Skip to main content
POST
Normalize and ingest raw records

Authorizations

Authorization
string
header
required

A 256-bit token generated by the Lookout CLI.

Path Parameters

normalizer
enum<string>
required
Available options:
zeek,
syslog-rfc5424,
opentelemetry-log,
tailscale-logs,
linux-journal

Query Parameters

logType
string

Required for Zeek and Tailscale inputs.

tailnet
string

Tailnet identifier for Tailscale records.

Body

application/json

The body is of type object.

Response

Records normalized, accepted, and evaluated

accepted
object[]
alerts
object[]
incidents
object[]