Atomic Overwrite for ALL types of enrichments
curl --request PUT \
--url https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"requestEnrichments": [
{
"enrichmentType": {
"geoIp": {
"withAsn": true
},
"aws": {
"resourceType": "aws:ec2:instance"
},
"customEnrichment": {
"id": 1
},
"suspiciousIp": {}
},
"fieldName": "sourceIPs",
"enrichedFieldName": "<string>",
"selectedColumns": [
"<string>"
],
"targets": [
{
"dataset": "dataset1"
}
]
}
]
}
'import requests
url = "https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all"
payload = { "requestEnrichments": [
{
"enrichmentType": {
"geoIp": { "withAsn": True },
"aws": { "resourceType": "aws:ec2:instance" },
"customEnrichment": { "id": 1 },
"suspiciousIp": {}
},
"fieldName": "sourceIPs",
"enrichedFieldName": "<string>",
"selectedColumns": ["<string>"],
"targets": [{ "dataset": "dataset1" }]
}
] }
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
requestEnrichments: [
{
enrichmentType: {
geoIp: {withAsn: true},
aws: {resourceType: 'aws:ec2:instance'},
customEnrichment: {id: 1},
suspiciousIp: {}
},
fieldName: 'sourceIPs',
enrichedFieldName: '<string>',
selectedColumns: ['<string>'],
targets: [{dataset: 'dataset1'}]
}
]
})
};
fetch('https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'requestEnrichments' => [
[
'enrichmentType' => [
'geoIp' => [
'withAsn' => true
],
'aws' => [
'resourceType' => 'aws:ec2:instance'
],
'customEnrichment' => [
'id' => 1
],
'suspiciousIp' => [
]
],
'fieldName' => 'sourceIPs',
'enrichedFieldName' => '<string>',
'selectedColumns' => [
'<string>'
],
'targets' => [
[
'dataset' => 'dataset1'
]
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all"
payload := strings.NewReader("{\n \"requestEnrichments\": [\n {\n \"enrichmentType\": {\n \"geoIp\": {\n \"withAsn\": true\n },\n \"aws\": {\n \"resourceType\": \"aws:ec2:instance\"\n },\n \"customEnrichment\": {\n \"id\": 1\n },\n \"suspiciousIp\": {}\n },\n \"fieldName\": \"sourceIPs\",\n \"enrichedFieldName\": \"<string>\",\n \"selectedColumns\": [\n \"<string>\"\n ],\n \"targets\": [\n {\n \"dataset\": \"dataset1\"\n }\n ]\n }\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"requestEnrichments\": [\n {\n \"enrichmentType\": {\n \"geoIp\": {\n \"withAsn\": true\n },\n \"aws\": {\n \"resourceType\": \"aws:ec2:instance\"\n },\n \"customEnrichment\": {\n \"id\": 1\n },\n \"suspiciousIp\": {}\n },\n \"fieldName\": \"sourceIPs\",\n \"enrichedFieldName\": \"<string>\",\n \"selectedColumns\": [\n \"<string>\"\n ],\n \"targets\": [\n {\n \"dataset\": \"dataset1\"\n }\n ]\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"requestEnrichments\": [\n {\n \"enrichmentType\": {\n \"geoIp\": {\n \"withAsn\": true\n },\n \"aws\": {\n \"resourceType\": \"aws:ec2:instance\"\n },\n \"customEnrichment\": {\n \"id\": 1\n },\n \"suspiciousIp\": {}\n },\n \"fieldName\": \"sourceIPs\",\n \"enrichedFieldName\": \"<string>\",\n \"selectedColumns\": [\n \"<string>\"\n ],\n \"targets\": [\n {\n \"dataset\": \"dataset1\"\n }\n ]\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"enrichments": [
{
"enrichmentType": {
"geoIp": {
"withAsn": true
},
"aws": {
"resourceType": "aws:ec2:instance"
},
"customEnrichment": {
"id": 1
},
"suspiciousIp": {}
},
"fieldName": "1",
"id": 1,
"enrichedFieldName": "1",
"selectedColumns": [
"city",
"population"
],
"targets": [
{
"dataset": "dataset1"
}
]
}
]
}Enrichments Service
Atomic Overwrite for ALL types of enrichments
Atomic Overwrite for ALL types of enrichments. The request is the desired state which will override ALL enrichments. WARNING: This operation will delete all existing enrichments and replace them with the provided ones.
