openapi: 3.2.0 info: title: Sumo Logic Content Management API description: '# Getting Started Welcome to the Sumo Logic API reference.' version: 1.0.0 x-logo: url: ./sumologic_logo.png servers: - url: https://api.au.sumologic.com/api/ description: AU deployment API server - url: https://api.ca.sumologic.com/api/ description: CA deployment API server - url: https://api.de.sumologic.com/api/ description: DE deployment API server - url: https://api.eu.sumologic.com/api/ description: EU deployment API server - url: https://api.fed.sumologic.com/api/ description: FED deployment API server - url: https://api.jp.sumologic.com/api/ description: JP deployment API server - url: https://api.kr.sumologic.com/api/ description: KR deployment API server - url: https://api.in.sumologic.com/api/ description: IN deployment API server - url: https://api.sumologic.com/api/ description: US1 deployment API server - url: https://api.us2.sumologic.com/api/ description: US2 deployment API server security: - basicAuth: [] tags: - name: Content Management description: Content management API. x-displayName: Content paths: /v2/content/path: get: tags: - Content Management summary: Get Content Item By Path description: 'Get a content item corresponding to the given path. _Path is specified in the required query parameter `path`. The path should be URL encoded._ For example, to get "Acme Corp" folder of a user "user@sumo.com" you can use the following curl command: ```bash curl https://api.sumologic.com/api/v2/content/path?path=/Library/Users/user%40sumo.com/Acme%20Corp ``` The absolute path to a content item should be specified to get the item. The content library has "Library" folder at the root level. For items in "Personal" folder, the base path is "/Library/Users/user@sumo.com" where "user@sumo.com" is the email address of the user. For example if a user with email address `wile@acme.com` has `Rockets` folder inside Personal folder, the path of Rockets folder will be `/Library/Users/wile@acme.com/Rockets`. For items in "Admin Recommended" folder, the base path is "/Library/Admin Recommended". For example, given a folder `Acme` in Admin Recommended folder, the path will be `/Library/Admin Recommended/Acme`.' operationId: getItemByPath parameters: - name: path in: query description: Path of the content item to retrieve. required: true schema: type: string example: /Library/Users/user@sumo.com/SampleFolder responses: '200': description: Content item corresponding to the given path. content: application/json: schema: $ref: '#/components/schemas/Content' default: description: Operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/{contentId}/path: get: tags: - Content Management summary: Get Path Of An Item description: Get full path of a content item with the given identifier. operationId: getPathById parameters: - name: contentId in: path description: Identifier of the content item to get the path. required: true schema: type: string responses: '200': description: Full path of the content item. content: application/json: schema: $ref: '#/components/schemas/ContentPath' default: description: Operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/{id}/export: post: tags: - Content Management summary: Start A Content Export Job description: 'Schedule an _asynchronous_ export of content with the given identifier. You will get back an asynchronous job identifier on success. Use the getAsyncExportStatus endpoint and the job identifier you got back in the response to track the status of an asynchronous export job. If the content item is a folder, everything under the folder is exported recursively. Keep in mind when exporting large folders that there is a limit of 1000 content objects that can be exported at once. If you want to import more than 1000 content objects, then be sure to split the import into batches of 1000 objects or less. The results from the export are compatible with the Library import feature in the Sumo Logic user interface as well as the API content import job.' operationId: beginAsyncExport parameters: - name: id in: path description: The identifier of the content item to export. Identifiers from the Library in the Sumo user interface are provided in decimal format which is incompatible with this API. The identifier needs to be in hexadecimal format. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string responses: '200': description: Export job has been scheduled. content: application/json: schema: $ref: '#/components/schemas/BeginAsyncJobResponse' default: description: Operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/{contentId}/export/{jobId}/status: get: tags: - Content Management summary: Content Export Job Status description: Get the status of an asynchronous content export request for the given job identifier. On success, use the getExportResult endpoint to get the result of the export job. operationId: getAsyncExportStatus parameters: - name: contentId in: path description: The identifier of the exported content item. required: true schema: type: string - name: jobId in: path description: The identifier of the asynchronous export job. