Commands
# log
Enumerate playbook runs in Logpresso Sonar.
Enumerate playbooks in Logpresso Sonar.
Add a comment to a ticket in Logpresso Sonar.
Enumerate address groups in Logpresso Sonar.
Enumerate address objects in Logpresso Sonar.
Enumerate apps in Logpresso Sonar.
Enumerate batch rules in Logpresso Sonar.
Enumerate behavior profiles.
Enumerate boot logs in Logpresso Sonar.
Check SSL certificates for dst_ip:dst_port combinations from input records with LRU caching
Clone dashboards that match the value of the GUID field in the input record. The new dashboard will be named with a 'Copy of' prefix.
Clone datasets that match the value of the GUID field in the input record. The new dataset will be named with a 'Copy of' prefix.
Clone widgets that match the value of the GUID field in the input record. The new widget will be named with a 'Copy of' prefix.
Create batch rules from input records. Rules are created disabled.
Create behavior profiles from input records.
Create a JSON ticket from an event in Logpresso Sonar.
Create a Markdown ticket in Logpresso Sonar.
Create stream rules from input records. Rules are created disabled.
List all dashboards
List all datasets
Deletes records in the specified lookup table based on the value of a key field in the input record.
Delete a command from stream rules from input records.
Enumerate departments in Logpresso Sonar.
Enumerate employees in Logpresso Sonar.
Enumerate explanation categories in Logpresso Sonar.
Enumerate explanation requests in Logpresso Sonar.
Retrieve explanations for a specific explanation request.
Fetch comments for each ticket from input records.
Enumerate indicators of compromise in Logpresso Sonar.
Insert input records to the specified lookup table.
Insert a command into existing stream rules from input records.
Enumerate log schema fields in Logpresso Sonar.
Enumerate log schemas in Logpresso Sonar.
Enumerate logger models in Logpresso Sonar.
Enumerate loggers in Logpresso Sonar.
Remove the IP address of input record from the specified address group.
Remove behavior profiles from input records.
Remove a ticket comment in Logpresso Sonar.
Replay batch rules over a past time range. Enumerates cron fire times of batch rules in the range. By default, outputs the replay plan only (dry run). With run=t, actually runs the rule query at each fire time and raises events and tickets. Constraints: requires administrator privilege, and run=t is rejected on standby nodes. Events are backdated to each fire time, but ticket created/updated times are the current time. Suppression windows are simulated within the replay only, independently of the live suppression state. Signature/ETIR risk scoring is not applied. now(), ago(), and duration= expressions in the rule query are rewritten to constants based on each fire time.
Enumerate response models in Logpresso Sonar.
Enumerate response targets in Logpresso Sonar.
Enumerate the command templates a stream rule's commands can be built from.
Enumerate stream rules in Logpresso Sonar.
Synchronize department supervisors in the Logpresso Sonar.
Synchronizes department objects based on the given input records, deleting departments that don't exist in the input record set.
Synchronizes employee objects based on the given input records, deleting employees that don't exist in the input record set.
Enumerate tags in Logpresso Sonar.
Enumerate tenants in Logpresso Sonar.
Enumerate ticket repositories in Logpresso Sonar.
Update batch rule properties from input records. Only the fields a record carries are changed, and an empty value clears the field.
Replace the query of batch rules from input records.
Update behavior profiles from input records.
Update the MITRE ATT&CK mapping of existing rules from input records.
Update stream rule properties from input records. Only the fields a record carries are changed, and an empty value clears the field.
Update an existing command of stream rules from input records.
Update a ticket comment in Logpresso Sonar.
Enumerate users in Logpresso Sonar.
Verify query syntax. The query to verify goes in brackets and is not quoted: sonar-verify-query [ QUERY_TO_VERIFY ]. Each stage is parsed on its own and reported as one row, so a stage that fails does not stop the ones after it.
List all widgets
Receive syslog packets in real-time for a specified time window.