Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Has the /siem/v1/events schema changed?

I found an article describing the events schema here https://community.sophos.com/kb/en-us/132726

The schema documented here appears to be different than the schema I get from the endpoint GET /siem/v1/events


{
 "appSha256": null,
"appCerts": null,
"when": "2019-08-07T14:31:27.000Z",
"core_remedy_items": null,
"id": "XXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX",
"created_at": "2019-08-07T14:38:59.894Z",
"source_info": {
"ip": "0.0.0.0"
},
"customer_id": "XXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX",
"severity": "low",
"threat": null,
"endpoint_id": "XXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXX",
"endpoint_type": "computer",
"user_id": "XXXXXXXXXXXXXXXXXXXX",
"origin": null,
"source": "John Smith",
"name": "'https://connect.facebook.net' blocked due to category 'Personals and Dating'",
"location": "XXXXXX",
"type": "Event::Endpoint::WebControlViolation",
 "group": "WEB"}

 

Some fields are present on both models but some are not. Is there another events endpoint that returns the schema listed in the KB article?

 

Thanks

Taylor



This thread was automatically locked due to age.