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string responses: '200': description: The status of the export job. content: application/json: schema: $ref: '#/components/schemas/AsyncJobStatus' default: description: Operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/{contentId}/export/{jobId}/result: get: tags: - Content Management summary: Content Export Job Result description: Get results from content export job for the given job identifier. The results from this export are incompatible with the Library import feature in the Sumo user interface. operationId: getAsyncExportResult parameters: - name: contentId in: path description: The identifier of the exported content item. required: true schema: type: string - name: jobId in: path description: The identifier of the asynchronous job. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string responses: '200': description: The result of export job. content: application/json: schema: $ref: '#/components/schemas/ContentSyncDefinition' default: description: Operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/folders/{folderId}/import: post: tags: - Content Management summary: Start A Content Import Job description: Schedule an asynchronous import of content inside an existing folder with the given identifier. Import requests can be used to create or update content within a folder. Content items need to have a unique name within their folder. If there is already a content item with the same name in the folder, you can set the `overwrite` parameter to `true` to overwrite existing content items. By default, the `overwrite` parameter is set to `false`, where the import will fail if a content item with the same name already exist. Keep in mind when importing large folders that there is a limit of 1000 content objects that can be imported at once. If you want to import more than 1000 content objects, then be sure to split the import into batches of 1000 objects or less. operationId: beginAsyncImport parameters: - name: folderId in: path description: The identifier of the folder to import into. Identifiers from the Library in the Sumo user interface are provided in decimal format which is incompatible with this API. The identifier needs to be in hexadecimal format. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string - name: overwrite in: query description: Set this to "true" to overwrite a content item if the name already exists. required: false schema: type: boolean default: false requestBody: description: The content to import. content: application/json: schema: $ref: '#/components/schemas/ContentSyncDefinition' required: true responses: '200': description: Import job has been scheduled. content: application/json: schema: $ref: '#/components/schemas/BeginAsyncJobResponse' default: description: The operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/folders/{folderId}/import/{jobId}/status: get: tags: - Content Management summary: Content Import Job Status description: Get the status of a content import job for the given job identifier. operationId: getAsyncImportStatus parameters: - name: folderId in: path description: The identifier of the folder to import into. required: true schema: type: string - name: jobId in: path description: The identifier of the import request. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string responses: '200': description: The status of the import job. content: application/json: schema: $ref: '#/components/schemas/AsyncJobStatus' default: description: The operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/folders/{folderId}/import/{jobId}/result: get: tags: - Content Management summary: Content Import Job Result description: Get the complete summary of content import job for the given job identifier. operationId: getAsyncImportResult parameters: - name: folderId in: path description: The identifier of the folder to import into. required: true schema: type: string - name: jobId in: path description: The identifier of the import request. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string responses: '200': description: The result of the import job. content: application/json: schema: $ref: '#/components/schemas/ImportResult' default: description: The operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/{id}/delete: delete: tags: - Content Management summary: Start A Content Deletion Job description: Start an asynchronous content deletion job with the given identifier. operationId: beginAsyncDelete parameters: - name: id in: path description: Identifier of the content to delete. Identifiers from the Library in the Sumo user interface are provided in decimal format which is incompatible with this API. The identifier needs to be in hexadecimal format. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string responses: '200': description: Deletion job has been scheduled. content: application/json: schema: $ref: '#/components/schemas/BeginAsyncJobResponse' default: description: Operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/{id}/delete/{jobId}/status: get: tags: - Content Management summary: Content Deletion Job Status description: Get the status of an asynchronous content deletion job request for the given job identifier. operationId: getAsyncDeleteStatus parameters: - name: id in: path description: Identifier of the content to delete. required: true schema: type: string - name: jobId in: path description: The identifier of the asynchronous job. