openapi: 3.2.0 info: description: Welcome to Cloudflare's API documentation site. license: name: BSD-3-Clause url: https://opensource.org/licenses/BSD-3-Clause title: Cloudflare Event API version: 4.0.0 servers: - description: Client API url: https://api.cloudflare.com/client/v4 security: - api_email: [] api_key: [] - api_token: [] - user_service_key: [] tags: - name: Event paths: /accounts/{account_id}/cloudforce-one/events: get: operationId: get_EventListGet summary: Filter and list events description: Use `datasetId=all` or `datasetId=*` for the legacy all-datasets scope, `datasetId=analytics` for datasets with `isAnalytics=true`, or `datasetId=operational` for datasets with `isAnalytics=false` (limited to 50). Scope values must be used alone. When `datasetId` is unspecified, events are listed from the default Cloudforce One Threat Events dataset. To list existing datasets, use the `List Datasets` endpoint. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: cursor in: query schema: description: Cursor for pagination. When provided, filters are embedded in the cursor so you only need to pass cursor and pageSize. Returned in the previous response's result_info.cursor field. Use cursor-based pagination for deep pagination (beyond 100,000 records) or for optimal performance. type: string example: eyJ2ZXJzaW9uIjoxLCJwb3NpdGlvbiI6eyJkYXRlIjoiMjAyNC0wMS0xMlQxMDowMDowMFoiLCJ1dWlkIjoiYWJjMTIzIn19 - name: search in: query schema: type: array items: anyOf: - additionalProperties: false properties: field: type: string enum: - attacker - attackerCountry - category - createdAt - date - event - indicator - indicatorType - mitreAttack - mitreCapec - tags - targetCountry - targetIndustry - tlp - uuid op: type: string enum: - equals - not - gt - gte - lt - lte - like - contains - startsWith - endsWith - find value: type: string maxLength: 512 minLength: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - attacker - attackerCountry - category - createdAt - date - event - indicator - indicatorType - mitreAttack - mitreCapec - tags - targetCountry - targetIndustry - tlp - uuid op: type: string enum: - in value: type: array items: maxLength: 512 minLength: 1 type: string maxItems: 100 minItems: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - killChain op: type: string enum: - equals - not - gt - gte - lt - lte value: anyOf: - type: number - pattern: ^-?(?:\d+\.?\d*|\.\d+)$ type: string required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - killChain op: type: string enum: - in value: type: array items: anyOf: - type: number - pattern: ^-?(?:\d+\.?\d*|\.\d+)$ type: string maxItems: 100 minItems: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - hasChildren op: type: string enum: - equals - not - gt - gte - lt - lte value: anyOf: - type: boolean - enum: - 'true' type: string - enum: - 'false' type: string - enum: - 1 type: number - enum: - 0 type: number - enum: - '1' type: string - enum: - '0' type: string required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - hasChildren op: type: string enum: - in value: type: array items: anyOf: - type: boolean - enum: - 'true' type: string - enum: - 'false' type: string - enum: - 1 type: number - enum: - 0 type: number - enum: - '1' type: string - enum: - '0' type: string maxItems: 100 minItems: 1 required: - field - op - value type: object default: [] maxItems: 10 - name: searchBranches in: query schema: description: 'JSON-encoded. OR branches of structured search filters. Filters within a branch are AND''d, branches are OR''d, and the result is AND''d with `search`: `AND(search) AND OR(AND(branch 1), ...)`. Max 8 branches of 1-10 conditions each. Not supported for analytics datasets, and `indicator` filters are not yet supported inside branches. Cursor pages carry the original branches, so do not resend them with `cursor`.' type: array items: items: anyOf: - additionalProperties: false properties: field: type: string enum: - attacker - attackerCountry - category - createdAt - date - event - indicator - indicatorType - mitreAttack - mitreCapec - tags - targetCountry - targetIndustry - tlp - uuid op: type: string enum: - equals - not - gt - gte - lt - lte - like - contains - startsWith - endsWith - find value: type: string maxLength: 512 minLength: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - attacker - attackerCountry - category - createdAt - date - event - indicator - indicatorType - mitreAttack - mitreCapec - tags - targetCountry - targetIndustry - tlp - uuid op: type: string enum: - in value: type: array items: maxLength: 512 minLength: 1 type: string maxItems: 100 minItems: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - killChain op: type: string enum: - equals - not - gt - gte - lt - lte value: anyOf: - type: number - pattern: ^-?(?:\d+\.?\d*|\.\d+)$ type: string required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - killChain op: type: string enum: - in value: type: array items: anyOf: - type: number - pattern: ^-?(?:\d+\.?\d*|\.\d+)$ type: string maxItems: 100 minItems: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - hasChildren op: type: string enum: - equals - not - gt - gte - lt - lte value: anyOf: - type: boolean - enum: - 'true' type: string - enum: - 'false' type: string - enum: - 1 type: number - enum: - 0 type: number - enum: - '1' type: string - enum: - '0' type: string required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - hasChildren op: type: string enum: - in value: type: array items: anyOf: - type: boolean - enum: - 'true' type: string - enum: - 'false' type: string - enum: - 1 type: number - enum: - 0 type: number - enum: - '1' type: string - enum: - '0' type: string maxItems: 100 minItems: 1 required: - field - op - value type: object maxItems: 10 minItems: 1 type: array maxItems: 8 minItems: 1 - name: page in: query schema: description: Page number (1-indexed) for offset-based pagination. Limited to offset of 100,000 records. For deep pagination, use cursor-based pagination instead. type: number - name: pageSize in: query schema: description: Number of results per page. Maximum 25,000. type: number - name: orderBy in: query schema: type: string - name: order in: query schema: type: string enum: - asc - desc - name: datasetId in: query schema: description: 'Dataset UUIDs to query, or one standalone scope value: ''all''/''*'' for the legacy all-datasets behavior, ''analytics'' for isAnalytics=true datasets, or ''operational'' for isAnalytics=false datasets. If not provided, uses the default dataset.' type: array items: type: string - name: forceRefresh in: query schema: type: boolean - name: format in: query schema: type: string enum: - json - stix2 - taxii - name: cache in: query schema: description: Cache strategy. 'from-graph' serves results from the graph-node KV cache when all requested UUIDs are cached; falls back to normal path on partial/zero hit. type: string enum: - from-graph responses: '200': description: Returns a list of events. content: application/json: schema: type: array items: properties: attacker: type: string example: Flying Yeti attackerCountry: type: string example: CN attackerCountryAlpha3: type: string example: CHN category: type: string example: Domain Resolution datasetId: type: string example: dataset-example-id date: type: string example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com hasChildren: type: boolean indicator: type: string example: domain.com indicatorType: type: string example: domain indicatorTypeId: type: number example: 5 insight: type: string killChain: type: number mitreAttack: type: array items: example: ' ' type: string mitreCapec: type: array items: example: ' ' type: string numReferenced: type: number numReferences: type: number rawId: type: string example: 453gw34w3 referenced: type: array items: example: ' ' type: string referencedIds: type: array items: type: number references: type: array items: example: ' ' type: string referencesIds: type: array items: type: number releasabilityId: type: string tags: type: array items: example: malware type: string targetCountry: type: string example: US targetCountryAlpha3: type: string example: USA targetIndustry: type: string example: Agriculture tlp: type: string example: amber uuid: type: string example: 12345678-1234-1234-1234-1234567890ab required: - uuid - date - targetCountry - targetCountryAlpha3 - attacker - attackerCountry - attackerCountryAlpha3 - targetIndustry - rawId - indicatorTypeId - indicator - event - numReferenced - numReferences - tlp - category - indicatorType - referenced - references - tags - killChain - mitreAttack - mitreCapec - referencedIds - referencesIds - hasChildren - datasetId type: object '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events x-fern-sdk-method-name: list x-forge-hidden: true post: operationId: post_EventList summary: Filter and list events description: 'Use `datasetId: ["all"]` or `datasetId: ["*"]` for the legacy all-datasets scope, `datasetId: ["analytics"]` for datasets with `isAnalytics=true`, or `datasetId: ["operational"]` for datasets with `isAnalytics=false` (limited to 50). Scope values must be used alone. When `datasetId` is unspecified, events are listed from the default Cloudforce One Threat Events dataset. To list existing datasets, use the `List Datasets` endpoint.' parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: forceRefresh in: query schema: type: boolean - name: format in: query description: Output format for event data. 'json' returns the default format, 'stix2' returns STIX 2.1 Sighting SROs with linked Indicator SDOs, Observed Data SDOs, and SCOs, 'taxii' returns a TAXII 2.1 Envelope with Content-Type application/taxii+json;version=2.1. schema: description: Output format for event data. 'json' returns the default format, 'stix2' returns STIX 2.1 Sighting SROs with linked Indicator SDOs, Observed Data SDOs, and SCOs, 'taxii' returns a TAXII 2.1 Envelope with Content-Type application/taxii+json;version=2.1. type: string example: json enum: - json - stix2 - taxii - name: cache in: query description: Cache strategy. 'from-graph' serves results from the graph-node KV cache when all requested UUIDs are cached; falls back to normal path on partial/zero hit. schema: description: Cache strategy. 'from-graph' serves results from the graph-node KV cache when all requested UUIDs are cached; falls back to normal path on partial/zero hit. type: string enum: - from-graph requestBody: content: application/json: schema: type: object properties: cursor: description: Cursor for pagination. When provided, filters are embedded in the cursor so you only need to pass cursor and pageSize. type: string example: eyJ2ZXJzaW9uIjoxLCJwb3NpdGlvbiI6eyJkYXRlIjoiMjAyNC0wMS0xMlQxMDowMDowMFoiLCJ1dWlkIjoiYWJjMTIzIn19 datasetId: description: 'Dataset UUIDs to query, or one standalone scope value: ''all''/''*'' for the legacy all-datasets behavior, ''analytics'' for isAnalytics=true datasets, or ''operational'' for isAnalytics=false datasets. If not provided, uses the default dataset.' type: array items: example: 7632a037-fdef-4899-9b12-148470aae772 type: string order: type: string enum: - asc - desc orderBy: type: string example: created page: type: number example: 1 pageSize: type: number example: 100 search: description: Structured search as a JSON array of {field, op, value} objects. Use the 'in' operator with an array value to bulk-check up to 100 values. Multiple conditions are AND'd together. Max 10 conditions per request. type: array items: anyOf: - additionalProperties: false properties: field: type: string enum: - attacker - attackerCountry - category - createdAt - date - event - indicator - indicatorType - mitreAttack - mitreCapec - tags - targetCountry - targetIndustry - tlp - uuid op: type: string enum: - equals - not - gt - gte - lt - lte - like - contains - startsWith - endsWith - find value: type: string maxLength: 512 minLength: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - attacker - attackerCountry - category - createdAt - date - event - indicator - indicatorType - mitreAttack - mitreCapec - tags - targetCountry - targetIndustry - tlp - uuid op: type: string enum: - in value: type: array items: maxLength: 512 minLength: 1 type: string maxItems: 100 minItems: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - killChain op: type: string enum: - equals - not - gt - gte - lt - lte value: anyOf: - type: number - pattern: ^-?(?:\d+\.?\d*|\.\d+)$ type: string required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - killChain op: type: string enum: - in value: type: array items: anyOf: - type: number - pattern: ^-?(?:\d+\.?\d*|\.\d+)$ type: string maxItems: 100 minItems: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - hasChildren op: type: string enum: - equals - not - gt - gte - lt - lte value: anyOf: - type: boolean - enum: - 'true' type: string - enum: - 'false' type: string - enum: - 1 type: number - enum: - 0 type: number - enum: - '1' type: string - enum: - '0' type: string required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - hasChildren op: type: string enum: - in value: type: array items: anyOf: - type: boolean - enum: - 'true' type: string - enum: - 'false' type: string - enum: - 1 type: number - enum: - 0 type: number - enum: - '1' type: string - enum: - '0' type: string maxItems: 100 minItems: 1 required: - field - op - value type: object default: [] maxItems: 10 searchBranches: description: 'OR branches of structured search filters. Filters within a branch are AND''d, branches are OR''d, and the result is AND''d with `search`: `AND(search) AND OR(AND(branch 1), ...)`. Max 8 branches of 1-10 conditions each. Not supported for analytics datasets, and `indicator` filters are not yet supported inside branches. Cursor pages carry the original branches, so do not resend them with `cursor`.' type: array items: items: anyOf: - additionalProperties: false properties: field: type: string enum: - attacker - attackerCountry - category - createdAt - date - event - indicator - indicatorType - mitreAttack - mitreCapec - tags - targetCountry - targetIndustry - tlp - uuid op: type: string enum: - equals - not - gt - gte - lt - lte - like - contains - startsWith - endsWith - find value: type: string maxLength: 512 minLength: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - attacker - attackerCountry - category - createdAt - date - event - indicator - indicatorType - mitreAttack - mitreCapec - tags - targetCountry - targetIndustry - tlp - uuid op: type: string enum: - in value: type: array items: maxLength: 512 minLength: 1 type: string maxItems: 100 minItems: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - killChain op: type: string enum: - equals - not - gt - gte - lt - lte value: anyOf: - type: number - pattern: ^-?(?:\d+\.?\d*|\.\d+)$ type: string required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - killChain op: type: string enum: - in value: type: array items: anyOf: - type: number - pattern: ^-?(?:\d+\.?\d*|\.