CloudGuard Intelligence API

CloudGuard Intelligence allows you to visualize and analyze Account Activity and Network Traffic into and out of your cloud environment.

Operations 9

POST /v2/view/magellan/disable-magellan-for-cloud-account Offboard Account #
PUT /v2/view/magellan/usage-notification-rate Set Usage Notification Rate #
PUT /v2/view/magellan/usage-notification-update-ancestors Set Usage Notification Ancestors Update #
POST /v2/view/magellan/magellan-flowlogs-onboarding Aws Network Traffic Onboarding #
POST /v2/view/magellan/magellan-cloudtrail-onboarding Aws Account Activity Onboarding #
POST /v2/view/magellan/magellan-custom-onboarding Aws Custom Onboarding #
POST /v2/view/magellan/magellan-alibaba-actiontrail-onboarding Alibaba Accoount Activity Onboarding #
POST /v2/view/magellan/provide-azure-storage-details Azure Network Traffic New Storage Onboarding #
POST /v2/view/magellan/magellan-gcp-onboarding Gcp Onboarding #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cloudguard-intelligence-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cloudguard-intelligence-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Intelligence API
  version: v2
  description: CloudGuard Intelligence allows you to visualize and analyze Account Activity and Network Traffic into and out of your cloud environment.
servers:
- url: https://api.dome9.com/
  description: US region
- url: https://api.{region}.dome9.com/
  description: Other regions
  variables:
    region:
      enum:
      - eu1
      - ap1
      - ap2
      - ap3
      - cace1
      default: eu1
security:
- basic: []
tags:
- name: Intelligence
  description: CloudGuard Intelligence allows you to visualize and analyze Account Activity and Network Traffic into and out of your cloud environment.
paths:
  /v2/view/magellan/disable-magellan-for-cloud-account:
    post:
      tags:
      - Intelligence
      summary: Offboard Account
      operationId: Intelligence_OffboardAccount_post_/v2/view/magellan/disable-magellan-for-cloud-account
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                enum:
                - Continue
                - SwitchingProtocols
                - OK
                - Created
                - Accepted
                - NonAuthoritativeInformation
                - NoContent
                - ResetContent
                - PartialContent
                - MultipleChoices
                - Ambiguous
                - MovedPermanently
                - Moved
                - Found
                - Redirect
                - SeeOther
                - RedirectMethod
                - NotModified
                - UseProxy
                - Unused
                - TemporaryRedirect
                - RedirectKeepVerb
                - BadRequest
                - Unauthorized
                - PaymentRequired
                - Forbidden
                - NotFound
                - MethodNotAllowed
                - NotAcceptable
                - ProxyAuthenticationRequired
                - RequestTimeout
                - Conflict
                - Gone
                - LengthRequired
                - PreconditionFailed
                - RequestEntityTooLarge
                - RequestUriTooLong
                - UnsupportedMediaType
                - RequestedRangeNotSatisfiable
                - ExpectationFailed
                - UpgradeRequired
                - InternalServerError
                - NotImplemented
                - BadGateway
                - ServiceUnavailable
                - GatewayTimeout
                - HttpVersionNotSupported
                type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanAccountOffboardingModel'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanAccountOffboardingModel'
        description: Block indicating cloud account id and vendor to be offboarded from Intelligence
        required: true
      description: Offboard cloud account from Intelligence. The cloud account must already be onboarded to Intelligence.
  /v2/view/magellan/usage-notification-rate:
    put:
      tags:
      - Intelligence
      summary: Set Usage Notification Rate
      operationId: Intelligence_SetUsageNotificationRate_put_/v2/view/magellan/usage-notification-rate
      parameters:
      - name: rate
        in: query
        description: Emails will be sent every {rate} % reached.
        required: true
        schema:
          type: integer
          format: int32
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                enum:
                - Continue
                - SwitchingProtocols
                - OK
                - Created
                - Accepted
                - NonAuthoritativeInformation
                - NoContent
                - ResetContent
                - PartialContent
                - MultipleChoices
                - Ambiguous
                - MovedPermanently
                - Moved
                - Found
                - Redirect
                - SeeOther
                - RedirectMethod
                - NotModified
                - UseProxy
                - Unused
                - TemporaryRedirect
                - RedirectKeepVerb
                - BadRequest
                - Unauthorized
                - PaymentRequired
                - Forbidden
                - NotFound
                - MethodNotAllowed
                - NotAcceptable
                - ProxyAuthenticationRequired
                - RequestTimeout
                - Conflict
                - Gone
                - LengthRequired
                - PreconditionFailed
                - RequestEntityTooLarge
                - RequestUriTooLong
                - UnsupportedMediaType
                - RequestedRangeNotSatisfiable
                - ExpectationFailed
                - UpgradeRequired
                - InternalServerError
                - NotImplemented
                - BadGateway
                - ServiceUnavailable
                - GatewayTimeout
                - HttpVersionNotSupported
                type: string
      description: 'Set usage notification emails rate.

