Spider API allows you to:
You may search through Packets, Tcp Sessions, Http Communications, download them, analyse them with ElasticSearch power, rebuild the content...
POST /customer/v1/service-accounts/sessions to get your JWT token to use in all further calls.POST /web-read/v1/http-com/_search to search for HTTP communicationsGET /web-read/v1/http-com/{id}/res/body/ to get the response body of a communicationGET /teams/v1/teams/{id}/user-token/Give basic info, can be used for healthcheck of service
| service required | string (ServiceNames) Enum: "alert" "capture-status-poller" "ciphers" "ciphers-status" "ciphers-status-poller" "ciphers-raw-status-poller" "ciphers-status-agg" "controls" "customer" "gui-logs" "gui-settings" "hosts" "hosts-agg" "hosts-poller" "job" "link" "mail-sender" "maintenance" "pack-poller" "pack-read" "pack-write" "pack-update" "parsing-status-tcpsession-poller" "parsing-status-httppers-poller" "parsing-status-pgparsing-poller" "pg-com-poller" "pg-com-content-poller" "pg-parser" "pg-parsing-poller" "pg-read" "plugins" "session" "stats-collector" "status-poller" "tcp-poller" "tcp-read" "tcp-write" "tcp-update" "teams" "tls-keys" "tls-keys-linker" "web-httpcom-poller" "web-httpcom-content-poller" "web-httppers-poller" "web-read" "web-write" "whisp" "whisp-status-poller" "whisps-status" "whisps-status-agg" Service name |
Spider Customer
Give metrics informations for HTTP Api of this service
| service required | string (ServiceNames) Enum: "alert" "capture-status-poller" "ciphers" "ciphers-status" "ciphers-status-poller" "ciphers-raw-status-poller" "ciphers-status-agg" "controls" "customer" "gui-logs" "gui-settings" "hosts" "hosts-agg" "hosts-poller" "job" "link" "mail-sender" "maintenance" "pack-poller" "pack-read" "pack-write" "pack-update" "parsing-status-tcpsession-poller" "parsing-status-httppers-poller" "parsing-status-pgparsing-poller" "pg-com-poller" "pg-com-content-poller" "pg-parser" "pg-parsing-poller" "pg-read" "plugins" "session" "stats-collector" "status-poller" "tcp-poller" "tcp-read" "tcp-write" "tcp-update" "teams" "tls-keys" "tls-keys-linker" "web-httpcom-poller" "web-httpcom-content-poller" "web-httppers-poller" "web-read" "web-write" "whisp" "whisp-status-poller" "whisps-status" "whisps-status-agg" Micro service name |
{- "application": "tcp-streams-update",
- "hostname": "traballand-Latitude-E7240",
- "instanceId": "c1033254c68f",
- "requests": 886,
- "successes": 886,
- "errors": 0,
- "errors4xx": 0,
- "errors5xx": 0,
- "duration": 2311,
- "api": {
- "POST /v1/parsing-jobs/:type": {
- "method": "POST",
- "endpoint": "/v1/parsing-jobs/:type",
- "requests": 213,
- "successes": 213,
- "errors": 0,
- "errors4xx": 0,
- "errors5xx": 0,
- "duration": 603,
- "percentiles": {
- "0": 1,
- "25": 1,
- "50": 1,
- "75": 2,
- "90": 4,
- "95": 4,
- "99": 4
}
}, - "GET /v1/waiting-stats": {
- "method": "GET",
- "endpoint": "/v1/waiting-stats",
- "requests": 180,
- "successes": 180,
- "errors": 0,
- "errors4xx": 0,
- "errors5xx": 0,
- "duration": 355,
- "percentiles": {
- "0": 1,
- "25": 1,
- "50": 1,
- "75": 2,
- "90": 2,
- "95": 2,
- "99": 2
}
}, - "PATCH /v1/tcp-sessions/": {
- "method": "PATCH",
- "endpoint": "/v1/tcp-sessions/",
- "requests": 70,
- "successes": 70,
- "errors": 0,
- "errors4xx": 0,
- "errors5xx": 0,
- "duration": 697,
- "percentiles": {
- "0": 4,
- "25": 4,
- "50": 5,
- "75": 5,
- "90": 5,
- "95": 5,
- "99": 5
}
}
}
}Give circuit breakers informations for downstream connections of this service
| service required | string (ServiceNames) Enum: "alert" "capture-status-poller" "ciphers" "ciphers-status" "ciphers-status-poller" "ciphers-raw-status-poller" "ciphers-status-agg" "controls" "customer" "gui-logs" "gui-settings" "hosts" "hosts-agg" "hosts-poller" "job" "link" "mail-sender" "maintenance" "pack-poller" "pack-read" "pack-write" "pack-update" "parsing-status-tcpsession-poller" "parsing-status-httppers-poller" "parsing-status-pgparsing-poller" "pg-com-poller" "pg-com-content-poller" "pg-parser" "pg-parsing-poller" "pg-read" "plugins" "session" "stats-collector" "status-poller" "tcp-poller" "tcp-read" "tcp-write" "tcp-update" "teams" "tls-keys" "tls-keys-linker" "web-httpcom-poller" "web-httpcom-content-poller" "web-httppers-poller" "web-read" "web-write" "whisp" "whisp-status-poller" "whisps-status" "whisps-status-agg" Micro service name |
{- "application": "tcp-streams-write",
- "hostname": "spider4",
- "instanceId": "9300ef2cec06",
- "circuitBreakers": {
- "Redis": {
- "Save sessions": {
- "name": "Save sessions",
- "group": "Redis",
- "time": 1548884598363,
- "open": false,
- "circuitDuration": 15000,
- "threshold": 1,
- "waitThreshold": 100,
- "stats": {
- "failed": 0,
- "timedOut": 0,
- "total": 14,
- "shortCircuited": 0,
- "latencyMean": 6,
- "successful": 14,
- "percentiles": {
- "0": 2,
- "1": 15,
- "0.25": 2,
- "0.5": 3,
- "0.75": 8,
- "0.9": 12,
- "0.95": 15,
- "0.99": 15,
- "0.995": 15
}
}
}, - "Get sessions": {
- "name": "Get sessions",
- "group": "Redis",
- "time": 1548884598363,
- "open": false,
- "circuitDuration": 15000,
- "threshold": 1,
- "waitThreshold": 100,
- "stats": {
- "failed": 0,
- "timedOut": 0,
- "total": 14,
- "shortCircuited": 0,
- "latencyMean": 0,
- "successful": 14,
- "percentiles": {
- "0": 0,
- "1": 1,
- "0.25": 0,
- "0.5": 0,
- "0.75": 1,
- "0.9": 1,
- "0.95": 1,
- "0.99": 1,
- "0.995": 1
}
}
}
}, - "ES": {
- "Get sessions": {
- "name": "Get sessions",
- "group": "ES",
- "time": 1548884598363,
- "open": false,
- "circuitDuration": 30000,
- "threshold": 1,
- "waitThreshold": 100,
- "stats": {
- "failed": 0,
- "timedOut": 0,
- "total": 0,
- "shortCircuited": 0,
- "latencyMean": 0,
- "successful": 0,
- "percentiles": {
- "0": 0,
- "1": 0,
- "0.25": 0,
- "0.5": 0,
- "0.75": 0,
- "0.9": 0,
- "0.95": 0,
- "0.99": 0,
- "0.995": 0
}
}
}
}, - "PackUpdate": {
- "POST /pack-update/packets/parsed": {
- "name": "POST /pack-update/packets/parsed",
- "group": "PackUpdate",
- "time": 1548884598359,
- "open": false,
- "circuitDuration": 10000,
- "threshold": 1,
- "waitThreshold": 100,
- "stats": {
- "failed": 0,
- "timedOut": 0,
- "total": 1,
- "shortCircuited": 0,
- "latencyMean": 3,
- "successful": 1,
- "percentiles": {
- "0": 3,
- "1": 3,
- "0.25": 3,
- "0.5": 3,
- "0.75": 3,
- "0.9": 3,
- "0.95": 3,
- "0.99": 3,
- "0.995": 3
}
}
}
}
}
}Give process metrics for this service
| service required | string (ServiceNames) Enum: "alert" "capture-status-poller" "ciphers" "ciphers-status" "ciphers-status-poller" "ciphers-raw-status-poller" "ciphers-status-agg" "controls" "customer" "gui-logs" "gui-settings" "hosts" "hosts-agg" "hosts-poller" "job" "link" "mail-sender" "maintenance" "pack-poller" "pack-read" "pack-write" "pack-update" "parsing-status-tcpsession-poller" "parsing-status-httppers-poller" "parsing-status-pgparsing-poller" "pg-com-poller" "pg-com-content-poller" "pg-parser" "pg-parsing-poller" "pg-read" "plugins" "session" "stats-collector" "status-poller" "tcp-poller" "tcp-read" "tcp-write" "tcp-update" "teams" "tls-keys" "tls-keys-linker" "web-httpcom-poller" "web-httpcom-content-poller" "web-httppers-poller" "web-read" "web-write" "whisp" "whisp-status-poller" "whisps-status" "whisps-status-agg" Micro service name |
{- "application": "tcp-streams-write",
- "hostname": "spider7",
- "instanceId": "dd8ff8ac5565",
- "startTime": "2019-01-16T21:56:26.109Z",
- "upTime": 1209512.309,
- "cpu": {
- "overall": {
- "cores": 2,
- "idle": 62050469.2,
- "usage": 27683911.2,
- "total": 89734380.4
}, - "process": {
- "user": 14021.34,
- "system": 1117.168
}
}, - "memory": {
- "total": 8061386752,
- "free": 2321321984,
- "process": 113864704
}
}Give metrics informations for parsing
| parser required | string (ParserNames) Enum: "web-write" "tls-keys-linker" Micro service name |
{- "application": "web-streams-write",
- "hostname": "spider4",
- "instanceId": "cce9207215ae",
- "parsed": 13259,
- "created": 5005,
- "errors": 0,
- "completed": 856,
- "duration": 131623.869581,
- "started": 856,
- "delay": 8747139,
- "durationPercentiles": {
- "0": 51.69567,
- "25": 67.413543,
- "50": 83.969753,
- "75": 94.689424,
- "90": 145.061248,
- "95": 1009.291372,
- "99": 1050.284597,
- "100": 1059.290069
}, - "delayPercentiles": {
- "0": 10012,
- "25": 10187,
- "50": 10297,
- "75": 10395,
- "90": 10425,
- "95": 10446,
- "99": 10458,
- "100": 10479
}
}{- "license": {
- "name": "MyCompany build factory",
- "expires": "2024-11-30"
}, - "probes": {
- "tooManyLogs": {
- "status": "INACTIVE",
- "statusSince": "2024-01-28T16:18:01.127Z",
- "lastChecked": "2024-01-28T21:39:02.365Z"
}, - "noNewStatus": {
- "status": "INACTIVE",
- "statusSince": "2024-01-28T16:18:01.128Z",
- "lastChecked": "2024-01-28T21:39:01.869Z"
}
}
}Create a new controller, and associate it to the owner customer.
Controller creation request
| customer required | string System Id of the customer. |
| name required | string Name of the controller to create. |
{- "customer": "YOD66VZ54Jih",
- "name": "Upload"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for controllers
If client is not admin, the search will be limited to the Controllers owned by this customer or shared with him, directly or by the team.
Search parameters
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Aggregation request, using Elasticsearch aggregation DSL. |
| size required | integer Page size. |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| includeETags | boolean Tells if response should include _eTags fields for update. |
{- "query": "string",
- "aggs": { },
- "sort": [
- {
- "key": "string",
- "order": "asc"
}
], - "next": [
- "string"
], - "size": 0,
- "avoidTotalHits": true,
- "includeETags": true
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get a controller's details.
| id required | string Internal id of Controller |
{- "@id": "string",
- "@type": "Controller",
- "version": "string",
- "name": "string",
- "customer": "string",
- "apikey": "string",
- "config": {
- "@id": "string",
- "@type": "ControllerConfig",
- "version": "string",
- "creator": "string",
- "dateCreated": "2019-08-24",
- "editor": "string",
- "dateModified": "2019-08-24",
- "attachments": [
- {
- "@id": "string",
- "@type": "Attachment",
- "controller": "string",
- "whisperer": "string",
- "item": "string",
- "namespace": "string",
- "collection": "string",
- "status": "ATTACHMENT_REQUESTED",
- "expires": "2019-08-24",
- "creator": "string",
- "dateCreated": "2019-08-24",
- "editor": "string",
- "dateModified": "2019-08-24"
}
]
}, - "users": [
- {
- "@id": "string",
- "email": "string",
- "rights": {
- "share": true,
- "config": true,
- "install": true,
- "delete": true
}, - "namespaces": {
- "*": true,
- "namespace-name": true
}
}
], - "teams": [
- {
- "@id": "string",
- "name": "string",
- "namespaces": {
- "*": true,
- "namespace-name": true
}
}
], - "status": {
- "linked": true,
- "connected": "2019-08-24",
- "subscriptions": 0,
- "last": { }
}, - "creator": "string",
- "dateCreated": "2019-08-24",
- "editor": "string",
- "dateModified": "2019-08-24"
}Updates a customer. You can:
| id required | string Internal id of Controller |
| If-Match required | string eTag of previous state of the controller |
Json patch with the changes
| op required | string Enum: "test" "remove" "add" "replace" "move" "copy" |
| path required | string |
| value | string |
| from | string |
[- {
- "op": "test",
- "path": "string",
- "value": "string",
- "from": "string"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Delete a controller.
| id required | string Internal id of Controller |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Create/Replace the controller API key used for controller connection to Spider.
The API key is a public/private key pair.
Any call to this API (if authorized) will overwrite the previous API key, and the controller will not be able to use the previous one. A connected controller will be disconnected when its current JWT token will expire. The API key is taken as a configuration AT START of controllers, and need a restart to be changed.
The API can supports two outputs:
| id required | string System id of Controller |
{- "controller": "abcdefghijklmnopqrstuv",
- "privatePem": "-----BEGIN RSA PRIVATE KEY-----\nline1\nline2\nline3\n...\n-----END RSA PRIVATE KEY-----\n"
}This endpoint is for testing purposes only:
| id required | string System id of Controller |
| timeStamp required | string <date-time> Timestamp to use in signature |
| instanceId required | string InstanceId to use in signature |
The controller RSA private key, as a PEM
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get the configuration of this Controller Usages:
The first call from controllers is made by:
const timeStamp = moment().toISOString();
const info = {
timeStamp,
controllerId
};
const privKey = new NodeRSA(privatePem);
const signature = privKey.sign(Buffer.from(JSON.stringify(info)), 'base64');
Spider-TimeStamp: timeStamp
Spider-Signature: signature //base 64 encoded
| id required | string System id of Controller |
| Spider-Signature | string <base64> Signature of the call by the Controller, with its API key |
| Spider-Timestamp | string <date-time> Provided with API key in first Controller call to get its JWT token with the config |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Updates a Controller configuration.
| id required | string System id of Controller |
| If-Match required | string eTag of previous state of the Controller's config |
Json patch with the changes
| op required | string Enum: "test" "remove" "add" "replace" "move" "copy" |
| path required | string |
| value | string |
| from | string |
[- {
- "op": "test",
- "path": "string",
- "value": "string",
- "from": "string"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get the list of namespaces names from the cluster.
Returns 404 if the controller is not connected.
| id required | string System id of Controller |
[- "string"
]Get the list of objects from the cluster.
Returns 404 if the controller is not connected.
| id required | string System id of Controller |
| namespace required | string Name of the namespace we want the object from |
| collection required | string Enum: "pods" "statefulsets" "deployments" "cronjobs" Collection we are interested in |
[- {
- "name": "alert",
- "children": [
- {
- "objectType": "replicasets",
- "name": "alert-855f6f6548",
- "children": [
- {
- "objectType": "pods",
- "name": "alert-855f6f6548-vbsfp"
}
]
}
]
}, - {
- "name": "capture-status-poller",
- "children": [
- {
- "objectType": "replicasets",
- "name": "capture-status-poller-5695d8487c",
- "children": [
- {
- "objectType": "pods",
- "name": "capture-status-poller-5695d8487c-cflqp"
}
]
}
]
}
]Create a new attachment, asking, by it, to spawn a Whisperer to each linked Pod
| id required | string System id of Controller |
Attachment creation request
| whisperer required | string Whisperer Id to attach. |
| namespace required | string Namespace where the workload is. |
| collection required | string Enum: "pods" "statefulsets" "daemonsets" "deployments" "cronjobs" Collection of the workload. |
| item required | string Name of the workload. |
| agent | string Enum: "whisperer" "gossiper" Agent to attach. |
{- "whisperer": "string",
- "namespace": "string",
- "collection": "pods",
- "item": "string",
- "agent": "whisperer"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get last logs of the attached Whisperer.
| id required | string System id of Controller |
| attachment required | string System id of the Attachment |
| container required | string Container id of the Whisperer |
[- {
- "time": "2024-12-01T09:52:51.791Z",
- "level": 30,
- "msg": "Gossiper starting.",
- "module": "main",
- "version": "7.2.1"
}
]Ask for the attachment to be terminated.
The Whisperers connected to the worload linked to this attachment will terminate the next time they check their status.
| id required | string System id of Controller |
| attachment required | string System id of the Attachment |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for attachments
If client has limited access to namespaces, the search will be limited to the Attachments the user can access, directly or by the team.
| id required | string System id of Controller |
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Returns the list of Whisperers that the Controller knows and manages.
| id required | string System id of Controller |
[- {
- "name": "spider-whisperer-qcc4tpvythic6fvayf2vtw-1693774449",
- "namespace": "spider-system",
- "pod": "job-688b6ddc85-swnx9",
- "attachment": {
- "@id": "MGO-9NowQzay09lPEytyFg",
- "@type": "Attachment",
- "controller": "local-controller",
- "whisperer": "qCC4TpvyThic6FVAYf2VTw",
- "item": "job",
- "namespace": "spider-system",
- "collection": "deployments",
- "status": "ATTACHED",
- "creator": "ILWAjWPGQLm3Qf2eSPCAUA",
- "dateCreated": "2023-09-03T20:54:09.116Z",
- "expires": "2023-09-03T22:54:09.116Z",
- "editor": "local-controller",
- "dateModified": "2023-09-03T20:54:10.491Z"
}, - "whisperer": "qCC4TpvyThic6FVAYf2VTw",
- "state": {
- "running": {
- "startedAt": "2023-09-03T20:54:09Z"
}
}
}
]Returns the list of Sidecar Whisperers that the Controller knows.
| id required | string System id of Controller |
[- {
- "@id": "spider-system.deployments.hosts.qCC4TpvyThic6FVAYf2VTw",
- "namespace": "spider-system",
- "kind": "deployments",
- "name": "hosts",
- "whisperer": "qCC4TpvyThic6FVAYf2VTw",
- "agent": "Gossiper",
- "instances": [
- {
- "@id": "spider-system.hosts-649c985c8f-9shvn.hosts-whisperer",
- "pod": "hosts-649c985c8f-9shvn",
- "container": "hosts-whisperer",
- "node": "192.168.1.56",
- "status": {
- "state": "running",
- "startedAt": "2024-11-30T22:54:18Z"
}
}
]
}
]Returns the last logs of the Sidecar Whisperer
| id required | string System id of Controller |
| key required | string @id of the sidecar whisperer container as returned by GET /whisperers/sidecars |
[- {
- "time": "2024-12-01T12:45:11.363Z",
- "level": 30,
- "msg": "Gossiper starting.",
- "module": "main",
- "version": "7.2.1"
}
]Returns the list of Gociphers that the Controller knows.
| id required | string System id of Controller |
[- {
- "@id": "spider-system.local-gocipher",
- "namespace": "spider-system",
- "kind": "daemonsets",
- "gocipher": "local-gocipher",
- "controller": "local-controller",
- "instances": [
- {
- "@id": "spider-system.local-gocipher-wv6f6",
- "pod": "local-gocipher-wv6f6",
- "container": "local-gocipher",
- "node": "192.168.1.56",
- "status": {
- "state": "running",
- "startedAt": "2024-12-01T12:42:28Z"
}
}
]
}
]Returns the last Logs of the Gocipher.
| id required | string System id of Controller |
| key required | string @id of the Gocipher container as returned by GET /gociphers |
[- {
- "time": "2024-12-01T12:42:28.398Z",
- "level": 30,
- "msg": "Gocipher starting.",
- "module": "main",
- "version": "1.3.2",
- "linuxKernel": "6.8.12",
- "code": "GCPH-MAIN-001"
}
]Save Network Usage to make it accessible for analysis
| id required | string System id of Controller |
Network Usage
| controller required | string |
| minute required | string <date-time> |
| nodes required | integer >= 0 |
required | Array of objects |
{- "controller": "string",
- "minute": "2019-08-24T14:15:22Z",
- "nodes": 0,
- "items": [
- {
- "client": {
- "namespace": "string",
- "name": "string",
- "ip": "string",
- "kind": "string",
- "actor": "string",
- "node": {
- "name": "string",
- "ip": "string",
- "podCIDRs": [
- "string"
]
}, - "instance": {
- "name": "string",
- "kind": "string"
}
}, - "server": {
- "namespace": "string",
- "name": "string",
- "ip": "string",
- "kind": "string",
- "actor": "string",
- "node": {
- "name": "string",
- "ip": "string",
- "podCIDRs": [
- "string"
]
}, - "instance": {
- "name": "string",
- "kind": "string"
}, - "port": 0
}, - "ingress": {
- "packetsCount": 0,
- "totalBytes": 0
}, - "egress": {
- "packetsCount": 0,
- "totalBytes": 0
}
}
]
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for Network Usage
If client has limited access to namespaces, the search will be limited to the Attachments the user can access, directly or by the team.
| id required | string System id of Controller |
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Returns the list of Attachments linked to a Whisperer.