\d+)$ type: string maxItems: 100 minItems: 1 required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - hasChildren op: type: string enum: - equals - not - gt - gte - lt - lte value: anyOf: - type: boolean - enum: - 'true' type: string - enum: - 'false' type: string - enum: - 1 type: number - enum: - 0 type: number - enum: - '1' type: string - enum: - '0' type: string required: - field - op - value type: object - additionalProperties: false properties: field: type: string enum: - hasChildren op: type: string enum: - in value: type: array items: anyOf: - type: boolean - enum: - 'true' type: string - enum: - 'false' type: string - enum: - 1 type: number - enum: - 0 type: number - enum: - '1' type: string - enum: - '0' type: string maxItems: 100 minItems: 1 required: - field - op - value type: object maxItems: 10 minItems: 1 type: array maxItems: 8 minItems: 1 responses: '200': description: Returns a list of events. content: application/json: schema: type: array items: properties: attacker: type: string example: Flying Yeti attackerCountry: type: string example: CN attackerCountryAlpha3: type: string example: CHN category: type: string example: Domain Resolution datasetId: type: string example: dataset-example-id date: type: string example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com hasChildren: type: boolean indicator: type: string example: domain.com indicatorType: type: string example: domain indicatorTypeId: type: number example: 5 insight: type: string killChain: type: number mitreAttack: type: array items: example: ' ' type: string mitreCapec: type: array items: example: ' ' type: string numReferenced: type: number numReferences: type: number rawId: type: string example: 453gw34w3 referenced: type: array items: example: ' ' type: string referencedIds: type: array items: type: number references: type: array items: example: ' ' type: string referencesIds: type: array items: type: number releasabilityId: type: string tags: type: array items: example: malware type: string targetCountry: type: string example: US targetCountryAlpha3: type: string example: USA targetIndustry: type: string example: Agriculture tlp: type: string example: amber uuid: type: string example: 12345678-1234-1234-1234-1234567890ab required: - uuid - date - targetCountry - targetCountryAlpha3 - attacker - attackerCountry - attackerCountryAlpha3 - targetIndustry - rawId - indicatorTypeId - indicator - event - numReferenced - numReferences - tlp - category - indicatorType - referenced - references - tags - killChain - mitreAttack - mitreCapec - referencedIds - referencesIds - hasChildren - datasetId type: object '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events x-fern-sdk-method-name: search x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/aggregate: get: operationId: get_EventAggregate summary: Aggregate events by single or multiple columns with optional date filtering description: Aggregate threat events by one or more columns (e.g., attacker, targetIndustry) with optional date filtering and daily grouping. Supports multi-dimensional aggregation for cross-analysis. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: aggregateBy in: query description: Column(s) to aggregate by - single column or comma-separated list (e.g., 'attacker', 'targetIndustry', 'attacker,targetIndustry') required: true schema: description: Column(s) to aggregate by - single column or comma-separated list (e.g., 'attacker', 'targetIndustry', 'attacker,targetIndustry') type: string - name: datasetId in: query description: 'Dataset UUIDs to filter by, or one standalone scope value: ''all''/''*'' for all accessible non-analytics event datasets (analytics datasets are silently excluded), ''analytics'' for isAnalytics=true datasets, or ''operational'' for isAnalytics=false datasets. If not provided, uses the default dataset.' schema: description: 'Dataset UUIDs to filter by, or one standalone scope value: ''all''/''*'' for all accessible non-analytics event datasets (analytics datasets are silently excluded), ''analytics'' for isAnalytics=true datasets, or ''operational'' for isAnalytics=false datasets. If not provided, uses the default dataset.' type: array items: type: string - name: startDate in: query description: Start date for filtering (ISO 8601 format, e.g., '2024-01-01') schema: description: Start date for filtering (ISO 8601 format, e.g., '2024-01-01') type: string - name: endDate in: query description: End date for filtering (ISO 8601 format, e.g., '2024-12-31') schema: description: End date for filtering (ISO 8601 format, e.g., '2024-12-31') type: string - name: groupByDate in: query description: Whether to group results by date (daily aggregation) schema: description: Whether to group results by date (daily aggregation) type: boolean - name: limit in: query description: Maximum number of results to return schema: description: Maximum number of results to return type: number default: 100 responses: '200': description: Returns aggregated event data. content: application/json: schema: type: object properties: aggregateBy: description: Column(s) that were aggregated by type: string aggregations: description: Array of aggregation results with dynamic fields based on aggregateBy columns type: array items: allOf: - additionalProperties: type: - string - 'null' type: object - properties: count: description: Number of events for this aggregation type: number date: description: Date (if groupByDate is true) type: string required: - count type: object dateRange: description: Date range used for filtering type: object properties: endDate: type: string startDate: type: string total: description: Total number of events in the aggregation type: number required: - aggregations - total - aggregateBy '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.aggregate x-fern-sdk-method-name: get x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/by-id/{event_id}/relationships: get: operationId: get_EventRelationships summary: Filter and list events related to specific event description: The `event_id` must be defined (to list existing events (and their IDs), use the `Filter and List Events` endpoint). Also, must provide query parameters. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string - name: direction in: query description: The direction to traverse the graph. Defaults to 'both' to search all. schema: description: The direction to traverse the graph. Defaults to 'both' to search all. type: string default: both enum: - ancestors - descendants - both - name: maxDepth in: query description: The maximum depth to traverse. Defaults to 5. schema: description: The maximum depth to traverse. Defaults to 5. type: number - name: relationshipTypes in: query description: An optional array of relationship types to filter by. schema: description: An optional array of relationship types to filter by. anyOf: - type: string - items: type: string type: array - name: indicatorTypeIds in: query description: An optional array of indicator type IDs to filter the results by. schema: description: An optional array of indicator type IDs to filter the results by. type: array items: type: string - name: datasetId in: query description: The dataset ID to search within. required: true schema: description: The dataset ID to search within. type: string - name: includeParent in: query description: Whether to include the starting event in the results. Defaults to true. schema: description: Whether to include the starting event in the results. Defaults to true. type: boolean default: true - name: page in: query schema: type: number - name: pageSize in: query schema: type: number responses: '200': description: Returns a list of events related to the specified starting event. content: application/json: schema: type: array items: properties: attacker: type: string example: Flying Yeti attackerCountry: type: string example: CN attackerCountryAlpha3: type: string example: CHN category: type: string example: Domain Resolution datasetId: type: string example: dataset-example-id date: type: string example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com hasChildren: type: boolean indicator: type: string example: domain.com indicatorType: type: string example: domain indicatorTypeId: type: number example: 5 insight: type: string killChain: type: number mitreAttack: type: array items: example: ' ' type: string mitreCapec: type: array items: example: ' ' type: string numReferenced: type: number numReferences: type: number rawId: type: string example: 453gw34w3 referenced: type: array items: example: ' ' type: string referencedIds: type: array items: type: number references: type: array items: example: ' ' type: string referencesIds: type: array items: type: number releasabilityId: type: string tags: type: array items: example: malware type: string targetCountry: type: string example: US targetCountryAlpha3: type: string example: USA targetIndustry: type: string example: Agriculture tlp: type: string example: amber uuid: type: string example: 12345678-1234-1234-1234-1234567890ab required: - uuid - date - targetCountry - targetCountryAlpha3 - attacker - attackerCountry - attackerCountryAlpha3 - targetIndustry - rawId - indicatorTypeId - indicator - event - numReferenced - numReferences - tlp - category - indicatorType - referenced - references - tags - killChain - mitreAttack - mitreCapec - referencedIds - referencesIds - hasChildren - datasetId type: object '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.relationships x-fern-sdk-method-name: get x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/create: post: operationId: post_EventCreate summary: Creates a new event description: To create a dataset, see the `Create Dataset` endpoint. When `datasetId` parameter is unspecified, it will be created in a default dataset named `Cloudforce One Threat Events`. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string requestBody: content: application/json: schema: type: object properties: accountId: type: number example: 123456 x-fern-property-name: accountId_body attacker: type: - string - 'null' example: Flying Yeti attackerCountry: type: string example: CN category: type: string example: Domain Resolution datasetId: type: string example: durableObjectName date: type: string format: date-time example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com indicator: type: string example: domain.com indicatorType: type: string example: domain indicators: description: Array of indicators for this event. Supports multiple indicators per event for complex scenarios. type: array items: properties: indicatorType: description: The type of indicator (e.g., DOMAIN, IP, JA3, HASH) type: string example: domain value: description: The indicator value (e.g., domain name, IP address, hash) type: string example: malicious.com required: - value - indicatorType type: object insight: type: string example: This domain was likely registered for phishing purposes raw: type: object properties: data: type: - object - 'null' additionalProperties: true source: type: string example: example.com tlp: type: string example: amber required: - data source: description: Controlled provenance for an event and its indicators derived from a Threat Signals article. type: object additionalProperties: false properties: resourceId: type: string format: uuid resourceType: type: string enum: - article system: type: string enum: - threat-signals title: description: Threat Signals article title; null for historical provenance without a stored title. type: - string - 'null' required: - system - resourceType - resourceId tags: type: array items: example: malware type: string targetCountry: type: string example: US targetIndustry: type: string example: Agriculture tlp: type: string example: amber required: - date - category - event - tlp - raw responses: '200': description: Returns the created event. content: application/json: schema: type: object properties: attacker: type: string example: Flying Yeti attackerCountry: type: string example: CN attackerCountryAlpha3: type: string example: CHN category: type: string example: Domain Resolution datasetId: type: string example: dataset-example-id date: type: string example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com hasChildren: type: boolean indicator: type: string example: domain.com indicatorType: type: string example: domain indicatorTypeId: type: number example: 5 insight: type: string killChain: type: number mitreAttack: type: array items: example: ' ' type: string mitreCapec: type: array items: example: ' ' type: string numReferenced: type: number numReferences: type: number rawId: type: string example: 453gw34w3 referenced: type: array items: example: ' ' type: string referencedIds: type: array items: type: number references: type: array items: example: ' ' type: string referencesIds: type: array items: type: number releasabilityId: type: string tags: type: array items: example: malware type: string targetCountry: type: string example: US targetCountryAlpha3: type: string example: USA targetIndustry: type: string example: Agriculture tlp: type: string example: amber uuid: type: string example: 12345678-1234-1234-1234-1234567890ab required: - uuid - date - targetCountry - targetCountryAlpha3 - attacker - attackerCountry - attackerCountryAlpha3 - targetIndustry - rawId - indicatorTypeId - indicator - event - numReferenced - numReferences - tlp - category - indicatorType - referenced - references - tags - killChain - mitreAttack - mitreCapec - referencedIds - referencesIds - hasChildren - datasetId '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events x-fern-sdk-method-name: create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/create/bulk: post: operationId: post_EventCreateBulk summary: Creates bulk events description: The `datasetId` parameter must be defined. To list existing datasets (and their IDs) in your account, use the `List Datasets` endpoint. