Sumo Logic Macro Management API

Macro Management APIs. Macros allow you to reference a predefined set of query language syntax across multiple queries. This enables reuse of commonly used logic, improves consistency, and reduces duplication. Macros can optionally accept arguments. When arguments are provided, the macro evaluates them dynamically and applies the resulting logic within the query. With the Macro Management APIs, you can create, update, retrieve, and delete macros to simplify and streamline your query writing process. For more information, see [Macros](https://www.sumologic.com/help/docs/manage/macro/).

Operations 5

GET /v2/macros List All Macros #
POST /v2/macros Create A New Macro #
GET /v2/macros/{id} Get A Macro #
PUT /v2/macros/{id} Edit A Macro #
DELETE /v2/macros/{id} Delete A Macro #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sumo-logic-macromanagement-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sumo-logic-macromanagement-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Sumo Logic Macro Management API
  description: '# Getting Started

    Welcome to the Sumo Logic API reference.'
  version: 1.0.0
  x-logo:
    url: ./sumologic_logo.png
servers:
- url: https://api.au.sumologic.com/api/
  description: AU deployment API server
- url: https://api.ca.sumologic.com/api/
  description: CA deployment API server
- url: https://api.de.sumologic.com/api/
  description: DE deployment API server
- url: https://api.eu.sumologic.com/api/
  description: EU deployment API server
- url: https://api.fed.sumologic.com/api/
  description: FED deployment API server
- url: https://api.jp.sumologic.com/api/
  description: JP deployment API server
- url: https://api.kr.sumologic.com/api/
  description: KR deployment API server
- url: https://api.in.sumologic.com/api/
  description: IN deployment API server
- url: https://api.sumologic.com/api/
  description: US1 deployment API server
- url: https://api.us2.sumologic.com/api/
  description: US2 deployment API server
security:
- basicAuth: []
tags:
- name: macroManagement
  description: Macro Management APIs.
  x-displayName: Macro Management APIs
paths:
  /v2/macros:
    get:
      tags:
      - macroManagement
      summary: List All Macros
      description: List all viewable macros for the customer.
      operationId: listMacros
      parameters:
      - name: limit
        in: query
        description: Limit the number of macro returned in the response. The number of macros returned may be less than the `limit`. Default 50.
        required: false
        schema:
          maximum: 100
          minimum: 1
          type: integer
          format: int32
          default: 50
        example: 50
      - name: token
        in: query
        description: Continuation token to get the next page of results. A page object with the next continuation token is returned in the response body. Subsequent GET requests should specify the continuation token to get the next page of results. `token` is set to null when no more pages are left.
        required: false
        schema:
          type: string
        example: GDCiRv4vebF3UWFJQ1kySXBOR3Bzh69GR0RyWm9vCtc
      responses:
        '200':
          description: Paginated list of viewable macros for the customer.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedMacros'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    post:
      tags:
      - macroManagement
      summary: Create A New Macro
      description: Creates a new macro.
      operationId: createMacro
      requestBody:
        description: Information to create the new macro.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MacroRequest'
        required: true
      responses:
        '200':
          description: The macro has been created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Macro'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v2/macros/{id}:
    get:
      tags:
      - macroManagement
      summary: Get A Macro
      description: Get a macro by the given identifier.
      operationId: getMacro
      parameters:
      - name: id
        in: path
        description: UUID of the macro.
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Macro object that was requested.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Macro'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    put:
      tags:
      - macroManagement
      summary: Edit A Macro
      description: Edits an existing macro by id. Macro name is immutable.
      operationId: editMacro
      parameters:
      - name: id
        in: path
        description: UUID of the macro to edit.
        required: true
        schema:
          type: string
      requestBody:
        description: Macro fields to update. Macro name is immutable.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/BaseMacroRequest'
        required: true
      responses:
        '200':
          description: The edited macro.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Macro'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    delete:
      tags:
      - macroManagement
      summary: Delete A Macro
      description: Delete a macro by id.
      operationId: deleteMacro
      parameters:
      - name: id
        in: path
        description: Id of macro to delete.
        required: true
        schema:
          type: string
      responses:
        '204':
          description: Macro was deleted successfully.
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    ErrorResponse:
      required:
      - errors
      - id
      type: object
      properties:
        id:
          type: string
          description: An identifier for the error; this is unique to the specific API request.
          example: IUUQI-DGH5I-TJ045
        errors:
          type: array
          description: A list of one or more causes of the error.
          example:
          - code: auth:password_too_short
            message: Your password was too short.
          - code: auth:password_character_classes
            message: Your password did not contain any non-alphanumeric characters
          items:
            $ref: '#/components/schemas/ErrorDescription'
    ErrorDescription:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: An error code describing the type of error.
          example: auth:password_too_short
        message:
          type: string
          description: A short English-language description of the error.
          example: Your password was too short.
        detail:
          type: string
          description: An optional fuller English-language description of the error.
          example: Your password was 5 characters long, the minimum length is 12 characters. See http://example.com/password for more information.
        meta:
          type: object
          description: An optional list of metadata about the error.
          example:
            minLength: 12
            actualLength: 5
    BaseMacroRequest:
      required:
      - definition
      type: object
      properties:
        description:
          maxLength: 4000
          type: string
          description: Description of the macro.
          example: Macro for geo lookup.
        definition:
          type: string
          description: The definition of the macro. Use a valid Sumo Log Search expression.
          example: 'lookup latitude, longitude from geo://location on ip = {{ip_field}} | count by latitude, longitude | sort _count"