The service will calls all referenced and connected Controllers to get the status of the Whisperers.
| id required | string System id of a Whisperer |
[- {
- "@id": "MGO-9NowQzay09lPEytyFg",
- "@type": "Attachment",
- "controller": "local-controller",
- "whisperer": "qCC4TpvyThic6FVAYf2VTw",
- "item": "job",
- "namespace": "spider-system",
- "collection": "deployments",
- "status": "ATTACHED",
- "creator": "ILWAjWPGQLm3Qf2eSPCAUA",
- "dateCreated": "2023-09-03T20:54:09.116Z",
- "expires": "2023-09-03T22:54:09.116Z",
- "editor": "local-controller",
- "dateModified": "2023-09-03T20:54:10.491Z",
- "whisperers": [
- {
- "name": "spider-whisperer-qcc4tpvythic6fvayf2vtw-1693774449",
- "namespace": "spider-system",
- "pod": "job-688b6ddc85-swnx9",
- "whisperer": "qCC4TpvyThic6FVAYf2VTw",
- "state": {
- "running": {
- "startedAt": "2023-09-03T20:54:09Z"
}
}
}
]
}
]Returns the last logs of the Controller.
| id required | string System id of a Controller |
[- {
- "name": "controller",
- "hostname": "local-controller-57f9559cfd-vbldj",
- "pid": 1,
- "level": 30,
- "msg": "Controller local-controller starting. Version: 1.6.0.",
- "time": "2024-12-01T12:42:16.553Z",
- "v": 0
}
]Connects a customer and returns a JWT token
When successful, a cookie is set in the answer, containing the refresh_token. The cookie is http only, secure, with strict domain and path.
The email/password for connection
| email required | string |
| password required | string <password> Password |
{- "email": "string",
- "password": "pa$$word"
}{- "customer": "string",
- "token": "string"
}Connects a customer using OIDC and returns a JWT token.
Takes in input the code provided by the Identity Provider
and the name of the IP, as set in configuration.
The code and IP to get the tokens from
| code required | string Code received from the authorization_endpoint |
| provider | string Identity provider name set in configuration |
{- "code": "string",
- "provider": "string"
}{- "customer": "string",
- "token": "string"
}Connects a service account and returns a JWT token.
Takes in input the client_id and client_secret of the service account.
grant_type must be equals to "client_credentials"application/x-www-form-urlencoded content type, client_id and client_secret may also be provided as a Basic Authorization headerThe service account credentials
| client_id required | string |
| client_secret required | string |
| grant_type required | string Value: "client_credentials" |
{- "client_id": "string",
- "client_secret": "string",
- "grant_type": "client_credentials"
}{- "access_token": "string",
- "token_type": "Bearer",
- "expires_in": 0
}Create a new customer.
All fields are optional at start, but checked for correctness.
To create an ACTIVE customer, all mandatory fields must be set. Status must be set as ACTIVE.
Either:
The customers details
| email required | string Customer's email. |
| _password required | string >= 6 characters Customer's password. |
| _admin | boolean True if user is an administrator. |
required | object |
| birthDate | string <date> Date of birth. |
| honorificPrefix | string An honorific prefix preceding a name such as Dr/Mrs/Mr. |
| givenName required | string The given name, the first name. |
| familyName required | string The family name, the last name. |
| nationality required | string Nationality. |
| jobTitle | string The job title (for example, Financial Manager). |
| worksFor | string Organizations'name that the person works for. |
{- "email": "example@gmail.com",
- "_password": "YGIUHIdzzf!/85F",
- "_admin": true,
- "givenName": "John",
- "familyName": "Doe",
- "nationality": "American",
- "address": {
- "addressCountry": "France"
}, - "technicalStatus": "DRAFT"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Create a new service account.
All fields are optional at start, but checked for correctness.
To create an ACTIVE service account, all mandatory fields must be set. Status must be set as ACTIVE.
The service account details
| name required | string |
| description | string |
| _password required | string >= 6 characters client_secret |
| _admin | boolean True if service account is an administrator. |
| worksFor | string Organizations'name that the person works for. |
{- "name": "Spider bot",
- "_password": "YGIUHOIUHIOEUKBEZUICUYEGIIdzzf!/85F",
- "technicalStatus": "ACTIVE"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for customers.
Also available by GET method on the collection
Search parameters
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Aggregation request, using Elasticsearch aggregation DSL. |
| size required | integer Page size. |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| includeETags | boolean Tells if response should include _eTags fields for update. |
{- "query": "string",
- "aggs": { },
- "sort": [
- {
- "key": "string",
- "order": "asc"
}
], - "next": [
- "string"
], - "size": 0,
- "avoidTotalHits": true,
- "includeETags": true
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get a customer's details.
_password field is always stripped out.Response is:
Response is limited to:
Response is limited to:
| id required | string Customer internal @id |
{- "@id": "Jz6lxOiuQYaIZNNouiyt6w",
- "@type": "Person",
- "version": "0.1",
- "technicalStatus": "ACTIVE",
- "creator": "AWUb00luIXCLtCIFlzoO",
- "dateCreated": "2018-12-21T10:00:00.837Z",
- "editor": "Jz6lxOiuQYaIZNNouiyt6w",
- "dateModified": "2018-12-21T16:15:18.978Z",
- "givenName": "John",
- "familyName": "Doe",
- "nationality": "American",
- "email": "example@gmail.com",
- "address": {
- "addressCountry": "France"
}, - "rights": {
- "whisperers": {
- "monitor": true
}
}, - "whisperers": [
- {
- "@id": "Gu0ManDYSXGr8Sxi3s-sxg",
- "name": "WhispTest"
}, - {
- "@id": "rSSa3P5gQ-2S037OBIp6NA",
- "name": "Private Whisp"
}
], - "_eTag": "\"d7-+6EM6pRmKNKDSTtAgeIK5g\""
}Updates a customer. You can:
Patch must be done with resource previous eTag
Technical fields are protected (@id, creator, dateCreated, @type)
For a customer to change its password or email, patch operations must include previous password value inside a test operation
{ "op":"test", "path":"_password", "value":"xxx" }When customer changes email:
When customer changes password:
When a customer changes from Draft to Active
User cannot change its own Whisperers list
Admins can:
User details, once in ACTIVE state, can only be modified by own customer
Whisp & Maintenance services can:
_password and _admin field cannot be removed, copied or moved
email field cannot be removed or moved
| id required | string Customer internal @id |
| If-Match required | string eTag of previous state of the customer |
Json patch with the changes
| op required | string Enum: "test" "remove" "add" "replace" "move" "copy" |
| path required | string |
| value | string |
| from | string |
[- {
- "op": "test",
- "path": "string",
- "value": "string",
- "from": "string"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Set a customer to DELETED status. When the customer has one to many own Whisperers of UPLOAD type, they are also deleted.
| id required | string Customer internal @id |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Same as GET /customer/v1/customers/{id}
| email required | string Customer email |
{- "@id": "Jz6lxOiuQYaIZNNouiyt6w",
- "@type": "Person",
- "version": "0.1",
- "technicalStatus": "ACTIVE",
- "creator": "AWUb00luIXCLtCIFlzoO",
- "dateCreated": "2018-12-21T10:00:00.837Z",
- "editor": "Jz6lxOiuQYaIZNNouiyt6w",
- "dateModified": "2018-12-21T16:15:18.978Z",
- "givenName": "John",
- "familyName": "Doe",
- "nationality": "American",
- "email": "example@gmail.com",
- "address": {
- "addressCountry": "France"
}, - "rights": {
- "whisperers": {
- "monitor": true
}
}, - "whisperers": [
- {
- "@id": "Gu0ManDYSXGr8Sxi3s-sxg",
- "name": "WhispTest"
}, - {
- "@id": "rSSa3P5gQ-2S037OBIp6NA",
- "name": "Private Whisp"
}
], - "_eTag": "\"d7-+6EM6pRmKNKDSTtAgeIK5g\""
}Generates a token for a user to be able to use another user whisperers and rights.
impersonated field.useUserRights is 'true')| id required | string Customer internal @id |
| useUserRights | boolean Ask to use user's right in the token. Keep caller's right if false. |
{- "token": "string"
}Create a password challenge to reinitialize a password. A token is created and sent by mail with a redirection link to the user. The redirection link:
The email of the account
| email required | string |
| redirectUrl required | string Base Url to construct the redirection link. Expected: Login UI endpoint. |
{- "email": "string",
- "redirectUrl": "string"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Set a new password to a user with:
An email is sent to the user to inform him of password change. Connections error count is reset ;)
The new password of the account
| email required | string |
| token required | string Token sent in challenge |
| password required | string Password choosen by the user |
{- "email": "string",
- "token": "string",
- "password": "string"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Used in mails sent to users to confirm their email addresses. This is why it is a GET, not a POST.
| email required | string |
| token required | string Mail confirmation token |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}OAuth 2.1 authorization server for human-delegated agent connections (RFC 7591 dynamic client registration, RFC 6749 authorization code + PKCE, RFC 7662 introspection, RFC 7009 revocation, per-user connected-app grants). Machine-to-machine integrations should keep using service accounts with the client_credentials flow instead. Requires the MCP licence capability (TEAM tier and above); ships off by default (customers.oauth.enabled).
Registers a new OAuth client (an agent such as claude.ai or ChatGPT) and returns its
client_id (and, unless token_endpoint_auth_method is none, a client_secret shown
exactly once, in this response, and never retrievable again).
Unauthenticated by design - this is the front door an agent calls before any Spider identity exists yet.
customers.oauth.enabled is true and
customers.oauth.dynamicRegistration is open or gated. Only disabled (or
oauth.enabled: false) always answers 404 not_found - never a distinguishing error - so
a scanner cannot tell "registration is closed here" from "this Spider has no OAuth
support".gated mode, every redirect_uri in the request must match an entry on the
server's callback catalogue (GET /customer/v1/oauth/callback-catalogue lists which
vendors an admin has authorised - see that path). A non-matching redirect_uri is
refused with the exact same 400 invalid_redirect_uri body as a structurally
malformed one - the caller learns its URI was unacceptable, never whether a catalogue
exists or what is on it.verified on the created client is true only when every redirect_uri matched an
enabled catalogue entry and none of them is a loopback address (localhost,
127.0.0.1, [::1]) - a loopback callback can be admitted (a native client has nowhere
else to redirect) but is never verified, since any local process can bind that port. This
is computed once, at registration; disabling the catalogue entry afterwards never revokes
an already-issued verified: true.customers.oauth.registrationRateLimit (default 10 per hour) - a
platform-wide ceiling behind the gateway, not a per-caller one: this service never
trusts X-Forwarded-For, so every external caller is counted against the same counter.application/json request bodies are accepted.resource parameter is accepted and silently ignored: the token this server
mints is opaque and carries no audience.gated (M6, final review) - the
catalogue match that decides gated's admission also feeds verified in open mode. A
fault reading the catalogue's own ES store therefore surfaces as this endpoint's generic
500 server_error in open mode too, not only gated.MCP licence capability (TEAM tier and above)The client metadata to register
| client_name required | string [ 1 .. 200 ] characters Human-readable name shown on the consent screen. Client-supplied and NOT verified - never trust it as proof of the caller's identity. |
| redirect_uris required | Array of strings <uri> [ 1 .. 20 ] items [ items <uri > ] Registerable redirect URIs. Matched byte-exact (no normalisation) at /authorize. |
| token_endpoint_auth_method | string Default: "none" Enum: "none" "client_secret_post" "client_secret_basic" How this client authenticates at /token and /revoke. none mints no client_secret (public client, e.g. a native/desktop agent using PKCE). |
| grant_types | Array of strings Default: ["authorization_code","refresh_token"] Items Enum: "authorization_code" "refresh_token" |
| response_types | Array of strings Default: ["code"] Items Value: "code" |
| client_uri | string <uri> Must be https. |
| logo_uri | string <uri> Must be https. |
| scope | string Value: "spider:full" The only scope this authorization server issues. |
{- "client_name": "string",
- "token_endpoint_auth_method": "none",
- "grant_types": [
- "authorization_code",
- "refresh_token"
], - "response_types": [
- "code"
], - "scope": "spider:full"
}{- "client_id": "string",
- "client_name": "string",
- "grant_types": [
- "string"
], - "response_types": [
- "string"
], - "token_endpoint_auth_method": "none",
- "client_id_issued_at": 0,
- "client_secret": "string"
}Exchanges an authorization code (with its PKCE code_verifier) or a refresh token for a
fresh access/refresh token pair. This endpoint authenticates the OAuth CLIENT, not a
Spider user, so it is unauthenticated by koa-jwt design - client authentication is one of
none (public client), client_secret_post (client_id/client_secret in the body),
client_secret_basic (Authorization: Basic base64(client_id:client_secret)), or
private_key_jwt (client_assertion_type/client_assertion, for a CIMD client whose
document declares it); only one method may be used per request.
Both application/json and application/x-www-form-urlencoded bodies are accepted.
Every response, success or error, carries Cache-Control: no-store (RFC 6749 §5.1).
access_token is opaque, not a JWT - it is meaningless to any Spider service other than
this one's own /introspect. Refresh tokens are single-use: presenting an already-rotated
refresh token revokes the whole grant (reuse detection), and RFC 6749 §6 scope narrowing
does not apply here, so scope is omitted from refresh_token responses.
grant_type=authorization_code requires code, redirect_uri and code_verifier; the
code, once redeemed, cannot be redeemed again, and its client_id/redirect_uri bindings
from consent time must match this request exactly.grant_type=refresh_token requires exactly refresh_token, and rejects it if it was
issued to a different client than the one authenticating this request.resource parameter is accepted and silently ignored.MCP licence capability (TEAM tier and above)The token request, per grant_type
| grant_type required | string Enum: "authorization_code" "refresh_token" |
| code | string Required for authorization_code; forbidden for refresh_token. |
| redirect_uri | string <uri> Required for authorization_code; forbidden for refresh_token. |
| code_verifier | string Required for authorization_code; forbidden for refresh_token. |
| refresh_token | string Required for refresh_token; forbidden for authorization_code. |
| client_id | string Omit when authenticating via HTTP Basic instead. |
| client_secret | string Omit when authenticating via HTTP Basic instead, or for a |
| client_assertion_type | string Value: "urn:ietf:params:oauth:client-assertion-type:jwt-bearer" RFC 7523 |
| client_assertion | string The signed JWT assertion - see |
| resource | string RFC 8707 - accepted and ignored. |
{- "access_token": "string",
- "token_type": "Bearer",
- "expires_in": 0,
- "refresh_token": "string",
- "scope": "string"
}Resolves an opaque OAuth token back to a live Spider identity. This is the interface an
external resource server (e.g. an MCP server) calls to authorize a tool call. The response
field names are a fixed contract for that caller - active: false is rendered alone for
any unknown, expired or revoked token, never as an error.
access_token in the response is a freshly-minted Spider JWT for the grant's customer
(refreshed transparently, single-flight, when the cached one has expired) - never the
OAuth access token itself, and never the underlying Spider refresh token.
Every response carries Cache-Control: no-store.
This endpoint's error responses (403, 404, 422) use the same {error, error_description}
OAuth error shape as every other endpoint on this surface (see
#/components/schemas/OAuthError).
MCP licence capability (TEAM tier and above)The token to introspect
| token required | string |
| token_type_hint | string Accepted per RFC 7662 §2.1 but never narrows the search - both access and refresh token stores are always tried. |
{- "token": "string",
- "token_type_hint": "string"
}{- "active": true,
- "customer": "string",
- "email": "string",
- "isAdmin": true,
- "whisperers": [
- "string"
], - "scopes": [
- "string"
], - "access_token": "string",
- "expires_in": 0
}Revokes the whole grant reachable from the presented access or refresh token value
(revocation is per-grant, not per-token). This endpoint authenticates the OAuth CLIENT,
not a Spider user, using the same methods as /token (none, client_secret_post,
client_secret_basic, private_key_jwt); it is unauthenticated by koa-jwt design for
the same reason /token is.
A tombstoned (already-rotated) refresh token still resolves to its grant and is honoured here - a client revoking a credential it once legitimately held gets the same whole-grant revoke a live token would produce.
Both application/json and application/x-www-form-urlencoded bodies are accepted, both
token and token_type_hint and the client credential fields.
RFC 7009 §2.2 requires this endpoint to answer 200 regardless of outcome - an unknown
token, a token belonging to a different client than the one authenticating this request
(refused, not revoked), and an actual revocation are all rendered identically, to avoid
turning this endpoint into an oracle for which token values are real. Every response
carries Cache-Control: no-store.
MCP licence capability (TEAM tier and above)The token to revoke, and the client's own credentials
| token required | string |
| token_type_hint | string Accepted per RFC 7009 §2.1 but never narrows the search. |
| client_id | string Omit when authenticating via HTTP Basic instead. |
| client_secret | string Omit when authenticating via HTTP Basic instead, or for a |
| client_assertion_type | string Value: "urn:ietf:params:oauth:client-assertion-type:jwt-bearer" RFC 7523 |
| client_assertion | string The signed JWT assertion - see |
{- "token": "string",
- "token_type_hint": "string",
- "client_id": "string",
- "client_secret": "string",
- "client_assertion_type": "urn:ietf:params:oauth:client-assertion-type:jwt-bearer",
- "client_assertion": "string"
}{- "error": "string",
- "error_description": "string"
}Publishes the public key an artefact issued by this authorization server could be verified
with. In practice nothing on this surface issues a JWT to a caller outside this process
(access/refresh tokens are opaque - see OAuthTokenResponse), so this endpoint exists for
completeness/future use rather than a verifier that exists today.
Unauthenticated by design - a JWKS document is meant to be publicly fetchable.
MCP licence capability (TEAM tier and above) - gated on licence alone,
independent of customers.oauth.enabled{- "keys": [
- {
- "kty": "string",
- "n": "string",
- "e": "string",
- "use": "sig",
- "alg": "RS256",
- "kid": "string"
}
]
}Lists every live OAuth grant belonging to the calling Spider customer - the "Connected
apps" view. This is one of only two OAuth paths that take an ordinary Spider user JWT
rather than OAuth client credentials (the other is the DELETE below).
Signing out of Spider does NOT revoke a connected agent's grant - a grant has its own,
independent Spider session by design, so it survives a browser logout. This listing (and
the DELETE below) is the only in-product way to end a grant short of its refresh token's
own TTL.
lastUsedAt/expiresAt are always null today - nothing on this surface populates them
yet; the keys are reserved for a future task.
MCP licence capability (TEAM tier and above) - gated on licence alone,
independent of customers.oauth.enabled (same exception as jwks above)[- {
- "grantId": "string",
- "clientId": "string",
- "clientName": "string",
- "scopes": [
- "string"
], - "createdAt": "2019-08-24T14:15:22Z",
- "lastUsedAt": "2019-08-24T14:15:22Z",
- "expiresAt": "2019-08-24T14:15:22Z"
}
]Ends a single grant - the "Connected apps" disconnect action. The other of the two OAuth
paths taking an ordinary Spider user JWT (see GET /customer/v1/oauth/grants above).
grant.customer must match the caller; a caller can never revoke another customer's grant.
