Update integration
Path Parameters
Integration ID
Body
Whether to enable or disable the integration
Whether the integration requires additional configuration
Custom fields to update
When false, Wirespeed will not sync verdict, status, notes, or comments back to this integration
Replacement API token for API-token integrations (when credentials expire)
Retention period for newly ingested raw data
THIRTY_DAYS, NINETY_DAYS, ONE_YEAR Response
Unique identifier for the integration
Integration platform type
admin-by-request, aws, axonius, bitwarden, box, checkpoint-firewall, checkpoint-harmony, cisco-catalyst, cisco-duo, cisco-meraki, cisco-secure-access, cisco-umbrella, cisco-xdr, connectwise-psa, crowdstrike-falcon, cyberark, darktrace, email, exium, fleet-dm, fortianalyzer, fortinet, freshservice, generic-json, generic-syslog, google-alert-center, google-chronicle, google-directory, google-security-center, halcyon, halo-itsm, have-i-been-pwned, horizon3, hyas-protect, ipinfo, jamf-pro, jamf-protect, jira-cloud, jira-data-center, jumpcloud, kandji, manage-engine-ad-audit-plus, microsoft, microsoft-entra, microsoft-teams, microsoft-teams-v2, mimecast, ninjaone, odoo-helpdesk, okta, one-password, onelogin, orca-security, pager-duty, palo-alto-networks-cortex, picus, ping-one, reversing-labs, safebreach, sandfly, sentinel-one, service-now, slack, sms, smtp, sonic-wall, sophos, splunk, stairwell, tenable-nessus, thinkst-canary, tracebit, unifi, vectra, watchguard-firebox, windows-event-logs, wirespeed, wiz, wordfence, zscaler-zpa Whether the integration is enabled
ID of the team that owns this integration
Integration configuration metadata
Whether a permissions update is available for this integration
Explanation for why a permissions update is available
Identity fields that uniquely identify this integration instance
Timestamp when integration was created
Timestamp of the last successful entitlement refresh
Public entitlements with their current values and warning states
Current health status of the integration
healthy, unhealthy, unstable, unknown Detailed health check information
Whether outbound updates (verdict, status, notes, comments) are synced back to this integration
Retention period for newly ingested raw data
THIRTY_DAYS, NINETY_DAYS, ONE_YEAR Name of the team that owns this integration
Whether the integration requires additional configuration
Mute hourly quality notifications by log type. Key is log type, value is timestamp until which it is muted.
Selected auth method id for this integration instance. Null means the first/default declared method. Corresponds to an entry in the metadata authMethods list.
Automated syslog fleet endpoints (one per listener); domain/ip/port are null until deployed
Syslog Forwarder protocol options (listeners, transport, TLS, framing) stored on the integration.

