Sumo Logic Threat Intel Ingest API

Threat Intel Datastore Management API The Threat Intel Datastore Management API allows you to: * Get information about the threat indicator datastore and sources. * Delete the threat indicator database. * View and set the retention period for threat intel indicators. For more information, see [Threat Intel Ingest Management](https://help.sumologic.com/Manage/Threat-Intel-Ingest)

Business capability
Threat Detection & Response Management BC-620.30

Operations 5

GET /v1/threatIntel/datastore/db Get Threat Intel Indicators DB Information #
DELETE /v1/threatIntel/datastore/db Remove The Threat Intel Indicators DB #
GET /v1/threatIntel/datastore/retentionPeriod Get Threat Intel Indicators Store Retention Period In Terms Of Days #
POST /v1/threatIntel/datastore/retentionPeriod Set The Threat Intel Indicators Store Retention Period In Terms Of Days #
PUT /v1/threatIntel/datastore/dataSource/{dataSourceName} Updates Source Properties #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sumo-logic-threatintelingest-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sumo-logic-threatintelingest-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Sumo Logic Threat Intel Ingest API
  description: '# Getting Started

    Welcome to the Sumo Logic API reference.'
  version: 1.0.0
  x-logo:
    url: ./sumologic_logo.png
servers:
- url: https://api.au.sumologic.com/api/
  description: AU deployment API server
- url: https://api.ca.sumologic.com/api/
  description: CA deployment API server
- url: https://api.de.sumologic.com/api/
  description: DE deployment API server
- url: https://api.eu.sumologic.com/api/
  description: EU deployment API server
- url: https://api.fed.sumologic.com/api/
  description: FED deployment API server
- url: https://api.jp.sumologic.com/api/
  description: JP deployment API server
- url: https://api.kr.sumologic.com/api/
  description: KR deployment API server
- url: https://api.in.sumologic.com/api/
  description: IN deployment API server
- url: https://api.sumologic.com/api/
  description: US1 deployment API server
- url: https://api.us2.sumologic.com/api/
  description: US2 deployment API server
security:
- basicAuth: []
tags:
- name: threatIntelIngest
  description: 'Threat Intel Datastore Management API


    The Threat Intel Datastore Management API allows you to:

    * Get information about the threat indicator datastore and sources.

    * Delete the threat indicator database.

    * View and set the retention period for threat intel indicators.