404 - never 403 - for BOTH "no such grant" and "exists, but belongs to
someone else". A 403 would confirm the grantId is real, letting a caller enumerate
other customers' grant ids by probing which ones come back 403 vs 404. The two cases
are told apart only in the server log, never in the response.404.MCP licence capability (TEAM tier and above) - gated on licence alone,
independent of customers.oauth.enabled (same exception as jwks above)| grantId required | string |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Lists every registered OAuth client (self-registered via POST /customer/v1/oauth/register
/customer/v1/oauth/callback-catalogue below), for the client-administration
view.query, if present, is an Elasticsearch query_string matched against the client's
_quick_search field (client_id, client_name).createdAt descending, newest-registered first (M2, final review). Capped at
100 results with no pagination cursor - a deployment with more than 100 registered
clients cannot page past the first 100 through this endpoint today.404, never 403 - see Access below.oauthClients.create right| query | string Elasticsearch query_string against the client's _quick_search field. |
[- {
- "client_id": "string",
- "client_name": "string",
- "verified": true,
- "disabled": true,
- "registration_type": "dynamic",
- "token_endpoint_auth_method": "none",
- "cimdExpiresAt": "2019-08-24T14:15:22Z",
- "createdAt": "2019-08-24T14:15:22Z",
- "lastUsedAt": "2019-08-24T14:15:22Z",
- "createdBy": "string",
- "liveGrants": 0
}
]Returns one registered client, including its current count of still-live grants.
oauthClients.create right| client_id required | string 32 hex characters for a registered client, or the URL-encoded metadata document URL of a CIMD client. |
{- "client_id": "string",
- "client_name": "string",
- "verified": true,
- "disabled": true,
- "registration_type": "dynamic",
- "token_endpoint_auth_method": "none",
- "cimdExpiresAt": "2019-08-24T14:15:22Z",
- "createdAt": "2019-08-24T14:15:22Z",
- "lastUsedAt": "2019-08-24T14:15:22Z",
- "createdBy": "string",
- "liveGrants": 0
}Toggles disabled, the only field this endpoint may change. Disabling stops new
authorizations, token issuance and refreshes for this client at /authorize, /token and
/revoke - it deliberately leaves every grant the client already holds untouched, so an
operator can pause a suspicious client and investigate before destroying evidence.
DELETE below is the separate, destructive step that also revokes live grants.
oauthClients.create right| client_id required | string 32 hex characters for a registered client, or the URL-encoded metadata document URL of a CIMD client. |
| disabled required | boolean |
{- "disabled": true
}{- "client_id": "string",
- "client_name": "string",
- "verified": true,
- "disabled": true,
- "registration_type": "dynamic",
- "token_endpoint_auth_method": "none",
- "cimdExpiresAt": "2019-08-24T14:15:22Z",
- "createdAt": "2019-08-24T14:15:22Z",
- "lastUsedAt": "2019-08-24T14:15:22Z",
- "createdBy": "string",
- "liveGrants": 0
}Deletes the client registration and cascades: revokes every grant this client still
holds live first, then deletes the client record. This is the destructive counterpart to
PATCH's disabled toggle above, which touches no grant.
404 as one that never
existed.oauthClients.create and oauthClients.delete rights (holding
only one of the two is refused identically to holding neither)| client_id required | string 32 hex characters for a registered client, or the URL-encoded metadata document URL of a CIMD client. |
{- "deleted": true,
- "grantsRevoked": 0
}Lists every callback-catalogue entry: the shipped vendor definitions (from the Config
service defaults, each with its live enabled state) plus any custom entries an admin has
added. This is the surface an admin uses to authorise which agent platforms may
self-register - D18: an admin authorises callbacks, never creates clients.
oauthClients.create right[- {
- "entry_id": "string",
- "vendor_name": "string",
- "match": "exact",
- "enabled": true,
- "custom": true,
- "createdBy": "string",
- "createdAt": "2019-08-24T14:15:22Z"
}
]Adds a custom entry for a self-hosted or bespoke client no vendor catalogue could know
about - the admin authorises its callback URL(s), and the client then self-registers
unattended like any other, once the entry is enabled (see PATCH below).
callback_urls must be https:// - no fragment, no userinfo - loopback URLs are never
accepted for a custom entry (loopback is reserved for the match: loopback kind, which
only a shipped entry uses today).PATCH below),
same as a shipped vendor entry.match is always exact for a custom entry.oauthClients.create right| vendor_name required | string [ 1 .. 120 ] characters |
| callback_urls required | Array of strings <uri> [ 1 .. 20 ] items [ items <uri > ] https only - no fragment, no userinfo. Loopback URLs are not accepted for a custom entry. |
| client_ids | Array of strings <uri> <= 20 items [ items <uri > ] Optional. Exact Client ID Metadata Document URLs this entry vouches for. |
{- "vendor_name": "string",
}{- "entry_id": "string",
- "vendor_name": "string",
- "match": "exact",
- "enabled": true,
- "custom": true,
- "createdBy": "string",
- "createdAt": "2019-08-24T14:15:22Z"
}Toggles enabled (shipped vendor entry or custom one alike) and/or sets client_ids
(custom entries only) - the only fields this endpoint may change.
verified flag, or any of its grants (D16 applied one
level up from the client PATCH above).client_ids can only be set on a custom entry - 400 on a shipped one.oauthClients.create right| entry_id required | string^[a-z0-9-]{1,64}$ |
| enabled | boolean |
| client_ids | Array of strings <uri> <= 20 items [ items <uri > ] Custom entries only - 400 on a shipped entry. |
{- "enabled": true,
}{- "entry_id": "string",
- "vendor_name": "string",
- "match": "exact",
- "enabled": true,
- "custom": true,
- "createdBy": "string",
- "createdAt": "2019-08-24T14:15:22Z"
}Removes a custom entry. A shipped vendor entry can only be disabled (PATCH above),
never removed - it ships again, unchanged, on the next deploy regardless of this call.
entry_id answers the same 404 as an unknown one - this endpoint
never confirms whether an id names a shipped entry.DELETE /customer/v1/oauth/clients/{client_id}, no second right is required:
removing a catalogue entry revokes a future authorisation, never a live credential.oauthClients.create right| entry_id required | string^[a-z0-9-]{1,64}$ |
{- "deleted": true
}Creates a new team and add the owner as the first full rights customer.
The team to create
| name required | string Team's name. |
| description | string Team's description. |
required | object Owner of the team. |
{- "name": "string",
- "description": "string",
- "owner": {
- "@id": "string",
- "email": "string"
}
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get a team's details.
Response is:
Response is limited to:
Response is limited to:
| id required | string Team internal @id |
{- "@id": "AnaRheQISOmLu8bKiQv11w",
- "@type": "Team",
- "version": "0.1",
- "name": "First team",
- "description": "Short team description.",
- "dateCreated": "2021-03-07T14:43:35.152Z",
- "creator": "hfQ1rsfcRKWslHwWAPJ9bg",
- "customers": [
- {
- "@id": "hfQ1rsfcRKWslHwWAPJ9bg",
- "email": "owner@gmail.com",
- "rights": {
- "share": true,
- "rights": true,
- "whisperers": true,
- "settings": true,
- "update": true
}
}, - {
- "@id": "FExgyFYtQdmskfNGpnKVBQ",
- "email": "test@gmail.com",
- "rights": {
- "rights": true,
- "whisperers": true,
- "share": false
}
}
], - "whisperers": [
- "dR6Gujz4RC2QyoAOyfDnWA",
- "H_rczKsfRXSJbkgQMk-ZYQ",
- "x7jxYx5PQb2wPEYa7D4Kgw",
- "M_OhNqT8TWGEEdVWVBOmiQ",
- "xGFWIX7zQMungzHcGz0YOw",
- "qCC4TpvyThic6FVAYf2VTw"
], - "settings": {
- "mergePattern": "^spiderdev_([^.]+).?",
- "clientsIdsCompactingPattern": "^http://spider.io/((?:apps|whisperers|customers)/.*)$"
}, - "technicalStatus": "ACTIVE",
- "dateModified": "2021-03-18T22:15:39.345Z",
- "token": "7p8i66dCQsynmFNULKdnjA",
- "editor": "hfQ1rsfcRKWslHwWAPJ9bg"
}Updates a team. You can:
Patch must be done with resource previous eTag
Patch cannot be done on DELETED team
Technical fields are protected (@id, creator, dateCreated, @type)
Customers with share right can update customers list and access filters
Customers with settings right can update team settings
Customers with update right can update name, description
Whisp and Maintenance services can:
Token cannot be changed with patch
A mail is sent to team administrators with changes made
After update,
| id required | string Team internal @id |
| If-Match required | string eTag of previous state of the team |
Json patch with the changes
| op required | string Enum: "test" "remove" "add" "replace" "move" "copy" |
| path required | string |
| value | string |
| from | string |
[- {
- "op": "test",
- "path": "string",
- "value": "string",
- "from": "string"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Set a team to DELETED status.
If the team is a training team, its own whisperers are deleted.
| id required | string Team internal @id |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Join a user to a team with:
An email is sent to the team admin to tell them about new user.
The new password of the account
| email required | string |
| token required | string Token sent in challenge |
| password required | string Password choosen by the user |
{- "email": "string",
- "token": "string",
- "password": "string"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Generates a token for the user to be able to use team's whisperers and rights.
| id required | string Team internal @id |
{- "token": "string"
}Same as GET /teams/v1/teams/{id}
| name required | string Team name |
{- "@id": "AnaRheQISOmLu8bKiQv11w",
- "@type": "Team",
- "version": "0.1",
- "name": "First team",
- "description": "Short team description.",
- "dateCreated": "2021-03-07T14:43:35.152Z",
- "creator": "hfQ1rsfcRKWslHwWAPJ9bg",
- "customers": [
- {
- "@id": "hfQ1rsfcRKWslHwWAPJ9bg",
- "email": "owner@gmail.com",
- "rights": {
- "share": true,
- "rights": true,
- "whisperers": true,
- "settings": true,
- "update": true
}
}, - {
- "@id": "FExgyFYtQdmskfNGpnKVBQ",
- "email": "test@gmail.com",
- "rights": {
- "rights": true,
- "whisperers": true,
- "share": false
}
}
], - "whisperers": [
- "dR6Gujz4RC2QyoAOyfDnWA",
- "H_rczKsfRXSJbkgQMk-ZYQ",
- "x7jxYx5PQb2wPEYa7D4Kgw",
- "M_OhNqT8TWGEEdVWVBOmiQ",
- "xGFWIX7zQMungzHcGz0YOw",
- "qCC4TpvyThic6FVAYf2VTw"
], - "settings": {
- "mergePattern": "^spiderdev_([^.]+).?",
- "clientsIdsCompactingPattern": "^http://spider.io/((?:apps|whisperers|customers)/.*)$"
}, - "technicalStatus": "ACTIVE",
- "dateModified": "2021-03-18T22:15:39.345Z",
- "token": "7p8i66dCQsynmFNULKdnjA",
- "editor": "hfQ1rsfcRKWslHwWAPJ9bg"
}Search for teams.
Also available by GET method on the collection
Search parameters
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Aggregation request, using Elasticsearch aggregation DSL. |
| size required | integer Page size. |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| includeETags | boolean Tells if response should include _eTags fields for update. |
{- "query": "string",
- "aggs": { },
- "sort": [
- {
- "key": "string",
- "order": "asc"
}
], - "next": [
- "string"
], - "size": 0,
- "avoidTotalHits": true,
- "includeETags": true
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}OTLP export of RED metrics: admin-managed collector targets, and per-team exporters selecting which captured traffic is aggregated and pushed.
Creates an OtelTarget: an OTLP/HTTP collector endpoint an administrator makes available to one or more teams. Teams then reference it from their own OtelExporters.
credential is write-only. It is accepted here and on PATCH, sealed at rest, and
never returned by any read: every response carries the literal "***" and cannot carry
anything else. Generated clients must not round-trip that placeholder back on an update -
omit the field instead.auth: none is the only mode that may omit credential; every other mode requires one.teams.otelTargets.create rightThe target to create
| name required | string Human-readable name, unique enough for an operator to pick from a list. |
| description | string |
| endpoint required | string The collector's base URL, e.g. |
| auth required | string Enum: "none" "bearer" "basic" "headers" How |
| credential | string The secret, in the shape Write-only. It is sealed at rest and never returned by any read - omit it on a
|
| tlsInsecureSkipVerify | boolean Accept an untrusted collector certificate. |
Array of objects Teams whose exporters may reference this target. | |
| disabled | boolean When true, no exporter pushes to it and the run loop skips it. |
{- "name": "string",
- "description": "string",
- "endpoint": "string",
- "auth": "none",
- "credential": "string",
- "tlsInsecureSkipVerify": true,
- "teams": [
- {
- "@id": "string",
- "name": "string"
}
], - "disabled": true
}{- "@id": "string",
- "@type": "string",
- "credential": "***",
- "name": "string",
- "description": "string",
- "endpoint": "string",
- "auth": "none",
- "credentialKeyId": "string",
- "tlsInsecureSkipVerify": true,
- "teams": [
- {
- "@id": "string",
- "name": "string"
}
], - "disabled": true,
- "lastUsedAt": "2019-08-24T14:15:22Z",
- "lastTestAt": "2019-08-24T14:15:22Z",
- "lastTestResult": "string",
- "createdBy": "string",
- "dateCreated": "2019-08-24T14:15:22Z",
- "dateModified": "2019-08-24T14:15:22Z",
- "technicalStatus": "string",
- "_eTag": "string"
}Lists the targets the caller may see. Every item's credential reads as "***".
otelTargets.create holder sees every target.otelTargets.create right{- "items": [
- {
- "@id": "string",
- "@type": "string",
- "credential": "***",
- "name": "string",
- "description": "string",
- "endpoint": "string",
- "auth": "none",
- "credentialKeyId": "string",
- "tlsInsecureSkipVerify": true,
- "teams": [
- {
- "@id": "string",
- "name": "string"
}
], - "disabled": true,
- "lastUsedAt": "2019-08-24T14:15:22Z",
- "lastTestAt": "2019-08-24T14:15:22Z",
- "lastTestResult": "string",
- "createdBy": "string",
- "dateCreated": "2019-08-24T14:15:22Z",
- "dateModified": "2019-08-24T14:15:22Z",
- "technicalStatus": "string",
- "_eTag": "string"
}
], - "lastSort": [
- "string"
]
}Returns the target. credential reads as the literal "***" here and in every other
response; the real value never leaves the server.
otelTargets.create right| id required | string Target internal @id |
{- "@id": "string",
- "@type": "string",
- "credential": "***",
- "name": "string",
- "description": "string",
- "endpoint": "string",
- "auth": "none",
- "credentialKeyId": "string",
- "tlsInsecureSkipVerify": true,
- "teams": [
- {
- "@id": "string",
- "name": "string"
}
], - "disabled": true,
- "lastUsedAt": "2019-08-24T14:15:22Z",
- "lastTestAt": "2019-08-24T14:15:22Z",
- "lastTestResult": "string",
- "createdBy": "string",
- "dateCreated": "2019-08-24T14:15:22Z",
- "dateModified": "2019-08-24T14:15:22Z",
- "technicalStatus": "string",
- "_eTag": "string"
}Merges the supplied fields into the stored target.
credential is write-only: supply it to replace the sealed credential, omit it to
keep the existing one. Sending an empty string is not "unchanged" - it is an invalid
credential for any mode other than none.endpoint clears the stored credential, so a request that repoints a target
must supply a fresh credential in the same body (or set auth to none); otherwise it
is refused with 400 credential is required when auth is "…". A credential is scoped to
the collector it was issued for: without this rule a caller holding only
otelTargets.create could repoint a target at a listener they control and have the
connection test hand that listener the real secret.@id, _eTag, technicalStatus, dateCreated, dateModified,
createdBy, lastUsedAt, lastTestAt, lastTestResult, credentialKeyId) are
stripped from the body rather than applied.otelTargets.create right| id required | string Target internal @id |
The fields to change
| name required | string Human-readable name, unique enough for an operator to pick from a list. |
| description | string |
| endpoint required | string The collector's base URL, e.g. |
| auth required | string Enum: "none" "bearer" "basic" "headers" How |
| credential | string The secret, in the shape Write-only. It is sealed at rest and never returned by any read - omit it on a
|
| tlsInsecureSkipVerify | boolean Accept an untrusted collector certificate. |
Array of objects Teams whose exporters may reference this target. | |
| disabled | boolean When true, no exporter pushes to it and the run loop skips it. |
{- "name": "string",
- "description": "string",
- "endpoint": "string",
- "auth": "none",
- "credential": "string",
- "tlsInsecureSkipVerify": true,
- "teams": [
- {
- "@id": "string",
- "name": "string"
}
], - "disabled": true
}{- "@id": "string",
- "@type": "string",
- "credential": "***",
- "name": "string",
- "description": "string",
- "endpoint": "string",
- "auth": "none",
- "credentialKeyId": "string",
- "tlsInsecureSkipVerify": true,
- "teams": [
- {
- "@id": "string",
- "name": "string"
}
], - "disabled": true,
- "lastUsedAt": "2019-08-24T14:15:22Z",
- "lastTestAt": "2019-08-24T14:15:22Z",
- "lastTestResult": "string",
- "createdBy": "string",
- "dateCreated": "2019-08-24T14:15:22Z",
- "dateModified": "2019-08-24T14:15:22Z",
- "technicalStatus": "string",
- "_eTag": "string"
}Soft-deletes the target (technicalStatus: DELETED). The Maintenance purge job removes the
document for good after its retention window.
otelTargets.create right| id required | string Target internal @id |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Performs the OTLP handshake against the target's endpoint, server-side, using the sealed credential, and reports whether it worked. This is the only reason the operation exists: the credential never has to reach a browser to be tested.
reachable, status, latencyMs and, on failure, a coarse error.lastTestAt and lastTestResult are stamped on the target, so it is
gated like PATCH, not like GET.otelTargets.create right| id required | string Target internal @id |
{- "reachable": true,
- "status": 0,
- "latencyMs": 0,
- "error": "string"
}Creates an OtelExporter: the team-owned selection of captured traffic that is rolled up into RED metrics and pushed to the referenced targets, once a minute, two minutes behind real time.
whisperers ∩ the team's whisperers, recomputed on every run.
A request naming a whisperer the team does not own is rejected with 403, and a whisperer
later removed from the team stops being exported without the exporter being edited.whisperers: an exporter must not emit metrics for traffic its author cannot read.INTERFACE; an UPLOAD whisperer
produces no live traffic to roll up.whisperers, protocols and targets must each be non-empty. An empty list has no
"means everything" meaning here.settings rightThe exporter to create
| name required | string |
| enabled | boolean When false the exporter is kept but nothing is pushed. |
| team required | string @id of the owning team. Set at creation and immutable: a |
| targets | Array of strings @ids of the OtelTargets to fan out to. Each must exist, be enabled, and list this exporter's team. |
| whisperers required | Array of strings @ids of the whisperers whose traffic is exported. The effective scope is this list
intersected with the team's whisperers, recomputed on every run - a stale exporter can
only ever narrow, never widen. Every entry must be an |
| protocols required | Array of strings Items Enum: "http" "postgresql" "redis" "grpc" "kafka" Must be non-empty; an empty list does not mean "all". |
| filter | string Author-supplied Lucene fragment narrowing what is aggregated. No access filter is injected into it implicitly. |
| endpointLabel | boolean Add |
object Per-protocol latency histogram bounds, overriding the service defaults. Keys are the protocol names above. Each list must be non-empty and strictly increasing; a protocol absent here falls back to the default. |
{- "name": "string",
- "enabled": true,
- "team": "string",
- "targets": [
- "string"
], - "whisperers": [
- "string"
], - "protocols": [
- "http"
], - "filter": "string",
- "endpointLabel": true,
- "bucketEdges": {
- "property1": [
- 0
], - "property2": [
- 0
]
}
}{- "@id": "string",
- "@type": "string",
- "name": "string",
- "enabled": true,
- "team": "string",
- "targets": [
- "string"
], - "whisperers": [
- "string"
], - "protocols": [
- "http"
], - "filter": "string",
- "accessFilters": {
- "property1": "string",
- "property2": "string"
}, - "endpointLabel": true,
- "bucketEdges": {
- "property1": [
- 0
], - "property2": [
- 0
]
}, - "status": {
- "property1": {
- "lastPushedWindow": "2019-08-24T14:15:22Z",
- "lastError": "string",
- "consecutiveFailures": 0
}, - "property2": {
- "lastPushedWindow": "2019-08-24T14:15:22Z",
- "lastError": "string",
- "consecutiveFailures": 0
}
}, - "createdBy": "string",
- "dateCreated": "2019-08-24T14:15:22Z",
- "dateModified": "2019-08-24T14:15:22Z",
- "technicalStatus": "string",
- "_eTag": "string"
}Lists exporters, with their durable per-target push status.
otelExportStale and otelExportDropping probes read.{- "items": [
- {
- "@id": "string",
- "@type": "string",
- "name": "string",
- "enabled": true,
- "team": "string",
- "targets": [
- "string"
], - "whisperers": [
- "string"
], - "protocols": [
- "http"
], - "filter": "string",
- "accessFilters": {
- "property1": "string",
- "property2": "string"
}, - "endpointLabel": true,
- "bucketEdges": {
- "property1": [
- 0
], - "property2": [
- 0
]
}, - "status": {
- "property1": {
- "lastPushedWindow": "2019-08-24T14:15:22Z",
- "lastError": "string",
- "consecutiveFailures": 0
}, - "property2": {
- "lastPushedWindow": "2019-08-24T14:15:22Z",
- "lastError": "string",
- "consecutiveFailures": 0
}
}, - "createdBy": "string",
- "dateCreated": "2019-08-24T14:15:22Z",
- "dateModified": "2019-08-24T14:15:22Z",
- "technicalStatus": "string",
- "_eTag": "string"
}
], - "lastSort": [
- "string"
]
}Runs the real rollup aggregation for an unsaved exporter body over the single window the run loop would process next, and returns a sample of the series plus the estimated series count. Nothing is stored and nothing is pushed.
