Sumo Logic Extraction Rule Management API

Field Extraction Rule management API. Field Extraction Rules allow you to parse fields from your log messages at the time the messages are ingested eliminating the need to parse fields in your query. For more information, see [Manage Field Extraction](https://help.sumologic.com/?cid=5313).

Operations 5

GET /v1/extractionRules Get A List Of Field Extraction Rules #
POST /v1/extractionRules Create A New Field Extraction Rule #
GET /v1/extractionRules/{id} Get A Field Extraction Rule #
PUT /v1/extractionRules/{id} Update A Field Extraction Rule #
DELETE /v1/extractionRules/{id} Delete A Field Extraction Rule #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sumo-logic-extractionrulemanagement-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sumo-logic-extractionrulemanagement-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Sumo Logic Extraction Rule Management API
  description: '# Getting Started

    Welcome to the Sumo Logic API reference.'
  version: 1.0.0
  x-logo:
    url: ./sumologic_logo.png
servers:
- url: https://api.au.sumologic.com/api/
  description: AU deployment API server
- url: https://api.ca.sumologic.com/api/
  description: CA deployment API server
- url: https://api.de.sumologic.com/api/
  description: DE deployment API server
- url: https://api.eu.sumologic.com/api/
  description: EU deployment API server
- url: https://api.fed.sumologic.com/api/
  description: FED deployment API server
- url: https://api.jp.sumologic.com/api/
  description: JP deployment API server
- url: https://api.kr.sumologic.com/api/
  description: KR deployment API server
- url: https://api.in.sumologic.com/api/
  description: IN deployment API server
- url: https://api.sumologic.com/api/
  description: US1 deployment API server
- url: https://api.us2.sumologic.com/api/
  description: US2 deployment API server
security:
- basicAuth: []
tags:
- name: extractionRuleManagement
  description: 'Field Extraction Rule management API.