        By default, the system will send an email notification when Intelligence usage reaches 80%, 90% and 100% of your allowed quota.

        Use this API call to configure sending an email notification every time you consumed the defined % of your quota.'
  /v2/view/magellan/usage-notification-update-ancestors:
    put:
      tags:
      - Intelligence
      summary: Set Usage Notification Ancestors Update
      operationId: Intelligence_SetUsageNotificationAncestorsUpdate_put_/v2/view/magellan/usage-notification-update-ancestors
      parameters:
      - name: shouldUpdate
        in: query
        description: Indicating if emails should be sent to ancestors.
        required: true
        schema:
          type: boolean
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                enum:
                - Continue
                - SwitchingProtocols
                - OK
                - Created
                - Accepted
                - NonAuthoritativeInformation
                - NoContent
                - ResetContent
                - PartialContent
                - MultipleChoices
                - Ambiguous
                - MovedPermanently
                - Moved
                - Found
                - Redirect
                - SeeOther
                - RedirectMethod
                - NotModified
                - UseProxy
                - Unused
                - TemporaryRedirect
                - RedirectKeepVerb
                - BadRequest
                - Unauthorized
                - PaymentRequired
                - Forbidden
                - NotFound
                - MethodNotAllowed
                - NotAcceptable
                - ProxyAuthenticationRequired
                - RequestTimeout
                - Conflict
                - Gone
                - LengthRequired
                - PreconditionFailed
                - RequestEntityTooLarge
                - RequestUriTooLong
                - UnsupportedMediaType
                - RequestedRangeNotSatisfiable
                - ExpectationFailed
                - UpgradeRequired
                - InternalServerError
                - NotImplemented
                - BadGateway
                - ServiceUnavailable
                - GatewayTimeout
                - HttpVersionNotSupported
                type: string
      description: Enable sending usage notification updates to parent accounts (all levels).
  /v2/view/magellan/magellan-flowlogs-onboarding:
    post:
      tags:
      - Intelligence
      summary: Aws Network Traffic Onboarding
      operationId: Intelligence_AwsNetworkTrafficOnboarding_post_/v2/view/magellan/magellan-flowlogs-onboarding
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Dome9.Web.Api.Views.Magellan.AwsLogicLogViewModel'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanOnboardingModel'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanOnboardingModel'
        description: Block indicating cloud account id and bucket name to be onboarded to Intelligence Network Traffic
        required: true
      description: 'Onboard an account for Network Traffic. The account must already be onboarded to CloudGuard

        Please follow the Intelligence onboarding "Prerequisites" screen and the "Prepare IAM Policy for CloudGuard Intelligence" screen on the CloudGuard portal.'
  /v2/view/magellan/magellan-cloudtrail-onboarding:
    post:
      tags:
      - Intelligence
      summary: Aws Account Activity Onboarding
      operationId: Intelligence_AwsAccountActivityOnboarding_post_/v2/view/magellan/magellan-cloudtrail-onboarding
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Dome9.Web.Api.Views.Magellan.AwsLogicLogViewModel'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanOnboardingModel'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanOnboardingModel'
        description: Block indicating cloud account id and bucket name to be onboarded to Intelligence Account Activity
        required: true
      description: 'Onboard an account for Account Activity. The account must already be onboarded to CloudGuard.

        Please follow the Intelligence onboarding "Prerequisites" screen and the "Prepare IAM Policy for CloudGuard Intelligence" screen on the CloudGuard portal.'
  /v2/view/magellan/magellan-custom-onboarding:
    post:
      tags:
      - Intelligence
      summary: Aws Custom Onboarding
      operationId: Intelligence_AwsCustomOnboarding_post_/v2/view/magellan/magellan-custom-onboarding
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                enum:
                - Continue
                - SwitchingProtocols
                - OK
                - Created
                - Accepted
                - NonAuthoritativeInformation
                - NoContent
                - ResetContent
                - PartialContent
                - MultipleChoices
                - Ambiguous
                - MovedPermanently
                - Moved
                - Found
                - Redirect
                - SeeOther
                - RedirectMethod
                - NotModified
                - UseProxy
                - Unused
                - TemporaryRedirect
                - RedirectKeepVerb
                - BadRequest
                - Unauthorized
                - PaymentRequired
                - Forbidden
                - NotFound
                - MethodNotAllowed
                - NotAcceptable
                - ProxyAuthenticationRequired
                - RequestTimeout
                - Conflict
                - Gone
                - LengthRequired
                - PreconditionFailed
                - RequestEntityTooLarge
                - RequestUriTooLong
                - UnsupportedMediaType
                - RequestedRangeNotSatisfiable
                - ExpectationFailed
                - UpgradeRequired
                - InternalServerError
                - NotImplemented
                - BadGateway
                - ServiceUnavailable
                - GatewayTimeout
                - HttpVersionNotSupported
                type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanCustomOnboardingModel'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanCustomOnboardingModel'
        description: Block indicating custom onboarding data to be onboarded to Intelligence
        required: true
      description: 'Custom onboard Account Activity or Network Traffic of your cloud environment to Intelligence.

