Skip to content

Custom detection configuration updated
Webhook

Request

An admin user has updated the configuration of a custom detection.

Security
X-Signature
Headers
X-Signaturestringrequired
Example:X-Signature: t=1492774577,v1=5257a869...
Bodyapplication/json
versionstringrequired

The version of the event.

Example:"1"
idstring, (uuid)required

The unique identifier for the event. This can be used as an idempotency key.

Example:"c478966c-f927-411c-b919-179832d3d50c"
tenantIdstring, (uuid)required

The unique identifier of the tenant the event belongs to.

Example:"4f9d2e7a-1b3c-4d5e-8f6a-7c8b9d0e1f2a"
timestampintegerrequired

When the event occurred, formatted as a UNIX timestamp (in seconds).

Example:1698604061
categorystringrequired

The category of the event.

Value:"AUDIT"
objectstringrequired

The type of event.

Value:"CUSTOM_DETECTION_UPDATED"
friendlyNamestringrequired

The friendly name of this object. Note: this is subject to change and should not be used to match on this object.

Example:"Custom detection configuration updated"
descriptionstringrequired

The description of the event. Note: this is subject to change and should not be used to match on this object.

Example:"user@example.com updated the configuration of a custom detection."
actorobject(Admin Audit Log Actor)required

This object contains information about the user that performed the action triggering the audit log.

newobject(Custom detection configuration)required

The current details of the updated custom detection.

Payload
{ "version": "1", "id": "c478966c-f927-411c-b919-179832d3d50c", "tenantId": "4f9d2e7a-1b3c-4d5e-8f6a-7c8b9d0e1f2a", "timestamp": 1698604061, "category": "AUDIT", "object": "CUSTOM_DETECTION_UPDATED", "friendlyName": "Custom detection configuration updated", "description": "user@example.com updated the configuration of a custom detection.", "actor": { "source": "UI", "email": "string", "sourceIpAddress": "string", "userAgent": "string", "role": "OWNER" }, "new": { "detectionEventName": "Torrent website visit", "detectionEventType": "CUSTOM_TORRENT_WEBSITE_VISIT", "detectionEventConfiguration": "input:\n type: navigation\nconditions:\n - url_pattern: '*.torrent.*'\n" } }

Responses

Return any 2XX status to indicate that the data was received successfully