Sumo Logic Lookup Management API

Lookup Table management API. A Lookup Table is a table of data hosted on Sumo Logic that you can use to enrich the log and event data received by Sumo Logic. You must create a table schema before you can populate the table. For more information, see [Lookup Tables](https://help.sumologic.com/?cid=10109).

Operations 9

POST /v1/lookupTables Create A Lookup Table #
GET /v1/lookupTables/{id} Get A Lookup Table #
PUT /v1/lookupTables/{id} Edit A Lookup Table #
DELETE /v1/lookupTables/{id} Delete A Lookup Table #
POST /v1/lookupTables/{id}/upload Upload A CSV File #
GET /v1/lookupTables/jobs/{jobId}/status Get The Status Of An Async Job #
POST /v1/lookupTables/{id}/truncate Empty A Lookup Table #
PUT /v1/lookupTables/{id}/row Insert Or Update A Lookup Table Row #
PUT /v1/lookupTables/{id}/deleteTableRow Delete A Lookup Table Row #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sumo-logic-lookupmanagement-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sumo-logic-lookupmanagement-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Sumo Logic Lookup Management API
  description: '# Getting Started

    Welcome to the Sumo Logic API reference.'
  version: 1.0.0
  x-logo:
    url: ./sumologic_logo.png
servers:
- url: https://api.au.sumologic.com/api/
  description: AU deployment API server
- url: https://api.ca.sumologic.com/api/
  description: CA deployment API server
- url: https://api.de.sumologic.com/api/
  description: DE deployment API server
- url: https://api.eu.sumologic.com/api/
  description: EU deployment API server
- url: https://api.fed.sumologic.com/api/
  description: FED deployment API server
- url: https://api.jp.sumologic.com/api/
  description: JP deployment API server
- url: https://api.kr.sumologic.com/api/
  description: KR deployment API server
- url: https://api.in.sumologic.com/api/
  description: IN deployment API server
- url: https://api.sumologic.com/api/
  description: US1 deployment API server
- url: https://api.us2.sumologic.com/api/
  description: US2 deployment API server
security:
- basicAuth: []
tags:
- name: lookupManagement
  description: 'Lookup Table management API.


    A Lookup Table is a table of data hosted on Sumo Logic that you can use to enrich the log and event data received by Sumo Logic. You must create a table schema before you can populate the table. For more information, see Lookup Tables.'
  x-displayName: Lookup Tables
paths:
  /v1/lookupTables:
    post:
      tags:
      - lookupManagement
      summary: Create A Lookup Table
      description: 'Create a new lookup table by providing a schema and specifying its configuration. Providing parentFolderId

        is mandatory. Use the getItemByPath endpoint to get content id of a path.

        Please check Content management API and Folder management API for all available options.'
      operationId: createTable
      parameters: []
      requestBody:
        description: The schema and configuration for the lookup table.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LookupTableDefinition'
        required: true
      responses:
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '200':
          description: Lookup table created successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LookupTable'
  /v1/lookupTables/{id}:
    get:
      tags:
      - lookupManagement
      summary: Get A Lookup Table
      description: Get a lookup table for the given identifier.
      operationId: lookupTableById
      parameters:
      - name: id
        in: path
        description: Identifier of the lookup table.
        required: true
        schema:
          type: string
          example: 0000000001C41EE4
      responses:
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '200':
          description: Definition of the lookup table.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LookupTable'
    put:
      tags:
      - lookupManagement
      summary: Edit A Lookup Table
      description: Edit the lookup table data. All the fields are mandatory in the request.
      operationId: updateTable
      parameters:
      - name: id
        in: path
        description: Identifier of the lookup table.
        required: true
        schema:
          type: string
          example: 0000000001C41EE4
      requestBody:
        description: The configuration changes for the lookup table.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LookupUpdateDefinition'
        required: true
      responses:
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '200':
          description: Configuration updated successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LookupTable'
    delete:
      tags:
      - lookupManagement
      summary: Delete A Lookup Table
      description: 'Delete a lookup table completely.

