openapi: 3.1.0 info: title: Cribl As Code API Credentials Edge Sources API description: The Cribl As Code API enables developers to manage Cribl configurations programmatically using infrastructure-as-code principles. The management plane API provides endpoints for administrative tasks in Cribl Cloud including managing organizations, workspaces, and API credentials. Developers can use this API alongside SDKs for Python, Go, and TypeScript, or through Terraform providers, to onboard sources, build and maintain pipelines, and standardize workflows at scale. The management plane supports creating and configuring Cribl Cloud workspaces, managing API credentials, and controlling access to organizational resources. version: '1.0' contact: name: Cribl Support url: https://cribl.io/support/ termsOfService: https://cribl.io/terms-of-service/ servers: - url: https://gateway.cribl.cloud description: Cribl Cloud Management Plane security: - bearerAuth: [] tags: - name: Edge Sources description: Manage data input sources on edge nodes including file monitors, Windows Event Log, system metrics, AppScope, and other local collection methods. paths: /m/{fleetId}/system/sources: get: operationId: listEdgeSources summary: List edge sources in a fleet description: Retrieves all data input sources configured for an edge fleet including file monitors, Windows Event Log, system metrics, AppScope, and other local collection sources. tags: - Edge Sources parameters: - $ref: '#/components/parameters/fleetId' responses: '200': description: Successfully retrieved edge sources content: application/json: schema: type: object properties: items: type: array items: $ref: '#/components/schemas/EdgeSource' count: type: integer description: Total number of sources '401': description: Unauthorized '404': description: Fleet not found post: operationId: createEdgeSource summary: Create an edge source in a fleet description: Creates a new data input source for an edge fleet to collect data from endpoints. tags: - Edge Sources parameters: - $ref: '#/components/parameters/fleetId' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/EdgeSource' responses: '200': description: Edge source created successfully content: application/json: schema: $ref: '#/components/schemas/EdgeSource' '400': description: Invalid source configuration '401': description: Unauthorized components: schemas: EdgeSource: type: object properties: id: type: string description: Unique identifier for the edge source type: type: string description: The source type such as file_monitor, windows_event_log, system_metrics, appscope, syslog, or journald disabled: type: boolean description: Whether the source is disabled description: type: string description: A human-readable description pipeline: type: string description: The pipeline to process events streamtags: type: array items: type: string description: Tags applied to events from this source parameters: fleetId: name: fleetId in: path required: true description: The edge fleet identifier schema: type: string securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: Bearer token obtained via OAuth 2.0 client credentials grant from https://login.cribl.cloud/oauth/token. Tokens expire after 24 hours (86400 seconds). oauth2: type: oauth2 description: OAuth 2.0 client credentials flow for Cribl Cloud management plane authentication. flows: clientCredentials: tokenUrl: https://login.cribl.cloud/oauth/token scopes: {} externalDocs: description: Cribl As Code Documentation url: https://docs.cribl.io/cribl-as-code/api/