Skip to main content

Threat Intel Ingest Management APIs

icon

The Threat Intel Ingest Management API allows you to:

  • Upload threat intelligence indicators
  • View storage status of threat intelligence ingest service
  • View and set the retention period for threat intelligence indicators

For more information about threat intelligence, see About Sumo Logic Threat Intelligence.

Documentation​

To get started with Sumo Logic APIs, see API Authentication, Endpoints, and Security.

Our APIs are built with OpenAPI. You can generate client libraries in several languages and explore automated testing.

To access our API documentation, navigate to the appropriate link based on your Sumo deployment. Deployment types differ based on geographic location and account creation date. If unsure, see Which endpoint should I use?

DeploymentDocumentation URL
AUhttps://api.au.sumologic.com/docs/#tag/threatIntelIngest
CAhttps://api.ca.sumologic.com/docs/#tag/threatIntelIngest
DEhttps://api.de.sumologic.com/docs/#tag/threatIntelIngest
EUhttps://api.eu.sumologic.com/docs/#tag/threatIntelIngest
FEDhttps://api.fed.sumologic.com/docs/#tag/threatIntelIngest
INhttps://api.in.sumologic.com/docs/#tag/threatIntelIngest
JPhttps://api.jp.sumologic.com/docs/#tag/threatIntelIngest
US1https://api.sumologic.com/docs/#tag/threatIntelIngest
US2https://api.us2.sumologic.com/docs/#tag/threatIntelIngest

Required role capabilities​

To use the APIs in this resource, the user or account executing APIs must have the following role capabilities:

  • Threat Intel
    • View Threat Intel Data Store
    • Manage Threat Intel Data Store
Status
Legal
Privacy Statement
Terms of Use

Copyright © 2025 by Sumo Logic, Inc.