        **Warning:** `This operation cannot be undone`.'
      operationId: deleteTable
      parameters:
      - name: id
        in: path
        description: Identifier of the lookup table.
        required: true
        schema:
          type: string
          example: 0000000001C41EE4
      responses:
        '204':
          description: Deletion successful.
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/lookupTables/{id}/upload:
    post:
      tags:
      - lookupManagement
      summary: Upload A CSV File
      description: Create a request to populate a lookup table with a CSV file.
      operationId: uploadFile
      parameters:
      - name: id
        in: path
        description: Identifier of the lookup table to populate.
        required: true
        schema:
          type: string
          example: 0000000001C41EE4
      - name: merge
        in: query
        description: This indicates whether the file contents will be merged with existing data in the lookup table or not. If this is true then data with the same primary keys will be updated while the rest of the rows will be appended. By default, merge is false. The response includes a request identifier that you need to use in the [Request Status API](#operation/requestStatus) to track the status of the upload request.
        schema:
          type: boolean
          example: true
          default: false
      - name: fileEncoding
        in: query
        description: File encoding of file being uploaded.
        schema:
          type: string
          example: UTF-16
          default: UTF-8
      requestBody:
        content:
          multipart/form-data:
            schema:
              required:
              - file
              type: object
              properties:
                file:
                  type: string
                  description: "The CSV file to upload.\n  - The size limit for the CSV file is 100MB.\n  - Use Unix format, with newlines (\"\\n\") separating rows.\n  - The first row should contain headers that match the lookup table schema. Matching is\n    case-insensitive."
                  format: binary
        required: true
      responses:
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '200':
          description: The upload request was accepted. Use the provided token in a status request to track the status of the upload.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LookupRequestToken'
  /v1/lookupTables/jobs/{jobId}/status:
    get:
      tags:
      - lookupManagement
      summary: Get The Status Of An Async Job
      description: Retrieve the status of a previously made request. If the request was successful, the status of the response object will be `Success`.
      operationId: requestJobStatus
      parameters:
      - name: jobId
        in: path
        description: An identifier returned in response to an asynchronous request.
        required: true
        schema:
          type: string
          example: 0000000001C41AA3
      responses:
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '200':
          description: The status of async job with given identifier.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LookupAsyncJobStatus'
  /v1/lookupTables/{id}/truncate:
    post:
      tags:
      - lookupManagement
      summary: Empty A Lookup Table
      description: Delete all data from a lookup table.
      operationId: truncateTable
      parameters:
      - name: id
        in: path
        description: Identifier of the table to clear.
        required: true
        schema:
          type: string
          example: 0000000001C41EE4
      responses:
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '200':
          description: The delete data request was accepted. Use the provided token in a status request to track the status of the delete.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LookupRequestToken'
  /v1/lookupTables/{id}/row:
    put:
      tags:
      - lookupManagement
      summary: Insert Or Update A Lookup Table Row
      description: Insert or update a row of a lookup table with the given identifier. A new row is inserted if the primary key does not exist already, otherwise the existing row with the specified primary key is updated. All the fields of the lookup table are required and will be updated to the given values. In case a field is not specified then it will be assumed to be set to null. If the table size exceeds the maximum limit of 100MB then based on the size limit action of the table the update will be processed or discarded.
      operationId: updateTableRow
      parameters:
      - name: id
        in: path
        description: Identifier of the lookup table.
        required: true
        schema:
          type: string
          example: 0000000001C41EE4
      requestBody:
        description: Lookup table row update definition.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RowUpdateDefinition'
        required: true
      responses:
        '204':
          description: Row updated successfully.
