Cribl Edge Sources API

Manage data input sources on edge nodes including file monitors, Windows Event Log, system metrics, AppScope, and other local collection methods.

Documentation

Specifications

Other Resources

OpenAPI Specification

cribl-edge-sources-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Cribl As Code API Credentials Edge Sources API
  description: The Cribl As Code API enables developers to manage Cribl configurations programmatically using infrastructure-as-code principles. The management plane API provides endpoints for administrative tasks in Cribl Cloud including managing organizations, workspaces, and API credentials. Developers can use this API alongside SDKs for Python, Go, and TypeScript, or through Terraform providers, to onboard sources, build and maintain pipelines, and standardize workflows at scale. The management plane supports creating and configuring Cribl Cloud workspaces, managing API credentials, and controlling access to organizational resources.
  version: '1.0'
  contact:
    name: Cribl Support
    url: https://cribl.io/support/
  termsOfService: https://cribl.io/terms-of-service/
servers:
- url: https://gateway.cribl.cloud
  description: Cribl Cloud Management Plane
security:
- bearerAuth: []
tags:
- name: Edge Sources
  description: Manage data input sources on edge nodes including file monitors, Windows Event Log, system metrics, AppScope, and other local collection methods.
paths:
  /m/{fleetId}/system/sources:
    get:
      operationId: listEdgeSources
      summary: List edge sources in a fleet
      description: Retrieves all data input sources configured for an edge fleet including file monitors, Windows Event Log, system metrics, AppScope, and other local collection sources.
      tags:
      - Edge Sources
      parameters:
      - $ref: '#/components/parameters/fleetId'
      responses:
        '200':
          description: Successfully retrieved edge sources
          content:
            application/json:
              schema:
                type: object
                properties:
                  items:
                    type: array
                    items:
                      $ref: '#/components/schemas/EdgeSource'
                  count:
                    type: integer
                    description: Total number of sources
        '401':
          description: Unauthorized
        '404':
          description: Fleet not found
    post:
      operationId: createEdgeSource
      summary: Create an edge source in a fleet
      description: Creates a new data input source for an edge fleet to collect data from endpoints.
      tags:
      - Edge Sources
      parameters:
      - $ref: '#/components/parameters/fleetId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EdgeSource'
      responses:
        '200':
          description: Edge source created successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EdgeSource'
        '400':
          description: Invalid source configuration
        '401':
          description: Unauthorized
components:
  schemas:
    EdgeSource:
      type: object
      properties:
        id:
          type: string
          description: Unique identifier for the edge source
        type:
          type: string
          description: The source type such as file_monitor, windows_event_log, system_metrics, appscope, syslog, or journald
        disabled:
          type: boolean
          description: Whether the source is disabled
        description:
          type: string
          description: A human-readable description
        pipeline:
          type: string
          description: The pipeline to process events
        streamtags:
          type: array
          items:
            type: string
          description: Tags applied to events from this source
  parameters:
    fleetId:
      name: fleetId
      in: path
      required: true
      description: The edge fleet identifier
      schema:
        type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Bearer token obtained via OAuth 2.0 client credentials grant from https://login.cribl.cloud/oauth/token. Tokens expire after 24 hours (86400 seconds).
    oauth2:
      type: oauth2
      description: OAuth 2.0 client credentials flow for Cribl Cloud management plane authentication.
      flows:
        clientCredentials:
          tokenUrl: https://login.cribl.cloud/oauth/token
          scopes: {}
externalDocs:
  description: Cribl As Code Documentation
  url: https://docs.cribl.io/cribl-as-code/api/