POST /otel-export/v1/otel/exporters enforces is enforced here too - the
whisperer scope in particular. Preview is not a way around it. The single relaxation is
that targets may be empty: there is nothing to push to.truncated is the field that matters: true means paging stopped because the series
budget ran out, so the saved exporter would drop the overflow (and log OTEX-RUN-008).
When it is true, estimatedSeries is a lower bound, not a count. Do not infer
truncation from estimatedSeries >= cappedAt - an exact count landing on the cap is not
truncation.settings rightThe unsaved exporter body to preview
| name required | string |
| enabled | boolean When false the exporter is kept but nothing is pushed. |
| team required | string @id of the owning team. Set at creation and immutable: a |
| targets | Array of strings @ids of the OtelTargets to fan out to. Each must exist, be enabled, and list this exporter's team. |
| whisperers required | Array of strings @ids of the whisperers whose traffic is exported. The effective scope is this list
intersected with the team's whisperers, recomputed on every run - a stale exporter can
only ever narrow, never widen. Every entry must be an |
| protocols required | Array of strings Items Enum: "http" "postgresql" "redis" "grpc" "kafka" Must be non-empty; an empty list does not mean "all". |
| filter | string Author-supplied Lucene fragment narrowing what is aggregated. No access filter is injected into it implicitly. |
| endpointLabel | boolean Add |
object Per-protocol latency histogram bounds, overriding the service defaults. Keys are the protocol names above. Each list must be non-empty and strictly increasing; a protocol absent here falls back to the default. |
{- "name": "string",
- "enabled": true,
- "team": "string",
- "targets": [
- "string"
], - "whisperers": [
- "string"
], - "protocols": [
- "http"
], - "filter": "string",
- "endpointLabel": true,
- "bucketEdges": {
- "property1": [
- 0
], - "property2": [
- 0
]
}
}{- "sampleSeries": [
- {
- "attrs": {
- "property1": "string",
- "property2": "string"
}, - "count": 0,
- "sum": 0,
- "edges": [
- 0
], - "buckets": [
- 0
]
}
], - "estimatedSeries": 0,
- "cappedAt": 0,
- "truncated": true,
- "window": {
- "start": "2019-08-24T14:15:22Z",
- "end": "2019-08-24T14:15:22Z"
}
}Returns the exporter, including its durable per-target push status.
| id required | string Exporter internal @id |
{- "@id": "string",
- "@type": "string",
- "name": "string",
- "enabled": true,
- "team": "string",
- "targets": [
- "string"
], - "whisperers": [
- "string"
], - "protocols": [
- "http"
], - "filter": "string",
- "accessFilters": {
- "property1": "string",
- "property2": "string"
}, - "endpointLabel": true,
- "bucketEdges": {
- "property1": [
- 0
], - "property2": [
- 0
]
}, - "status": {
- "property1": {
- "lastPushedWindow": "2019-08-24T14:15:22Z",
- "lastError": "string",
- "consecutiveFailures": 0
}, - "property2": {
- "lastPushedWindow": "2019-08-24T14:15:22Z",
- "lastError": "string",
- "consecutiveFailures": 0
}
}, - "createdBy": "string",
- "dateCreated": "2019-08-24T14:15:22Z",
- "dateModified": "2019-08-24T14:15:22Z",
- "technicalStatus": "string",
- "_eTag": "string"
}Merges the supplied fields into the stored exporter and re-validates the whole result.
team cannot be changed. The request is authorised against the exporter's current
team, so allowing the field to change would spend that authorisation on a different
resource than the one it was checked against; the field is stripped from the body.status is stripped too: the run loop owns it, and a stale copy echoed back would
overwrite live push watermarks.POST enforces is re-checked against the merged result.settings right| id required | string Exporter internal @id |
The fields to change
| name required | string |
| enabled | boolean When false the exporter is kept but nothing is pushed. |
| team required | string @id of the owning team. Set at creation and immutable: a |
| targets | Array of strings @ids of the OtelTargets to fan out to. Each must exist, be enabled, and list this exporter's team. |
| whisperers required | Array of strings @ids of the whisperers whose traffic is exported. The effective scope is this list
intersected with the team's whisperers, recomputed on every run - a stale exporter can
only ever narrow, never widen. Every entry must be an |
| protocols required | Array of strings Items Enum: "http" "postgresql" "redis" "grpc" "kafka" Must be non-empty; an empty list does not mean "all". |
| filter | string Author-supplied Lucene fragment narrowing what is aggregated. No access filter is injected into it implicitly. |
| endpointLabel | boolean Add |
object Per-protocol latency histogram bounds, overriding the service defaults. Keys are the protocol names above. Each list must be non-empty and strictly increasing; a protocol absent here falls back to the default. |
{- "name": "string",
- "enabled": true,
- "team": "string",
- "targets": [
- "string"
], - "whisperers": [
- "string"
], - "protocols": [
- "http"
], - "filter": "string",
- "endpointLabel": true,
- "bucketEdges": {
- "property1": [
- 0
], - "property2": [
- 0
]
}
}{- "@id": "string",
- "@type": "string",
- "name": "string",
- "enabled": true,
- "team": "string",
- "targets": [
- "string"
], - "whisperers": [
- "string"
], - "protocols": [
- "http"
], - "filter": "string",
- "accessFilters": {
- "property1": "string",
- "property2": "string"
}, - "endpointLabel": true,
- "bucketEdges": {
- "property1": [
- 0
], - "property2": [
- 0
]
}, - "status": {
- "property1": {
- "lastPushedWindow": "2019-08-24T14:15:22Z",
- "lastError": "string",
- "consecutiveFailures": 0
}, - "property2": {
- "lastPushedWindow": "2019-08-24T14:15:22Z",
- "lastError": "string",
- "consecutiveFailures": 0
}
}, - "createdBy": "string",
- "dateCreated": "2019-08-24T14:15:22Z",
- "dateModified": "2019-08-24T14:15:22Z",
- "technicalStatus": "string",
- "_eTag": "string"
}Soft-deletes the exporter (technicalStatus: DELETED); it stops being picked up by the run
loop immediately. The Maintenance purge job removes the document after its retention window.
settings right| id required | string Exporter internal @id |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Bulk export of captured communications to CSV: create a background job over a search, list your own jobs, fetch a protocol's column catalog, and download a completed export.
Exports a search over one protocol's communications to CSV, run as a background job: the
server pages the search, joins each com's content, explodes it into rows and writes the CSV to
object storage. GET /export/v1/exports lists progress; GET /export/v1/exports/{jobId}/download
hands back the finished file.
Rows are per-payload, not per-com: http and webmessagestream export one row per com; redis
exports one row per reply value (req.values[] / res.values[], carrying meta.index); kafka
exports one row per record (meta.topic, meta.partition, meta.offset, meta.headers); grpc
exports one row per stream message (meta.compressed, meta.size). explode picks which side's
payloads become rows for a protocol with more than one payload per com - req or res forces a
side; anything else follows the com's own direction, then prefers res, then req.
Each column names a source: com, req, res or payload. For grpc and webmessagestream,
a stream message belongs to one side of the exchange, so req/res is empty for every message
travelling the other way; the API only warns about this - it does not reject the column. The
Network-View export dialog offers just com and payload for these two collections as a
convention. A unary gRPC com is the exception: it carries both request and response messages on
one document, so req and res are meaningful there and the API accepts them.
When the licence carries TRANSCODE, a schema-bound payload body decodes the same way the
protocol's own transcoded content view does (http, redis, kafka, grpc - webmessagestream
has no schema binding surface and always stays raw). A value with no bound schema, or one that
fails to decode, exports raw rather than being dropped, so meta.index never drifts out of sync
with the reply it belongs to.
protocols per export.whisperers
empty to export across every whisperer.size:0 search) and returned as coms; the
request is refused if it exceeds the install's configured cap.429.EXPORT licence assess (TEAM tier and above)The search, columns and format to export
| protocols required | Array of strings = 1 items Items Enum: "http" "webmessagestream" "redis" "kafka" "grpc" Exactly one protocol per export. |
| query | string Lucene query narrowing the search, same syntax as the grid. |
object | |
| whisperers | Array of strings Whisperer @ids to export. A non-admin caller must name at least one whisperer they own; an admin may leave this empty to export across every whisperer. |
| explode | string Which side's payloads become rows for a protocol with more than one payload per com. |
required | Array of objects (ExportColumnSpec) non-empty |
object | |
object | |
| name | string Optional label for this export. Max 120 characters. |
| description | string Optional longer description. Max 500 characters. |
{- "protocols": [
- "http"
], - "query": "string",
- "timeRange": {
- "gte": "2019-08-24T14:15:22Z",
- "lte": "2019-08-24T14:15:22Z"
}, - "whisperers": [
- "string"
], - "explode": "string",
- "columns": [
- {
- "label": "string",
- "source": "com",
- "path": "string",
- "paths": [
- "string"
], - "format": {
- "type": "",
- "layout": "string",
- "tz": "string",
- "decimals": 0,
- "decimalSep": "string",
- "thousandsSep": "string",
- "in": "string",
- "out": "string"
}, - "resolve": {
- "kind": "string",
- "map": {
- "property1": "string",
- "property2": "string"
}, - "fallback": "passthrough"
}
}
], - "format": {
- "delimiter": "string",
- "bom": true,
- "zip": true,
- "tz": "string",
- "dateLayout": "string",
- "decimalSep": "string",
- "thousandsSep": "string",
- "sanitizeFormulas": true
}, - "notify": {
- "email": true
}, - "name": "string",
- "description": "string"
}{- "jobId": "string",
- "coms": 0,
- "warnings": [
- {
- "column": "string",
- "message": "string"
}
]
}Lists export jobs, newest first. available and expiresAt are computed against object
storage at read time; they are not part of the stored job document.
all=true explicitly.all=true for every caller's jobs| status | string Filter by |
| whisperers | string Comma-separated whisperer @ids to filter on |
| size | integer <= 99 Page size, capped at 99 |
| next | string JSON-encoded |
| from | integer Lower bound, epoch seconds. Defaults to 0. |
| to | integer Upper bound, epoch seconds. Defaults to now plus 24 hours. |
| all | boolean Admin only. |
{- "total": 0,
- "items": [
- {
- "jobId": "string",
- "creationTime": "2019-08-24T14:15:22Z",
- "startTime": "2019-08-24T14:15:22Z",
- "endTime": "2019-08-24T14:15:22Z",
- "actionStatus": "string",
- "progress": 0,
- "protocol": "string",
- "coms": 0,
- "rows": 0,
- "bytes": 0,
- "available": true,
- "expiresAt": "2019-08-24T14:15:22Z",
- "name": "string",
- "description": "string",
- "query": "string",
- "columns": [
- "string"
]
}
], - "nextPage": {
- "query": {
- "next": [
- null
]
}
}
}Returns the Elasticsearch-mapping-derived column paths for one protocol's com document, plus its
fixed meta.* keys. Tag keys (tags.<key>) are not included - they are data-dependent and vary
per protocol; a tags.<key> or value.<path> column is still accepted by POST /export/v1/exports
even though it is not listed here.
| protocol required | string Enum: "http" "webmessagestream" "redis" "kafka" "grpc" The protocol to fetch columns for |
{- "protocol": "string",
- "columns": [
- "string"
]
}Redirects to a presigned, time-limited object-storage URL for the finished CSV (or zipped CSV). The URL forces a download with the export's own name, rather than an in-browser render.
A caller sending Accept: application/json gets the same presigned URL as a JSON body instead
of a redirect, since a cross-origin 302 cannot be followed by a browser fetch().
creator and whisperer set, never on the request - a
caller cannot widen access by any query parameter.| jobId required | string Export job @id |
{- "url": "string",
- "filename": "string"
}Process a json payload of packets and:
Json payload with packets to analyse by Spider.
| @id | string Unique id of the packet in the system. |
| @type | string Value: "Packet" |
| version | string Value: "2.0" Version of the schema. |
| name | string Name of the packet (for display). |
| whisperer | string Whisperer that captured the packet |
| instanceId | string Instance id of the whisperer |
| tcpSession | string Id of the Tcp session the packet is in |
| timestamp | number <double> Unix timestamp of capture, with microseconds |
| length | integer Size of the packet (size of rawPacket.buf buffer) |
object List of protocols used by this packet, keys are protocols name: TCP, UDP, IPv4... | |
object |
{- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": "",
- "header": ""
}
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Searches or aggregation analysis on packets
Also available by GET method on the collection
Admin may search without specifying a whisperer
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get a packet
| id required | string Internal id of packet |
{- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}Build the tcp payload of the packets listed in input.
Also available by GET method
List of packets identifiers
System id of packet
[- "string"
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get the packets listed in input (by id).
Also available by GET method
List of packets identifiers
System id of packet
[- "string"
][- { }
]Get the packets of the {tcpSession} in input, from {indexStart} to {indexEnd} (opt).
Range of packets to receive
| tcpSession | string Id of the Tcp session the packet is in |
| indexStart | integer Index above which the first packet to send must be (exclusive) |
| indexEnd | string Index before which the last packet to send must be (inclusive), optional |
{- "tcpSession": "string",
- "indexStart": 0,
- "indexEnd": "string"
}[- { }
]Build the tcp payload of the list of packets groups listed in input.
Also available by GET method
List of packets groups
| requestId | string Id of group of packets, internal to client |
| packetIds | Array of strings |
[- {
- "requestId": "string",
- "packetIds": [
- "string"
]
}
][- {
- "requestId": "string",
- "packetIds": [
- "string"
], - "data": [
- 0
], - "errorCode": "string",
- "errorMessage": "string"
}
]Set the packets of {tcpSession} before {maxIndex} as parsed. When parsed, they are removed from working memory in Redis. Depending of whisperer settings to save Packets:
This API is used in real time processing of packets to optimise Redis usage and speed of processing.
| tcpSession | string System id of the TCP session owning the packets |
| maxIndex | integer Maximum index that has been parsed (inclusive) |
[- {
- "tcpSession": "string",
- "maxIndex": 0
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Create a asynchronous purging job of packets.
List of packets identifiers
| whisperers | Array of strings |
| from | number <double> Start unix timestamp of purge window. Up to 6 decimals for microseconds. |
| to | number <double> Stop unix timestamp of purge window. Up to 6 decimals for microseconds. |
{- "whisperers": [
- "string"
], - "from": 0.1,
- "to": 0.1
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get purge progress
| job required | string Internal id of job |
{- "completed": true,
- "total": 0,
- "deleted": 0,
- "failures": [
- { }
], - "durationMs": 0
}TCP sessions: consistent stateful communications of packets between 2 hosts. Can contain any kind of exchanges. ANSI layer 4.
Stores TCP sessions and trigger parsing of payload according to Whisperers parsing configuration.
Tcp Session with packets id to analyse by Spider.
| @id | string System id of TCP session |
| name | string |
object Client host | |
object Server host | |
| state | string Enum: "SYN_SENT" "SYN_RECEIVED" "ESTABLISHED" "CLOSE_WAIT" "LAST_ACK" "CLOSED" State of TCP session lifecycle |
| packetsCount | integer Count of packets in the sessions |
| synTimestamp | number <double> Timestamp of SYN packet |
| missedSyn | boolean If whisperer missed SYN |
| connectTimestamp | number <double> Timestamp when connection was established |
| firstTimestamp | number <double> Timestamp of first packet (different from SYN when missedSyn) |
| lastTimestamp | number <double> Timestamp of last packet |
object Out packets (responses from server) | |
object In packets (responses from server) |
[- {
- "@id": "OOX8KrBXTaKpLHhy1is0ng==.1457182652.130872.1",
- "whisperer": "OOX8KrBXTaKpLHhy1is0ng==",
- "name": "1457182652.130872.1",
- "state": "ESTABLISHED",
- "src": {
- "ip": "192.168.1.22",
- "port": 47566,
- "name": "web-write"
}, - "dst": {
- "ip": "5.135.41.230",
- "port": 80
}, - "in": {
- "ip": 2480,
- "tcp": 3976,
- "payload": 168567,
- "initialSeq": 237657365354
}, - "out": {
- "ip": 1400,
- "tcp": 2376,
- "payload": 4506,
- "initialSeq": 237657365354
}, - "minInSeq": 1341521279,
- "minOutSeq": 1877837644,
- "packetsCount": 5,
- "firstTimestamp": 1457182652.130872,
- "synTimestamp": 1457182652.130872,
- "connectTimestamp": 1457182653.1638,
- "lastTimestamp": 1457182654.871751,
- "missedSyn": false
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get a TCP session
| id required | string Internal id of TCP session |
{- "@id": "string",
- "@type": "Tcp session",
- "version": "string",
- "name": "string",
- "whisperer": "string",
- "instanceId": "string",
- "src": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "dst": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "state": "SYN_SENT",
- "packetsCount": 0,
- "syn": 0.1,
- "missedSyn": true,
- "connect": 0.1,
- "first": 0.1,
- "firstDate": "2019-08-24",
- "last": 0.1,
- "lastDate": "2019-08-24",
- "duration": 0.1,
- "timespan": {
- "gte": "2019-08-24",
- "lte": 0
}, - "latency": 0.1,
- "out": {
- "ip": 0,
- "tcp": 0,
- "payload": 0,
- "initialSeq": 0
}, - "in": {
- "ip": 0,
- "tcp": 0,
- "payload": 0,
- "initialSeq": 0
}, - "parsers": {
- "http": {
- "status": "PARSING_COMPLETED",
- "lastParsing": "2019-08-24",
- "httpPers": "string",
- "itemsCount": 0,
- "lastPacketLotComplete": 0,
- "lastPacketParsedIndex": 0
}
}, - "dateModified": "2019-08-24"
}Searches or aggregation analysis on TCP sessions
Also available by GET method on the collection
May ask for an aggregation, with size:0 and no whisperers defined:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
| type | string Enum: "TcpSession" "UdpFlow" "UdpConversation" Filter results by session type. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw"
], - "startDate": "2019-01-18T05:28:18.676123",
- "stopDate": "2019-01-18T10:01:57.362456",
- "type": "UdpConversation"
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Histogram aggregation analysis on TCP sessions
Size:0, no next, no sort.
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Update the Tcp session once the parsing is done.
| id required | string Internal id of TCP session |
| If-Match required | string eTag of previous state of the TCP session |
Json patch with the changes
| op required | string Enum: "test" "remove" "add" "replace" "move" "copy" |
| path required | string |
| value | string |
| from | string |
[- {
- "op": "replace",
- "path": "/parsers/http/status",
- "value": "PARSED"
}, - {
- "op": "replace",
- "path": "/parsers/http/lastParsing",
- "value": "2017-01-08T20:34:30.013Z"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Update Tcp sessions once the parsing is done.