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/lookupTables/{id}/deleteTableRow:
    put:
      tags:
      - lookupManagement
      summary: Delete A Lookup Table Row
      description: Delete a row from lookup table by providing the row's primary keys' values. The complete set of primary key fields of the lookup table should be provided.
      operationId: deleteTableRow
      parameters:
      - name: id
        in: path
        description: Identifier of the lookup table.
        required: true
        schema:
          type: string
          example: 0000000001C41EE4
      requestBody:
        description: Lookup table row delete definition.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RowDeleteDefinition'
        required: true
      responses:
        '204':
          description: Row deleted successfully.
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    MetadataModel:
      required:
      - createdAt
      - createdBy
      - modifiedAt
      - modifiedBy
      type: object
      properties:
        createdAt:
          type: string
          description: Creation timestamp in UTC in [RFC3339](https://tools.ietf.org/html/rfc3339) format.
          format: date-time
          example: 2018-10-16 09:10:00+00:00
        createdBy:
          type: string
          description: Identifier of the user who created the resource.
          example: 0000000006743FDD
        modifiedAt:
          type: string
          description: Last modification timestamp in UTC.
          format: date-time
          example: 2018-10-16 09:10:00+00:00
        modifiedBy:
          type: string
          description: Identifier of the user who last modified the resource.
          example: 0000000006743FE8
    LookupTableDefinition:
      required:
      - name
      - parentFolderId
      type: object
      description: Definition of the lookup table.
      allOf:
      - $ref: '#/components/schemas/ExportableLookupTableInfo'
      - properties:
          name:
            maxLength: 255
            type: string
            description: The name of the lookup table.
            example: SampleLookupTable
          parentFolderId:
            type: string
            description: The parent-folder-path identifier of the lookup table in the Library.
            example: 0000000001C41EE4
    ErrorResponse:
      required:
      - errors
      - id
      type: object
      properties:
        id:
          type: string
          description: An identifier for the error; this is unique to the specific API request.
          example: IUUQI-DGH5I-TJ045
        errors:
          type: array
          description: A list of one or more causes of the error.
          example:
          - code: auth:password_too_short
            message: Your password was too short.
          - code: auth:password_character_classes
            message: Your password did not contain any non-alphanumeric characters
          items:
            $ref: '#/components/schemas/ErrorDescription'
    RowDeleteDefinition:
      required:
      - primaryKey
      type: object
      properties:
        primaryKey:
          maxItems: 1000
          type: array
          description: A list of all the primary key field identifiers and their corresponding values which defines the row to delete.
          items:
            $ref: '#/components/schemas/TableRow'
      description: Lookup table primary key of the row to be deleted.
    ErrorDescription:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: An error code describing the type of error.
          example: auth:password_too_short
        message:
          type: string
          description: A short English-language description of the error.
          example: Your password was too short.
        detail:
          type: string
          description: An optional fuller English-language description of the error.
          example: Your password was 5 characters long, the minimum length is 12 characters. See http://example.com/password for more information.
        meta:
          type: object
          description: An optional list of metadata about the error.
          example:
            minLength: 12
            actualLength: 5
    RowUpdateDefinition:
      required:
      - row
      type: object
      properties:
        row:
          maxItems: 1000
          type: array
          description: A list of all the field identifiers and their corresponding values.
          items:
            $ref: '#/components/schemas/TableRow'
      description: Lookup table data to be uploaded.
    LookupTable:
      required:
      - id
      type: object
      description: Lookup table definition and metadata.
      allOf:
      - $ref: '#/components/schemas/MetadataModel'
      - $ref: '#/components/schemas/LookupTableDefinition'
      - properties:
          id:
            type: string
            description: Identifier of the lookup table as a content item.
            example: 0000000001C41EE4
          contentPath:
            type: string
            description: 'Address/path of the parent folder of this lookup table in content library. For example, a lookup table existing  in the personal/lookupTable folder for user johndoe would be: /Library/Users/johndoe@acme.com/lookupTable'
            example: /Library/Users/johndoe@acme.com/lookupTable
          size:
            type: integer
            description: The current size of the lookup table in bytes
            format: int64
            example: 100
    LookupTableField:
      required:
      - fieldName
      - fieldType
      type: object
      properties:
        fieldName:
          type: string
          description: The name of the field.
