the incident is being closed.

reason_id values

reason_id Meaning
1 False Positive
2 True Positive
3 No Action 
4 Resolved
5 Other

Example Request

POST /set_incident_status?api_key=YOUR_API_KEY&incident_id=123
Content-Type: application/json 

{
    "reason_id": 4,
    "comment": "close comment str"
}

For example, sending reason_id 4 closes the incident as Resolved.

 

10. Incident Comment

Adds a comment to an incident.

POST/incident_comment30/min

Query Parameters

Parameter Type Required Description
api_key string Yes API key

Body Parameters

Parameter Type Required Description
incident_id string Yes Incident ID
message string Yes Comment text

Example Request

POST /incident_comment?api_key=YOUR_API_KEY
Content-Type: application/json

{
  "incident_id": "INC-001",
  "message": "Incident reviewed and closed as false positive."
}

 

11. Get Alert Configs

Returns all alert configurations grouped by alert blocks.

GET/get_alert_configs1/min

Parameters

Parameter Type Required Description
api_key string Yes API key

Example Request

GET /get_alert_configs?api_key=YOUR_API_KEY

Example Response

[
  {
    "uid": "block-001",
    "name": "Network Alerts",
    "alerts": [
      {
        "uid": "alert-001",
        "name": "High Traffic Alert",
        "disabled": false,
        "block_uid": "block-001"
      }
    ]
  }
]

Error Responses

HTTP Code Description
403 Invalid API key or missing required parameter
400 Invalid request body (JSON parse error)
429 Rate limit exceeded

 

12. Get System Events

Returns system events (DataType:system) matching the given query with pagination support.

GET/get_system_events 30/min

Parameters

Parameter Type Required Description
api_key string Yes API key
time_frame string Yes Time frame for the query (format: <number> <unit>)
query string No Search query (if omitted, all system events are returned)
page int No Page number (default: 1)
size int No Results per page (default: 100, max: 1000)

time_frame units

Unit Meaning Upper bound
min Minutes 1440 (24 hours)
hour Hours 168 (7 days)
day Days 7

Example Request

GET /get_system_events?api_key=YOUR_API_KEY&time_frame=1 hour

Example Response

json
{
  "success": true,
  "events": [
    {
      "Time": { "Generated": "..." },
      "DataType": "system",
      "...": "..."
    }
  ],
  "total_count": 1342
}

Notes

  • Results are sorted by Time.Generated descending (newest first).
  • Use total_count to calculate total pages: ceil(total_count / size).
  • Unlike /get_events, the query parameter is optional; omitting it returns all system events.

 

 

 

13. Data Collection List

Returns the list of data sources defined in the system: type, host, vendor/product (if set), logging state, enabled/disabled status and tags.

GET/data_collection_list 10/min

Parameters

Parameter Type Required Description
api_key string Yes API key

Example Request

GET /data_collection_list?api_key=YOUR_API_KEY

Example Response

json
{
  "success": true,
  "data_collection": [
    {
      "type": "Windows",
      "description": "DC01 Windows Event Log",
      "host": "10.0.0.15",
      "vendor": "Microsoft",
      "product": "Windows",
      "logging_state": "Active",
      "status": "Enabled",
      "tags": "Domain Controller, Critical"
    },
    {
      "type": "Syslog",
      "description": "Legacy Firewall",
      "host": "10.0.0.20",
      "logging_state": "Passive",
      "status": "Enabled",
      "tags": "-"
    }
  ],
  "total_count": 2
}

Notes

  • The response does not include a raw last-log timestamp. Instead, logging_state reports whether the source is currently Active (received logs within its expected health-check period) or Passive.
  • status reflects the source's admin configuration (Enabled/Disabled), not its logging activity.
  • vendor and product are only present when both are set on the source configuration.
  • tags is a comma-separated list of tag descriptions attached to the source, or - if none.

 

Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.