Array of Patches to TcpSessions
| @id | string System Id of the Tcp session to update |
| _eTag | string eTag of the Tcp session to update |
Array of objects (JsonPatch) |
[- {
- "@id": "OOX8KrBXTaKpLHhy1is0ng==.1457182652.130872.1",
- "_eTag": "\"43-E6FGZXDbp5+5MDzDUKD0RNz6ApA\"",
- "patch": [
- {
- "op": "replace",
- "path": "/parsers/http/status",
- "value": "PARSED"
}, - {
- "op": "replace",
- "path": "/parsers/http/lastParsing",
- "value": "2017-01-08T20:34:30.013Z"
}, - {
- "op": "replace",
- "path": "/parsers/http/itemsCount",
- "value": 3
}, - {
- "op": "replace",
- "path": "/parsers/http/lastPacketLotComplete",
- "value": 6
}, - {
- "op": "replace",
- "path": "/parsers/http/lastPacketParsedIndex",
- "value": 24
}
]
}
]{- "successes": [
- {
- "@id": "string"
}
], - "failures": [
- {
- "@id": "string",
- "code": "ETAG_MISMATCH",
- "reason": "string"
}
]
}Get a set of TCP session from a list of client ranndoms.
Array of Whisperer+ClientRandom
| whisperer | string Whisperer Id of Whisperer having captured the TcpSession |
| clientRandom | string Client random found in the TLS handshake |
[- {
- "whisperer": "OOX8KrBXTaKpLHhy1is0ng",
- "clientRandom": "1fa2b42654f4deede463f394406ece35c2a3aee704a65f0d700d1bb3ca2be7a7"
}
][- { }
]Get Tcp sessions that needs parsing by {type} parser
| type required | string Value: "HTTP" Type of parsing |
Polling parameters
| before | string <date-time> Date before which to get sessions to parse. Safety delay. |
{- "before": "2019-08-24T14:15:22Z"
}{- "total": 0,
- "items": [
- { }
]
}Get Tcp sessions that have already been parsed by {type} parser, but that ended in WARNING parsing status. Indeed, most often the WARNING status means that the TCP session could not be parsed do to missing packets. We retry a bit ater once packets should be there.
| type required | string Value: "HTTP" Type of parsing |
Polling parameters
| before | string <date-time> Date before which to get sessions to parse. Safety delay. |
{- "before": "2019-08-24T14:15:22Z"
}{- "total": 0,
- "items": [
- { }
]
}Create a asynchronous purging job of TCP sessions.
List of TCP sessions identifiers
| whisperers | Array of strings |
| from | number <double> Start unix timestamp of purge window. Up to 6 decimals for microseconds. |
| to | number <double> Stop unix timestamp of purge window. Up to 6 decimals for microseconds. |
{- "whisperers": [
- "string"
], - "from": 0.1,
- "to": 0.1
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get purge progress
| job required | string Internal id of job |
{- "completed": true,
- "total": 0,
- "deleted": 0,
- "failures": [
- { }
], - "durationMs": 0
}Create a asynchronous purging job of HTTP communications.
List of HTTP communications identifiers
| whisperers | Array of strings |
| from | number <double> Start unix timestamp of purge window. Up to 6 decimals for microseconds. |
| to | number <double> Stop unix timestamp of purge window. Up to 6 decimals for microseconds. |
{- "whisperers": [
- "string"
], - "from": 0.1,
- "to": 0.1
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get purge progress
| job required | string Internal id of job |
{- "completed": true,
- "total": 0,
- "deleted": 0,
- "failures": [
- { }
], - "durationMs": 0
}Create a asynchronous purging job of HTTP parsing logs.
List of HTTP parsing logs identifiers
| whisperers | Array of strings |
| from | number <double> Start unix timestamp of purge window. Up to 6 decimals for microseconds. |
| to | number <double> Stop unix timestamp of purge window. Up to 6 decimals for microseconds. |
{- "whisperers": [
- "string"
], - "from": 0.1,
- "to": 0.1
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get purge progress
| job required | string Internal id of job |
{- "completed": true,
- "total": 0,
- "deleted": 0,
- "failures": [
- { }
], - "durationMs": 0
}Renamed from /web-parser/v1/playground - the path now distinguishes it from the sibling
/web-parser/v1/wms-playground (SSE/WebSocket message tags & templates), served by the same pod.
Runs draft tag and template rules through the actual Go (RE2) HTTP parsing engine against a set of already-parsed HTTP communications. Used by the Whisperer parsing-config "Playground". Because it uses the real engine, it reflects exactly what the parser would extract - and reports regexes the parser cannot use (RE2 rejects backreferences / lookaround).
When contentSchemas is supplied, each per-com result also carries the transcoded request/response
bodies and the per-side schema resolution (which binding fired, or an error explaining the miss/decode
failure). Invalid URI templates in contentSchemas are surfaced as rule errors with scope
"contentSchema".
Communications to test against, plus the draft tag/template rules
| ids required | Array of strings @ids of already-parsed HttpCom to test against (1–50) |
object | |
| templates | Array of objects Request template rules |
Array of objects Draft content-schema bindings to test. Each binding declares which HTTP method, URI
template, and content-type should trigger transcoding, and the schema (format + schemaId +
messageType) to use for the request and/or response side. When supplied, the playground
transcodes matching binary bodies before tag/template extraction - mirroring the live
parser hot path - and attaches |
{- "ids": [
- "string"
], - "tags": {
- "req": [
- { }
], - "res": [
- { }
]
}, - "templates": [
- { }
], - "contentSchemas": [
- {
- "name": "string",
- "method": "string",
- "uriTemplate": "string",
- "req": {
- "format": "protobuf",
- "schemaId": "string",
- "messageType": "string"
}, - "res": {
- "format": "protobuf",
- "schemaId": "string",
- "messageType": "string"
}
}
]
}{- "results": {
- "property1": {
- "tags": {
- "req": { },
- "res": { }
}, - "template": "string",
- "summary": "string",
- "error": "string",
- "transcoded": {
- "req": "string",
- "res": "string"
}, - "schemaResolution": {
- "req": {
- "matched": true,
- "bindingIndex": 0,
- "bindingName": "string",
- "schemaId": "string",
- "messageType": "string",
- "error": "string"
}, - "res": {
- "matched": true,
- "bindingIndex": 0,
- "bindingName": "string",
- "schemaId": "string",
- "messageType": "string",
- "error": "string"
}
}
}, - "property2": {
- "tags": {
- "req": { },
- "res": { }
}, - "template": "string",
- "summary": "string",
- "error": "string",
- "transcoded": {
- "req": "string",
- "res": "string"
}, - "schemaResolution": {
- "req": {
- "matched": true,
- "bindingIndex": 0,
- "bindingName": "string",
- "schemaId": "string",
- "messageType": "string",
- "error": "string"
}, - "res": {
- "matched": true,
- "bindingIndex": 0,
- "bindingName": "string",
- "schemaId": "string",
- "messageType": "string",
- "error": "string"
}
}
}
}, - "ruleErrors": [
- {
- "scope": "string",
- "name": "string",
- "error": "string"
}
]
}Served by the web parser (web-parser), alongside the sibling /web-parser/v1/http-playground.
Runs draft per-message tag and template rules through the actual Go SSE parsing engine against a set of
already-parsed WebMessageStreamCom messages. Used by the Whisperer parsing-config "Playground" for the
stream's server.sse rules. Because it uses the real engine, it reflects exactly what the parser would
extract.
Each result carries both the merged outcome AND the two halves that produced it: template/tags is what
this message ends up with (inherited value, overridden/unioned by this message's own rules - see
addMatchesToTag's union semantics), while inheritedTemplate/inheritedTags is what the opening
request's handshake already established, on its own, before this message's rules ran. A merge that changed
nothing is otherwise indistinguishable from a rule that never fired; comparing the two tells them apart.
An SSE message has no request side of its own - identity (URI) lives on req for both directions, but
every extracted/inherited tag or template value lands under the res side of tags/inheritedTags.
Communications to test against, plus the draft per-message tag/template rules
| ids required | Array of strings @ids of already-parsed WebMessageStreamCom to test against (1–50) |
object | |
| templates | Array of objects Message template rules |
{- "ids": [
- "string"
], - "tags": {
- "req": [
- { }
], - "res": [
- { }
]
}, - "templates": [
- { }
]
}{- "results": {
- "property1": {
- "template": "string",
- "inheritedTemplate": "string",
- "tags": {
- "req": { },
- "res": { }
}, - "inheritedTags": {
- "req": { },
- "res": { }
}, - "error": "string"
}, - "property2": {
- "template": "string",
- "inheritedTemplate": "string",
- "tags": {
- "req": { },
- "res": { }
}, - "inheritedTags": {
- "req": { },
- "res": { }
}, - "error": "string"
}
}, - "ruleErrors": [
- {
- "scope": "string",
- "name": "string",
- "error": "string"
}
]
}Import a collection of Http communications
| @type | string Value: "HttpComDownload" |
| user | string |
| totalItems | integer Count of Http communications to import |
Array of objects (HttpCommunication) Array of Http communications |
{- "@type": "HttpComDownload",
- "user": "string",
- "totalItems": 0,
- "items": [
- {
- "@id": "string",
- "@type": "string",
- "version": "string",
- "name": "string",
- "tcpSession": "string",
- "httpPers": "string",
- "whisperer": "string",
- "instanceId": "string",
- "uploaded": true,
- "stats": {
- "statusCode": "string",
- "statusText": 0,
- "duration": 0.1,
- "timespan": {
- "gte": "2019-08-24",
- "lte": 0
}, - "src": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string",
- "origin": "192.168.0.1",
- "identification": "string"
}, - "dst": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "prox": [
- "string"
]
}, - "req": {
- "status": "COMPLETE",
- "method": "string",
- "httpVersion": "string",
- "uri": "string",
- "query": "string",
- "hash": "string",
- "template": "string",
- "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "size": 0.1,
- "packets": [
- "string"
], - "headers": { },
- "rawHeaders": {
- "size": 0,
- "filtered": true,
- "content": "string"
}, - "body": {
- "contentType": "string",
- "embedded": true,
- "filtered": true,
- "length": 0,
- "size": 0,
- "content": "string"
}, - "tags": { }
}, - "res": {
- "status": "COMPLETE",
- "httpVersion": "string",
- "start": 0.1,
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0.1,
- "packets": [
- "string"
], - "headers": { },
- "rawHeaders": {
- "size": 0,
- "filtered": true,
- "content": "string"
}, - "body": {
- "contentType": "string",
- "embedded": null,
- "filtered": true,
- "length": 0,
- "size": 0,
- "content": "string"
}, - "tags": { }
}
}
]
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get an Http communication by its Id
| id required | string System id of HTTP Communication |
{- "@id": "string",
- "@type": "string",
- "version": "string",
- "name": "string",
- "tcpSession": "string",
- "httpPers": "string",
- "whisperer": "string",
- "instanceId": "string",
- "uploaded": true,
- "stats": {
- "statusCode": "string",
- "statusText": 0,
- "duration": 0.1,
- "timespan": {
- "gte": "2019-08-24",
- "lte": 0
}, - "src": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string",
- "origin": "192.168.0.1",
- "identification": "string"
}, - "dst": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "prox": [
- "string"
]
}, - "req": {
- "status": "COMPLETE",
- "method": "string",
- "httpVersion": "string",
- "uri": "string",
- "query": "string",
- "hash": "string",
- "template": "string",
- "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "size": 0.1,
- "packets": [
- "string"
], - "headers": { },
- "rawHeaders": {
- "size": 0,
- "filtered": true,
- "content": "string"
}, - "body": {
- "contentType": "string",
- "embedded": true,
- "filtered": true,
- "length": 0,
- "size": 0,
- "content": "string"
}, - "tags": { }
}, - "res": {
- "status": "COMPLETE",
- "httpVersion": "string",
- "start": 0.1,
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0.1,
- "packets": [
- "string"
], - "headers": { },
- "rawHeaders": {
- "size": 0,
- "filtered": true,
- "content": "string"
}, - "body": {
- "contentType": "string",
- "embedded": null,
- "filtered": true,
- "length": 0,
- "size": 0,
- "content": "string"
}, - "tags": { }
}
}Get the HTTP headers of an Http communication by its Id
| id required | string System id of HTTP Communication |
| part required | string Enum: "req" "res" Request or Response |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get the payload body of an Http communication by its Id
The output can be in 5 types, based on view parameter:
| id required | string System id of HTTP Communication |
| part required | string Enum: "req" "res" Request or Response |
| view required | string Enum: "raw" "download" "octet-stream" "transcoded" Format of output:
|
Get an Http parsing log by its Id
| id required | string System id of HTTP Persistent Connection |
{- "@id": "string",
- "@type": "string",
- "version": "string",
- "name": "string",
- "tcpSession": "string",
- "whisperer": "string",
- "instanceId": "string",
- "first": 0.1,
- "last": 0.1,
- "lastPacketLotComplete": 0,
- "lastPacketParsedIndex": 0,
- "parsingCount": 0,
- "itemsFound": 0,
- "packetLots": [
- {
- "@id": "string",
- "@type": "string",
- "index": 0,
- "dir": "in",
- "fetched": [
- {
- "date": "string"
}
], - "packets": [
- { }
], - "status": "PENDING",
- "error": {
- "code": "string",
- "message": "string"
}
}
]
}Searches or aggregation analysis on Http communications
Also available by GET method on the collection
May ask for an aggregation, with size:0 and no whisperers defined:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Histogram aggregation analysis on Http communications
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}PostgreSQL communications: unitary communications using PostgreSQL protocol. ANSI layer 5-7.
Import a collection of PostgreSQL communications
| @type | string Value: "PgComDownload" |
| user | string |
| totalItems | integer Count of PostgreSQL communications to import |
Array of objects (PgCommunication) Array of PostgreSQL communications |
{- "@type": "PgComDownload",
- "user": "string",
- "totalItems": 0,
- "items": [
- {
- "@id": "string",
- "@type": "string",
- "version": "string",
- "name": "string",
- "tcpSession": "string",
- "pgParsing": "string",
- "whisperer": "string",
- "instanceId": "string",
- "uploaded": true,
- "stats": {
- "statusCode": "string",
- "statusText": 0,
- "duration": 0.1,
- "timespan": {
- "gte": "2019-08-24",
- "lte": 0
}, - "src": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "dst": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}
}, - "req": {
- "status": "COMPLETE",
- "command": "string",
- "template": "string",
- "tables": [
- "string"
], - "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "size": 0.1,
- "packets": [
- "string"
], - "tags": { },
- "subCommands": [
- {
- "messageType": "string",
- "command": "string",
- "content": {
- "query": "string",
- "_analyzedQuery": { }
}
}
], - "commandsCount": 0
}, - "res": {
- "status": "COMPLETE",
- "start": 0.1,
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0.1,
- "packets": [
- "string"
], - "tags": { },
- "rowCount": 0,
- "resultsCount": 0,
- "subResults": [
- {
- "messageType": "string",
- "content": {
- "fields": [
- {
- "name": "string",
- "tableOID": 0,
- "colAttr": 0,
- "dataTypeOID": 0,
- "dataTypeSize": 0,
- "typeModifier": 0,
- "format": 0
}
], - "values": [
- "string"
]
}, - "rowCount": 0,
- "statusCode": 0
}
]
}, - "connectionMetadata": {
- "user": "string",
- "database": "string",
- "protocolVersion": "string",
- "server_version": "string",
- "session_authorization": "string",
- "is_superuser": "string",
- "client_encoding": "string",
- "DateStyle": "string",
- "TimeZone": "string"
}
}
]
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Runs draft tag and template rules through the actual Go (RE2) PostgreSQL parsing engine against a set of already-parsed PostgreSQL communications. Used by the Whisperer parsing-config "Playground". Because it uses the real engine, it reflects exactly what the parser would extract - and reports regexes the parser cannot use (RE2 rejects backreferences / lookaround).
Communications to test against, plus the draft tag/template rules
| ids | Array of strings @ids of already-parsed PgCom to test against (1–50) |
object | |
| templates | Array of objects Request template rules |
{- "ids": [
- "string"
], - "tags": {
- "req": [
- { }
], - "res": [
- { }
]
}, - "templates": [
- { }
]
}{- "results": {
- "property1": {
- "tags": {
- "req": { },
- "res": { }
}, - "template": "string",
- "summary": "string",
- "error": "string"
}, - "property2": {
- "tags": {
- "req": { },
- "res": { }
}, - "template": "string",
- "summary": "string",
- "error": "string"
}
}, - "ruleErrors": [
- {
- "scope": "string",
- "name": "string",
- "error": "string"
}
]
}Get an PostgreSQL communication by its Id
| id required | string System id of PostgreSQL Communication |
{- "@id": "string",
- "@type": "string",
- "version": "string",
- "name": "string",
- "tcpSession": "string",
- "pgParsing": "string",
- "whisperer": "string",
- "instanceId": "string",
- "uploaded": true,
- "stats": {
- "statusCode": "string",
- "statusText": 0,
- "duration": 0.1,
- "timespan": {
- "gte": "2019-08-24",
- "lte": 0
}, - "src": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "dst": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}
}, - "req": {
- "status": "COMPLETE",
- "command": "string",
- "template": "string",
- "tables": [
- "string"
], - "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "size": 0.1,
- "packets": [
- "string"
], - "tags": { },
- "subCommands": [
- {
- "messageType": "string",
- "command": "string",
- "content": {
- "query": "string",
- "_analyzedQuery": { }
}
}
], - "commandsCount": 0
}, - "res": {
- "status": "COMPLETE",
- "start": 0.1,
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0.1,
- "packets": [
- "string"
], - "tags": { },
- "rowCount": 0,
- "resultsCount": 0,
- "subResults": [
- {
- "messageType": "string",
- "content": {
- "fields": [
- {
- "name": "string",
- "tableOID": 0,
- "colAttr": 0,
- "dataTypeOID": 0,
- "dataTypeSize": 0,
- "typeModifier": 0,
- "format": 0
}
], - "values": [
- "string"
]
}, - "rowCount": 0,
- "statusCode": 0
}
]
}, - "connectionMetadata": {
- "user": "string",
- "database": "string",
- "protocolVersion": "string",
- "server_version": "string",
- "session_authorization": "string",
- "is_superuser": "string",
- "client_encoding": "string",
- "DateStyle": "string",
- "TimeZone": "string"
}
}Get an PostgreSQL parsing log by its Id
| id required | string System id of PostgreSQL parsing log |
{- "@id": "string",
- "@type": "string",
- "version": "string",
- "name": "string",
- "tcpSession": "string",
- "whisperer": "string",
- "instanceId": "string",
- "first": 0.1,
- "last": 0.1,
- "lastPacketLotComplete": 0,
- "lastPacketParsedIndex": 0,
- "parsingCount": 0,
- "itemsFound": 0,
- "packetLots": [
- {
- "@id": "string",
- "@type": "string",
- "index": 0,
- "dir": "in",
- "fetched": [
- {
- "date": "string"
}
], - "packets": [
- { }
], - "status": "PENDING",
- "error": {
- "code": "string",
- "message": "string"
}
}
]
}Searches or aggregation analysis on PostgreSQL communications
Also available by GET method on the collection
May ask for an aggregation, with size:0 and no whisperers defined:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Histogram aggregation analysis on PostgreSQL communications
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Redis communications: unitary command/reply exchanges decoded from the Redis RESP protocol (RESP2/RESP3). ANSI layer 5-7.
Import a collection of Redis communications
| @type | string Value: "RedisComDownload" |
| user | string |
| totalItems | integer Count of Redis communications to import |
Array of objects (RedisCommunication) Array of Redis communications |
{- "@type": "RedisComDownload",
- "user": "string",
- "totalItems": 0,
- "items": [
- {
- "@id": "string",
- "@type": "string",
- "version": "string",
- "dateModified": "2019-08-24",
- "name": "string",
- "tcpSession": "string",
- "redisParsing": "string",
- "whisperer": "string",
- "instanceId": "string",
- "uploaded": true,
- "kind": "simple",
- "transactionId": "string",
- "stats": {
- "statusCode": 0,
- "statusText": "string",
- "duration": 0.1,
- "respVersion": 0,
- "timespan": {
- "gte": "2019-08-24",
- "lte": "2019-08-24"
}, - "src": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "dst": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "tags": {
- "values": { },
- "count": { },
- "cardinality": { }
}
}, - "req": {
- "status": "COMPLETE",
- "command": "string",
- "key": "string",
- "template": "string",
- "args": [
- "string"
], - "argCount": 0,
- "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "startMinute": "2019-08-24",
- "size": 0.1,
- "packets": [
- "string"
], - "tags": { }
}, - "res": {
- "status": "COMPLETE",
- "replyType": "string",
- "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0.1,
- "packets": [
- "string"
], - "tags": { }
}, - "connectionMetadata": {
- "user": "string",
- "db": "string"
}
}
]
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Runs draft tag and template rules through the actual Go (RE2) Redis parsing engine against a set of already-parsed Redis communications. Used by the Whisperer parsing-config "Playground". Because it uses the real engine, it reflects exactly what the parser would extract - and reports regexes the parser cannot use (RE2 rejects backreferences / lookaround).