            '
        enabled:
          type: boolean
          description: If the macro is enabled or not (default True)
          default: true
        arguments:
          type: array
          description: Arguments used in the macro.
          items:
            $ref: '#/components/schemas/Argument'
        argumentValidations:
          type: array
          description: Validation expressions for the arguments.
          items:
            $ref: '#/components/schemas/ArgumentValidation'
    Argument:
      required:
      - name
      type: object
      properties:
        name:
          type: string
          description: Argument name for the macro.
          example: ip_field
        type:
          pattern: ^(String|Any|Number|Keyword)$
          type: string
          description: The type of the macro.
          example: String
          default: String
          x-pattern-message: Must be `String`, `Any`, `Number or `Keyword`.
    MacroRequest:
      allOf:
      - $ref: '#/components/schemas/BaseMacroRequest'
      - required:
        - name
        type: object
        properties:
          name:
            maxLength: 128
            minLength: 1
            type: string
            description: Name of the macro.
            example: MacroGeoLookup
          macroCreationSuggestionId:
            type: string
            description: Identifier if the suggestion comes from an macro creation suggestion. This id is used to track macro creation suggestions, and to delete the suggestion once the macro is created.
            example: ABC12
    Macro:
      allOf:
      - $ref: '#/components/schemas/MacroRequest'
      - required:
        - createdAt
        - createdBy
        - id
        type: object
        properties:
          id:
            type: string
            description: 'Unique identifier for the macro. This id is used to get detailed information about the macro, such as name, definition, arguments and argument validations.

              '
            example: C03E086C137F38B4
          createdAt:
            type: string
            description: Creation timestamp of the macro in UTC in [RFC3339](https://tools.ietf.org/html/rfc3339) format.
            format: date-time
            example: 2024-10-01 09:10:00+00:00
          createdBy:
            type: string
            description: The identifier of the user who created the macro.
            example: 0000000006743FDD
    PaginatedMacros:
      required:
      - macros
      type: object
      properties:
        data:
          type: array
          description: List of macros.
          items:
            $ref: '#/components/schemas/Macro'
        next:
          type: string
          description: Next continuation token. `token` is set to null when no more pages are left.
          example: GDCiRv4vebF3UWFJQ1kySXBOR3Bzh69GR0RyWm9vCtc
    ArgumentValidation:
      required:
      - errorMessage
      - evalExpression
      type: object
      properties:
        evalExpression:
          type: string
          description: The expression to validate a macro argument.
          example: isValidIp(ip_field)
        errorMessage:
          type: string
          description: Error message to be shown if the macro argument validation fails.
          example: You need to enter a field name which is a valid ip.
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
x-tagGroups:
- name: Archive Management
  tags:
  - archiveManagement
- name: Health Events
  tags:
  - healthEvents
- name: Infrequent Data Tier
  tags:
  - logSearchesEstimatedUsage
- name: Ingest Budgets Management V2
  tags:
  - ingestBudgetManagementV2
- name: Library Management
  tags:
  - appManagement
  - appManagementV2
  - contentManagement
  - dashboardManagement
  - folderManagement
  - lookupManagement
  - contentPermissions
  - logSearchesManagement
  - parsersLibraryManagement
- name: Metrics
  tags:
  - metricsSearchesManagement
  - transformationRuleManagement
  - metricsQuery
  - metricsSearchesManagementV2
- name: Security Management
  tags:
  - accessKeyManagement
  - oauthManagement
  - accountManagement
  - passwordPolicy
  - policiesManagement
  - samlConfigurationManagement
  - serviceAllowlistManagement
  - serviceAccountManagement
  - scimUserManagement
- name: Organizations Management
  tags:
  - orgsManagement
- name: Settings Management
  tags:
  - connectionManagement
  - dynamicParsingRuleManagement
  - extractionRuleManagement
  - fieldManagementV1
  - partitionManagement
  - scheduledViewManagement
  - logsDataForwardingManagement
  - dataDeletionRules
- name: Tokens Management
  tags:
  - tokensLibraryManagement
- name: Tracing
  tags:
  - traces
  - spanAnalytics
  - serviceMap
- name: Users and Roles Management
  tags:
  - roleManagement
  - roleManagementV2
  - userManagement
- name: Threat Intel Ingest Management
  tags:
  - threatIntelIngest
  - threatIntelIngestProducer
- name: OpenTelemetry Collector Management
  tags:
  - otCollectorManagementExternal
- name: Source Template Management
  tags:
  - sourceTemplateManagementExternal
- name: Schema Base Management
  tags:
  - schemaBaseManagement
- name: Event Analytics Management
  tags:
  - eventAnalytics
- name: Budget Management
  tags:
  - budgetManagement
- name: Macro Management
  tags:
  - macroManagement
- name: Muting Schedules Management
  tags:
  - mutingSchedulesLibraryManagement
- name: SLO Management
  tags:
  - slosLibraryManagement
- name: Monitor Management
  tags:
  - monitorsLibraryManagement