# Logz.io Security events API

**Canonical:** https://apis.io/apis/logz-io/logz-io-security-events-api/  
**Provider:** Logz.io — https://apis.io/providers/logz-io/  
**Base URL:** https://api.logz.io/v1/search  
**Documentation:** https://api-docs.logz.io/docs/logz/search/

Logz.io Security events API is one of 57 APIs that [Logz.io](https://apis.io/providers/logz-io/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. This API exposes 4 JSON Schema definitions. Tagged areas include Security Events. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, a JSON-LD context, and 4 JSON Schemas.

A security event is logged whenever a security rule triggers in your [Logz.io Cloud SIEM account](https://app.logz.io/#/dashboard/security/rules/rule-definitions?from=0&sortBy=updatedAt&sortOrder=DESC). Your Logz.io Cloud SIEM is pre-loaded with hundreds of security rules created and maintained by Logz.io's security analysts. The list continues to be expanded and updated on a regular basis. You can also add your own security rules. To investigate into security events, you can begin by running a bulk query to fetch security event logs, either with or without applying filtering criteria. This query returns all of the events that match the query parameters and can potentially fetch events going back many months. Whenever you encounter a particular event you would like to further investigate, you can run the drilldown query to fetch the logs that triggered the security event to delve deeper into the event details. These queries can be used to integrate with an automated response solution such as Cortex xSOAR or simply to understand your security posture and identify suspicious activity in your accounts.

## Operations (3)

| Method | Path | Summary |
|---|---|---|
| POST | `/v2/security/rules/events/search` | Fetch security events |
| PUT | `/v2/security/rules/events/{ruleId}` | Edit security events |
| POST | `/v2/security/rules/events/logs/search` | Fetch the logs that triggered a security event |

## Machine-readable artifacts (26)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/logz-io/refs/heads/main/openapi/logz-io-security-events-api-openapi.yml
- **Documentation** — https://api-docs.logz.io/docs/logz/search/
- **Documentation** — https://docs.logz.io/api/
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/logz-io/refs/heads/main/json-schema/logz-io-search-request-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/logz-io/refs/heads/main/json-schema/logz-io-log-document-schema.json
- **JSONLD** — https://raw.githubusercontent.com/api-evangelist/logz-io/refs/heads/main/json-ld/logz-io-context.jsonld
- **Documentation** — https://api-docs.logz.io/docs/logz/archive-logs/
- **Documentation** — https://api-docs.logz.io/docs/logz/drop-filters/
- **Documentation** — https://api-docs.logz.io/docs/logz/get-all-alerts/
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/logz-io/refs/heads/main/json-schema/logz-io-alert-rule-schema.json
- **Documentation** — https://api-docs.logz.io/docs/logz/endpoints/
- **Documentation** — https://api-docs.logz.io/docs/logz/manage-users/
- **Documentation** — https://api-docs.logz.io/docs/logz/manage-api-tokens/
- **Documentation** — https://api-docs.logz.io/docs/logz/manage-time-based-log-accounts/
- **Documentation** — https://api-docs.logz.io/docs/logz/metrics-gateway/
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/logz-io/refs/heads/main/json-schema/logz-io-metric-sample-schema.json
- **Documentation** — https://api-docs.logz.io/docs/logz/grafana-alerting/
- **Documentation** — https://api-docs.logz.io/docs/logz/perses/
- **Documentation** — https://api-docs.logz.io/docs/logz/security-rules/
- **Documentation** — https://api-docs.logz.io/docs/logz/connect-to-cloud-trail/
- **Documentation** — https://api-docs.logz.io/docs/logz/parsing/
- **Documentation** — https://api-docs.logz.io/docs/logz/lookups/
- **Documentation** — https://api-docs.logz.io/docs/logz/insights/
- **Documentation** — https://api-docs.logz.io/docs/logz/deployments/
- **Documentation** — https://api-docs.logz.io/docs/logz/snapshots/
- **Documentation** — https://api-docs.logz.io/docs/logz/retrieve-audit-trail/

## Other Logz.io APIs (12)

- [Logz.io Alerts API](https://apis.io/apis/logz-io/logz-io-alerts-api/)
- [Logz.io Archive logs API](https://apis.io/apis/logz-io/logz-io-archive-logs-api/)
- [Logz.io Associated accounts API](https://apis.io/apis/logz-io/logz-io-associated-accounts-api/)
- [Logz.io Authentication groups API](https://apis.io/apis/logz-io/logz-io-authentication-groups-api/)
- [Logz.io Connect to CloudTrail API](https://apis.io/apis/logz-io/logz-io-connect-to-cloudtrail-api/)
- [Logz.io Connect to S3 Buckets API](https://apis.io/apis/logz-io/logz-io-connect-to-s3-buckets-api/)
- [Logz.io Dashboards create new API](https://apis.io/apis/logz-io/logz-io-dashboards-create-new-api/)
- [Logz.io Dashboards create new folder API](https://apis.io/apis/logz-io/logz-io-dashboards-create-new-folder-api/)
- [Logz.io Dashboards delete API](https://apis.io/apis/logz-io/logz-io-dashboards-delete-api/)
- [Logz.io Dashboards delete folder API](https://apis.io/apis/logz-io/logz-io-dashboards-delete-folder-api/)
- [Logz.io Dashboards get all API](https://apis.io/apis/logz-io/logz-io-dashboards-get-all-api/)
- [Logz.io Dashboards get all folders API](https://apis.io/apis/logz-io/logz-io-dashboards-get-all-folders-api/)

## Tags

Security Events

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/logz-io/logz-io-security-events-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/logz-io/.