Communications to test against, plus the draft tag/template rules
| ids | Array of strings @ids of already-parsed RedisCom to test against (1–50) |
object | |
| templates | Array of objects Request template rules |
{- "ids": [
- "string"
], - "tags": {
- "req": [
- { }
], - "res": [
- { }
]
}, - "templates": [
- { }
]
}{- "results": {
- "property1": {
- "tags": {
- "req": { },
- "res": { }
}, - "template": "string",
- "summary": "string",
- "error": "string"
}, - "property2": {
- "tags": {
- "req": { },
- "res": { }
}, - "template": "string",
- "summary": "string",
- "error": "string"
}
}, - "ruleErrors": [
- {
- "scope": "string",
- "name": "string",
- "error": "string"
}
]
}Create an asynchronous purging job of Redis communications.
Purge window and target whisperers
| whisperers | Array of strings |
| from | number <double> Start unix timestamp of purge window. Up to 6 decimals for microseconds. |
| to | number <double> Stop unix timestamp of purge window. Up to 6 decimals for microseconds. |
{- "whisperers": [
- "string"
], - "from": 0.1,
- "to": 0.1
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get purge progress
| job required | string Internal id of job |
{- "completed": true,
- "total": 0,
- "deleted": 0,
- "failures": [
- { }
], - "durationMs": 0
}Create an asynchronous purging job of Redis parsing logs.
Purge window and target whisperers
| whisperers | Array of strings |
| from | number <double> Start unix timestamp of purge window. Up to 6 decimals for microseconds. |
| to | number <double> Stop unix timestamp of purge window. Up to 6 decimals for microseconds. |
{- "whisperers": [
- "string"
], - "from": 0.1,
- "to": 0.1
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get purge progress
| job required | string Internal id of job |
{- "completed": true,
- "total": 0,
- "deleted": 0,
- "failures": [
- { }
], - "durationMs": 0
}Get a Redis communication by its Id
| id required | string System id of Redis Communication |
{- "@id": "string",
- "@type": "string",
- "version": "string",
- "dateModified": "2019-08-24",
- "name": "string",
- "tcpSession": "string",
- "redisParsing": "string",
- "whisperer": "string",
- "instanceId": "string",
- "uploaded": true,
- "kind": "simple",
- "transactionId": "string",
- "stats": {
- "statusCode": 0,
- "statusText": "string",
- "duration": 0.1,
- "respVersion": 0,
- "timespan": {
- "gte": "2019-08-24",
- "lte": "2019-08-24"
}, - "src": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "dst": {
- "ip": "192.168.0.1",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "tags": {
- "values": { },
- "count": { },
- "cardinality": { }
}
}, - "req": {
- "status": "COMPLETE",
- "command": "string",
- "key": "string",
- "template": "string",
- "args": [
- "string"
], - "argCount": 0,
- "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "startMinute": "2019-08-24",
- "size": 0.1,
- "packets": [
- "string"
], - "tags": { }
}, - "res": {
- "status": "COMPLETE",
- "replyType": "string",
- "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0.1,
- "packets": [
- "string"
], - "tags": { }
}, - "connectionMetadata": {
- "user": "string",
- "db": "string"
}
}Returns the value(s) carried by the request (req) or the reply (res) of a Redis communication, fetched
on demand from the dedicated content store. Multi-value commands and replies (MSET, MGET, HSET,
HGETALL, LRANGE…) return one entry per value.
The view query parameter controls the representation:
raw - the RESP values as a per-value JSON array (one element per value)transcoded - when a content schema is bound to the (database, key glob), the values decoded from their
binary form (Protobuf / MessagePack) to JSON. Falls back to raw when no binding matches or decoding fails.download - the byte-exact raw bytes, as an attachment| id required | string System id of Redis Communication |
| part required | string Enum: "req" "res" Which side to fetch: request or response values |
| view | string Enum: "raw" "transcoded" "download" Representation of the values (defaults to raw) |
[- { }
]Get a Redis parsing log by its Id
| id required | string System id of Redis parsing log |
{- "@id": "string",
- "@type": "string",
- "version": "string",
- "name": "string",
- "tcpSession": "string",
- "whisperer": "string",
- "instanceId": "string",
- "first": 0.1,
- "last": 0.1,
- "lastPacketLotComplete": 0,
- "lastPacketParsedIndex": 0,
- "parsingCount": 0,
- "itemsFound": 0,
- "packetLots": [
- {
- "@id": "string",
- "@type": "string",
- "index": 0,
- "dir": "in",
- "fetched": [
- {
- "date": "string"
}
], - "packets": [
- { }
], - "status": "PENDING",
- "error": {
- "code": "string",
- "message": "string"
}
}
]
}Searches or aggregation analysis on Redis communications
Also available by GET method on the collection
May ask for an aggregation, with size:0 and no whisperers defined:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Histogram aggregation analysis on Redis communications
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}gRPC communications: unitary Remote Procedure Calls decoded from gRPC-over-HTTP/2. ANSI layer 5-7.
Re-import a collection of already-parsed gRPC communications (the Network-View download → upload
round-trip). Each communication carries its per-message content inline on req.messages / res.messages,
which the parser turns back into the per-message content store.
Served by the web parser (web-parser); the standalone gRPC parser service was retired in the
M2a absorption and the /grpc-parser path prefix is kept for compatibility with existing clients.
| @type | string Value: "GrpcComDownload" |
| user | string |
| totalItems | integer Count of gRPC communications to import |
Array of objects (GrpcCommunication) Array of gRPC communications |
{- "@type": "GrpcComDownload",
- "user": "string",
- "totalItems": 0,
- "items": [
- {
- "@id": "string",
- "@type": "string",
- "version": "string",
- "dateModified": "2019-08-24",
- "name": "string",
- "tcpSession": "string",
- "grpcParsing": "string",
- "whisperer": "string",
- "instanceId": "string",
- "uploaded": true,
- "kind": "unary",
- "transactionId": "string",
- "direction": "req",
- "index": 0,
- "terminal": true,
- "stats": {
- "withTls": true,
- "statusCode": 0,
- "statusText": "string",
- "duration": 0.1,
- "timespan": {
- "gte": "2019-08-24",
- "lte": "2019-08-24"
}, - "src": {
- "ip": "string",
- "port": 0,
- "socket": "string",
- "name": "string",
- "identification": "string"
}, - "dst": {
- "ip": "string",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "tags": {
- "values": { },
- "count": { },
- "cardinality": { }
}
}, - "req": {
- "status": "COMPLETE",
- "service": "string",
- "method": "string",
- "fullMethod": "string",
- "template": "string",
- "streamingKind": "string",
- "httpStatus": 0,
- "messageCount": 0,
- "totalSize": 0,
- "metadata": { },
- "start": 0.1,
- "startDate": "2019-08-24",
- "startMinute": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0
}, - "connectionMetadata": { },
- "res": {
- "status": "COMPLETE",
- "fullMethod": "string",
- "template": "string",
- "streamingKind": "string",
- "grpcStatus": 0,
- "grpcStatusName": "string",
- "grpcMessage": "string",
- "httpStatus": 0,
- "messageCount": 0,
- "totalSize": 0,
- "metadata": { },
- "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0
}
}
]
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Served by the web parser (web-parser). Renamed from /grpc-parser/v1/playground in the M2a absorption --
the HTTP and gRPC playgrounds now share a service and cannot share a path (the gateway strips the first
path segment, so both prefixes arrive at the pod identically).
Runs draft tag and template rules through the actual Go gRPC parsing engine against a set of already-parsed
gRPC communications. Used by the Whisperer parsing-config "Playground". gRPC tags are field paths (into the
request/response metadata or the decoded protobuf message), while templates are regular expressions over a
selected fullMethod / metadata / message concatenation, defaulting to the full method. Because it uses the
real engine, it reflects exactly what the parser would extract - and reports invalid rules (e.g. a content
schema binding the transcoder cannot use).
Communications to test against, plus the draft tag/template rules
| ids | Array of strings @ids of already-parsed GrpcCom to test against (1–50) |
object | |
| templates | Array of objects Request template rules |
{- "ids": [
- "string"
], - "tags": {
- "req": [
- { }
], - "res": [
- { }
]
}, - "templates": [
- { }
]
}{- "results": {
- "property1": {
- "tags": {
- "req": { },
- "res": { }
}, - "template": "string",
- "summary": "string",
- "error": "string"
}, - "property2": {
- "tags": {
- "req": { },
- "res": { }
}, - "template": "string",
- "summary": "string",
- "error": "string"
}
}, - "ruleErrors": [
- {
- "scope": "string",
- "name": "string",
- "error": "string"
}
]
}Create an asynchronous purging job of gRPC communications. The associated per-message content is purged in the same cascade.
Served by the web parser (web-parser); the standalone gRPC parser service was retired in the
M2a absorption and the /grpc-parser path prefix is kept for compatibility with existing clients.
Purge window and target whisperers
| whisperers | Array of strings |
| from | number <double> Start unix timestamp of purge window. Up to 6 decimals for microseconds. |
| to | number <double> Stop unix timestamp of purge window. Up to 6 decimals for microseconds. |
{- "whisperers": [
- "string"
], - "from": 0.1,
- "to": 0.1
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get purge progress
Served by the web parser (web-parser); the standalone gRPC parser service was retired in the
M2a absorption and the /grpc-parser path prefix is kept for compatibility with existing clients.
| job required | string Internal id of job |
{- "completed": true,
- "total": 0,
- "deleted": 0,
- "failures": [
- { }
], - "durationMs": 0
}Create an asynchronous purging job of gRPC parsing logs.
Served by the web parser (web-parser); the standalone gRPC parser service was retired in the
M2a absorption and the /grpc-parser path prefix is kept for compatibility with existing clients.
Purge window and target whisperers
| whisperers | Array of strings |
| from | number <double> Start unix timestamp of purge window. Up to 6 decimals for microseconds. |
| to | number <double> Stop unix timestamp of purge window. Up to 6 decimals for microseconds. |
{- "whisperers": [
- "string"
], - "from": 0.1,
- "to": 0.1
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get purge progress
Served by the web parser (web-parser); the standalone gRPC parser service was retired in the
M2a absorption and the /grpc-parser path prefix is kept for compatibility with existing clients.
| job required | string Internal id of job |
{- "completed": true,
- "total": 0,
- "deleted": 0,
- "failures": [
- { }
], - "durationMs": 0
}Get a gRPC communication by its Id. The response also carries a transcode hint reporting, independently
for the request and the response side, whether a content schema is bound and would decode the protobuf
message(s).
| id required | string System id of gRPC Communication |
{- "@id": "string",
- "@type": "string",
- "version": "string",
- "dateModified": "2019-08-24",
- "name": "string",
- "tcpSession": "string",
- "grpcParsing": "string",
- "whisperer": "string",
- "instanceId": "string",
- "uploaded": true,
- "kind": "unary",
- "transactionId": "string",
- "direction": "req",
- "index": 0,
- "terminal": true,
- "stats": {
- "withTls": true,
- "statusCode": 0,
- "statusText": "string",
- "duration": 0.1,
- "timespan": {
- "gte": "2019-08-24",
- "lte": "2019-08-24"
}, - "src": {
- "ip": "string",
- "port": 0,
- "socket": "string",
- "name": "string",
- "identification": "string"
}, - "dst": {
- "ip": "string",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "tags": {
- "values": { },
- "count": { },
- "cardinality": { }
}
}, - "req": {
- "status": "COMPLETE",
- "service": "string",
- "method": "string",
- "fullMethod": "string",
- "template": "string",
- "streamingKind": "string",
- "httpStatus": 0,
- "messageCount": 0,
- "totalSize": 0,
- "metadata": { },
- "start": 0.1,
- "startDate": "2019-08-24",
- "startMinute": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0
}, - "connectionMetadata": { },
- "res": {
- "status": "COMPLETE",
- "fullMethod": "string",
- "template": "string",
- "streamingKind": "string",
- "grpcStatus": 0,
- "grpcStatusName": "string",
- "grpcMessage": "string",
- "httpStatus": 0,
- "messageCount": 0,
- "totalSize": 0,
- "metadata": { },
- "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0
}
}Returns the protobuf message(s) carried by the request (req) or the response (res) of a gRPC
communication, fetched on demand from the per-message content store, as a JSON array with one entry per
message (index, tsStart, tsEnd, size, compressed, message). For a streaming-message
communication only its own side carries content.
The view query parameter controls the representation:
raw - the raw protobuf message bytes (base64) as a per-message JSON arraytranscoded - when a content schema is bound to the (service, method), each message decoded from its
binary protobuf form to JSON. Falls back to raw per message when no binding matches or decoding fails.download / octet-stream - the side's message bytes concatenated in index order, as an attachment| id required | string System id of gRPC Communication |
| part required | string Enum: "req" "res" Which side to fetch: request or response messages |
| view | string Enum: "raw" "transcoded" "download" "octet-stream" Representation of the messages (defaults to raw) |
[- { }
]Reconstructs each gRPC call from its per-message communications, grouped by transactionId. Returns one
entry per call with its start / stop, request and response message counts, and the denormalized
fullMethod / kind / final gRPC status. Used to present a streaming call as a single row.
{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Reconstructs a single gRPC call by its transactionId.
| transactionId required | string Transaction (call) id grouping the per-message communications |
{ }Get a gRPC parsing log by its Id
| id required | string System id of gRPC parsing log |
{- "@id": "string",
- "@type": "string",
- "name": "string",
- "state": "string",
- "tcpSession": "string",
- "whisperer": "string",
- "instanceId": "string",
- "first": 0.1,
- "firstDate": "2019-08-24",
- "last": 0.1,
- "lastDate": "2019-08-24",
- "dateModified": "2019-08-24",
- "packetLots": [
- {
- "@id": "string",
- "@type": "string",
- "dir": "in",
- "packets": [
- { }
], - "status": "string",
- "error": {
- "code": 0,
- "message": "string"
}
}
]
}Searches or aggregation analysis on gRPC communications
Also available by GET method on the collection
May ask for an aggregation, with size:0 and no whisperers defined:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Kafka communications: unitary request/response exchanges decoded from the Kafka wire protocol (ApiKey-keyed). ANSI layer 5-7.
Re-import a collection of already-parsed Kafka communications (the Network-View download → upload
round-trip). Each communication carries its per-record content inline on req.records / res.records,
which the parser turns back into the per-record content store.
| @type | string Value: "KafkaComDownload" |
| user | string |
| totalItems | integer Count of Kafka communications to import |
Array of objects (KafkaCom) Array of Kafka communications |
{- "@type": "KafkaComDownload",
- "user": "string",
- "totalItems": 0,
- "items": [
- {
- "@id": "string",
- "@type": "KafkaCom",
- "kind": "string",
- "whisperer": "string",
- "instanceId": "string",
- "tcpSession": "string",
- "kafkaParsing": "string",
- "status": "COMPLETE",
- "_update": 0,
- "dateCreated": "2019-08-24",
- "dateModified": "2019-08-24",
- "stats": {
- "withTls": true,
- "duration": 0.1,
- "statusCode": 0,
- "statusText": "string",
- "timespan": {
- "gte": "2019-08-24",
- "lte": "2019-08-24"
}, - "src": {
- "ip": "string",
- "port": 0,
- "socket": "string",
- "name": "string",
- "identification": "string"
}, - "dst": {
- "ip": "string",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "schemaIds": [
- 0
], - "confluentFramed": true,
- "tags": {
- "values": { },
- "count": { },
- "cardinality": { }
}
}, - "req": {
- "status": "COMPLETE",
- "command": "string",
- "apiKey": 0,
- "apiVersion": 0,
- "clientId": "string",
- "correlationId": 0,
- "flexible": true,
- "topic": [
- "string"
], - "partition": [
- 0
], - "offset": [
- 0
], - "recordKey": [
- "string"
], - "recordCount": 0,
- "batchCount": 0,
- "compression": "string",
- "messageFormat": 0,
- "errorCode": 0,
- "errorMessage": "string",
- "template": "string",
- "keySchemaId": [
- 0
], - "valueSchemaId": [
- 0
], - "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0,
- "packets": [
- "string"
], - "records": [
- {
- "topic": "string",
- "partition": 0,
- "offset": 0,
- "key": "string",
- "value": "string",
- "filtered": true
}
]
}, - "res": {
- "status": "COMPLETE",
- "command": "string",
- "apiKey": 0,
- "apiVersion": 0,
- "clientId": "string",
- "correlationId": 0,
- "flexible": true,
- "topic": [
- "string"
], - "partition": [
- 0
], - "offset": [
- 0
], - "recordKey": [
- "string"
], - "recordCount": 0,
- "batchCount": 0,
- "compression": "string",
- "messageFormat": 0,
- "errorCode": 0,
- "errorMessage": "string",
- "template": "string",
- "keySchemaId": [
- 0
], - "valueSchemaId": [
- 0
], - "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0,
- "packets": [
- "string"
], - "records": [
- {
- "topic": "string",
- "partition": 0,
- "offset": 0,
- "key": "string",
- "value": "string",
- "filtered": true
}
]
}
}
]
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Runs draft tag and template rules through the actual Go Kafka parsing engine against a set of already-parsed
Kafka communications. Used by the Whisperer parsing-config "Playground". Kafka tags are field paths (into the
decoded record key or value JSON), while templates are regular expressions over a selected command / topic
/ clientId / decoded message concatenation, defaulting to command + topics. Because it uses the
real engine, it reflects exactly what the parser would extract - and reports invalid rules (e.g. a content
schema binding the transcoder cannot use).
Communications to test against, plus the draft tag/template rules
| ids | Array of strings @ids of already-parsed KafkaCom to test against (1–50) |
object | |
| templates | Array of objects Request template rules |
{- "ids": [
- "string"
], - "tags": {
- "req": [
- { }
], - "res": [
- { }
]
}, - "templates": [
- { }
]
}{- "results": {
- "property1": {
- "tags": {
- "req": { },
- "res": { }
}, - "template": "string",
- "summary": "string",
- "error": "string"
}, - "property2": {
- "tags": {
- "req": { },
- "res": { }
}, - "template": "string",
- "summary": "string",
- "error": "string"
}
}, - "ruleErrors": [
- {
- "scope": "string",
- "name": "string",
- "error": "string"
}
]
}Create an asynchronous purging job of Kafka communications. The associated per-record content is purged in the same cascade.
Purge window and target whisperers
| whisperers | Array of strings |
| from | number <double> Start unix timestamp of purge window. Up to 6 decimals for microseconds. |
| to | number <double> Stop unix timestamp of purge window. Up to 6 decimals for microseconds. |
{- "whisperers": [
- "string"
], - "from": 0.1,
- "to": 0.1
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get purge progress
| job required | string Internal id of job |
{- "completed": true,
- "total": 0,
- "deleted": 0,
- "failures": [
- { }
], - "durationMs": 0
}Create an asynchronous purging job of Kafka parsing logs.
