# Workspot SIEM (Splunk) Events API

**Canonical:** https://apis.io/apis/workspot/siem/  
**Provider:** Workspot — https://apis.io/providers/workspot/  
**Base URL:** https://api.workspot.com  
**Documentation:** https://docs.workspot.com/docs/workspot-splunksiem-api-user-guide

Workspot SIEM (Splunk) Events API is one of 2 APIs that [Workspot](https://apis.io/providers/workspot/) publishes on the [APIs.io](https://apis.io/) network. Tagged areas include SIEM, Security Events, Audit Logs, and Splunk. The published artifact set on APIs.io includes API documentation.

HMAC-SHA256 authenticated REST API for fetching Workspot Control event data — end-user and administrator actions — into Splunk or any other SIEM. Uses a submit/poll/fetch flow with checkpoint-based incremental delivery: POST an events request with the last checkpoint, poll the returned request token with HEAD until ready, then GET batches of up to 1000 events with the new checkpoint returned in the X-Ws-Checkpoint response header.

## Machine-readable artifacts (2)

- **Documentation** — https://docs.workspot.com/docs/workspot-splunksiem-api-user-guide
- **Events** — https://raw.githubusercontent.com/api-evangelist/workspot/refs/heads/main/asyncapi/workspot-siem-events.yml

## Other Workspot APIs (1)

- [Workspot Control REST API](https://apis.io/apis/workspot/control/)

## Tags

SIEM, Security Events, Audit Logs, Splunk

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/workspot/siem/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/workspot/.
