curl -X POST "https://app.cotool.ai/api/detection-queries/generate" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"prompt":"string","siemType":"splunk","category":"baseline_anomaly"}'import requests
url = "https://app.cotool.ai/api/detection-queries/generate"
payload = { "prompt": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({prompt: '<string>'})
};
fetch('https://app.cotool.ai/api/detection-queries/generate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));HttpResponse<String> response = Unirest.post("https://app.cotool.ai/api/detection-queries/generate")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"prompt\": \"<string>\"\n}")
.asString();package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.cotool.ai/api/detection-queries/generate"
payload := strings.NewReader("{\n \"prompt\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"query": "<string>",
"systemPrompt": "<string>",
"explanation": "<string>"
}{
"error": "<string>",
"issues": [
{}
]
}{
"error": "<string>"
}{
"error": "<string>",
"missingPerms": [
"<string>"
]
}{
"error": "<string>"
}Generate a SIEM query using AI
⚠️ Deprecated Standalone query generation is superseded by detection authoring with agents. Run an agent that has your SIEM tool attached (POST /api/agents//run-sync) or author detections in the Cotool app. No sunset is scheduled; the endpoint will be removed once its remaining integration retires. Use instead:
/api/agents/:agentId/run-sync
Generates a SIEM query based on a natural language prompt using AI.
curl -X POST "https://app.cotool.ai/api/detection-queries/generate" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"prompt":"string","siemType":"splunk","category":"baseline_anomaly"}'import requests
url = "https://app.cotool.ai/api/detection-queries/generate"
payload = { "prompt": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({prompt: '<string>'})
};
fetch('https://app.cotool.ai/api/detection-queries/generate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));HttpResponse<String> response = Unirest.post("https://app.cotool.ai/api/detection-queries/generate")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"prompt\": \"<string>\"\n}")
.asString();package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.cotool.ai/api/detection-queries/generate"
payload := strings.NewReader("{\n \"prompt\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"query": "<string>",
"systemPrompt": "<string>",
"explanation": "<string>"
}{
"error": "<string>",
"issues": [
{}
]
}{
"error": "<string>"
}{
"error": "<string>",
"missingPerms": [
"<string>"
]
}{
"error": "<string>"
}Authorizations
API Key authentication for programmatic access. Include your API key in the Authorization header as: Bearer your_api_key_here
Body
Request body for generating a detection query using AI
Natural language description of what the query should accomplish
1The detection tool platform to generate the query for (SIEM or endpoint tools like SentinelOne)
splunk, sumologic, elastic, databricks, datadog, scanner, runreveal, microsoftsentinel, cotool, sentinelone, gadmin The detection category to optimize the query for
baseline_anomaly, first_occurrence, sequence_pattern, privilege_escalation, custom Was this page helpful?