        The cloud accounts must already be onboarded to CloudGuard.

        Please follow the Intelligence onboarding "Prerequisites" screen and the "Prepare IAM Policy for CloudGuard Intelligence" screen on the CloudGuard portal.'
  /v2/view/magellan/magellan-alibaba-actiontrail-onboarding:
    post:
      tags:
      - Intelligence
      summary: Alibaba Accoount Activity Onboarding
      operationId: Intelligence_AlibabaAccoountActivityOnboarding_post_/v2/view/magellan/magellan-alibaba-actiontrail-onboarding
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                enum:
                - Continue
                - SwitchingProtocols
                - OK
                - Created
                - Accepted
                - NonAuthoritativeInformation
                - NoContent
                - ResetContent
                - PartialContent
                - MultipleChoices
                - Ambiguous
                - MovedPermanently
                - Moved
                - Found
                - Redirect
                - SeeOther
                - RedirectMethod
                - NotModified
                - UseProxy
                - Unused
                - TemporaryRedirect
                - RedirectKeepVerb
                - BadRequest
                - Unauthorized
                - PaymentRequired
                - Forbidden
                - NotFound
                - MethodNotAllowed
                - NotAcceptable
                - ProxyAuthenticationRequired
                - RequestTimeout
                - Conflict
                - Gone
                - LengthRequired
                - PreconditionFailed
                - RequestEntityTooLarge
                - RequestUriTooLong
                - UnsupportedMediaType
                - RequestedRangeNotSatisfiable
                - ExpectationFailed
                - UpgradeRequired
                - InternalServerError
                - NotImplemented
                - BadGateway
                - ServiceUnavailable
                - GatewayTimeout
                - HttpVersionNotSupported
                type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanOnboardingAzurePricingStorage.MagellanAlibabaActionTrailOnboardingModel'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanOnboardingAzurePricingStorage.MagellanAlibabaActionTrailOnboardingModel'
        description: Block indicating data to be onboarded to Intelligence Event Activity
        required: true
      description: 'Onboard Alibaba account for Account Activity. The account must already be onboarded to CloudGuard.

        Please follow Intelligence onboarding "Prerequisites" screen on CloudGuard portal.'
  /v2/view/magellan/provide-azure-storage-details:
    post:
      tags:
      - Intelligence
      summary: Azure Network Traffic New Storage Onboarding
      operationId: Intelligence_AzureNetworkTrafficNewStorageOnboarding_post_/v2/view/magellan/provide-azure-storage-details
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                enum:
                - Continue
                - SwitchingProtocols
                - OK
                - Created
                - Accepted
                - NonAuthoritativeInformation
                - NoContent
                - ResetContent
                - PartialContent
                - MultipleChoices
                - Ambiguous
                - MovedPermanently
                - Moved
                - Found
                - Redirect
                - SeeOther
                - RedirectMethod
                - NotModified
                - UseProxy
                - Unused
                - TemporaryRedirect
                - RedirectKeepVerb
                - BadRequest
                - Unauthorized
                - PaymentRequired
                - Forbidden
                - NotFound
                - MethodNotAllowed
                - NotAcceptable
                - ProxyAuthenticationRequired
                - RequestTimeout
                - Conflict
                - Gone
                - LengthRequired
                - PreconditionFailed
                - RequestEntityTooLarge
                - RequestUriTooLong
                - UnsupportedMediaType
                - RequestedRangeNotSatisfiable
                - ExpectationFailed
                - UpgradeRequired
                - InternalServerError
                - NotImplemented
                - BadGateway
                - ServiceUnavailable
                - GatewayTimeout
                - HttpVersionNotSupported
                type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanOnboardingAzurePricingStorage.MagellanAzureNewStorageDetailsAfterArmModel'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanOnboardingAzurePricingStorage.MagellanAzureNewStorageDetailsAfterArmModel'
        description: Block indicating data of storage keys to be onboarded to Intelligence Network Traffic
        required: true
      description: After calling AzureNetworkTrafficOnboardingWithArm and creating the required resources in Azure using the ARM template, Intelligence needs access to the storage keys.
  /v2/view/magellan/magellan-gcp-onboarding:
    post:
      tags:
      - Intelligence
      summary: Gcp Onboarding
      operationId: Intelligence_GcpOnboarding_post_/v2/view/magellan/magellan-gcp-onboarding
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                enum:
                - Continue
                - SwitchingProtocols
                - OK
                - Created
                - Accepted
                - NonAuthoritativeInformation
                - NoContent
                - ResetContent
                - PartialContent
                - MultipleChoices
                - Ambiguous
                - MovedPermanently
                - Moved
                - Found
                - Redirect
                - SeeOther
                - RedirectMethod
                - NotModified
                - UseProxy
                - Unused
                - TemporaryRedirect
                - RedirectKeepVerb
                - BadRequest
                - Unauthorized
                - PaymentRequired
                - Forbidden
                - NotFound
                - MethodNotAllowed
                - NotAcceptable
                - ProxyAuthenticationRequired
                - RequestTimeout
                - Conflict
                - Gone
                - LengthRequired
                - PreconditionFailed
                - RequestEntityTooLarge
                - RequestUriTooLong
                - UnsupportedMediaType
                - RequestedRangeNotSatisfiable
                - ExpectationFailed
                - UpgradeRequired
                - InternalServerError
                - NotImplemented
                - BadGateway
                - ServiceUnavailable
                - GatewayTimeout
                - HttpVersionNotSupported
                type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanGcpOnboardingModel'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/Falconetix.Model.Magellan.MagellanGcpOnboardingModel'
        description: Block indicating data to be onboarded to Intelligence
        required: true
      description: 'Onboard Gcp project. The project must already be onboarded to CloudGuard.

