Skip to main content
POST
cURL

Authorizations

Authorization
string
header
required

API Key authentication for programmatic access. Include your API key in the Authorization header as: Bearer your_api_key_here

Body

application/json

Request body for generating a detection query using AI

prompt
string
required

Natural language description of what the query should accomplish

Minimum string length: 1
siemType
enum<string>
required

The detection tool platform to generate the query for (SIEM or endpoint tools like SentinelOne)

Available options:
splunk,
sumologic,
elastic,
databricks,
datadog,
scanner,
runreveal,
sentinelone,
gadmin
category
enum<string>

The detection category to optimize the query for

Available options:
baseline_anomaly,
first_occurrence,
sequence_pattern,
privilege_escalation,
custom

Response

Successful response

Async detection query generation job identifier

jobId
string<uuid>
required

Background job ID for this query generation request