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string requestBody: content: application/json: schema: type: object properties: data: type: array items: properties: accountId: type: number example: 123456 attacker: type: - string - 'null' example: Flying Yeti attackerCountry: type: string example: CN category: type: string example: Domain Resolution datasetId: type: string example: durableObjectName date: type: string format: date-time example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com indicator: type: string example: domain.com indicatorType: type: string example: domain indicators: description: Array of indicators for this event. Supports multiple indicators per event for complex scenarios. type: array items: properties: indicatorType: description: The type of indicator (e.g., DOMAIN, IP, JA3, HASH) type: string example: domain value: description: The indicator value (e.g., domain name, IP address, hash) type: string example: malicious.com required: - value - indicatorType type: object insight: type: string example: This domain was likely registered for phishing purposes raw: type: object properties: data: type: - object - 'null' additionalProperties: true source: type: string example: example.com tlp: type: string example: amber required: - data tags: type: array items: example: malware type: string targetCountry: type: string example: US targetIndustry: type: string example: Agriculture tlp: type: string example: amber required: - date - category - event - tlp - raw type: object datasetId: type: string example: durableObjectName includeCreatedEvents: description: When true, response includes array of created event UUIDs and shard IDs. Useful for tracking which events were created and where. type: boolean required: - data - datasetId responses: '202': description: Accepted. Events created; indicators queued for async processing. content: application/json: schema: description: Detailed result of bulk event creation with auto-tag management type: object properties: createBulkEventsRequestId: description: Correlation ID for async indicator processing type: string format: uuid createdEvents: description: Array of created events with UUIDs and shard locations. Only present when includeCreatedEvents=true type: array items: properties: eventIndex: description: Original index in the input data array type: number shardId: description: Dataset ID of the shard where the event was created type: string uuid: description: UUID of the created event type: string format: uuid required: - eventIndex - uuid - shardId type: object createdEventsCount: description: Number of events created type: number createdTagsCount: description: Number of new tags created in SoT type: number errorCount: description: Number of errors encountered type: number errors: description: Array of error details type: array items: properties: error: description: Error message type: string eventIndex: description: Index of the event that caused the error type: number required: - eventIndex - error type: object queuedIndicatorsCount: description: Number of indicators queued for async processing type: number required: - createdEventsCount - queuedIndicatorsCount - createdTagsCount - errorCount '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events x-fern-sdk-method-name: bulk-create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/create/bulk/relationships: post: operationId: post_DOSEventCreateBulkWithRelationships summary: Creates bulk DOS event with relationships and indicators description: This method is deprecated. Please use `event_create_bulk` instead parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string requestBody: content: application/json: schema: type: object properties: data: type: array items: properties: accountId: type: number example: 123456 attacker: type: - string - 'null' example: Flying Yeti attackerCountry: type: string example: CN category: type: string example: Domain Resolution datasetId: type: string example: durableObjectName date: type: string format: date-time example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com indicator: type: string example: domain.com indicatorType: type: string example: domain indicators: description: Array of indicators for this event. Supports multiple indicators per event for complex scenarios. type: array items: properties: indicatorType: description: The type of indicator (e.g., DOMAIN, IP, JA3, HASH) type: string example: domain value: description: The indicator value (e.g., domain name, IP address, hash) type: string example: malicious.com required: - value - indicatorType type: object insight: type: string example: This domain was likely registered for phishing purposes raw: type: object properties: data: type: - object - 'null' additionalProperties: true source: type: string example: example.com tlp: type: string example: amber required: - data tags: type: array items: example: malware type: string targetCountry: type: string example: US targetIndustry: type: string example: Agriculture tlp: type: string example: amber required: - date - category - event - tlp - raw type: object datasetId: type: string example: durableObjectName required: - data - datasetId responses: '200': description: Returns the number of created bulk events with relationships. content: application/json: schema: description: Result of bulk relationship creation operation type: object properties: createdEventsCount: description: Number of events created type: number createdIndicatorsCount: description: Number of indicators created type: number createdRelationshipsCount: description: Number of relationships created type: number errorCount: description: Number of errors encountered type: number errors: description: Array of error details type: array items: properties: error: description: Error message type: string eventIndex: description: Index of the event that caused the error type: number required: - eventIndex - error type: object required: - createdEventsCount - createdIndicatorsCount - createdRelationshipsCount - errorCount '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors deprecated: true security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: deprecated x-fern-sdk-group-name: cloudforce-one.events.create-bulk.relationships x-fern-sdk-method-name: create x-forge-hidden: true x-forge-sunset: date: '2030-01-01T00:00:00Z' /accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/copy: post: operationId: post_EventCopyToNewDS summary: Copies specified events from one dataset to another dataset parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: dataset_id in: path description: Dataset UUID. required: true schema: description: Dataset UUID. type: string format: uuid - name: keepRawData in: query description: If true, copies raw data to the destination dataset. Default is false (raw data is stripped/not copied). schema: description: If true, copies raw data to the destination dataset. Default is false (raw data is stripped/not copied). type: boolean requestBody: content: application/json: schema: type: object properties: destDatasetId: type: string example: 12345678-1234-1234-1234-1234567890ab eventIds: type: array items: example: 7632a037-fdef-4899-9b12-148470aae772 type: string required: - destDatasetId - eventIds responses: '200': description: Returns the number of copied events content: application/json: schema: type: object properties: copied: description: Number of events successfully copied type: number example: 2 indicatorsCopied: description: Number of indicators successfully copied type: number example: 5 insertFailures: description: Array of events that failed to insert into destination type: array items: properties: index: description: Index of the event that failed to insert type: number reason: description: Reason for the failure type: string required: - index - reason type: object relationshipsCopied: description: Number of relationships successfully copied type: number example: 3 required: - copied - indicatorsCopied - relationshipsCopied '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.dataset.copy x-fern-sdk-method-name: create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/events/{event_id}: get: operationId: get_EventRead summary: Reads an event description: Retrieves a specific event by its UUID. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: dataset_id in: path description: Dataset ID. required: true schema: description: Dataset ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string responses: '200': description: Returns the event. content: application/json: schema: type: object properties: attacker: type: string example: Flying Yeti attackerCountry: type: string example: CN attackerCountryAlpha3: type: string example: CHN category: type: string example: Domain Resolution datasetId: type: string example: dataset-example-id date: type: string example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com hasChildren: type: boolean indicator: type: string example: domain.com indicatorType: type: string example: domain indicatorTypeId: type: number example: 5 insight: type: string killChain: type: number mitreAttack: type: array items: example: ' ' type: string mitreCapec: type: array items: example: ' ' type: string numReferenced: type: number numReferences: type: number rawId: type: string example: 453gw34w3 referenced: type: array items: example: ' ' type: string referencedIds: type: array items: type: number references: type: array items: example: ' ' type: string referencesIds: type: array items: type: number releasabilityId: type: string tags: type: array items: example: malware type: string targetCountry: type: string example: US targetCountryAlpha3: type: string example: USA targetIndustry: type: string example: Agriculture tlp: type: string example: amber uuid: type: string example: 12345678-1234-1234-1234-1234567890ab required: - uuid - date - targetCountry - targetCountryAlpha3 - attacker - attackerCountry - attackerCountryAlpha3 - targetIndustry - rawId - indicatorTypeId - indicator - event - numReferenced - numReferences - tlp - category - indicatorType - referenced - references - tags - killChain - mitreAttack - mitreCapec - referencedIds - referencesIds - hasChildren - datasetId '404': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.dataset.events x-fern-sdk-method-name: get x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/dataset/{dataset_id}/move: post: operationId: post_EventMoveToNewDS summary: Moves specified events from one dataset to another dataset parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: dataset_id in: path description: Dataset UUID. required: true schema: description: Dataset UUID. type: string format: uuid - name: keepRawData in: query description: If true, copies raw data to the destination dataset. Default is false (raw data is stripped/not copied). Raw data is always deleted from the source. schema: description: If true, copies raw data to the destination dataset. Default is false (raw data is stripped/not copied). Raw data is always deleted from the source. type: boolean requestBody: content: application/json: schema: type: object properties: destDatasetId: type: string example: 12345678-1234-1234-1234-1234567890ab eventIds: type: array items: example: 7632a037-fdef-4899-9b12-148470aae772 type: string required: - destDatasetId - eventIds responses: '200': description: 'Returns the number of moved events ' content: application/json: schema: type: object properties: deletionFailures: description: Array of source datasets where deletion failed type: array items: properties: datasetId: description: Dataset ID where deletion failed type: string reason: description: Reason for the deletion failure type: string required: - datasetId - reason type: object indicatorsCopied: description: Number of indicators successfully copied type: number example: 5 insertFailures: description: Array of events that failed to insert into destination type: array items: properties: index: description: Index of the event that failed to insert type: number reason: description: Reason for the failure type: string required: - index - reason type: object moved: description: Number of events successfully moved type: number example: 2 relationshipsCopied: description: Number of relationships successfully copied type: number example: 3 required: - moved - indicatorsCopied - relationshipsCopied '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.dataset.move x-fern-sdk-method-name: create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/datasets/{dataset_id}/events: delete: operationId: delete_EventDelete summary: Deletes one or more events parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: dataset_id in: path description: Dataset UUID. required: true schema: description: Dataset UUID. type: string format: uuid - name: eventIds in: query description: Array of Event IDs to delete. required: true schema: description: Array of Event IDs to delete. type: array items: minLength: 1 type: string responses: '200': description: Returns the number of deleted events. content: application/json: schema: description: Number of deleted events type: number '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.delete x-fern-sdk-method-name: delete x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/datasets/{dataset_id}/events/{event_id}/raw: get: operationId: get_EventRawReadDS summary: Reads raw data for an event by UUID description: Retrieves the raw data associated with an event. Searches across all shards in the dataset. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event ID. required: true schema: description: Event ID. type: string - name: dataset_id in: path description: Dataset ID. required: true schema: description: Dataset ID. type: string responses: '200': description: Returns the raw event data. content: application/json: schema: type: object properties: accountId: type: number example: 1234 created: type: string example: '1970-01-01T00:00:00Z' data: type: string example: '{"foo": "bar"}' id: type: number example: 1 source: type: string example: https://example.com tlp: type: string example: amber required: - id - accountId - created - data - source - tlp '404': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors '500': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events.datasets x-fern-sdk-method-name: raw x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/event_tag/{event_id}: delete: operationId: delete_EventTagDelete summary: Removes a tag from an event description: Removes a tag from a threat event in Cloudforce One. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string requestBody: content: application/json: schema: type: object properties: tags: type: array items: example: malware type: string required: - tags responses: '200': description: Returns success if operation succeeded. content: application/json: schema: type: object properties: result: type: object properties: success: type: boolean example: true required: - success success: type: boolean example: true required: - success - result '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events.event-tags x-fern-sdk-method-name: delete x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/event_tag/{event_id}/create: post: operationId: post_EventTagCreate summary: Adds a tag to an event description: Adds a tag to a threat event in Cloudforce One for classification and filtering. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string requestBody: content: application/json: schema: type: object properties: tags: type: array items: example: botnet type: string required: - tags responses: '200': description: Returns success if operation succeeded. content: application/json: schema: type: object properties: result: type: object properties: success: type: boolean example: true required: - success success: type: boolean example: true required: - success - result '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events.event-tags x-fern-sdk-method-name: create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/graphql: post: operationId: post_EventGraphQL summary: GraphQL endpoint for event aggregation description: Execute GraphQL aggregations over threat events. Supports multi-dimensional group-bys, optional date range filtering, and multi-dataset aggregation. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string responses: '200': description: GraphQL response payload (data and errors). content: application/json: schema: type: object properties: data: type: - object - 'null' errors: type: - array - 'null' items: type: object '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.graphql.create.graph x-fern-sdk-method-name: ql x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/queries: get: operationId: get_EventQueryList summary: List all saved event queries description: Retrieve all saved event queries for the account parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string responses: '200': description: Returns a list of event queries. content: application/json: schema: type: array items: properties: account_id: description: Account ID type: integer alert_enabled: description: Whether alerts are enabled type: boolean alert_rollup_enabled: description: Whether alert rollup is enabled type: boolean created_at: description: Creation timestamp type: string custom_threat_feed_id: description: Intel Indicator Feed ID (numeric) type: - integer - 'null' id: description: Unique identifier for the saved query type: integer name: description: Name of the saved query type: string query_json: description: JSON string containing the query parameters type: string rule_enabled: description: Whether rule is enabled type: boolean rule_list_id: description: WAF rules list ID for blocking type: string rule_scope: description: Scope for the rule type: string updated_at: description: Last update timestamp type: string user_email: description: Email of the user who created the query type: string required: - id - account_id - name - user_email - query_json - alert_enabled - alert_rollup_enabled - rule_enabled - created_at - updated_at type: object '500': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors 4XX: $ref: '#/components/responses/cloudforce-one-events_ApiV4ClientError' security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.queries.get x-fern-sdk-method-name: event x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/queries/create: post: operationId: post_EventQueryCreate summary: Create a saved event query description: Create a new saved event query for the account parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string requestBody: content: application/json: schema: type: object properties: alert_enabled: description: Enable alerts for this query type: boolean alert_rollup_enabled: description: Enable alert rollup for this query type: boolean name: description: Unique name for the saved query type: string query_json: description: JSON string containing the query parameters type: string rule_enabled: description: Enable rule for this query type: boolean rule_scope: description: Scope for the rule type: string required: - name - query_json - alert_enabled - alert_rollup_enabled - rule_enabled responses: '200': description: Returns the created event query. content: application/json: schema: type: object properties: account_id: description: Account ID type: integer alert_enabled: description: Whether alerts are enabled type: boolean alert_rollup_enabled: description: Whether alert rollup is enabled type: boolean created_at: description: Creation timestamp type: string custom_threat_feed_id: description: Intel Indicator Feed ID (numeric) type: - integer - 'null' id: description: Unique identifier for the saved query type: integer name: description: Name of the saved query type: string query_json: description: JSON string containing the query parameters type: string rule_enabled: description: Whether rule is enabled type: boolean rule_list_id: description: WAF rules list ID for blocking type: string rule_scope: description: Scope for the rule type: string updated_at: description: Last update timestamp type: string user_email: description: Email of the user who created the query type: string required: - id - account_id - name - user_email - query_json - alert_enabled - alert_rollup_enabled - rule_enabled - created_at - updated_at '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.queries x-fern-sdk-method-name: create-create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/queries/{query_id}: delete: operationId: delete_EventQueryDelete summary: Delete a saved event query description: Delete a saved event query by its ID parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: query_id in: path description: Event query ID required: true schema: description: Event query ID type: integer responses: '200': description: Event query deleted successfully. '404': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.queries x-fern-sdk-method-name: delete x-forge-hidden: true get: operationId: get_EventQueryRead summary: Read a saved event query description: Retrieve a saved event query by its ID parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: query_id in: path description: Event query ID required: true schema: description: Event query ID type: integer responses: '200': description: Returns the event query. content: application/json: schema: type: object properties: account_id: description: Account ID type: integer alert_enabled: description: Whether alerts are enabled type: boolean alert_rollup_enabled: description: Whether alert rollup is enabled type: boolean created_at: description: Creation timestamp type: string custom_threat_feed_id: description: Intel Indicator Feed ID (numeric) type: - integer - 'null' id: description: Unique identifier for the saved query type: integer name: description: Name of the saved query type: string query_json: description: JSON string containing the query parameters type: string rule_enabled: description: Whether rule is enabled type: boolean rule_list_id: description: WAF rules list ID for blocking type: string rule_scope: description: Scope for the rule type: string updated_at: description: Last update timestamp type: string user_email: description: Email of the user who created the query type: string required: - id - account_id - name - user_email - query_json - alert_enabled - alert_rollup_enabled - rule_enabled - created_at - updated_at '404': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.queries.get x-fern-sdk-method-name: v2 x-forge-hidden: true patch: operationId: patch_EventQueryUpdate summary: Update a saved event query description: Update an existing saved event query by its ID parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: query_id in: path description: Event query ID required: true schema: description: Event query ID type: integer requestBody: content: application/json: schema: type: object properties: alert_enabled: description: Enable alerts for this query type: boolean alert_rollup_enabled: description: Enable alert rollup for this query type: boolean name: description: Unique name for the saved query type: string query_json: description: JSON string containing the query parameters type: string rule_enabled: description: Enable rule for this query type: boolean rule_scope: description: Scope for the rule type: string responses: '200': description: Returns the updated event query. content: application/json: schema: type: object properties: account_id: description: Account ID type: integer alert_enabled: description: Whether alerts are enabled type: boolean alert_rollup_enabled: description: Whether alert rollup is enabled type: boolean created_at: description: Creation timestamp type: string custom_threat_feed_id: description: Intel Indicator Feed ID (numeric) type: - integer - 'null' id: description: Unique identifier for the saved query type: integer name: description: Name of the saved query type: string query_json: description: JSON string containing the query parameters type: string rule_enabled: description: Whether rule is enabled type: boolean rule_list_id: description: WAF rules list ID for blocking type: string rule_scope: description: Scope for the rule type: string updated_at: description: Last update timestamp type: string user_email: description: Email of the user who created the query type: string required: - id - account_id - name - user_email - query_json - alert_enabled - alert_rollup_enabled - rule_enabled - created_at - updated_at '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors '404': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.queries x-fern-sdk-method-name: patch x-forge-hidden: true post: operationId: post_EventQueryUpdate summary: Update a saved event query description: Update an existing saved event query by its ID parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: query_id in: path description: Event query ID required: true schema: description: Event query ID type: integer requestBody: content: application/json: schema: type: object properties: alert_enabled: description: Enable alerts for this query type: boolean alert_rollup_enabled: description: Enable alert rollup for this query type: boolean name: description: Unique name for the saved query type: string query_json: description: JSON string containing the query parameters type: string rule_enabled: description: Enable rule for this query type: boolean rule_scope: description: Scope for the rule type: string responses: '200': description: Returns the updated event query. content: application/json: schema: type: object properties: account_id: description: Account ID type: integer alert_enabled: description: Whether alerts are enabled type: boolean alert_rollup_enabled: description: Whether alert rollup is enabled type: boolean created_at: description: Creation timestamp type: string custom_threat_feed_id: description: Intel Indicator Feed ID (numeric) type: - integer - 'null' id: description: Unique identifier for the saved query type: integer name: description: Name of the saved query type: string query_json: description: JSON string containing the query parameters type: string rule_enabled: description: Whether rule is enabled type: boolean rule_list_id: description: WAF rules list ID for blocking type: string rule_scope: description: Scope for the rule type: string updated_at: description: Last update timestamp type: string user_email: description: Email of the user who created the query type: string required: - id - account_id - name - user_email - query_json - alert_enabled - alert_rollup_enabled - rule_enabled - created_at - updated_at '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors '404': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.queries x-fern-sdk-method-name: create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/raw/{dataset_id}/{event_id}: get: operationId: get_LegacyEventRawReadDS summary: Reads raw data for an event by UUID description: Deprecated; use GET /events/datasets/{dataset_id}/events/{event_id}/raw. Available through 2026-11-28. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event ID. required: true schema: description: Event ID. type: string - name: dataset_id in: path description: Dataset ID. required: true schema: description: Dataset ID. type: string responses: '200': description: Returns the raw event data. content: application/json: schema: type: object properties: accountId: type: number example: 1234 created: type: string example: '1970-01-01T00:00:00Z' data: type: string example: '{"foo": "bar"}' id: type: number example: 1 source: type: string example: https://example.com tlp: type: string example: amber required: - id - accountId - created - data - source - tlp '404': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors '500': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors deprecated: true security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: deprecated x-fern-sdk-group-name: cloudforce-one.events.raw.legacy x-fern-sdk-method-name: get x-forge-hidden: true x-forge-sunset: date: '2026-11-28T00:00:00Z' x-stainless-deprecation-message: Use GET /events/datasets/{dataset_id}/events/{event_id}/raw before 2026-11-28. /accounts/{account_id}/cloudforce-one/events/relate/{event_id}: delete: operationId: delete_EventReferenceDelete summary: Removes an event reference description: Removes a reference link between related threat events in Cloudforce One. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string requestBody: content: application/json: schema: type: object properties: events: type: array items: example: 88888888-4444-4444-4444-121212121212 type: string required: - events responses: '200': description: Returns success if operation succeeded. content: application/json: schema: type: object properties: result: type: object properties: success: type: boolean example: true required: - success success: type: boolean example: true required: - success - result '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events.relate x-fern-sdk-method-name: delete x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/relate/{event_id}/create: post: operationId: post_EventReferenceCreate summary: Creates event references for a event parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string requestBody: content: application/json: schema: type: object properties: events: type: array items: example: 88888888-4444-4444-4444-121212121212 type: string required: - events responses: '200': description: Returns success if operation succeeded. content: application/json: schema: type: object properties: result: type: object properties: success: type: boolean example: true required: - success success: type: boolean example: true required: - success - result '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.relate.create x-fern-sdk-method-name: create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/relationships/create: post: operationId: post_CreateEventRelationship summary: Create a relationship between two events description: Creates a directed relationship between two events. The relationship is from parent to child with a specified type. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string requestBody: content: application/json: schema: type: object properties: childIds: description: Array of UUIDs for child events. Single child = 1:1 relationship, multiple = 1:many relationships type: array items: format: uuid type: string minItems: 1 datasetId: description: Dataset identifier where the events are stored type: string parentId: description: UUID of the parent event that will be the source of the relationship type: string format: uuid relationshipType: description: Type of relationship to create between parent and child events type: string enum: - related_to - caused_by - attributed_to required: - parentId - childIds - relationshipType - datasetId responses: '200': description: Relationship created successfully content: application/json: schema: type: object properties: childIds: description: Array of child event UUIDs that were processed type: array items: format: uuid type: string errors: description: Array of errors for relationships that failed to be created (only present if some relationships failed) type: array items: properties: childId: description: UUID of the child event that failed to create a relationship type: string format: uuid error: description: Error message describing why the relationship creation failed type: string errorType: description: Type/category of the error that occurred type: string required: - childId - error type: object message: description: Human-readable message describing the operation result type: string relationships: description: Array of successfully created relationship objects type: array items: properties: childDatasetId: description: Dataset ID where the child event resides type: string childId: description: UUID of the child event in the relationship type: string format: uuid parentDatasetId: description: Dataset ID where the parent event resides type: string parentId: description: UUID of the parent event in the relationship type: string format: uuid relationshipType: description: Type of relationship between the events type: string enum: - related_to - caused_by - attributed_to required: - parentId - childId - relationshipType - parentDatasetId - childDatasetId type: object relationshipsCreated: description: Number of relationships that were successfully created type: number success: description: Whether the relationship creation operation completed successfully type: boolean required: - success - message - relationships '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.relationships.create x-fern-sdk-method-name: create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/update/bulk: patch: operationId: patch_EventUpdateBulk summary: Bulk update events description: Updates multiple events with the same field values. Maximum 100 events per request. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string requestBody: content: application/json: schema: type: object properties: datasetId: description: Dataset ID containing the events to update. Required to prevent cross-account modifications. type: string example: 9b769969-a211-466c-8ac3-cb91266a066a eventIds: description: List of event UUIDs to update (1-100) type: array items: example: 12345678-1234-1234-1234-1234567890ab type: string example: - uuid-1 - uuid-2 - uuid-3 maxItems: 100 minItems: 1 updates: description: Fields to update on all specified events. All fields including 'insight' are supported, except 'date' which requires shard migration. type: object properties: attacker: type: - string - 'null' example: Flying Yeti attackerCountry: type: string example: CN category: type: string example: Domain Resolution createdAt: type: string format: date-time example: '2025-12-19T00:00:00Z' event: type: string example: An attacker registered the domain domain.com indicator: type: string example: domain2.com indicatorType: type: string example: domain insight: type: string example: This event indicates a potential phishing campaign raw: type: object properties: data: type: - object - 'null' additionalProperties: true source: type: string example: example.com tlp: type: string example: amber targetCountry: type: string example: US targetIndustry: type: string example: Insurance tlp: type: string example: amber required: - eventIds - datasetId - updates responses: '200': description: Returns the count of updated events and any failures. content: application/json: schema: type: object properties: failedCount: type: number example: 1 failures: description: List of events that failed to update with error messages type: array items: properties: error: type: string example: Event not found eventId: type: string example: 12345678-1234-1234-1234-1234567890ab required: - eventId - error type: object updatedCount: type: number example: 5 required: - updatedCount - failedCount '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.update.bulk x-fern-sdk-method-name: patch x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/{dataset_id}/delete: delete: operationId: delete_LegacyEventDelete summary: Deletes one or more events description: Deprecated; use DELETE /events/datasets/{dataset_id}/events. Available through 2026-11-28. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: dataset_id in: path description: Dataset UUID. required: true schema: description: Dataset UUID. type: string format: uuid - name: eventIds in: query description: Array of Event IDs to delete. required: true schema: description: Array of Event IDs to delete. type: array items: minLength: 1 type: string responses: '200': description: Returns the number of deleted events. content: application/json: schema: description: Number of deleted events type: number '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors deprecated: true security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write x-fern-availability: deprecated x-fern-sdk-group-name: cloudforce-one.events.legacy x-fern-sdk-method-name: delete x-forge-hidden: true x-forge-sunset: date: '2026-11-28T00:00:00Z' x-stainless-deprecation-message: Use DELETE /events/datasets/{dataset_id}/events before 2026-11-28. /accounts/{account_id}/cloudforce-one/events/{event_id}: get: operationId: get_EventReadDeprecated summary: Reads an event description: This Method is deprecated. Please use /events/dataset/:dataset_id/events/:event_id instead. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string responses: '200': description: Returns an event. content: application/json: schema: type: object properties: attacker: type: string example: Flying Yeti attackerCountry: type: string example: CN attackerCountryAlpha3: type: string example: CHN category: type: string example: Domain Resolution datasetId: type: string example: dataset-example-id date: type: string example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com hasChildren: type: boolean indicator: type: string example: domain.com indicatorType: type: string example: domain indicatorTypeId: type: number example: 5 insight: type: string killChain: type: number mitreAttack: type: array items: example: ' ' type: string mitreCapec: type: array items: example: ' ' type: string numReferenced: type: number numReferences: type: number rawId: type: string example: 453gw34w3 referenced: type: array items: example: ' ' type: string referencedIds: type: array items: type: number references: type: array items: example: ' ' type: string referencesIds: type: array items: type: number releasabilityId: type: string tags: type: array items: example: malware type: string targetCountry: type: string example: US targetCountryAlpha3: type: string example: USA targetIndustry: type: string example: Agriculture tlp: type: string example: amber uuid: type: string example: 12345678-1234-1234-1234-1234567890ab required: - uuid - date - targetCountry - targetCountryAlpha3 - attacker - attackerCountry - attackerCountryAlpha3 - targetIndustry - rawId - indicatorTypeId - indicator - event - numReferenced - numReferences - tlp - category - indicatorType - referenced - references - tags - killChain - mitreAttack - mitreCapec - referencedIds - referencesIds - hasChildren - datasetId '404': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors deprecated: true security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events x-fern-sdk-method-name: get x-forge-hidden: true patch: operationId: patch_EventUpdate summary: Updates an event description: Partially updates a threat event in Cloudforce One, modifying specific fields without replacing the entire event. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string requestBody: content: application/json: schema: type: object properties: attacker: type: - string - 'null' example: Flying Yeti attackerCountry: type: string example: CN category: type: string example: Domain Resolution createdAt: type: string format: date-time example: '2025-12-19T00:00:00Z' datasetId: description: Dataset ID containing the event to update. type: string example: 9b769969-a211-466c-8ac3-cb91266a066a date: type: string format: date-time example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com indicator: type: string example: domain2.com indicatorType: type: string example: domain insight: type: string example: new insight raw: type: object properties: data: type: - object - 'null' additionalProperties: true source: type: string example: example.com tlp: type: string example: amber targetCountry: type: string example: US targetIndustry: type: string example: Insurance tlp: type: string example: amber required: - datasetId responses: '200': description: Returns the updated event. content: application/json: schema: type: object properties: attacker: type: string example: Flying Yeti attackerCountry: type: string example: CN attackerCountryAlpha3: type: string example: CHN category: type: string example: Domain Resolution datasetId: type: string example: dataset-example-id date: type: string example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com hasChildren: type: boolean indicator: type: string example: domain.com indicatorType: type: string example: domain indicatorTypeId: type: number example: 5 insight: type: string killChain: type: number mitreAttack: type: array items: example: ' ' type: string mitreCapec: type: array items: example: ' ' type: string numReferenced: type: number numReferences: type: number rawId: type: string example: 453gw34w3 referenced: type: array items: example: ' ' type: string referencedIds: type: array items: type: number references: type: array items: example: ' ' type: string referencesIds: type: array items: type: number releasabilityId: type: string tags: type: array items: example: malware type: string targetCountry: type: string example: US targetCountryAlpha3: type: string example: USA targetIndustry: type: string example: Agriculture tlp: type: string example: amber uuid: type: string example: 12345678-1234-1234-1234-1234567890ab required: - uuid - date - targetCountry - targetCountryAlpha3 - attacker - attackerCountry - attackerCountryAlpha3 - targetIndustry - rawId - indicatorTypeId - indicator - event - numReferenced - numReferences - tlp - category - indicatorType - referenced - references - tags - killChain - mitreAttack - mitreCapec - referencedIds - referencesIds - hasChildren - datasetId '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events x-fern-sdk-method-name: edit x-forge-hidden: true post: operationId: post_EventUpdate summary: Updates an event parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string requestBody: content: application/json: schema: type: object properties: attacker: type: - string - 'null' example: Flying Yeti attackerCountry: type: string example: CN category: type: string example: Domain Resolution createdAt: type: string format: date-time example: '2025-12-19T00:00:00Z' datasetId: description: Dataset ID containing the event to update. type: string example: 9b769969-a211-466c-8ac3-cb91266a066a date: type: string format: date-time example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com indicator: type: string example: domain2.com indicatorType: type: string example: domain insight: type: string example: new insight raw: type: object properties: data: type: - object - 'null' additionalProperties: true source: type: string example: example.com tlp: type: string example: amber targetCountry: type: string example: US targetIndustry: type: string example: Insurance tlp: type: string example: amber required: - datasetId responses: '200': description: Returns the updated event. content: application/json: schema: type: object properties: attacker: type: string example: Flying Yeti attackerCountry: type: string example: CN attackerCountryAlpha3: type: string example: CHN category: type: string example: Domain Resolution datasetId: type: string example: dataset-example-id date: type: string example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com hasChildren: type: boolean indicator: type: string example: domain.com indicatorType: type: string example: domain indicatorTypeId: type: number example: 5 insight: type: string killChain: type: number mitreAttack: type: array items: example: ' ' type: string mitreCapec: type: array items: example: ' ' type: string numReferenced: type: number numReferences: type: number rawId: type: string example: 453gw34w3 referenced: type: array items: example: ' ' type: string referencedIds: type: array items: type: number references: type: array items: example: ' ' type: string referencesIds: type: array items: type: number releasabilityId: type: string tags: type: array items: example: malware type: string targetCountry: type: string example: US targetCountryAlpha3: type: string example: USA targetIndustry: type: string example: Agriculture tlp: type: string example: amber uuid: type: string example: 12345678-1234-1234-1234-1234567890ab required: - uuid - date - targetCountry - targetCountryAlpha3 - attacker - attackerCountry - attackerCountryAlpha3 - targetIndustry - rawId - indicatorTypeId - indicator - event - numReferenced - numReferences - tlp - category - indicatorType - referenced - references - tags - killChain - mitreAttack - mitreCapec - referencedIds - referencesIds - hasChildren - datasetId '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events x-fern-sdk-method-name: create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/{event_id}/raw/{raw_id}: get: operationId: get_EventRawRead summary: Reads data for a raw event description: Retrieves raw threat event data for a specific event in Cloudforce One. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string - name: raw_id in: path description: Raw Event UUID. required: true schema: description: Raw Event UUID. type: string responses: '200': description: Returns the raw event. content: application/json: schema: type: object properties: accountId: type: number example: 1234 created: type: string example: '1970-01-01T00:00:00Z' data: type: object id: type: string example: '1234' source: type: string example: https://example.com tlp: type: string example: amber required: - accountId - created - data - id - source - tlp '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events.raw x-fern-sdk-method-name: get x-forge-hidden: true patch: operationId: patch_EventRawUpdate summary: Updates a raw event description: Partially updates raw threat event data in Cloudforce One, modifying specific fields of the event. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string - name: raw_id in: path description: Raw Event UUID. required: true schema: description: Raw Event UUID. type: string requestBody: content: application/json: schema: type: object properties: data: type: object source: type: string example: example.com tlp: type: string example: amber responses: '200': description: Returns the uuid of the updated raw event and its data. content: application/json: schema: type: object properties: data: type: object id: type: string example: '1234' required: - id - data '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.threat-events.raw x-fern-sdk-method-name: edit x-forge-hidden: true post: operationId: post_EventRawUpdate summary: Updates a raw event parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string - name: raw_id in: path description: Raw Event UUID. required: true schema: description: Raw Event UUID. type: string requestBody: content: application/json: schema: type: object properties: data: type: object source: type: string example: example.com tlp: type: string example: amber responses: '200': description: Returns the uuid of the updated raw event and its data. content: application/json: schema: type: object properties: data: type: object id: type: string example: '1234' required: - id - data '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.raw x-fern-sdk-method-name: create x-forge-hidden: true /accounts/{account_id}/cloudforce-one/events/{event_id}/relationships: get: operationId: get_LegacyEventRelationships summary: Filter and list events related to specific event description: Deprecated; use GET /events/by-id/{event_id}/relationships. Available through 2026-11-28. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string - name: event_id in: path description: Event UUID. required: true schema: description: Event UUID. type: string - name: direction in: query description: The direction to traverse the graph. Defaults to 'both' to search all. schema: description: The direction to traverse the graph. Defaults to 'both' to search all. type: string default: both enum: - ancestors - descendants - both - name: maxDepth in: query description: The maximum depth to traverse. Defaults to 5. schema: description: The maximum depth to traverse. Defaults to 5. type: number - name: relationshipTypes in: query description: An optional array of relationship types to filter by. schema: description: An optional array of relationship types to filter by. anyOf: - type: string - items: type: string type: array - name: indicatorTypeIds in: query description: An optional array of indicator type IDs to filter the results by. schema: description: An optional array of indicator type IDs to filter the results by. type: array items: type: string - name: datasetId in: query description: The dataset ID to search within. required: true schema: description: The dataset ID to search within. type: string - name: includeParent in: query description: Whether to include the starting event in the results. Defaults to true. schema: description: Whether to include the starting event in the results. Defaults to true. type: boolean default: true - name: page in: query schema: type: number - name: pageSize in: query schema: type: number responses: '200': description: Returns a list of events related to the specified starting event. content: application/json: schema: type: array items: properties: attacker: type: string example: Flying Yeti attackerCountry: type: string example: CN attackerCountryAlpha3: type: string example: CHN category: type: string example: Domain Resolution datasetId: type: string example: dataset-example-id date: type: string example: '2022-04-01T00:00:00Z' event: type: string example: An attacker registered the domain domain.com hasChildren: type: boolean indicator: type: string example: domain.com indicatorType: type: string example: domain indicatorTypeId: type: number example: 5 insight: type: string killChain: type: number mitreAttack: type: array items: example: ' ' type: string mitreCapec: type: array items: example: ' ' type: string numReferenced: type: number numReferences: type: number rawId: type: string example: 453gw34w3 referenced: type: array items: example: ' ' type: string referencedIds: type: array items: type: number references: type: array items: example: ' ' type: string referencesIds: type: array items: type: number releasabilityId: type: string tags: type: array items: example: malware type: string targetCountry: type: string example: US targetCountryAlpha3: type: string example: USA targetIndustry: type: string example: Agriculture tlp: type: string example: amber uuid: type: string example: 12345678-1234-1234-1234-1234567890ab required: - uuid - date - targetCountry - targetCountryAlpha3 - attacker - attackerCountry - attackerCountryAlpha3 - targetIndustry - rawId - indicatorTypeId - indicator - event - numReferenced - numReferences - tlp - category - indicatorType - referenced - references - tags - killChain - mitreAttack - mitreCapec - referencedIds - referencesIds - hasChildren - datasetId type: object '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors deprecated: true security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write - Cloudforce One Read x-fern-availability: deprecated x-fern-sdk-group-name: cloudforce-one.events.relationships.legacy x-fern-sdk-method-name: get x-forge-hidden: true x-forge-sunset: date: '2026-11-28T00:00:00Z' x-stainless-deprecation-message: Use GET /events/by-id/{event_id}/relationships before 2026-11-28. /accounts/{account_id}/cloudforce-one/v2/events/graphql: post: operationId: post_EventGraphQLV2 summary: GraphQL endpoint for event aggregation description: Execute GraphQL aggregations over threat events. Supports multi-dimensional group-bys, optional date range filtering, and multi-dataset aggregation. parameters: - name: account_id in: path description: Account ID. required: true schema: description: Account ID. type: string responses: '200': description: GraphQL response payload (data and errors). content: application/json: schema: type: object properties: data: type: - object - 'null' errors: type: - array - 'null' items: type: object '400': description: Bad Request. content: application/json: schema: type: object properties: errors: type: array items: properties: message: type: string example: An error occurred. required: - message type: object result: type: object success: type: boolean required: - result - success - errors security: - api_token: [] tags: - Event x-api-token-group: - Cloudforce One Write x-fern-availability: generally-available x-fern-sdk-group-name: cloudforce-one.events.graphql.create.graph x-fern-sdk-method-name: qlv2 x-forge-hidden: true components: responses: cloudforce-one-events_ApiV4ClientError: description: Client error response. securitySchemes: api_email: in: header name: X-Auth-Email type: apiKey api_key: in: header name: X-Auth-Key type: apiKey api_token: scheme: bearer type: http user_service_key: in: header name: X-Auth-User-Service-Key type: apiKey externalDocs: description: Cloudflare Radar Documentation url: https://developers.cloudflare.com/radar/ x-forge-commands: abuse-reports: description: Submit and track abuse reports for phishing, malware, and other policy violations on Cloudflare-proxied sites groups: appeals: description: Appeal eligibility for abuse reports emails: description: Emails sent for abuse reports mitigations: description: Mitigation actions taken in response to abuse reports accounts: description: Account settings, members, roles, subscriptions, and API tokens for your Cloudflare account groups: applications: description: Applications operations categories: description: Categories operations organizations: description: Move accounts between organizations profile: description: View and manage the profile for a Cloudflare account roles: description: View the roles available for assigning to account members, each defining a set of permissions subscriptions: description: View and manage plan subscriptions attached to this account tokens: description: Create and manage scoped API tokens for programmatic access to the Cloudflare API ai-gateway: description: Proxy, cache, rate-limit, and observe requests to AI providers — OpenAI, Anthropic, Workers AI, and more groups: custom-domains: description: Manage custom hostnames that route requests through an AI Gateway custom-providers: description: Manage account-level custom AI providers and their endpoint settings datasets: description: 'Deprecated: manage filtered collections of gateway logs used by evaluations' dynamic-routing: description: Route requests across multiple AI providers with fallback, load-balancing, and versioned deployments dynamic-routing.deployments: description: Deploy dynamic route versions and view deployment history dynamic-routing.versions: description: Create and inspect saved versions of a dynamic route evaluation-types: description: 'Deprecated: list the evaluator types that evaluations can use' evaluations: description: 'Deprecated: score the logs in a dataset with selected evaluator types' gateways: description: Create and configure AI Gateways for an account gateways.providers: description: Store and rotate upstream AI provider keys for a gateway logs: description: Inspect, annotate, and delete gateway request logs stored by Legacy Logs ai-search: description: 'Managed search-as-a-service: crawl, index, and query content with AI-powered relevance and chat completions' groups: items: description: Content indexed by AI Search instances jobs: description: Indexing job lifecycle for AI Search instances namespace: description: Logical groupings for organizing AI Search instances tokens: description: Credentials used by AI Search instances ai-security: description: Detect prompt injection, PII, and unsafe topics in traffic to your AI applications groups: custom-topics: description: Organization-specific topic categories used by AI Security for Apps content detection analytics: description: Zone-level traffic analytics — dashboard summaries, per-colo breakdowns, and Argo latency metrics groups: colo: description: Per-data-center (colo) traffic analytics breakdown for the zone dashboard: description: Aggregated zone dashboard analytics — requests, bandwidth, threats, and page views latency: description: Argo Smart Routing latency analytics showing time-to-first-byte improvements argo: description: Network optimization features that speed up and improve reliability of traffic to your origins groups: smart-routing: description: Route traffic through the fastest network paths to your origin using real-time latency data tiered-caching: description: Reduce origin load by having upper-tier data centers serve cache misses before reaching your origin basin-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables billing: description: Account billing profiles and usage data for Cloudflare subscriptions and add-on services groups: profiles: description: Billing profile with payment method, address, and invoice preferences usage: description: Metered usage data for billed services — requests, bandwidth, and feature consumption botnet-feed: description: Botnet threat intelligence feeds — IP and ASN-level data on known command-and-control infrastructure groups: asn: description: ASN-level botnet activity data showing networks with known C2 infrastructure configs: description: Botnet feed subscription configuration and notification preferences builds: description: Build and deploy Workers from connected repositories, then inspect build status and logs. groups: deploy-hooks: description: Manage branch-specific HTTP hooks that start builds. limits: description: View build-minute availability and refresh information. logs: description: Retrieve build logs. repos: description: Manage source repository connections for Workers Builds. tokens: description: Manage credentials used by Workers Builds to deploy Workers. triggers: description: Configure how repository changes build and deploy Workers. versions: description: Find builds associated with Worker versions. workers: description: Manage repository-backed build configuration for Workers. cache: description: Purge cached content and configure Cache Reserve, tiered caching, and variant serving groups: origin-cloud-regions: description: Manage Origin Cloud Regions routing and failover configurations settings: description: Configure Cache Reserve, tiered caching, and variant serving settings.regional-tiered-cache: description: Restrict tiered cache topology to data centers within a specific geographic region settings.reserve: description: Persistent storage tier that keeps cached assets even after eviction from edge caches settings.smart-tiered-cache: description: Automatically determine the best upper-tier data centers for tiered cache topology settings.variants: description: Serve different cached versions of an image based on the Accept header (WebP, AVIF, etc.) client-side-security: description: Client-Side Security — monitor JavaScript, connections, and cookies on your pages for supply-chain attacks groups: connections: description: Third-party connections made by scripts on your pages — track data exfiltration risks cookies: description: Cookies set by your pages with classification and same-site attribute tracking policies: description: Content Security Policies that control which scripts and connections are allowed on your pages scripts: description: JavaScript files detected on your pages with change tracking and malicious code detection settings: description: Fine tune Client-Side Security behaviors cloud-connector: description: Route traffic from Cloudflare directly to cloud provider services (AWS, Azure, GCP) without origin servers groups: rules: description: Routing rules that map request patterns to cloud provider endpoints cloudforce-one: description: Detection rule management APIs groups: binary-storage: description: Upload and retrieve malware samples and suspicious binaries for analysis requests: description: Additional request operations — priority listing and asset creation rules: description: Rule management operations groups: approvals: description: Approval workflow operations email: description: Email rule operations exemptions: description: Exemption rule operations managed: description: Managed rule operations stats: description: Rule statistics operations tree: description: Rule navigation tree operations scans: description: Scan URLs, IPs, and domains for threat intelligence indicators containers: description: Deploy and manage Containers applications on Cloudflare's global network groups: applications: description: Manage Containers applications applications.instances: description: Inspect Containers instances belonging to applications applications.rollouts: description: Manage rollouts for scheduler-backed applications applications.versions: description: Inspect versions of scheduler-backed applications registries: description: Manage Containers image registries registries.credentials: description: Generate image registry credentials content-scan: description: Malicious uploads detection, scan uploaded content in HTTP requests for malware and malicious payloads groups: expressions: description: Custom expressions that tell the scanner how to reach content objects it cannot parse on its own custom-pages: description: Manage custom error and challenge pages and their assets for accounts and zones groups: account-custom-pages: description: Manage account-level custom pages account-custom-pages.preview-tokens: description: Preview tokens for account-level custom pages assets: description: Manage account- and zone-level custom assets zone-custom-pages: description: Manage zone-level custom pages zone-custom-pages.preview-tokens: description: Preview tokens for zone-level custom pages d1: description: D1 is Cloudflare's managed, serverless database with SQLite's SQL semantics, built-in disaster recovery, and Worker and HTTP API access. groups: time-travel: description: use specific point-in-time backups of your D1 database x-forge-epilogue: For more information about Time Travel, see https://developers.cloudflare.com/d1/reference/time-travel diagnostics: description: Network diagnostic tools — traceroutes from Cloudflare's edge and endpoint health checks groups: endpoint-healthchecks: description: Monitor external endpoint availability with periodic HTTP/HTTPS health checks traceroutes: description: Run traceroutes from Cloudflare data centers to diagnose network path issues email-routing: description: Route incoming email to verified destination addresses or Workers with routing rules, catch-all behavior, and managed DNS records groups: addresses: description: Verified destination email addresses that can receive forwarded mail dns: description: Inspect or unlock the DNS records required by Email Routing rules: description: Match incoming email addresses and forward messages to destination mailboxes or Workers settings: description: Inspect and update Email Routing settings email-security: description: Cloud email security — investigate threats, manage allow/block policies, and detect phishing groups: analytics: description: Analytics and reporting — monthly report and per-day breakdowns of threat activity bulk-actions: description: Asynchronous jobs that move or release every message matching a search — create, monitor, and manage bulk jobs investigate: description: Search and investigate email messages — view detections, traces, raw content, and take remediation actions phishguard: description: PhishGuard user-reported phishing reports — view detected threats for a date range settings: description: Email security configuration — block senders, allow policies, content policies, domains, trusted domains, impersonation registry, and URL handling submissions: description: Reclassify submissions — track user and team reports of false positives and missed detections email-sending: description: Send transactional email and manage sending subdomains and their DNS configuration groups: limits: description: Inspect account-level sending quotas and current usage subdomains: description: Configure sending subdomains and keep their DNS records healthy suppressions: description: Prevent delivery to suppressed addresses and manage the account suppression list filters: description: Filter expressions used by legacy firewall rules to match requests — prefer Rulesets for new configurations firewall: description: Legacy firewall rules, zone lockdowns, access rules, user-agent blocking, and WAF packages groups: access-rules: description: IP-based access rules that allow, block, challenge, or whitelist traffic globally or per-zone lockdowns: description: Zone lockdown rules that restrict access to URLs by IP address or range rules: description: Legacy firewall rules with filter expressions — prefer Rulesets for new configurations ua-rules: description: Block or challenge requests based on the User-Agent header string waf: description: Legacy WAF managed rule packages, rule groups, individual rules, and override configurations zone-access-rules: description: Zone-scoped IP access rules for blocking or allowing traffic google-tag-gateway: description: Google Tag Gateway operations groups: config: description: Google Tag Gateway config operations healthchecks: description: Standalone health checks that monitor origin server availability from Cloudflare's edge groups: previews: description: Test a health check configuration before deploying it to production hyperdrive: description: Accelerate access to existing databases by caching queries and pooling connections at the edge iam: description: Identity and access management — permission groups, resource groups, user groups, and SSO connectors groups: permission-groups: description: View the permission groups that can be assigned to API tokens and policies resource-groups: description: Define scopes that limit which account resources a policy or token can access sso: description: Configure single sign-on connectors to authenticate account members through an external identity provider user-groups: description: Organize account members into groups for easier permission assignment images: description: Store, resize, and deliver optimized images globally — variants, signing keys, and direct uploads groups: flows: description: Zone-level transformation flows that control how images are resized and optimized on delivery import: description: Import images from S3 keys: description: Manage signing keys for generating private image URLs variants: description: Manage named resize variants for transforming images on delivery intel: description: Threat intelligence lookups — IP reputation, domain info, ASN details, WHOIS, and indicator feeds groups: asn: description: ASN intelligence — ownership, geolocation, and subnet details for autonomous systems attack-surface-report: description: Attack surface intelligence — exposed assets, vulnerabilities, and infrastructure mapping dns: description: Passive DNS data showing historical DNS resolution records for domains domain-history: description: Historical domain registration and categorization changes over time domains: description: Domain intelligence — risk scores, categories, and associated infrastructure indicator-feeds: description: Threat indicator feeds — subscribe to and manage curated lists of malicious IPs, domains, and URLs ip-lists: description: Curated IP lists used for threat detection and policy enforcement ips: description: IP address intelligence — geolocation, risk assessment, and hosting provider details miscategorizations: description: Report and track domain miscategorization corrections whois: description: WHOIS registration data for domains including registrant, registrar, and nameservers k2: description: Durable, ordered event streams that you produce records to and consume from with subscriptions groups: streams: description: K2 streams, their retention, and the HTTP and Workers binding inputs used to produce records streams.subscriptions: description: Subscriptions that consume a K2 stream, with committed-position lag leaked-credential-checks: description: Detect compromised credentials in login requests by checking against known breach databases groups: detections: description: Custom detection locations that tell the WAF where to find usernames and passwords in requests load-balancers: description: Distribute traffic across origin pools with health monitoring, geo-steering, and failover groups: monitor-groups: description: Group monitors together for shared configuration and bulk management monitor-groups.references: description: List references to monitor groups used by load balancer pools monitors: description: Health check configurations that probe origin servers and determine pool availability monitors.previews: description: Health check configurations that probe origin servers and determine pool availability monitors.references: description: Health check configurations that probe origin servers and determine pool availability pools: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.health: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences pools.references: description: Origin server pools with weighted traffic distribution, health thresholds, and geographic preferences previews: description: Preview the result of a health check monitor configuration before applying it regions: description: Geographic regions used for regional pool steering and traffic policies searches: description: Search across all load balancer resources (pools, monitors, load balancers) by name or reference logs: description: Log control, retention, and raw log access — CMB config, ray ID lookups, and received fields groups: control: description: Log control operations received: description: Received log operations magic-network-monitoring: description: Flow-based network traffic monitoring with configurable alerting rules and VPC flow ingestion groups: configs: description: Account-level monitoring configuration — sampling rates, thresholds, and notification settings rules: description: Monitoring rules that define traffic thresholds and trigger alerts or prefix advertisements vpc-flows: description: Ingest VPC flow logs from cloud providers for network visibility and anomaly detection magic-transit: description: DDoS-protected network transit — GRE/IPsec tunnels, static routes, Magic WAN sites, connectors, and packet captures groups: advanced-dns-protection: description: Advanced Dns Protection operations advanced-tcp-protection: description: Advanced Tcp Protection operations apps: description: Application-aware traffic policies for Magic WAN that steer traffic by app type bgp-filter-profiles: description: BGP filter profiles for controlling which routes are allowed or denied on Magic Transit tunnels bgp-settings: description: BGP settings for controlling default ASN and route redistribution on Magic Transit tunnels cf-interconnects: description: Cloudflare Network Interconnect (CNI) links for direct physical or virtual peering gre-tunnels: description: GRE tunnel endpoints that connect your network to Cloudflare for Magic Transit ipsec-tunnels: description: IPsec tunnel endpoints with pre-shared key management for encrypted transit pcaps: description: Packet capture requests for debugging traffic flowing through Magic Transit tunnels routes: description: Static routes that direct IP prefix traffic through specific GRE/IPsec tunnels sites: description: Magic WAN branch sites — base CRUD, LAN/WAN interface configuration, ACLs, connectors, app configuration, and NetFlow config mcp: description: Manage MCP portals and upstream MCP servers for Cloudflare Access AI controls groups: portals: description: Manage MCP portals, attached servers, and Code Mode settings servers: description: Manage upstream MCP servers, credentials, capabilities, and sync state network-interconnects: description: Physical and virtual private interconnects between your infrastructure and Cloudflare's network groups: cnis: description: Cloud Network Interconnect (CNI) connections — private links from cloud providers to Cloudflare interconnects: description: Physical cross-connect and partner interconnect sessions with LOA and status tracking settings: description: Account-level interconnect settings and default configurations slots: description: Available interconnect facility slots showing port capacity at Cloudflare data centers organizations: description: Multi-user organizations that group accounts, members, and shared settings under a single entity groups: account-organizations: description: List organizations associated with a specific account accounts: description: Accounts operations members: description: Members operations members-batch-create: description: Members Batch Create operations organization-profile: description: View and update the public profile information for an organization shares: description: Shares operations origin-post-quantum-encryption: description: Enable post-quantum key exchange for connections between Cloudflare and your origin server pages: description: Full-stack application hosting with Git-integrated builds, preview deployments, and custom domains groups: projects: description: Pages projects, deployments, build logs, and custom domain bindings pipelines: description: Ingest, transform, and route event streams into R2, analytics, or other destinations in real time groups: sinks: description: Destinations where pipeline data is written — R2 buckets, HTTP endpoints, or other storage streams: description: Inbound data streams that feed events into a pipeline for processing precursor: description: Precursor settings for a zone queues: description: Reliable message queuing between Workers — produce, consume, and batch-process messages at scale groups: consumers: description: Workers that automatically receive and process messages from a queue messages: description: Push messages to a queue and pull or acknowledge them from consumers purge: description: Remove all pending messages from a queue subscriptions: description: Manage queue subscriptions for event-driven message routing r2: description: S3-compatible object storage with zero egress fees — buckets, lifecycle rules, event notifications, and data migration groups: buckets: description: Create and configure R2 buckets including CORS, lifecycle, custom domains, event notifications, and object locks buckets.jobs: description: Create and inspect background jobs for an R2 bucket buckets.local-uploads: description: R2 bucket local upload configuration super-slurper: description: Migrate data from external S3-compatible storage into R2 buckets with resumable transfer jobs temporary-credentials: description: Generate short-lived S3-compatible credentials scoped to specific buckets and operations r2-data-catalog: description: Iceberg-compatible data catalog for R2 — organize objects into tables and namespaces for SQL query engines groups: credentials: description: Catalog access credentials for external query engines (Spark, Trino, etc.) maintenance-configs: description: Table maintenance settings — compaction schedules and snapshot expiration policies namespaces: description: Logical namespaces that group related tables within the data catalog namespaces.tables: description: Tables within catalog namespaces namespaces.tables.maintenance-configs: description: Table-level maintenance configurations and operations namespaces.tables.maintenance-runs: description: History of maintenance runs performed on tables radar: description: Internet-wide traffic intelligence — BGP, DNS, HTTP trends, attack data, and network quality insights groups: agent-readiness: description: Agent readiness summary statistics across the Cloudflare network ai: description: AI inference trends and model usage statistics across the Cloudflare network annotations: description: Radar annotations marking significant Internet events (outages, cable cuts, etc.) as112: description: AS112 DNS sinkhole statistics — reverse DNS query volumes for private address space attacks: description: DDoS and application-layer attack trends, vectors, and target analysis bgp: description: BGP routing data — prefix announcements, AS-level stats, route leaks, and hijack events bots: description: Internet-wide bot traffic trends, categories, and distribution statistics ct: description: Certificate Transparency log monitoring and newly-issued certificate discovery datasets: description: Downloadable Radar datasets for offline analysis and research dns: description: Global DNS query trends — top domains, resolver stats, and DNSSEC adoption email: description: Email security trends — DMARC/SPF/DKIM adoption, spam, and phishing statistics entities: description: Look up ASNs, IPs, domains, and locations with metadata and traffic summaries geolocations: description: Geographic location metadata used for regional traffic analysis http: description: HTTP protocol trends — TLS versions, HTTP versions, browser share, and OS distribution leaked-credentials: description: Leaked credential detection trends and exposure statistics netflows: description: Network-layer traffic flow data and volumetric trend analysis origins: description: Cloud and hosting origin providers (e.g. Amazon, by region) and their traffic metrics post-quantum: description: Post-quantum encryption adoption and deployment trends across the Internet quality: description: Internet connection quality metrics — speed, latency, and jitter by geography and ASN ranking: description: Top domain rankings based on DNS query popularity across the Cloudflare network robots-txt: description: Robots.txt adoption and crawler directive trends across the web search: description: Search Radar data across IPs, ASNs, domains, and locations tcp-resets-timeouts: description: TCP connection reset and timeout statistics indicating network health issues tlds: description: Top-level domain (TLD) metadata and performance trends traffic-anomalies: description: Detected traffic anomalies and unusual patterns in Internet traffic flows verified-bots: description: Catalog of known good bots (Googlebot, Bingbot, etc.) and their traffic patterns rate-limits: description: Legacy per-zone rate limiting rules — prefer Advanced Rate Limiting in Rulesets for new configurations realtime: description: Real-time audio, video, and data services on Cloudflare's global network groups: kit: description: SDK-backed meetings, participants, recordings, livestreams, and webhooks kit.analytics: description: Usage and livestream analytics for RealtimeKit applications kit.analytics.livestreams: description: Livestream analytics for RealtimeKit applications kit.analytics.livestreams.daily: description: Daily livestream analytics for RealtimeKit applications kit.analytics.usage: description: Usage analytics for RealtimeKit applications kit.apps: description: RealtimeKit applications that group meetings, sessions, and configuration kit.livestreams: description: Independent and meeting-based livestreams and their sessions kit.livestreams.sessions: description: Sessions for RealtimeKit livestreams kit.meetings: description: Meetings, participants, access tokens, and meeting livestreams kit.meetings.active: description: Live meeting state and participant controls kit.meetings.active.polls: description: Polls for active meeting sessions kit.meetings.livestream: description: Livestream operations associated with RealtimeKit meetings kit.meetings.participants: description: Participants in RealtimeKit meetings kit.meetings.participants.tokens: description: Access tokens for RealtimeKit meeting participants kit.presets: description: Reusable meeting configuration for media, permissions, and interface behavior kit.recordings: description: Meeting and participant-track recordings and recording controls kit.recordings.active: description: Active recordings for RealtimeKit meetings kit.recordings.tracks: description: Participant-track recordings for RealtimeKit meetings kit.sessions: description: Historical session data, participants, chat, transcripts, and summaries kit.sessions.chat: description: Chat messages from historical RealtimeKit sessions kit.sessions.livestreams: description: Livestreams associated with historical RealtimeKit sessions kit.sessions.participants: description: Participants in historical RealtimeKit sessions kit.sessions.peers: description: Peer details from historical RealtimeKit sessions kit.sessions.summaries: description: Summaries of historical RealtimeKit sessions kit.sessions.transcripts: description: Transcripts from historical RealtimeKit sessions kit.webhooks: description: Webhook endpoints and supported events for RealtimeKit notifications kit.webhooks.events: description: Supported events for RealtimeKit webhooks moq: description: MoQ relays for publishing and subscribing to media streams moq.relays: description: Relays are isolated MoQ scopes that carry media between publishers and subscribers moq.relays.tokens: description: Tokens that authorize publishers and subscribers to connect to a relay sfu: description: SFU apps that route WebRTC media and data between participants sfu.apps: description: SFU application namespaces for sessions and tracks turn: description: TURN keys that help clients traverse NATs and firewalls turn.keys: description: Keys used to generate short-lived TURN credentials request-tracers: description: Trace how a request would be processed through Cloudflare's rules and configuration pipeline groups: traces: description: Simulate request processing to debug rule matches, transforms, and routing decisions resource-sharing: description: Share Cloudflare resources (zones, accounts) across organizations with granular access controls groups: recipients: description: Update share recipients resources: description: Individual resources (zones, configs) that have been shared with recipients rules: description: Resources used by Cloudflare rules and rulesets groups: lists: description: Custom account-level lists of IPs, hostnames, ASNs, or redirects used in rule expressions rum: description: Real User Measurement (Web Analytics) — track page loads, Core Web Vitals, and visitor metrics groups: rules: description: Rules that control which pages and paths are tracked by Web Analytics site-info: description: Web Analytics sites — register domains and get the JavaScript beacon snippet scim: description: SCIM 2.0 provisioning — manage users, groups, and identity provider sync for your account groups: groups: description: Groups operations resource-types: description: Resource Types operations schemas: description: Schemas operations service-provider-config: description: Service Provider Config operations users: description: Users operations secrets-store: description: Centralized secret management — store API keys, tokens, and credentials for use across Workers and other products groups: quota: description: Account quota limits for secrets stores, secrets count, and storage capacity secrets: description: Encrypted key-value secrets within a store. Pass --store-id to scope. stores: description: Secret stores that hold encrypted key-value secrets accessible by Workers and services security-center: description: Security posture dashboard — view and manage security insights, misconfigurations, and vulnerabilities groups: insights: description: Security findings and recommendations across your account — DNS, SSL, WAF misconfigurations, etc. zone-insights: description: Zone-scoped security insights — counts by class, severity, type, and dismissal security-txt: description: Manage the /.well-known/security.txt file that tells security researchers how to report vulnerabilities smart-shield: description: Smart Shield settings, health checks, and cache reserve management groups: cache-reserve-clear: description: Cache Reserve Clear operations health-checks: description: Health checks operations spectrum: description: Proxy and protect arbitrary TCP/UDP applications through Cloudflare's network with DDoS mitigation groups: analytics: description: Real-time and historical connection analytics for Spectrum applications apps: description: Spectrum application configurations that map protocols and ports to origin servers speed: description: Observatory speed tests — run Lighthouse audits, track performance trends, and schedule recurring tests groups: availabilities: description: Check which speed test regions and configurations are available for your zone pages: description: Tested pages with their performance history, trends, and individual test results schedule: description: Scheduled recurring speed tests that automatically run at regular intervals ssl: description: SSL/TLS certificate management — certificate packs, Universal SSL, verification, and TLS mode recommendations groups: automatic-upgrader: description: SSL automatic mode enrollment — get or update automatic SSL/TLS upgrader settings recommendations: description: Get the recommended SSL/TLS encryption mode based on your origin server's certificate configuration stream: description: Video encoding, storage, and delivery — upload, live-stream, clip, caption, and embed video at scale groups: audio-tracks: description: Add, edit, or remove additional audio tracks on a video captions: description: Upload, generate, or retrieve captions and subtitles for videos in multiple languages clip: description: Create a new video clip from an existing video by specifying start and end times copy: description: Import a video from a URL into Stream for processing and delivery direct-upload: description: Generate a tokenized URL that lets end-users upload video directly to Stream downloads: description: Create downloadable MP4 renditions of a video for offline viewing embed: description: Retrieve the HTML embed code snippet for a video keys: description: Signing keys used to generate short-lived signed URLs for private video playback live-inputs: description: Enable and disable live input streams token: description: Generate short-lived signed URL tokens for secure private video playback typed-downloads: description: Type-specific stream download creation and deletion videos: description: Aggregate video storage usage statistics for the account watermarks: description: Watermark profiles that overlay an image on every video in the account webhooks: description: Webhook notifications for video lifecycle events (ready, error, etc.) tenants: description: Multi-tenant account management — manage tenant accounts, entitlements, and memberships groups: account-types: description: Account Types operations accounts: description: Accounts operations entitlements: description: Entitlements operations memberships: description: Memberships operations turnstile: description: CAPTCHA-free bot verification widgets that protect forms and APIs without degrading user experience groups: widgets: description: Turnstile widget configurations — site keys, secret rotation, and challenge mode settings url-scanner: description: Scan URLs for phishing, malware, and other threats — submit scans and retrieve detailed results groups: response: description: Response operations responses: description: Raw HTTP response data captured during URL scans scan: description: Scan operations scans: description: URL scan requests and results — submit URLs for analysis and retrieve threat verdicts user: description: Your Cloudflare user profile, invitations, organizations, billing, and personal API tokens groups: billing: description: View billing history and payment profile for your user (deprecated — prefer account-level billing) firewall: description: Firewall operations load-balancers.monitors: description: Load Balancers operations load-balancers.monitors.preview: description: Load Balancers operations load-balancers.monitors.references: description: Load Balancers operations load-balancers.pools: description: Load Balancers operations load-balancers.pools.edit.pools: description: Load Balancers operations load-balancers.pools.health: description: Load Balancers operations load-balancers.pools.preview: description: Load Balancers operations load-balancers.pools.references: description: Load Balancers operations load-balancers.preview: description: Load Balancers operations load-balancing-analytics.events: description: Load Balancing Analytics operations subscriptions: description: View and manage zone-level plan subscriptions owned by your user tenants: description: Tenants operations tokens: description: Create and manage personal API tokens scoped to your user for programmatic API access user.analytics: description: User-level traffic analytics — aggregated totals and timeseries across all zones vectorize: description: Globally distributed vector database for building semantic search, recommendations, and RAG applications on Workers groups: deprecated-indexes: description: Deprecated v1 Vectorize index operations metadata-index: description: Metadata indexes for filtered vector search waiting-rooms: description: Virtual queues that throttle traffic to your site during peak demand with customizable waiting pages groups: account-waiting-rooms: description: Account-scoped waiting room listing events: description: Scheduled events that temporarily override waiting room settings for sales, launches, etc. page: description: Custom HTML waiting page templates and preview rendering rules: description: Rules that bypass or modify waiting room behavior for specific request patterns settings: description: Zone-level waiting room defaults and cookie configuration statuses: description: Real-time queue status showing active users, queued users, and estimated wait times workflows: description: Durable, multi-step workflows that run on Workers with automatic retries and state persistence groups: instances: description: Workflow instance operations versions: description: Workflow version operations zaraz: description: Server-side tag manager — load third-party tools (analytics, pixels, etc.) from Cloudflare's edge without client-side JS groups: config: description: Full Zaraz configuration including tools, triggers, and variables for the zone default: description: Default Zaraz configuration template used as a starting point for new zones export: description: Export the current Zaraz configuration as a portable JSON document history: description: Configuration version history — browse and restore previous Zaraz configurations publish: description: Publish pending Zaraz configuration changes to make them live on the zone workflow: description: Workflow state for Zaraz configuration changes (draft vs. published) zero-trust: description: Cloudflare's SASE platform — secure access, device posture, DLP, tunnels, gateway policies, and network segmentation groups: dex: description: Digital Experience Monitoring — synthetic tests, fleet-wide device metrics, and network path diagnostics dlp.custom-prompt-topics: description: Data Loss Prevention - manage custom prompt topics for AI-based content detection dlp.data-classes: description: Data Loss Prevention - manage data classes used to classify sensitive information dlp.data-tag-categories: description: Data Loss Prevention - manage categories that organize data tags dlp.data-tag-category-templates: description: Data Loss Prevention - browse templates for creating data tag categories dlp.data-tags: description: Data Loss Prevention - manage tags used to classify and organize sensitive data dlp.datasets: description: Data Loss Prevention - manage datasets, versions, and uploads dlp.document-fingerprints: description: Data Loss Prevention - manage document fingerprints for detecting matching documents dlp.email.account-mapping: description: Data Loss Prevention - configure account mappings for outbound email scanning dlp.email.rules: description: Data Loss Prevention - manage outbound email scanning rules and their priorities dlp.entries: description: Data Loss Prevention - list and manage detection entries dlp.limits: description: Data Loss Prevention - view account limits and resource quotas dlp.patterns: description: Data Loss Prevention - validate regular expressions used for content detection dlp.profiles: description: Data Loss Prevention - list and retrieve profiles dlp.profiles.custom: description: Data Loss Prevention - manage custom profiles dlp.profiles.predefined: description: Data Loss Prevention - manage predefined profiles dlp.sensitivity-group-templates: description: Data Loss Prevention - browse templates for creating sensitivity groups dlp.sensitivity-groups: description: Data Loss Prevention - manage sensitivity groups and their level ordering dlp.sensitivity-levels: description: Data Loss Prevention - manage sensitivity levels within sensitivity groups dlp.settings: description: Data Loss Prevention - manage account-level settings dlp.validators: description: Data Loss Prevention - list and retrieve content validators dlp.validators.proximity-words: description: Data Loss Prevention - manage proximity-word validators risk-scoring: description: User Risk Scoring - retrieve and reset user risk scores risk-scoring.behaviours: description: User Risk Scoring - manage behaviors used to calculate user risk scores risk-scoring.integrations: description: User Risk Scoring - manage integrations that provide risk score signals risk-scoring.integrations.references: description: User Risk Scoring - retrieve integrations by external reference risk-scoring.summary: description: User Risk Scoring - retrieve account risk score summaries zones: description: Zones are domains on Cloudflare — list, create, and configure domain settings groups: aegis: description: Aegis operations fonts: description: Fonts operations origin-h2-max-streams: description: Origin H2 Max Streams operations origin-max-http-version: description: Origin Max Http Version operations origin-tls-compliance-modes: description: Manage zone Origin TLS Compliance Modes setting rum: description: Rum operations speed-brain: description: Speed Brain operations