          example: FieldName1
        fieldType:
          pattern: ^(boolean|int|long|double|string)$
          type: string
          description: "The data type of the field. Supported types:\n  - `boolean`\n  - `int`\n  - `long`\n  - `double`\n  - `string`"
          example: boolean
          x-pattern-message: 'must be one of the following: `boolean`, `int`, `long`, `double`, `string`'
      description: The definition of the field.
    warningDescription:
      required:
      - message
      type: object
      properties:
        message:
          type: string
          description: Description of the warning.
          example: 60 rows were dropped.
        cause:
          type: string
          description: An optional cause of this warning.
          example: Primary key values were duplicate.
      description: Warning description
    LookupAsyncJobStatus:
      required:
      - createdAt
      - eventType
      - jobId
      - lookupContentId
      - lookupContentPath
      - lookupName
      - modifiedAt
      - status
      - userId
      type: object
      properties:
        jobId:
          type: string
          description: An identifier returned in response to an asynchronous request.
          example: 0000000001C41EF2
        status:
          type: string
          description: Whether or not the request is pending (`Pending`), in progress (`InProgress`), has completed successfully (`Success`), has completed partially with warnings (`PartialSuccess`) or has completed with an error (`Failed`).
        statusMessages:
          type: array
          description: Additional status messages generated if any if the status is `Success`.
          items:
            type: string
        errors:
          type: array
          description: More information about the failures, if the status is `Failed`.
          items:
            $ref: '#/components/schemas/ErrorDescription'
        warnings:
          type: array
          description: More information about the warnings, if the status is `PartialSuccess`.
          items:
            $ref: '#/components/schemas/warningDescription'
        lookupContentId:
          type: string
          description: Content id of lookup table on which this operation was performed.
          example: 0000000001C41EE4
        lookupName:
          type: string
          description: Name of lookup table on which this operation was performed.
          example: sampleLookup
        lookupContentPath:
          type: string
          description: Content path of lookup table on which this operation was performed.
          example: /Library/Users/xyz@demo.com/sampleLookup
        requestType:
          type: string
          description: "Type of asynchronous request made:\n  - `BulkMerge`\n  - `BulkReplace`\n  - `Truncate`"
          example: BulkMerge
        userId:
          type: string
          description: User id of user who initiated this operation.
          example: 0000000006743FDD
        createdAt:
          type: string
          description: Creation time of this job in UTC.
          format: date-time
          example: 2018-10-16 09:10:00+00:00
        modifiedAt:
          type: string
          description: Timestamp in UTC when status was last updated.
          format: date-time
          example: 2018-10-16 09:10:00+00:00
      description: Lookup table async job status.
    TableRow:
      required:
      - columnName
      - columnValue
      type: object
      properties:
        columnName:
          type: string
          description: Name of the column of the table.
          example: user_id
        columnValue:
          type: string
          description: Value of the specified column.
          example: user1
      description: Lookup table row column and column value.
    LookupUpdateDefinition:
      required:
      - description
      - ttl
      type: object
      properties:
        ttl:
          maximum: 525600
          minimum: 0
          type: integer
          description: A time to live for each entry in the lookup table (in minutes). 0 is a special value. A TTL of 0 implies entry will never be deleted from the table.
          format: int32
          example: 100
          default: 0
        description:
          maxLength: 1000
          type: string
          description: The description of the lookup table. The description cannot be blank.
          example: This is a sample lookup table description.
        sizeLimitAction:
          type: string
          description: The action that needs to be taken when the size limit is reached for the table. The possible values can be `StopIncomingMessages` or `DeleteOldData`. DeleteOldData will starting deleting old data once size limit is reached whereas StopIncomingMessages will discard all the updates made to the lookup table once size limit is reached.
          example: DeleteOldData
          default: StopIncomingMessages
      description: The updated lookup table parameters.