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string responses: '200': description: The status of the content deletion job. content: application/json: schema: $ref: '#/components/schemas/AsyncJobStatus' default: description: Operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/{id}/copy: post: tags: - Content Management summary: Start A Content Copy Job description: Start an asynchronous content copy job with the given identifier to the destination folder. If the content item is a folder, everything under the folder is copied recursively. operationId: beginAsyncCopy parameters: - name: id in: path description: The identifier of the content item to copy. Identifiers from the Library in the Sumo user interface are provided in decimal format which is incompatible with this API. The identifier needs to be in hexadecimal format. required: true schema: type: string - name: destinationFolder in: query description: The identifier of the destination folder. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string responses: '200': description: Content copy job has been scheduled. content: application/json: schema: $ref: '#/components/schemas/BeginAsyncJobResponse' default: description: Operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/{id}/copy/{jobId}/status: get: tags: - Content Management summary: Content Copy Job Status description: 'Get the status of the copy request with the given job identifier. On success, field `statusMessage` will contain identifier of the newly copied content in format: `id: {hexIdentifier}`.' operationId: asyncCopyStatus parameters: - name: id in: path description: The identifier of the content which was copied. required: true schema: type: string - name: jobId in: path description: The identifier of the asynchronous copy request job. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string responses: '200': description: The status of the content copy job. content: application/json: schema: $ref: '#/components/schemas/AsyncJobStatus' example: status: Success statusMessage: 'id: 0000000000000197' default: description: Operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' /v2/content/{id}/move: post: tags: - Content Management summary: Move An Item description: Moves an item from its current location to another folder. operationId: moveItem parameters: - name: destinationFolderId in: query description: Identifier of the destination folder. required: true schema: type: string - name: id in: path description: Identifier of the item the user wants to move. required: true schema: type: string - name: isAdminMode in: header description: Set this to "true" if you want to perform the request as a Content Administrator. required: false schema: type: string responses: '200': description: Content was moved successfully. default: description: Operation failed with an error. content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' components: schemas: MetadataModel: required: - createdAt - createdBy - modifiedAt - modifiedBy type: object properties: createdAt: type: string description: Creation timestamp in UTC in [RFC3339](https://tools.ietf.org/html/rfc3339) format. format: date-time example: 2018-10-16 09:10:00+00:00 createdBy: type: string description: Identifier of the user who created the resource. example: 0000000006743FDD modifiedAt: type: string description: Last modification timestamp in UTC. format: date-time example: 2018-10-16 09:10:00+00:00 modifiedBy: type: string description: Identifier of the user who last modified the resource. example: 0000000006743FE8 Content: type: object allOf: - $ref: '#/components/schemas/MetadataModel' - required: - id - itemType - name - parentId - permissions properties: id: type: string description: Identifier of the content item. example: 000000000C1C17C6 name: type: string description: The name of the content item. example: Personal itemType: type: string description: "Type of the content item. Supported values are:\n 1. Folder\n 2. Search\n 3. Report (for old dashboards)\n 4. Dashboard (for new dashboards)\n 5. Lookups" example: Folder parentId: type: string description: Identifier of the parent content item. example: 0000000001C41EF2 permissions: type: array description: List of permissions the user has on the content item. example: - View - GrantView - Edit items: type: string description: type: string description: Description of the content item. example: Personal folder for John Doe isScheduled: type: boolean description: Indicates whether the content item refers to scheduled search. This field is only relevant to `Search` content type. example: false default: false ErrorResponse: required: - errors - id type: object properties: id: type: string description: An identifier for the error; this is unique to the specific API request. example: IUUQI-DGH5I-TJ045 errors: type: array description: A list of one or more causes of the error. example: - code: auth:password_too_short message: Your password was too short. - code: auth:password_character_classes message: Your password did not contain any non-alphanumeric characters items: $ref: '#/components/schemas/ErrorDescription' PathSegment: required: - id - name type: object properties: id: type: string description: The identifier of the path segment. example: 0000000013D98A2A name: type: string description: The name of the path segment. example: Test Folder description: type: string description: An optional description of the path segment. example: This is a test folder description: A segment of a path. ContentPath: required: - path type: object properties: path: type: string description: Path of the content item. example: /Library/Users/user@test.com/SampleFolder pathItems: type: array description: The items in the path of the content. items: $ref: '#/components/schemas/PathSegment' ErrorDescription: required: - code - message type: object properties: code: type: string description: An error code describing the type of error. example: auth:password_too_short message: type: string description: A short English-language description of the error. example: Your password was too short. detail: type: string description: An optional fuller English-language description of the error. example: Your password was 5 characters long, the minimum length is 12 characters. See http://example.com/password for more information. meta: type: object description: An optional list of metadata about the error. example: minLength: 12 actualLength: 5 ImportResult: type: object properties: status: type: string description: Whether or not the request is in progress (`InProgress`), has completed successfully (`Success`), or has completed with an error (`Failed`). summary: type: object properties: totalItems: type: integer description: Total content items attempted in the import. example: 15 successCount: type: integer description: Number of content items successfully imported. example: 12 failureCount: type: integer description: Number of content items that failed to import. example: 3 description: Summary about the import job indicating total, success and failure count. failures: type: array description: Detailed listing of failed import items. items: $ref: '#/components/schemas/ImportErrorResultItem' ImportErrorResultItem: type: object properties: path: type: string description: Full folder path to the failed item. example: /Marketing/Website Analytics/Daily Traffic Report type: type: string description: The type of the content item (e.g., Folder, Search, Dashboard). example: Dashboard error: type: string description: Reason why the item failed to import. example: Invalid JSON format in widget configuration. AsyncJobStatus: required: - status type: object properties: status: type: string description: Whether or not the request is in progress (`InProgress`), has completed successfully (`Success`), or has completed with an error (`Failed`). statusMessage: type: string description: Additional status message generated if the status is not `Failed`. error: $ref: '#/components/schemas/ErrorDescription' example: status: Success statusMessage: '' BeginAsyncJobResponse: required: - id type: object properties: id: type: string description: Identifier to get the status of an asynchronous job. example: C03E086C137F38B4 ContentSyncDefinition: required: - name - type type: object properties: type: type: string description: "The content item type.\n**Note:**\n - `MewboardSyncDefinition` _is depreciated, and will soon be removed. Please use_ `DashboardV2SyncDefinition`\n _instead_.\n - Dashboard links are not supported for dashboards." name: type: string description: The name of the item. discriminator: propertyName: type securitySchemes: basicAuth: type: http scheme: basic x-tagGroups: - name: Archive Management tags: - archiveManagement - name: Health Events tags: - healthEvents - name: Infrequent Data Tier tags: - logSearchesEstimatedUsage - name: Ingest Budgets Management V2 tags: - ingestBudgetManagementV2 - name: Library Management tags: - appManagement - appManagementV2 - contentManagement - dashboardManagement - folderManagement - lookupManagement - contentPermissions - logSearchesManagement - parsersLibraryManagement - name: Metrics tags: - metricsSearchesManagement - transformationRuleManagement - metricsQuery - metricsSearchesManagementV2 - name: Security Management tags: - accessKeyManagement - oauthManagement - accountManagement - passwordPolicy - policiesManagement - samlConfigurationManagement - serviceAllowlistManagement - serviceAccountManagement - scimUserManagement - name: Organizations Management tags: - orgsManagement - name: Settings Management tags: - connectionManagement - dynamicParsingRuleManagement - extractionRuleManagement - fieldManagementV1 - partitionManagement - scheduledViewManagement - logsDataForwardingManagement - dataDeletionRules - name: Tokens Management tags: - tokensLibraryManagement - name: Tracing tags: - traces - spanAnalytics - serviceMap - name: Users and Roles Management tags: - roleManagement - roleManagementV2 - userManagement - name: Threat Intel Ingest Management tags: - threatIntelIngest - threatIntelIngestProducer - name: OpenTelemetry Collector Management tags: - otCollectorManagementExternal - name: Source Template Management tags: - sourceTemplateManagementExternal - name: Schema Base Management tags: - schemaBaseManagement - name: Event Analytics Management tags: - eventAnalytics - name: Budget Management tags: - budgetManagement - name: Macro Management tags: - macroManagement - name: Muting Schedules Management tags: - mutingSchedulesLibraryManagement - name: SLO Management tags: - slosLibraryManagement - name: Monitor Management tags: - monitorsLibraryManagement