Purge window and target whisperers
| whisperers | Array of strings |
| from | number <double> Start unix timestamp of purge window. Up to 6 decimals for microseconds. |
| to | number <double> Stop unix timestamp of purge window. Up to 6 decimals for microseconds. |
{- "whisperers": [
- "string"
], - "from": 0.1,
- "to": 0.1
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get purge progress
| job required | string Internal id of job |
{- "completed": true,
- "total": 0,
- "deleted": 0,
- "failures": [
- { }
], - "durationMs": 0
}Get a Kafka communication by its Id.
| id required | string System id of Kafka Communication |
{- "@id": "string",
- "@type": "KafkaCom",
- "kind": "string",
- "whisperer": "string",
- "instanceId": "string",
- "tcpSession": "string",
- "kafkaParsing": "string",
- "status": "COMPLETE",
- "_update": 0,
- "dateCreated": "2019-08-24",
- "dateModified": "2019-08-24",
- "stats": {
- "withTls": true,
- "duration": 0.1,
- "statusCode": 0,
- "statusText": "string",
- "timespan": {
- "gte": "2019-08-24",
- "lte": "2019-08-24"
}, - "src": {
- "ip": "string",
- "port": 0,
- "socket": "string",
- "name": "string",
- "identification": "string"
}, - "dst": {
- "ip": "string",
- "port": 0,
- "socket": "string",
- "name": "string"
}, - "schemaIds": [
- 0
], - "confluentFramed": true,
- "tags": {
- "values": { },
- "count": { },
- "cardinality": { }
}
}, - "req": {
- "status": "COMPLETE",
- "command": "string",
- "apiKey": 0,
- "apiVersion": 0,
- "clientId": "string",
- "correlationId": 0,
- "flexible": true,
- "topic": [
- "string"
], - "partition": [
- 0
], - "offset": [
- 0
], - "recordKey": [
- "string"
], - "recordCount": 0,
- "batchCount": 0,
- "compression": "string",
- "messageFormat": 0,
- "errorCode": 0,
- "errorMessage": "string",
- "template": "string",
- "keySchemaId": [
- 0
], - "valueSchemaId": [
- 0
], - "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0,
- "packets": [
- "string"
], - "records": [
- {
- "topic": "string",
- "partition": 0,
- "offset": 0,
- "key": "string",
- "value": "string",
- "filtered": true
}
]
}, - "res": {
- "status": "COMPLETE",
- "command": "string",
- "apiKey": 0,
- "apiVersion": 0,
- "clientId": "string",
- "correlationId": 0,
- "flexible": true,
- "topic": [
- "string"
], - "partition": [
- 0
], - "offset": [
- 0
], - "recordKey": [
- "string"
], - "recordCount": 0,
- "batchCount": 0,
- "compression": "string",
- "messageFormat": 0,
- "errorCode": 0,
- "errorMessage": "string",
- "template": "string",
- "keySchemaId": [
- 0
], - "valueSchemaId": [
- 0
], - "start": 0.1,
- "startDate": "2019-08-24",
- "end": 0.1,
- "endDate": "2019-08-24",
- "size": 0,
- "packets": [
- "string"
], - "records": [
- {
- "topic": "string",
- "partition": 0,
- "offset": 0,
- "key": "string",
- "value": "string",
- "filtered": true
}
]
}
}Returns the record key/value bytes carried by the request (req) or the response (res) of a Kafka
communication, fetched on demand from the dedicated per-record content store. Each entry carries the record
topic, partition, offset, raw key and value bytes (base64), and a filtered flag for suppressed
records.
The view query parameter controls the representation:
raw - the raw record bytes (base64) as a per-record JSON arraytranscoded - when a content schema binding matches the (topic, side), each record's key and value are
decoded from their Avro or Confluent-framed binary form to JSON. Falls back to raw per record when no
binding matches or decoding fails.| id required | string System id of Kafka Communication |
| part required | string Enum: "req" "res" Which side to fetch: request or response records |
| view | string Enum: "raw" "transcoded" "download" Representation of the records (defaults to raw) |
{- "@id": "string",
- "@type": "KafkaComContent",
- "whisperer": "string",
- "dateModified": "2019-08-24",
- "req": {
- "records": [
- {
- "topic": "string",
- "partition": 0,
- "offset": 0,
- "key": "string",
- "value": "string",
- "filtered": true
}
], - "truncated": true,
- "droppedCount": 0
}, - "res": {
- "records": [
- {
- "topic": "string",
- "partition": 0,
- "offset": 0,
- "key": "string",
- "value": "string",
- "filtered": true
}
], - "truncated": true,
- "droppedCount": 0
}
}Get a Kafka parsing log by its Id
| id required | string System id of Kafka parsing log |
{- "@id": "string",
- "@type": "string",
- "name": "string",
- "state": "string",
- "status": "string",
- "tcpSession": "string",
- "whisperer": "string",
- "instanceId": "string",
- "first": 0.1,
- "firstDate": "2019-08-24",
- "last": 0.1,
- "lastDate": "2019-08-24",
- "dateModified": "2019-08-24",
- "packetLots": [
- {
- "@id": "string",
- "@type": "string",
- "dir": "in",
- "packets": [
- { }
], - "status": "string",
- "error": {
- "code": 0,
- "message": "string"
}
}
]
}Searches or aggregation analysis on Kafka communications
Also available by GET method on the collection
May ask for an aggregation, with size:0 and no whisperers defined:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Histogram aggregation analysis on Kafka communications
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Stores Tls keys and trigger parsing of to link them to TCP sessions.
Tls Keys to store.
[- {
- "@id": "baf9dE5LRBC7Ok-wk9Fgfg-1fa2b42654f4deede463f394406ece35c2a3aee704a65f0d700d1bb3ca2be7a7",
- "@type": "TlsKey",
- "gocipher": "local-gocipher",
- "instanceId": "local-gocipher-bwfbk",
- "captureDate": "2024-10-15T04:22:12.613262368Z",
- "whisperer": "baf9dE5LRBC7Ok-wk9Fgfg",
- "tlsVersion": "TLS 1.3",
- "clientRandom": "1fa2b42654f4deede463f394406ece35c2a3aee704a65f0d700d1bb3ca2be7a7",
- "serverRandom": "088dc4da39e951395a7a006e62b7f2f9e9e205ba26ce23e09d4175a84064e963",
- "masterKey": "",
- "cipher": {
- "name": "TLS_AES_256_GCM_SHA384",
- "version": 3
}, - "handshakeSecret": "090e4cbb3fa81bd4bf613b45f785db6d5734153c045a077f45d082e4437156b7099441a493f45972802b09440d88fbce",
- "handshakeTrafficHash": "99d196bff2813190fe8779f638d490cec246b54eea5047e33e48a2dd33daafdf6cb38b82fb17b877da38677513bc1fc7",
- "clientHandshakeTrafficSecret": "98c38930cb0a4276f22ccad85eb714f0a2260aabed3b58cfdc3bdda2d313dee54855fc650fbaf6711af61a70ecb1f63e",
- "serverHandshakeTrafficSecret": "20be12139df9ccbd5c4e61d9fee02e20d4a92276bfa56036086076752291cb13ef65946d78302a38303ae333781558a2",
- "clientAppTrafficSecret": "a19b4986e0b8acc6dee38363e77da9dce6f414a3d8280bc273df82939ed052a43f2f9d8ebc53287271565d1f2c5d2232",
- "serverAppTrafficSecret": "b1f7cbb2e73411993fe1a394cdcf00ab6a7da7d8319ce37aedf204480f344a76a8a8c5a0b3abec779d4a9302f585ef75",
- "exporterMasterSecret": "340f2570571bbffb682f9977b0465fbfafbfe4a06be2ddfb8af7d6351ff183ae87fb16e0def4cba554c93297c2cffe29"
}
]{- "message": "3 Tls keys saved successfully.",
- "saved": 3,
- "rejected": 0
}Get Tls keys that needs linking
Polling parameters
| before | string <date-time> Date before which to get tls keys to parse. Safety delay. |
{- "before": "2019-08-24T14:15:22Z"
}{- "total": 0,
- "items": [
- { }
]
}Create a new Gocipher, and associate it to the owner customer.
Gocipher creation request
| customer required | string System Id of the customer. |
| name required | string Name of the Gocipher to create. |
{- "customer": "YOD66VZ54Jih",
- "name": "Dev cluster"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for Gociphers
Also available by GET method on the collection
If client is not admin, the search will be limited to the Gociphers owned by this customer or shared with him.
Search parameters
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Aggregation request, using Elasticsearch aggregation DSL. |
| size required | integer Page size. |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| includeETags | boolean Tells if response should include _eTags fields for update. |
{- "query": "string",
- "aggs": { },
- "sort": [
- {
- "key": "string",
- "order": "asc"
}
], - "next": [
- "string"
], - "size": 0,
- "avoidTotalHits": true,
- "includeETags": true
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get a Gocipher's details.
Only admins can see DELETED Gociphers.
| id required | string Internal id of Gocipher |
{- "@id": "string",
- "@type": "Gocipher",
- "version": "string",
- "name": "string",
- "customer": "string",
- "apikey": "string",
- "config": {
- "@id": "string",
- "@type": "ControllerConfig",
- "version": "string",
- "creator": "string",
- "dateCreated": "2019-08-24",
- "editor": "string",
- "dateModified": "2019-08-24"
}, - "users": [
- {
- "@id": "string",
- "email": "string",
- "rights": {
- "share": true,
- "config": true,
- "install": true,
- "delete": true
}
}
], - "teams": [
- {
- "@id": "string",
- "name": "string"
}
], - "creator": "string",
- "dateCreated": "2019-08-24",
- "editor": "string",
- "dateModified": "2019-08-24"
}Updates a customer. You can:
| id required | string Internal id of Gocipher |
| If-Match required | string eTag of previous state of the Gocipher |
Json patch with the changes
| op required | string Enum: "test" "remove" "add" "replace" "move" "copy" |
| path required | string |
| value | string |
| from | string |
[- {
- "op": "test",
- "path": "string",
- "value": "string",
- "from": "string"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Delete a Gocipher.
| id required | string Internal id of Gocipher |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Create/Replace the Gocipher API key used for Gocipher connection to Spider.
The API key is a public/private key pair.
Any call to this API (if authorized) will overwrite the previous API key, and the Gocipher will not be able to use the previous one. A connected Gocipher will be disconnected when its current JWT token will expire. The API key is taken as a configuration AT START of Gociphers, and need a restart to be changed.
The API can supports two outputs:
| id required | string System id of Gocipher |
{- "Gocipher": "abcdefghijklmnopqrstuv",
- "privatePem": "-----BEGIN RSA PRIVATE KEY-----\nline1\nline2\nline3\n...\n-----END RSA PRIVATE KEY-----\n"
}This endpoint is for testing purposes only:
| id required | string System id of Gocipher |
| timeStamp required | string <date-time> Timestamp to use in signature |
| instanceId required | string InstanceId to use in signature |
The Gocipher RSA private key, as a PEM
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get the configuration of this Gocipher Usages:
The first call from Gociphers is made by:
const timeStamp = moment().toISOString();
const info = {
timeStamp,
GocipherId,
instanceId
};
const privKey = new NodeRSA(privatePem);
const signature = privKey.sign(Buffer.from(JSON.stringify(info)), 'base64');
Spider-TimeStamp: timeStamp
Spider-InstanceId: instanceId,
Spider-Signature: signature //base 64 encoded
The view parameter allows to modulate the output:
| id required | string System id of Gocipher |
| view | string Enum: "server" "client" "full" Type of configuration to get |
| Spider-Signature | string <base64> Signature of the call by the Gocipher, with its API key |
| Spider-Timestamp | string <date-time> Provided with API key in first Gocipher call to get its JWT token with the config |
| Spider-InstanceId | string Provided with API key in first Gocipher call to get its JWT token with the config |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Updates a Gocipher configuration.
| id required | string System id of Gocipher |
| If-Match required | string eTag of previous state of the Gocipher's config |
Json patch with the changes
| op required | string Enum: "test" "remove" "add" "replace" "move" "copy" |
| path required | string |
| value | string |
| from | string |
[- {
- "op": "test",
- "path": "string",
- "value": "string",
- "from": "string"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}An hosts list contains all hosts the whisperer has seen during its capture.
When processing the list, Spider can create a new entry of hosts for this Whisperer or update the nearest one.
Hosts lists can be sent in any order (to support upload).
| id required | string System id of Whisperer |
| ip required | string <ipv4> IP address of host |
| name required | string FQDN of host as given by DNS |
| type required | string Enum: "SERVER" "CLIENT" null Type of host |
| firstSeen required | string <date-time> Date of first packet seen for this host |
| lastSeen required | string <date-time> Date of last packet seen for this host |
| lastUpdate required | string <date-time> Last time the DNS was queried to update the host name |
[- {
- "ip": "10.0.0.116",
- "name": "terminal_businessappsconfigs_service",
- "type": "SERVER",
- "lastSeen": "2019-01-27T13:43:44.260Z",
- "lastUpdate": "2019-01-27T13:43:16.092Z",
- "firstSeen": "2019-01-25T00:41:51.087Z"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Update an Host:
The update:
| whisperers required | Array of strings non-empty List of whisperers on which to do the update |
| ip required | string <ipv4> IP of the host for which to set custom name |
| startTime required | number <double> Timestamp of period start for which to change |
| stopTime required | number <double> Timestamp of period end for which to change |
| customName | string The new name / optional - can be null |
{- "whisperers": [
- "YVWyUFNPRyCouvPBNmV9aw",
- "Y2GaZbDXRLq3cj-m8Zjviw",
- "GAf8TMCVRA-p8clfrxuduw"
], - "ip": "10.0.0.236",
- "startTime": 1548595820.545,
- "stopTime": 1548595882.677,
- "customName": "test-service"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for hosts Returns a collection of HostsList
May ask searching without specifying a whisperer:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Whisperers are sending status every x seconds when started
| time required | string <date-time> Time of status |
| whisperer required | string System Id of whisperer |
| instanceId required | string Instance id of the whisperer |
| whispererName | string Name of whisperer - enriched by service |
| hostname required | string FQDN of the host |
| startTime required | string <date-time> Start time of the whisperer |
| sessionStartTime | string Recording session start time |
| upTime required | number Uptime of whisperer |
| state required | string Enum: "STARTING" "RECORDING" "STOPPED" "SERVER_DOWN" "BREAK" "INTERNAL_ERROR" "INVALID_CONFIG" State of the whisperer |
object Statistics of REST API calls to the server, by API | |
required | object Total of metrics values since start of session |
object Metrics values since last send of status | |
Array of objects List of network interfaces of the host |
{- "@id": "Y2GaZbDXRLq3cj-m8Zjviw.1548595914874",
- "time": "2019-01-27T13:31:54.874Z",
- "whisperer": "Y2GaZbDXRLq3cj-m8Zjviw",
- "hostname": "node-3.streetsmart.sit3",
- "instanceId": "1a2aebcf734f",
- "startTime": "2019-01-16T14:40:19.843Z",
- "sessionStartTime": "2019-01-25T11:17:40.234Z",
- "upTime": 946295.88,
- "state": "RECORDING",
- "circuitBreakers": {
- "summary": {
- "totalCount": 20,
- "totalSuccessful": 20,
- "totalErrors": 0
}, - "Get whisperer config with API key": {
- "key": "Get whisperer config with API key",
- "open": false,
- "max90": 0,
- "latencyMean": 0,
- "successful": 0,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 0
}, - "Post status": {
- "key": "Post status",
- "open": false,
- "max90": 27,
- "latencyMean": 27,
- "successful": 1,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 1
}, - "Post packets": {
- "key": "Post packets",
- "open": false,
- "max90": 44,
- "latencyMean": 26,
- "successful": 9,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 9
}, - "Post sessions": {
- "key": "Post sessions",
- "open": false,
- "max90": 17,
- "latencyMean": 12,
- "successful": 7,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 7
}, - "Get whisperer config with token": {
- "key": "Get whisperer config with token",
- "open": false,
- "max90": 14,
- "latencyMean": 12,
- "successful": 2,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 2
}, - "Post hosts": {
- "key": "Post hosts",
- "open": false,
- "max90": 18,
- "latencyMean": 18,
- "successful": 1,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 1
}
}, - "total": {
- "cpuUsage": {
- "overall": 6080110.3,
- "process": 19450.72
}, - "memoryUsage": {
- "free": 162,
- "process": 132
}, - "pcapSession": {
- "received": 90041092,
- "dropped": 208,
- "ifDropped": 0
}, - "tcpSessions": 399033,
- "hosts": 43,
- "packets": {
- "count": 4067089,
- "size": 1677558858
}, - "queues": {
- "packets": {
- "length": 0,
- "overflow": 0
}, - "packetsVxlan": { },
- "tcpSessions": {
- "length": 0,
- "overflow": 0
}
}
}, - "new": {
- "cpuUsage": {
- "overall": 2.33,
- "process": 0.02
}, - "packets": {
- "count": 925,
- "size": 391289
}, - "queues": {
- "packets": {
- "overflow": 0
}, - "packetsVxlan": { },
- "tcpSessions": {
- "overflow": 0
}
}, - "pcapSession": {
- "received": 10516,
- "dropped": 0,
- "ifDropped": 0
}, - "tcpSessions": 89
}, - "interfaces": [
- {
- "interface": "lo",
- "address": "127.0.0.1",
- "netmask": "255.0.0.0",
- "family": "IPv4",
- "mac": "00:00:00:00:00:00",
- "internal": true,
- "cidr": "127.0.0.1/8"
}, - {
- "interface": "eth0",
- "address": "10.255.0.8",
- "netmask": "255.255.0.0",
- "family": "IPv4",
- "mac": "02:42:0a:ff:00:08",
- "internal": false,
- "cidr": "10.255.0.8/16"
}, - {
- "interface": "eth2",
- "address": "172.18.0.3",
- "netmask": "255.255.0.0",
- "family": "IPv4",
- "mac": "02:42:ac:12:00:03",
- "internal": false,
- "cidr": "172.18.0.3/16"
}, - {
- "interface": "eth1",
- "address": "10.0.0.7",
- "netmask": "255.255.255.0",
- "family": "IPv4",
- "mac": "02:42:0a:00:00:07",
- "internal": false,
- "cidr": "10.0.0.7/24"
}
]
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get the statuses listed in input (by id).
Also available by GET method
List of whisperers identifiers (or whisperer instance identifiers)
System id of whisperer
[- "string"
][- { }
]Search for raw status
May ask searching without specifying a whisperer:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Histogram aggregation analysis on Whisperers status
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Search for current status of whisperers
May ask searching without specifying a whisperer:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resources fetched to get next ones. |
| size required | integer Page size. |
| avoidTotalHits | boolean Tells if response should include total hits count. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "query": "",
- "sort": [
- {
- "key": "time",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Gociphers are sending status every x seconds when started
| time required | string <date-time> Time of status |
| whisperer required | string System Id of whisperer |
| instanceId required | string Instance id of the whisperer |
| whispererName | string Name of whisperer - enriched by service |
| hostname required | string FQDN of the host |
| startTime required | string <date-time> Start time of the whisperer |
| sessionStartTime | string Recording session start time |
| upTime required | number Uptime of whisperer |
| state required | string Enum: "STARTING" "RECORDING" "STOPPED" "SERVER_DOWN" "BREAK" "INTERNAL_ERROR" "INVALID_CONFIG" State of the whisperer |
object Statistics of REST API calls to the server, by API | |
required | object Total of metrics values since start of session |
object Metrics values since last send of status | |
Array of objects List of network interfaces of the host |
{- "@id": "Y2GaZbDXRLq3cj-m8Zjviw.1548595914874",
- "time": "2019-01-27T13:31:54.874Z",
- "whisperer": "Y2GaZbDXRLq3cj-m8Zjviw",
- "hostname": "node-3.streetsmart.sit3",
- "instanceId": "1a2aebcf734f",
- "startTime": "2019-01-16T14:40:19.843Z",
- "sessionStartTime": "2019-01-25T11:17:40.234Z",
- "upTime": 946295.88,
- "state": "RECORDING",
- "circuitBreakers": {
- "summary": {
- "totalCount": 20,
- "totalSuccessful": 20,
- "totalErrors": 0
}, - "Get whisperer config with API key": {
- "key": "Get whisperer config with API key",
- "open": false,
- "max90": 0,
- "latencyMean": 0,
- "successful": 0,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 0
}, - "Post status": {
- "key": "Post status",
- "open": false,
- "max90": 27,
- "latencyMean": 27,
- "successful": 1,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 1
}, - "Post packets": {
- "key": "Post packets",
- "open": false,
- "max90": 44,
- "latencyMean": 26,
- "successful": 9,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 9
}, - "Post sessions": {
- "key": "Post sessions",
- "open": false,
- "max90": 17,
- "latencyMean": 12,
- "successful": 7,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 7
}, - "Get whisperer config with token": {
- "key": "Get whisperer config with token",
- "open": false,
- "max90": 14,
- "latencyMean": 12,
- "successful": 2,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 2
}, - "Post hosts": {
- "key": "Post hosts",
- "open": false,
- "max90": 18,
- "latencyMean": 18,
- "successful": 1,
- "errors": 0,
- "shortCircuited": 0,
- "failed": 0,
- "timedOut": 0,
- "totalCount": 1
}
}, - "total": {
- "cpuUsage": {
- "overall": 6080110.3,
- "process": 19450.72
}, - "memoryUsage": {
- "free": 162,
- "process": 132
}, - "pcapSession": {
- "received": 90041092,
- "dropped": 208,
- "ifDropped": 0
}, - "tcpSessions": 399033,
- "hosts": 43,
- "packets": {
- "count": 4067089,
- "size": 1677558858
}, - "queues": {
- "packets": {
- "length": 0,
- "overflow": 0
}, - "packetsVxlan": { },
- "tcpSessions": {
- "length": 0,
- "overflow": 0
}
}
}, - "new": {
- "cpuUsage": {
- "overall": 2.33,
- "process": 0.02
}, - "packets": {
- "count": 925,
- "size": 391289
}, - "queues": {
- "packets": {
- "overflow": 0
}, - "packetsVxlan": { },
- "tcpSessions": {
- "overflow": 0
}
}, - "pcapSession": {
- "received": 10516,
- "dropped": 0,
- "ifDropped": 0
}, - "tcpSessions": 89
}, - "interfaces": [
- {
- "interface": "lo",
- "address": "127.0.0.1",
- "netmask": "255.0.0.0",
- "family": "IPv4",
- "mac": "00:00:00:00:00:00",
- "internal": true,
- "cidr": "127.0.0.1/8"
}, - {
- "interface": "eth0",
- "address": "10.255.0.8",
- "netmask": "255.255.0.0",
- "family": "IPv4",
- "mac": "02:42:0a:ff:00:08",
- "internal": false,
- "cidr": "10.255.0.8/16"
}, - {
- "interface": "eth2",
- "address": "172.18.0.3",
- "netmask": "255.255.0.0",
- "family": "IPv4",
- "mac": "02:42:ac:12:00:03",
- "internal": false,
- "cidr": "172.18.0.3/16"
}, - {
- "interface": "eth1",
- "address": "10.0.0.7",
- "netmask": "255.255.255.0",
- "family": "IPv4",
- "mac": "02:42:0a:00:00:07",
- "internal": false,
- "cidr": "10.0.0.7/24"
}
]
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get the statuses listed in input (by id).