        For network traffic please follow the Intelligence onboarding "Prerequisites" screen on the CloudGuard portal.

        This is the API for onboarding your gcp project in CloudGuard side. In addition, you need to create some

        resources in GCP as part of the onboarding. The following GIT contains a code that you can run on your computer.

        The code creates the needed resources and makes an API call to CloudGuard:

        https://github.com/dome9/gcp-onboarding/tree/main/onboarding-api'
components:
  schemas:
    Falconetix.Model.Magellan.MagellanGcpOnboardingModel:
      type: object
      properties:
        cloudAccounts:
          type: array
          items:
            type: string
        logType:
          enum:
          - NetworkTraffic
          - AccountActivity
          - Both
          type: string
    Falconetix.Model.Magellan.MagellanCustomOnboardingModel:
      type: object
      properties:
        bucketName:
          type: string
        bucketAccountId:
          type: string
        topicArn:
          type: string
        cloudAccountIds:
          type: array
          items:
            type: string
        onboardingType:
          enum:
          - flowlogs
          - CloudTrail
          - Both
          - GuardDuty
          type: string
        isUnifiedOnboarding:
          description: Boolean that check if the request was from UnifiedOnboarding method. not needed for API.
          type: boolean
        rulesetsIds:
          description: List of rule sets.  not needed for API.
          type: array
          items:
            format: int64
            type: integer
        isSubscribedAlready:
          description: Boolean that check if the account connect to centralized bucket on other account.
          type: boolean
        isAutoDiscoveryEnabled:
          description: Boolean that check if the bucket should support auto discovery of additional accounts
          type: boolean
    Falconetix.Model.Magellan.MagellanOnboardingAzurePricingStorage.MagellanAlibabaActionTrailOnboardingModel:
      type: object
      properties:
        cloudAccountNumbers:
          type: array
          items:
            type: string
    Falconetix.Model.Magellan.MagellanOnboardingAzurePricingStorage.MagellanAzureNewStorageDetailsAfterArmModel:
      type: object
      properties:
        storageDetails:
          type: array
          items:
            type: string
        subscriptionId:
          type: string
    Falconetix.Model.Magellan.MagellanOnboardingModel:
      type: object
      properties:
        cloudAccountId:
          description: AWS cloud account id
          type: string
        bucketName:
          description: The name of the bucket that Magellan (logic) will use for the onboarding [case sensitive]
          type: string
        isUnifiedOnboarding:
          type: boolean
        rulesetsIds:
          type: array
          items:
            format: int64
            type: integer
    Dome9.Web.Api.Views.Magellan.AwsLogicLogViewModel:
      type: object
      properties:
        cloudAccountId:
          description: AWS cloud account id
          type: string
        isOnboarded:
          description: indicates whether the account was successfully onboarded to Magellan (Log.ic)
          type: boolean
        bucketName:
          description: The name of the bucket that Magellan (logic) will use for the onboarding [case sensitive]
          type: string
    Falconetix.Model.Magellan.MagellanAccountOffboardingModel:
      type: object
      properties:
        cloudAccountId:
          type: string
        vendor:
          enum:
          - AWS
          - Azure
          - GCP
          - Kubernetes
          - Alibaba
          - OCI
          type: string
        logTypes:
          type: array
          items:
            enum:
            - flowlogs
            - CloudTrail
            - Both
            - GuardDuty
            type: string
  securitySchemes:
    basic:
      type: http
      scheme: basic
x-readme:
  explorer-enabled: true
  proxy-enabled: true