Read one detection library entry
Returns the entry with its notebook source and the globally cached logic summary, for review before adding. Requires tool.read.
Authorizations
API Key authentication for programmatic access. Include your API key in the Authorization header as: Bearer your_api_key_here
Path Parameters
^[a-z0-9]+(-[a-z0-9]+)*$Response
Successful response
Kebab-case library entry identity
1–3 sentence plain-prose headline of what the detection is meant to detect
Operational GitHub-flavored markdown covering the signal and the fire condition
SHA-256 of the entry notebook
^[0-9a-f]{64}$Tool actions the entry notebook calls
Cotool Logs warehouse sources the notebook queries (e.g. okta); eligibility requires the org to have their log ingest enabled
Schedule enabled when the entry is added
low, medium, high, critical Whether missingLogSources and missingTools are both empty
The org detection created from this entry, when already added
The entry notebook source, for read-only preview
Logic summary computed once per notebook revision and cached globally; null until the interpretation job produces it
Required log sources the organization is not ingesting
Required integration tool actions the organization cannot run