Lookup Datasets
APIs for lookup datasets
Add or update data in a lookup dataset.
When updating data, any field not specified in the data field, but specified on at least one of the rows, will be set to None.
The Add or update data in a lookup dataset endpoint does not support concurrent edits. Sending concurrent calls to this endpoint can cause data to be unintentionally overwritten or deleted. To allow sufficient time for each API call to complete its operation before initiating another one, assume that 1000 entries can be added per API every 10 seconds.
**Note: **
The maximum size of a lookup dataset is 50 MB. Attemping to exceed this limit will fail.
Requests time out after three minutes.
Required license: Cortex AgentiX Enterprise or Cortex AgentiX Base
{api_key}
{api_key_id}
OK
POST /public_api/v1/xql/lookups/add_data HTTP/1.1
Host: api-yourfqdn
Authorization: text
x-xdr-auth-id: text
Content-Type: application/json
Accept: */*
Content-Length: 315
{
"request_data": {
"dataset_name": "users",
"key_fields": [
"uid",
"username"
],
"data": [
{
"uid": "123abc",
"username": "john",
"zipcode": 58672,
"salary": 5.1,
"is_admin": false,
"birthday": "31-05-1982T10:22:45Z"
},
{
"uid": "124abc",
"username": "jane",
"zipcode": 58642,
"salary": 5000000,
"is_admin": true,
"birthday": "31-03-1982T10:22:45Z"
}
]
}
}OK
{
"added": 1,
"updated": 1,
"skipped": 1
}Remove data from a dataset based on the specified parameters. If any one of the filter sets are not found, the API does not delete any data.
The Remove data from a lookup dataset endpoint does not support concurrent edits. Sending concurrent calls to this endpoint can cause data to be unintentionally overwritten or deleted. To allow sufficient time for each API call to complete its operation before initiating another one, assume that 1000 entries can be added per API every 10 seconds.
Note:
All lookup entries matching any of the filter blocks are deleted. To match a filter block, a lookup entry must match all the specified fields as if there were an
ANDoperator between them.Requests time out after three minutes.
Required license: Cortex AgentiX Enterprise or Cortex AgentiX Base
{api_key}
{api_key_id}
OK
Number of entries deleted successfully.
POST /public_api/v1/xql/lookups/remove_data HTTP/1.1
Host: api-yourfqdn
Authorization: text
x-xdr-auth-id: text
Content-Type: application/json
Accept: */*
Content-Length: 115
{
"request_data": {
"dataset_name": "users",
"filters": [
{
"uid": "123",
"username": "john"
},
{
"uid": "124",
"zipcode": 58672
}
]
}
}OK
{
"deleted": 1
}Get data from a lookup dataset according to the specified filter fields. All lookup entries matching any of the filter blocks are returned. To match a filter block, a lookup entry must match all the specified fields as if there were an AND operator between them. If no filters are specified, return all lookup entries.
Note:
The maximum number of entries returned is 10,000.
Requests time out after three minutes.
Required license: Cortex AgentiX Enterprise or Cortex AgentiX Base
{api_key}
{api_key_id}
OK
Number of entries that match the filter.
Total number of entries.
POST /public_api/v1/xql/lookups/get_data HTTP/1.1
Host: api-yourfqdn
Authorization: text
x-xdr-auth-id: text
Content-Type: application/json
Accept: */*
Content-Length: 135
{
"request_data": {
"dataset_name": "users",
"filters": [
{
"uid": "123",
"username": "john"
},
{
"department": "dev",
"zipcode": "58674"
}
],
"limit": 20
}
}OK
{
"reply": {
"data": [
{
"uid": "uid5",
"salary": 5.1,
"zipcode": 70005,
"birthday": 386418165000,
"is_admin": true,
"username": "username5",
"_insert_time": 1718807765000,
"_update_time": 1718807765000,
"_collector_name": "Console",
"_collector_type": "Console"
},
{
"uid": "uid6",
"salary": 6.1,
"zipcode": 70006,
"birthday": 386418165000,
"is_admin": true,
"username": "username6",
"_insert_time": 1718807765000,
"_update_time": 1718807765000,
"_collector_name": "Console",
"_collector_type": "Console"
}
],
"filter count": 2,
"total count": 10
}
}Last updated
Was this helpful?