Atomic Overwrite for ALL types of enrichments
curl --request PUT \
--url https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"requestEnrichments": [
{
"enrichmentType": {
"geoIp": {
"withAsn": true
},
"aws": {
"resourceType": "aws:ec2:instance"
},
"customEnrichment": {
"id": 1
},
"suspiciousIp": {}
},
"fieldName": "sourceIPs",
"enrichedFieldName": "<string>",
"selectedColumns": [
"<string>"
],
"targets": [
{
"dataset": "dataset1"
}
]
}
]
}
'import requests
url = "https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all"
payload = { "requestEnrichments": [
{
"enrichmentType": {
"geoIp": { "withAsn": True },
"aws": { "resourceType": "aws:ec2:instance" },
"customEnrichment": { "id": 1 },
"suspiciousIp": {}
},
"fieldName": "sourceIPs",
"enrichedFieldName": "<string>",
"selectedColumns": ["<string>"],
"targets": [{ "dataset": "dataset1" }]
}
] }
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
requestEnrichments: [
{
enrichmentType: {
geoIp: {withAsn: true},
aws: {resourceType: 'aws:ec2:instance'},
customEnrichment: {id: 1},
suspiciousIp: {}
},
fieldName: 'sourceIPs',
enrichedFieldName: '<string>',
selectedColumns: ['<string>'],
targets: [{dataset: 'dataset1'}]
}
]
})
};
fetch('https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'requestEnrichments' => [
[
'enrichmentType' => [
'geoIp' => [
'withAsn' => true
],
'aws' => [
'resourceType' => 'aws:ec2:instance'
],
'customEnrichment' => [
'id' => 1
],
'suspiciousIp' => [
]
],
'fieldName' => 'sourceIPs',
'enrichedFieldName' => '<string>',
'selectedColumns' => [
'<string>'
],
'targets' => [
[
'dataset' => 'dataset1'
]
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all"
payload := strings.NewReader("{\n \"requestEnrichments\": [\n {\n \"enrichmentType\": {\n \"geoIp\": {\n \"withAsn\": true\n },\n \"aws\": {\n \"resourceType\": \"aws:ec2:instance\"\n },\n \"customEnrichment\": {\n \"id\": 1\n },\n \"suspiciousIp\": {}\n },\n \"fieldName\": \"sourceIPs\",\n \"enrichedFieldName\": \"<string>\",\n \"selectedColumns\": [\n \"<string>\"\n ],\n \"targets\": [\n {\n \"dataset\": \"dataset1\"\n }\n ]\n }\n ]\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"requestEnrichments\": [\n {\n \"enrichmentType\": {\n \"geoIp\": {\n \"withAsn\": true\n },\n \"aws\": {\n \"resourceType\": \"aws:ec2:instance\"\n },\n \"customEnrichment\": {\n \"id\": 1\n },\n \"suspiciousIp\": {}\n },\n \"fieldName\": \"sourceIPs\",\n \"enrichedFieldName\": \"<string>\",\n \"selectedColumns\": [\n \"<string>\"\n ],\n \"targets\": [\n {\n \"dataset\": \"dataset1\"\n }\n ]\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.coralogix.com/mgmt/openapi/5/enrichment-rules/enrichment-rules/v1/all")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"requestEnrichments\": [\n {\n \"enrichmentType\": {\n \"geoIp\": {\n \"withAsn\": true\n },\n \"aws\": {\n \"resourceType\": \"aws:ec2:instance\"\n },\n \"customEnrichment\": {\n \"id\": 1\n },\n \"suspiciousIp\": {}\n },\n \"fieldName\": \"sourceIPs\",\n \"enrichedFieldName\": \"<string>\",\n \"selectedColumns\": [\n \"<string>\"\n ],\n \"targets\": [\n {\n \"dataset\": \"dataset1\"\n }\n ]\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"enrichments": [
{
"enrichmentType": {
"geoIp": {
"withAsn": true
},
"aws": {
"resourceType": "aws:ec2:instance"
},
"customEnrichment": {
"id": 1
},
"suspiciousIp": {}
},
"fieldName": "1",
"id": 1,
"enrichedFieldName": "1",
"selectedColumns": [
"city",
"population"
],
"targets": [
{
"dataset": "dataset1"
}
]
}
]
}Authorizations
API key authentication
Body
application/json
Request to atomically replace all enrichment rules.
Complete list of enrichment rules to replace all existing rules. The total number of enrichment rules is limited by the account's enrichment limit (5 by default).
Maximum array length:
100Show child attributes
Show child attributes
Response
200 - application/json
Response returned after atomically replacing all enrichment rules.
List of enrichments.
Maximum array length:
1000Show child attributes
Show child attributes
Was this page helpful?