    For more information, see Threat Intel Ingest Management'
  x-displayName: Threat Intel Datastore Management
paths:
  /v1/threatIntel/datastore/db:
    get:
      tags:
      - threatIntelIngest
      summary: Get Threat Intel Indicators DB Information
      description: Get threat intel indicators DB information, such as storage utilization and indicator counts
      operationId: datastoreGet
      responses:
        '200':
          description: Threat intel ingest DB information.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DatastoreStatusResponse'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    delete:
      tags:
      - threatIntelIngest
      summary: Remove The Threat Intel Indicators DB
      description: Removes the entire database and all indicators associated with this tenant
      operationId: removeDatastore
      responses:
        '204':
          description: Removing the indicator database succeeded
        default:
          description: Operation failed with an error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/threatIntel/datastore/retentionPeriod:
    get:
      tags:
      - threatIntelIngest
      summary: Get Threat Intel Indicators Store Retention Period In Terms Of Days
      description: Get the threat intel indicators store retention period in terms of days.
      operationId: retentionPeriod
      responses:
        '200':
          description: Threat intel indicators store retention period.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DatastoreRetentionPeriod'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
    post:
      tags:
      - threatIntelIngest
      summary: Set The Threat Intel Indicators Store Retention Period In Terms Of Days
      description: Sets the threat intel indicators store retention period in terms of days.
      operationId: setRetentionPeriod
      parameters: []
      requestBody:
        description: The threat intel indicators store retention period in terms of days.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DatastoreRetentionPeriod'
        required: true
      responses:
        '200':
          description: Threat intel indicators store retention period.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DatastoreRetentionPeriod'
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
  /v1/threatIntel/datastore/dataSource/{dataSourceName}:
    put:
      tags:
      - threatIntelIngest
      summary: Updates Source Properties
      description: Updates source properties
      operationId: dataSourcePropertiesUpdate
      parameters:
      - name: dataSourceName
        in: path
        description: Source name
        required: true
        schema:
          type: string
      requestBody:
        description: Source properties
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DataSourceProperties'
        required: true
      responses:
        '204':
          description: Data source properties successfuly updated.
        default:
          description: Operation failed with an error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    ErrorResponse:
      required:
      - errors
      - id
      type: object
      properties:
        id:
          type: string
          description: An identifier for the error; this is unique to the specific API request.
          example: IUUQI-DGH5I-TJ045
        errors:
          type: array
          description: A list of one or more causes of the error.
          example:
          - code: auth:password_too_short
            message: Your password was too short.
          - code: auth:password_character_classes
            message: Your password did not contain any non-alphanumeric characters
          items:
            $ref: '#/components/schemas/ErrorDescription'
    DatastoreStatusResponse:
      required:
      - diskSize
      - indicatorCount
      - indicatorLimit
      - sourceStatus
      type: object
      properties:
        diskSize:
          type: integer
          description: Total DB size in terms of disk bytes
          format: int64
          example: 1024
        indicatorCount:
          type: integer
          description: Total number of indicators in the DB
          format: int64
          example: 100
        indicatorLimit:
          type: integer
          description: Limit number of indicators supported in the DB
          format: int64
          example: 10000000
        sourceStatus:
          type: array
          description: A list of sources and their individual DB sizes and indicator counts
          items:
            $ref: '#/components/schemas/DatastoreSourceStatusResponse'
    ErrorDescription:
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: An error code describing the type of error.
          example: auth:password_too_short
        message:
          type: string
          description: A short English-language description of the error.
          example: Your password was too short.
        detail:
          type: string
          description: An optional fuller English-language description of the error.
          example: Your password was 5 characters long, the minimum length is 12 characters. See http://example.com/password for more information.
        meta:
          type: object
          description: An optional list of metadata about the error.
          example:
            minLength: 12
            actualLength: 5
    DatastoreRetentionPeriod:
      required:
      - retentionPeriod
      type: object
      properties:
        retentionPeriod:
          type: integer
          description: Retention period in days.
          format: int64
          example: 120
    DataSourceProperties:
      type: object
      properties:
        enabled:
          type: boolean
          description: True if enabled.
          example: true
        description:
          type: string
          description: The data source description.
          example: This is a stix1.2 data source.
    DatastoreSourceStatusResponse:
      required:
      - source
      type: object
      properties:
        source:
          type: string
          description: The source name
          example: unit42_source
        description:
          type: string
          description: The source description
          example: This is a stix1.2 indicators source
        diskSize:
          type: integer
          description: Disk utilization in bytes estimate for the indicator source
          format: int64
          example: 1024
        indicatorCount:
          type: integer
          description: Number of indicators for the indicator source
          format: int64
          example: 1024
        sumoProvided:
          type: boolean
          description: True if sumo provided source
          example: false
        supportsCat:
          type: boolean
          description: True if can be used in cat operator
          example: false
        enabled:
          type: boolean
          description: True if enabled
          example: true
      description: DB sizes and indicator counts for an individual source
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
x-tagGroups:
- name: Archive Management
  tags:
  - archiveManagement
- name: Health Events
  tags:
  - healthEvents
- name: Infrequent Data Tier
  tags:
  - logSearchesEstimatedUsage
- name: Ingest Budgets Management V2
  tags:
  - ingestBudgetManagementV2
- name: Library Management
  tags:
  - appManagement
  - appManagementV2
  - contentManagement
  - dashboardManagement
  - folderManagement
  - lookupManagement
  - contentPermissions
  - logSearchesManagement
  - parsersLibraryManagement
- name: Metrics
  tags:
  - metricsSearchesManagement
  - transformationRuleManagement
  - metricsQuery
  - metricsSearchesManagementV2
- name: Security Management
  tags:
  - accessKeyManagement
  - oauthManagement
  - accountManagement
  - passwordPolicy
  - policiesManagement
  - samlConfigurationManagement
  - serviceAllowlistManagement
  - serviceAccountManagement
  - scimUserManagement
- name: Organizations Management
  tags:
  - orgsManagement
- name: Settings Management
  tags:
  - connectionManagement
  - dynamicParsingRuleManagement
  - extractionRuleManagement
  - fieldManagementV1
  - partitionManagement
  - scheduledViewManagement
  - logsDataForwardingManagement
  - dataDeletionRules
- name: Tokens Management
  tags:
  - tokensLibraryManagement
- name: Tracing
  tags:
  - traces
  - spanAnalytics
  - serviceMap
- name: Users and Roles Management
  tags:
  - roleManagement
  - roleManagementV2
  - userManagement
- name: Threat Intel Ingest Management
  tags:
  - threatIntelIngest
  - threatIntelIngestProducer
- name: OpenTelemetry Collector Management
  tags:
  - otCollectorManagementExternal
- name: Source Template Management
  tags:
  - sourceTemplateManagementExternal
- name: Schema Base Management
  tags:
  - schemaBaseManagement
- name: Event Analytics Management
  tags:
  - eventAnalytics
- name: Budget Management
  tags:
  - budgetManagement
- name: Macro Management
  tags:
  - macroManagement
- name: Muting Schedules Management
  tags:
  - mutingSchedulesLibraryManagement
- name: SLO Management
  tags:
  - slosLibraryManagement
- name: Monitor Management
  tags:
  - monitorsLibraryManagement