Skip to main content
PUT
Add basic authentication integration

Query Parameters

integration
enum<string>
required
Available options:
admin-by-request,
aws,
axonius,
bitwarden,
box,
checkpoint-firewall,
checkpoint-harmony,
cisco-catalyst,
cisco-duo,
cisco-meraki,
cisco-secure-access,
cisco-umbrella,
cisco-xdr,
connectwise-psa,
crowdstrike-falcon,
cyberark,
darktrace,
email,
exium,
fleet-dm,
fortianalyzer,
fortinet,
freshservice,
generic-json,
generic-syslog,
google-alert-center,
google-chronicle,
google-directory,
google-security-center,
halcyon,
halo-itsm,
have-i-been-pwned,
horizon3,
hyas-protect,
ipinfo,
jamf-pro,
jamf-protect,
jira-cloud,
jira-data-center,
jumpcloud,
kandji,
manage-engine-ad-audit-plus,
microsoft,
microsoft-entra,
microsoft-teams,
microsoft-teams-v2,
mimecast,
ninjaone,
odoo-helpdesk,
okta,
one-password,
onelogin,
orca-security,
pager-duty,
palo-alto-networks-cortex,
picus,
ping-one,
reversing-labs,
safebreach,
sandfly,
sentinel-one,
service-now,
slack,
sms,
smtp,
sonic-wall,
sophos,
splunk,
stairwell,
tenable-nessus,
thinkst-canary,
tracebit,
unifi,
vectra,
watchguard-firebox,
windows-event-logs,
wirespeed,
wiz,
wordfence,
zscaler-zpa

Body

application/json
fields
object[]
required

Fields for basic authentication integration

retentionType
enum<string>

Retention period for raw data ingested by the integration

Available options:
THIRTY_DAYS,
NINETY_DAYS,
ONE_YEAR

Response

id
string
required

Unique identifier for the integration

platform
enum<string>
required

Integration platform type

Available options:
admin-by-request,
aws,
axonius,
bitwarden,
box,
checkpoint-firewall,
checkpoint-harmony,
cisco-catalyst,
cisco-duo,
cisco-meraki,
cisco-secure-access,
cisco-umbrella,
cisco-xdr,
connectwise-psa,
crowdstrike-falcon,
cyberark,
darktrace,
email,
exium,
fleet-dm,
fortianalyzer,
fortinet,
freshservice,
generic-json,
generic-syslog,
google-alert-center,
google-chronicle,
google-directory,
google-security-center,
halcyon,
halo-itsm,
have-i-been-pwned,
horizon3,
hyas-protect,
ipinfo,
jamf-pro,
jamf-protect,
jira-cloud,
jira-data-center,
jumpcloud,
kandji,
manage-engine-ad-audit-plus,
microsoft,
microsoft-entra,
microsoft-teams,
microsoft-teams-v2,
mimecast,
ninjaone,
odoo-helpdesk,
okta,
one-password,
onelogin,
orca-security,
pager-duty,
palo-alto-networks-cortex,
picus,
ping-one,
reversing-labs,
safebreach,
sandfly,
sentinel-one,
service-now,
slack,
sms,
smtp,
sonic-wall,
sophos,
splunk,
stairwell,
tenable-nessus,
thinkst-canary,
tracebit,
unifi,
vectra,
watchguard-firebox,
windows-event-logs,
wirespeed,
wiz,
wordfence,
zscaler-zpa
enabled
boolean
required

Whether the integration is enabled

teamId
string
required

ID of the team that owns this integration

config
object
required

Integration configuration metadata

permissionsUpdateAvailable
boolean
required

Whether a permissions update is available for this integration

permissionUpdateExplanation
string | null
required

Explanation for why a permissions update is available

identityFields
object
required

Identity fields that uniquely identify this integration instance

createdAt
string
required

Timestamp when integration was created

lastEntitlementRefreshAt
string | null
required

Timestamp of the last successful entitlement refresh

publicEntitlements
object[]
required

Public entitlements with their current values and warning states

healthStatus
enum<string> | null
required

Current health status of the integration

Available options:
healthy,
unhealthy,
unstable,
unknown
healthDetails
object | null
required

Detailed health check information

sourceSystemUpdates
boolean
required

Whether outbound updates (verdict, status, notes, comments) are synced back to this integration

retentionType
enum<string>
required

Retention period for newly ingested raw data

Available options:
THIRTY_DAYS,
NINETY_DAYS,
ONE_YEAR
teamName
string

Name of the team that owns this integration

requiresConfiguration
boolean

Whether the integration requires additional configuration

muteHourlyQuality
object

Mute hourly quality notifications by log type. Key is log type, value is timestamp until which it is muted.

authMethod
string | null

Selected auth method id for this integration instance. Null means the first/default declared method. Corresponds to an entry in the metadata authMethods list.

syslogEndpoints
object[]

Automated syslog fleet endpoints (one per listener); domain/ip/port are null until deployed

syslogProtocolSettings
object

Syslog Forwarder protocol options (listeners, transport, TLS, framing) stored on the integration.