    ExportableLookupTableInfo:
      required:
      - description
      - fields
      - primaryKeys
      type: object
      properties:
        description:
          maxLength: 1000
          type: string
          description: The description of the lookup table.
          example: This is a sample lookup table description.
        fields:
          minItems: 1
          type: array
          description: The list of fields in the lookup table.
          items:
            $ref: '#/components/schemas/LookupTableField'
        primaryKeys:
          minItems: 1
          uniqueItems: true
          type: array
          description: The names of the fields that make up the primary key for the lookup table. These will be a subset of the fields that the table will contain.
          example:
          - FieldName1
          items:
            type: string
        ttl:
          maximum: 525600
          minimum: 0
          type: integer
          description: A time to live for each entry in the lookup table (in minutes). 365 days is the maximum time to live for each entry that you can specify. Setting it to 0 means that the records will not expire automatically.
          format: int32
          example: 100
          default: 0
        sizeLimitAction:
          pattern: ^(StopIncomingMessages|DeleteOldData)$
          type: string
          description: The action that needs to be taken when the size limit is reached for the table. The possible values can be `StopIncomingMessages` or `DeleteOldData`. DeleteOldData will start deleting old data once size limit is reached whereas StopIncomingMessages will discard all the updates made to the lookup table once size limit is reached.
          example: DeleteOldData
          default: StopIncomingMessages
          x-pattern-message: must be either `StopIncomingMessages` or `DeleteOldData`
      description: The lookup table definition independent of its location in the Library and name.
    LookupRequestToken:
      required:
      - id
      type: object
      properties:
        id:
          type: string
          description: The identifier used to track the request.
          example: 0000000001C41EF2
      description: Allows you to track the status of an upload or export request.
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
x-tagGroups:
- name: Archive Management
  tags:
  - archiveManagement
- name: Health Events
  tags:
  - healthEvents
- name: Infrequent Data Tier
  tags:
  - logSearchesEstimatedUsage
- name: Ingest Budgets Management V2
  tags:
  - ingestBudgetManagementV2
- name: Library Management
  tags:
  - appManagement
  - appManagementV2
  - contentManagement
  - dashboardManagement
  - folderManagement
  - lookupManagement
  - contentPermissions
  - logSearchesManagement
  - parsersLibraryManagement
- name: Metrics
  tags:
  - metricsSearchesManagement
  - transformationRuleManagement
  - metricsQuery
  - metricsSearchesManagementV2
- name: Security Management
  tags:
  - accessKeyManagement
  - oauthManagement
  - accountManagement
  - passwordPolicy
  - policiesManagement
  - samlConfigurationManagement
  - serviceAllowlistManagement
  - serviceAccountManagement
  - scimUserManagement
- name: Organizations Management
  tags:
  - orgsManagement
- name: Settings Management
  tags:
  - connectionManagement
  - dynamicParsingRuleManagement
  - extractionRuleManagement
  - fieldManagementV1
  - partitionManagement
  - scheduledViewManagement
  - logsDataForwardingManagement
  - dataDeletionRules
- name: Tokens Management
  tags:
  - tokensLibraryManagement
- name: Tracing
  tags:
  - traces
  - spanAnalytics
  - serviceMap
- name: Users and Roles Management
  tags:
  - roleManagement
  - roleManagementV2
  - userManagement
- name: Threat Intel Ingest Management
  tags:
  - threatIntelIngest
  - threatIntelIngestProducer
- name: OpenTelemetry Collector Management
  tags:
  - otCollectorManagementExternal
- name: Source Template Management
  tags:
  - sourceTemplateManagementExternal
- name: Schema Base Management
  tags:
  - schemaBaseManagement
- name: Event Analytics Management
  tags:
  - eventAnalytics
- name: Budget Management
  tags:
  - budgetManagement
- name: Macro Management
  tags:
  - macroManagement
- name: Muting Schedules Management
  tags:
  - mutingSchedulesLibraryManagement
- name: SLO Management
  tags:
  - slosLibraryManagement
- name: Monitor Management
  tags:
  - monitorsLibraryManagement