    Field Extraction Rules allow you to parse fields from your log messages at the time the messages are ingested eliminating the need to parse fields in your query. For more information, see Manage Field Extraction.'
  x-displayName: Field Extraction Rules
paths:
  /v1/extractionRules:
    get:
      tags:
      - extractionRuleManagement
      summary: Get A List Of Field Extraction Rules
      description: Get a list of all field extraction rules. The response is paginated with a default limit of 100 field extraction rules per page.
      operationId: listExtractionRules
      parameters:
      - name: limit
        in: query
        description: Limit the number of field extraction rules returned in the response. The number of field extraction rules returned may be less than the `limit`.
        required: false
        schema:
          maximum: 1000
          minimum: 1
          type: integer
          format: int32
          default: 100
      - name: token
        in: query
        description: Continuation token to get the next page of results. A page object with the next continuation token is returned in the response body. Subsequent GET requests should specify the continuation token to get the next page of results.
        required: false
        schema:
          type: string
      responses:
        '200':
          description: A paginated list of field extraction rules.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListExtractionRulesResponse'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    post:
      tags:
      - extractionRuleManagement
      summary: Create A New Field Extraction Rule
      description: Create a new field extraction rule.
      operationId: createExtractionRule
      parameters: []
      requestBody:
        description: Information about the new field extraction rule.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ExtractionRuleDefinition'
        required: true
      responses:
        '200':
          description: The field extraction rule has been created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExtractionRule'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      x-tf-create: createExtractionRule
  /v1/extractionRules/{id}:
    get:
      tags:
      - extractionRuleManagement
      summary: Get A Field Extraction Rule
      description: Get a field extraction rule with the given identifier.
      operationId: getExtractionRule
      parameters:
      - name: id
        in: path
        description: Identifier of field extraction rule to return.
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Extraction rule object that was requested.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExtractionRule'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      x-tf-read: getExtractionRule
    put:
      tags:
      - extractionRuleManagement
      summary: Update A Field Extraction Rule
      description: Update an existing field extraction rule. All properties specified in the request are replaced. Missing properties are set to their default values.
      operationId: updateExtractionRule
      parameters:
      - name: id
        in: path
        description: Identifier of the field extraction rule to update.
        required: true
        schema:
          type: string
      requestBody:
        description: Information to update about the field extraction rule.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateExtractionRuleDefinition'
        required: true
      responses:
        '200':
          description: The field extraction rule was successfully modified.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExtractionRule'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      x-tf-update: updateExtractionRule
    delete:
      tags:
      - extractionRuleManagement
      summary: Delete A Field Extraction Rule
      description: Delete a field extraction rule with the given identifier.
      operationId: deleteExtractionRule
      parameters:
      - name: id
        in: path
        description: Identifier of the field extraction rule to delete.
        required: true
        schema:
          type: string
      responses:
        '204':
          description: Extraction rule was deleted successfully.
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      x-tf-delete: deleteExtractionRule
components:
  schemas:
    MetadataModel:
      required:
      - createdAt
      - createdBy
      - modifiedAt
      - modifiedBy
      type: object
      properties:
        createdAt:
          type: string
          description: Creation timestamp in UTC in [RFC3339](https://tools.ietf.org/html/rfc3339) format.
          format: date-time
          example: 2018-10-16 09:10:00+00:00
        createdBy:
          type: string
          description: Identifier of the user who created the resource.
          example: 0000000006743FDD
        modifiedAt:
          type: string
          description: Last modification timestamp in UTC.
          format: date-time
          example: 2018-10-16 09:10:00+00:00
        modifiedBy:
          type: string
          description: Identifier of the user who last modified the resource.
          example: 0000000006743FE8
    ErrorResponse:
      required:
      - errors
      - id
      type: object
      properties:
        id:
          type: string
          description: An identifier for the error; this is unique to the specific API request.
          example: IUUQI-DGH5I-TJ045
        errors:
          type: array
          description: A list of one or more causes of the error.
          example:
          - code: auth:password_too_short
            message: Your password was too short.
          - code: auth:password_character_classes
            message: Your password did not contain any non-alphanumeric characters
          items:
            $ref: '#/components/schemas/ErrorDescription'
    ExtractionRuleDefinition:
      allOf:
      - $ref: '#/components/schemas/BaseExtractionRuleDefinition'
      - type: object
        properties:
          enabled:
            type: boolean
            description: Is the field extraction rule enabled.
            default: true
    ErrorDescription:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: An error code describing the type of error.
          example: auth:password_too_short
        message:
          type: string
          description: A short English-language description of the error.
          example: Your password was too short.
        detail:
          type: string
          description: An optional fuller English-language description of the error.
          example: Your password was 5 characters long, the minimum length is 12 characters. See http://example.com/password for more information.
        meta:
          type: object
          description: An optional list of metadata about the error.
          example:
            minLength: 12
            actualLength: 5
    BaseExtractionRuleDefinition:
      required:
      - name
      - parseExpression
      - scope
      type: object
      properties:
        name:
          maxLength: 256
          minLength: 1
          type: string
          description: Name of the field extraction rule. Use a name that makes it easy to identify the rule.
          example: ExtractionRule123
        scope:
          maxLength: 2048
          minLength: 0
          type: string
          description: Scope of the field extraction rule. This could be a sourceCategory, sourceHost, or any other metadata that describes the data you want to extract from. Think of the Scope as the first portion of an ad hoc search, before the first pipe ( | ). You'll use the Scope to run a search against the rule.
          example: _sourceHost=127.0.0.1
        parseExpression:
          maxLength: 16384
          type: string
          description: Describes the fields to be parsed.
          example: csv _raw extract 1 as f1
    UpdateExtractionRuleDefinition:
      allOf:
      - $ref: '#/components/schemas/BaseExtractionRuleDefinition'
      - required:
        - enabled
        type: object
        properties:
          enabled:
            type: boolean
            description: Is the field extraction rule enabled.
    ExtractionRule:
      type: object
      allOf:
      - $ref: '#/components/schemas/ExtractionRuleDefinition'
      - $ref: '#/components/schemas/MetadataModel'
      - required:
        - id
        properties:
          id:
            type: string
            description: Unique identifier for the field extraction rule.
          fieldNames:
            type: array
            description: List of extracted fields from "parseExpression".
            items:
              type: string
      x-tf-generated-properties: id,name,scope,parseExpression,enabled
      x-tf-resource-name: ExtractionRule
    ListExtractionRulesResponse:
      required:
      - data
      type: object
      properties:
        data:
          type: array
          description: List of field extraction rules.
          items:
            $ref: '#/components/schemas/ExtractionRule'
        next:
          type: string
          description: Next continuation token.
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
x-tagGroups:
- name: Archive Management
  tags:
  - archiveManagement
- name: Health Events
  tags:
  - healthEvents
- name: Infrequent Data Tier
  tags:
  - logSearchesEstimatedUsage
- name: Ingest Budgets Management V2
  tags:
  - ingestBudgetManagementV2
- name: Library Management
  tags:
  - appManagement
  - appManagementV2
  - contentManagement
  - dashboardManagement
  - folderManagement
  - lookupManagement
  - contentPermissions
  - logSearchesManagement
  - parsersLibraryManagement
- name: Metrics
  tags:
  - metricsSearchesManagement
  - transformationRuleManagement
  - metricsQuery
  - metricsSearchesManagementV2
- name: Security Management
  tags:
  - accessKeyManagement
  - oauthManagement
  - accountManagement
  - passwordPolicy
  - policiesManagement
  - samlConfigurationManagement
  - serviceAllowlistManagement
  - serviceAccountManagement
  - scimUserManagement
- name: Organizations Management
  tags:
  - orgsManagement
- name: Settings Management
  tags:
  - connectionManagement
  - dynamicParsingRuleManagement
  - extractionRuleManagement
  - fieldManagementV1
  - partitionManagement
  - scheduledViewManagement
  - logsDataForwardingManagement
  - dataDeletionRules
- name: Tokens Management
  tags:
  - tokensLibraryManagement
- name: Tracing
  tags:
  - traces
  - spanAnalytics
  - serviceMap
- name: Users and Roles Management
  tags:
  - roleManagement
  - roleManagementV2
  - userManagement
- name: Threat Intel Ingest Management
  tags:
  - threatIntelIngest
  - threatIntelIngestProducer
- name: OpenTelemetry Collector Management
  tags:
  - otCollectorManagementExternal
- name: Source Template Management
  tags:
  - sourceTemplateManagementExternal
- name: Schema Base Management
  tags:
  - schemaBaseManagement
- name: Event Analytics Management
  tags:
  - eventAnalytics
- name: Budget Management
  tags:
  - budgetManagement
- name: Macro Management
  tags:
  - macroManagement
- name: Muting Schedules Management
  tags:
  - mutingSchedulesLibraryManagement
- name: SLO Management
  tags:
  - slosLibraryManagement
- name: Monitor Management
  tags:
  - monitorsLibraryManagement