Also available by GET method
List of Gociphers identifiers (or Gocipher instance identifiers)
System id of Gocipher
[- "string"
][- { }
]Search for raw status
May ask searching without specifying a Gocipher:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Search for current status of Gociphers
May ask searching without specifying a Gocipher:
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resources fetched to get next ones. |
| size required | integer Page size. |
| avoidTotalHits | boolean Tells if response should include total hits count. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "query": "",
- "sort": [
- {
- "key": "time",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get the targets being watched for this Whisperer.
Also available by GET method
| whisperer required | string Internal id of Whisperer |
[- { }
]Stores a UI state and gives a link in returns.
The state to link
required | object |
object | |
| main required | object |
required | object |
| search required | object |
{- "userInfo": {
- "whisp": {
- "selected": [
- "string"
]
}, - "impersonate": {
- "selected": "string"
}
}, - "time": {
- "timeSpan": {
- "start": "2019-08-24T14:15:22Z",
- "stop": "2019-08-24T14:15:22Z"
}, - "timeAggregation": "string"
}, - "main": { },
- "networkMap": {
- "origin": { },
- "zoom": { }
}, - "search": { }
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for links.
Also available by GET method on the collection
May ask searching without specifying a whisperer:
Search parameters
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Aggregation request, using Elasticsearch aggregation DSL. |
| size required | integer Page size. |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| includeETags | boolean Tells if response should include _eTags fields for update. |
{- "query": "string",
- "aggs": { },
- "sort": [
- {
- "key": "string",
- "order": "asc"
}
], - "next": [
- "string"
], - "size": 0,
- "avoidTotalHits": true,
- "includeETags": true
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get a link
The link may be public or not
| id required | string Links system Id |
{- "@id": "fH5R3ZjhR7WPHBn2GDg1cA",
- "@type": "sp:link",
- "dateCreated": "2019-01-27T20:58:30.421Z",
- "creator": "VBqPbgjYRsK00O76DVeroQ==",
- "version": "0.1",
- "content": { }
}Stores a UI state and gives a public link in return.
required | Array of objects A collection of filters defining access control. |
| freeAccess | boolean Flag indicating if the link provides free access without restrictions. |
| sendEmail | boolean Indicates whether an email notification should be sent. |
| dateDeprecated | string <date> The ISO date when the public link becomes deprecated. |
| domains required | Array of strings List of domains whose emails have access to the public link. Starting with '@'. |
| recipients required | Array of strings Email addresses of the recipients with access. |
| stateToShare required | object Object representing the UI state to be shared. |
{- "accessFilters": [
- {
- "view": "string",
- "query": "string",
- "accessForbidden": true
}
], - "freeAccess": true,
- "sendEmail": true,
- "dateDeprecated": "2019-08-24",
- "domains": [
- "string"
], - "recipients": [
- "string"
], - "stateToShare": { }
}{- "urlToShare": "string"
}Search for public links.
Also available by GET method on the collection
content is removedurlToShare field is added with the Url of the linkSearch parameters
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Aggregation request, using Elasticsearch aggregation DSL. |
| size required | integer Page size. |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| includeETags | boolean Tells if response should include _eTags fields for update. |
{- "query": "string",
- "aggs": { },
- "sort": [
- {
- "key": "string",
- "order": "asc"
}
], - "next": [
- "string"
], - "size": 0,
- "avoidTotalHits": true,
- "includeETags": true
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Set a public link to DELETED status, making it invisible to searches and get.
| id required | string Public link system Id |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Create a One Time Password for a user trying to connect to a Public link. Send this OTP to the email of the user.
| id required | string Public link system Id |
Array of strings Email address of the user trying to access. |
{- "email": [
- "string"
]
}{- "status": "string"
}Connects a public user by generating a JWT specific to this public link, with dedicated access filters. Issues also a cookie with refresh token scoped to the token renewal api.
| id required | string Public link system Id |
Array of strings Email address of the user trying to access. | |
| otp | Array of strings One Time Password associated to this email. |
{- "email": [
- "string"
], - "otp": [
- "string"
]
}{- "token": "string"
}Logs out a user and clears the refresh token cookie
| id required | string Public link system Id |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for sessions. Sessions are confidential, searching them is much restricted.
Also available by GET method on the collection
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get a session
| id required | string Sessions system Id |
{- "@id": "06cb72b6-5a87-4baa-a3ca-620806a6aa7b",
- "dateCreated": "2019-01-27T21:03:38.750Z",
- "creator": "VBqPbgjYRsK00dhzdVeroQ",
- "version": "0.1",
- "dateModified": "2019-01-27T21:18:41.746Z",
- "updater": "VBqPbgjYRsK00dhzdVeroQ",
- "user": {
- "@id": "VBqPbgjYRsK00dhzdVeroQ",
- "email": "user@nomail.com"
}, - "main": {
- "app": "network-view",
- "start": "2019-01-27T20:57:47.468Z",
- "stop": "2019-01-27T20:58:38.320Z",
- "duration": 50,
- "reloads": 2,
- "activeHours": [
- "2019-01-27T20:00:00.000Z"
]
}, - "views": {
- "HTTP": {
- "duration": 44,
- "active": true,
- "start": "2019-01-27T20:58:38.320Z"
}, - "TCP": { },
- "PACKET": { }
}, - "subViews": {
- "TABLE": {
- "duration": 44,
- "active": true,
- "start": "2019-01-27T20:58:38.320Z"
}, - "SEQ_DIAG": { },
- "STATS": { }
}, - "options": {
- "hideGateways": {
- "active": false,
- "duration": 0
}, - "mergedReplicas": {
- "active": false,
- "duration": 0
}, - "showCircle": {
- "active": false,
- "duration": 0
}, - "menuOpened": {
- "active": false,
- "duration": 0
}, - "drawerOpened": {
- "active": true,
- "start": "2019-01-27T20:58:38.320Z",
- "duration": 44
}, - "detailsPinned": {
- "active": false,
- "duration": 0
}
}, - "whisperers": {
- "selected": [
- "SIT1 - W1",
- "SIT1 - W2",
- "SIT1 - W3",
- "SIT1 - W4",
- "SIT1 - W5"
]
}, - "actions": [
- {
- "name": "menu.whisperers.search",
- "count": 2
}, - {
- "name": "menu.whisperers.select",
- "count": 4
}, - {
- "name": "map.zoom",
- "count": 2
}, - {
- "name": "timeLine.drag",
- "count": 1
}, - {
- "name": "links.create",
- "count": 1
}
], - "actionsTotalCount": 11
}Save a session
| id required | string Sessions system Id |
The session
| @id required | string System id |
required | object Connected user |
required | object |
| views required | object Statistics on the view used |
| subViews | object Statistics on the subview used |
| options | object Options selected |
| whisperers | object List of selected whisperers |
Array of objects Statistics on the actions triggered by the user |
{- "@id": "06cb72b6-5a87-4baa-a3ca-620806a6aa7b",
- "dateCreated": "2019-01-27T21:03:38.750Z",
- "creator": "VBqPbgjYRsK00dhzdVeroQ",
- "version": "0.1",
- "dateModified": "2019-01-27T21:18:41.746Z",
- "updater": "VBqPbgjYRsK00dhzdVeroQ",
- "user": {
- "@id": "VBqPbgjYRsK00dhzdVeroQ",
- "email": "user@nomail.com"
}, - "main": {
- "app": "network-view",
- "start": "2019-01-27T20:57:47.468Z",
- "stop": "2019-01-27T20:58:38.320Z",
- "duration": 50,
- "reloads": 2,
- "activeHours": [
- "2019-01-27T20:00:00.000Z"
]
}, - "views": {
- "HTTP": {
- "duration": 44,
- "active": true,
- "start": "2019-01-27T20:58:38.320Z"
}, - "TCP": { },
- "PACKET": { }
}, - "subViews": {
- "TABLE": {
- "duration": 44,
- "active": true,
- "start": "2019-01-27T20:58:38.320Z"
}, - "SEQ_DIAG": { },
- "STATS": { }
}, - "options": {
- "hideGateways": {
- "active": false,
- "duration": 0
}, - "mergedReplicas": {
- "active": false,
- "duration": 0
}, - "showCircle": {
- "active": false,
- "duration": 0
}, - "menuOpened": {
- "active": false,
- "duration": 0
}, - "drawerOpened": {
- "active": true,
- "start": "2019-01-27T20:58:38.320Z",
- "duration": 44
}, - "detailsPinned": {
- "active": false,
- "duration": 0
}
}, - "whisperers": {
- "selected": [
- "SIT1 - W1",
- "SIT1 - W2",
- "SIT1 - W3",
- "SIT1 - W4",
- "SIT1 - W5"
]
}, - "actions": [
- {
- "name": "menu.whisperers.search",
- "count": 2
}, - {
- "name": "menu.whisperers.select",
- "count": 4
}, - {
- "name": "map.zoom",
- "count": 2
}, - {
- "name": "timeLine.drag",
- "count": 1
}, - {
- "name": "links.create",
- "count": 1
}
], - "actionsTotalCount": 11
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Create a job
The Job details
| jobType required | string Enum: "PurgeJob" "DownloadJob" "UploadJob" "..." Type of job |
| jobParameters required | object Input of the job |
| progress required | integer Progress in % |
| whisperer required | Array of strings List of whisperers |
| startTime | string <date-time> Start of the job |
| endTime | string <date-time> End of the job |
| updateTime | string <date-time> Last update of the job |
| actionStatus required | string Enum: "ActiveActionStatus" "CompletedActionStatus" "FailedActionStatus" "PotentialActionStatus" Status of the job |
| result | object Result of the job |
| error | object Error of the job, if any |
{- "jobType": "PurgeJob",
- "jobParameters": { },
- "progress": 0,
- "whisperer": [
- "string"
], - "startTime": "2019-08-24T14:15:22Z",
- "endTime": "2019-08-24T14:15:22Z",
- "updateTime": "2019-08-24T14:15:22Z",
- "actionStatus": "ActiveActionStatus",
- "result": { },
- "error": { }
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for jobs.
Also available by GET method on the collection
Admin and monitoring admin may search without specifying a whisperer
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get a jobs details.
| id required | string Customer internal @id |
{- "@id": "Ju_4O7N9QvWLC8x7PswfnQ",
- "@type": "Job",
- "jobType": "DownloadJsonJob",
- "creator": "wB0wdZgkTJqxcSZYv8yZ8g",
- "creationTime": "2019-01-18T15:20:09.158Z",
- "updateTime": "2019-01-18T15:20:09.159Z",
- "endTime": "2019-01-18T15:20:09.106Z",
- "actionStatus": "CompletedActionStatus",
- "progress": 100,
- "jobParameters": {
- "user": "user@nomail.com",
- "resourceType": "HTTP",
- "totalItems": 25
}, - "result": {
- "totalItems": 25,
- "totalHosts": 6,
- "base64Size": 198684
}, - "whisperer": [
- "3k_C6E1STvy6VWGRdPC4Qg",
- "YN1W5EgyRBKw1qqghVINyA"
]
}Update a Job
Impossible to update the following fields:
| id required | string Customer internal @id |
| If-Match required | string eTag of previous state of the job |
Json patch with the changes
| op required | string Enum: "test" "remove" "add" "replace" "move" "copy" |
| path required | string |
| value | string |
| from | string |
[- {
- "op": "test",
- "path": "string",
- "value": "string",
- "from": "string"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Sends an email from the configured account. Can be configured to be connected by OAuth (gmail for instance) or login/password.
Can send to one or several recipients, a text message or html. Txt message being mandatory.
As it is not intended for mass mailing, it makes a connection to the SMTP server for each email.
The email to send
| to required | Array of strings List of recipients |
| subject required | string Subject of the mail. Accepts unicodes characters (for icons) |
| text required | string The plain message |
| html | string The message in html |
{- "to": [
- "string"
], - "subject": "string",
- "text": "string",
- "html": "string"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Create a Gui Log to trace an error happened on GUI
The Gui Log
| app required | string Enum: "Login" "NetworkView" "SelfMonitoring" Name of application |
| time required | string <date-time> Time of log |
| type required | string Enum: "BAD REQUEST" "SERVER ERROR" "UNEXPECTED" "TIMEOUT" "UNKNOWN" "XXX RENDER" Type of error |
| name required | string Enum: "Saga Error" "React Error" Name of the error |
| level required | string Enum: "ERROR" "WARNING" Level of Log |
| message required | string Message of the error (from JS error.message) |
| stack required | string Stack of the error |
| details | string Details of the error. Component stack in React. |
| whisperer | Array of strings List of whisperers |
| customer | string System id of the customer |
| timeout | integer Timeout value in case of timeouts |
object Request that failed | |
object Response that failed |
{- "app": "Login",
- "time": "2019-08-24T14:15:22Z",
- "type": "BAD REQUEST",
- "name": "Saga Error",
- "level": "ERROR",
- "message": "string",
- "stack": "string",
- "details": "string",
- "whisperer": [
- "string"
], - "customer": "string",
- "timeout": 0,
- "req": {
- "method": "string",
- "uri": "string",
- "body": "string",
- "headers": { }
}, - "res": {
- "status": "string",
- "statusText": "string",
- "body": "string",
- "headers": { }
}
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for Gui Logs.
Also available by GET method on the collection
Admin and monitoring admin may search without specifying a whisperer
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Stores the user settings. Mostly used by the UI itself
The settings to save
| @id | string Id of the settings, and of the customer |
required | object GUI settings |
{- "@id": "string",
- "settings": {
- "global": { },
- "user": { }
}
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for settings.
Also available by GET method on the collection
Search parameters
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Aggregation request, using Elasticsearch aggregation DSL. |
| size required | integer Page size. |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| includeETags | boolean Tells if response should include _eTags fields for update. |
{- "query": "string",
- "aggs": { },
- "sort": [
- {
- "key": "string",
- "order": "asc"
}
], - "next": [
- "string"
], - "size": 0,
- "avoidTotalHits": true,
- "includeETags": true
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get settings
| id required | string Settings Id == Id of user |
{- "@id": "string",
- "@type": "GuiSettings",
- "creator": "string",
- "dateCreated": "2019-08-24",
- "version": "string",
- "settings": {
- "global": { },
- "user": { }
}
}Uploads a plugin.
Depending on global setting, the plugin is stored locally in ES
or remotely in Floocus managed S3 service.
plugins.upload permissionThe plugin to store
| @id required | string Id of the plugin, unique for the organisation |
| @type required | string Type of the plugin |
| @version required | string Version of the plugin |
| name required | string Human name of the plugin |
| description | string Explains what the plugins does |
| source required | string Base64 encoded javascript source code of the plugin |
{- "@id": "string",
- "@type": "string",
- "@version": "string",
- "name": "string",
- "description": "string",
- "source": "string"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}When global, searches for both own organisation plugins and 'Floocus' ones.
When local, searches for any plugin.
Also available by GET method on the collection
The plugin to store
| type | string Type of the plugin |
Array of objects Sorting option. | |
| next | Array of strings Ids of the last plugin fetched. |
| size required | integer Page size. |
{- "type": "string",
- "sort": [
- {
- "key": "string",
- "order": "asc"
}
], - "next": [
- "string"
], - "size": 0
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get plugin manifest
| id required | string Plugin @id |
{- "@id": "string",
- "@type": "GuiSettings",
- "creator": "string",
- "dateCreated": "2019-08-24",
- "version": "string",
- "settings": {
- "global": { },
- "user": { }
}
}Get the code
| id required | string Plugin @id |
{- "@id": "string",
- "@type": "GuiSettings",
- "creator": "string",
- "dateCreated": "2019-08-24",
- "version": "string",
- "settings": {
- "global": { },
- "user": { }
}
}Searches or aggregation analysis on monitored metrics:
Also available by GET method on the collections
| collection required | string Enum: "pollers" "parsers" "parsingqueues" "circuitbreakers" "redis" "elasticsearch" "elasticsearchNodes" "processes" "api" "logs" Collection of metrics |
Search parameters
| whisperers | Array of strings List of whisperers to search on. |
| startTime | number <double> Start unix timestamp of search window. Up to 6 decimals for microseconds. |
| stopTime | number <double> Stop unix timestamp of search window. Up to 6 decimals for microseconds. |
| startDate | string <date-time> Start date of search window (can replace startTime). |
| stopDate | string <date-time> Stop date of search window (can replace stopTime). |
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Ids of the last resource already fetched to get next ones. |
| size | integer Page size. |
| withContent | boolean True if you want to embed content in the result items (only for HTTP coms) |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| async | boolean Ask for an async search (when supported). |
| asyncDelayMs | number <integer> How long (in milliseconds) server should wait for an answer before answering with a partial answer (when async). |
| asyncId | string Id of previous async answer from server (to get follow up). Included in hypermedia answer from server when async answer. |
| asyncKeepAliveS | number <integer> How long (in seconds) the async answer is allowed to search before being killed. |
{- "size": 20,
- "whisperers": [
- "KxZOoCLxSM6cVee7xq6iPw",
- "Km77Vs-SS4yRDXwivW8nlA"
], - "startTime": 1547789298.676,
- "stopTime": 1547805717.362,
- "query": "!req.uri:contexts AND !req.uri:version AND !req.query:afterUpdate*",
- "sort": [
- {
- "key": "req.start",
- "order": "asc"
}
]
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Give the queue status of this poller
| service required | string (PollerNames) Enum: "pack-poller" "tcp-poller" "pg-com-poller" "pg-com-content-poller" "pg-parsing-poller" "web-httpcom-poller" "web-httpcom-content-poller" "web-httppers-poller" "hosts-poller" "hosts-agg" "whisp-status-poller" "whisps-status-agg" "status-poller" "capture-status-poller" "ciphers-status-poller" "ciphers-raw-status-poller" "ciphers-status-agg" "parsing-status-tcpsession-poller" "parsing-status-httppers-poller" "parsing-status-pgparsing-poller" Pollers service name |
{- "count": 182,
- "first": "2019-01-30T22:35:51.254Z",
- "last": "2019-01-30T22:36:01.641Z"
}Content-addressed schema store used for binary payload transcoding (protobuf, MessagePack). Schemas are immutable: the @id is the SHA-256 hash of the file bundle.
Upload a content-addressed schema bundle used for binary payload transcoding (protobuf, MessagePack, JSON). The bundle is validated on upload (protobuf is compiled, JSON is parsed). If the same file content has already been stored, the existing document is returned with HTTP 200 instead of 201.
For protobuf bundles (contentType: application/x-protobuf or application/protobuf), the list of
fully-qualified message type names is extracted at upload time and stored alongside the files.
Maximum total upload size: 16 MB.
Multipart form data: one contentType field and one or more files file parts.
| contentType required | string MIME type of the schema files. Supported values: "application/x-protobuf", "application/protobuf", "application/json", "application/x-msgpack". |
| files required | Array of strings <binary> [ items <binary > ] One or more schema files (e.g. .proto files for protobuf bundles). |
{- "@id": "string",
- "@type": "Schema",
- "creator": "string",
- "dateCreated": "2019-08-24T14:15:22Z",
- "contentType": "string",
- "files": [
- {
- "filename": "string",
- "content": "string"
}
], - "size": 0,
- "messageTypes": [
- "string"
]
}Returns a paginated list of schema summaries filtered by content type. File contents are not included -
use GET /schemas/v1/schemas/{id} to retrieve a full schema with file bytes.
| contentType required | string Filter by MIME type (e.g. "application/x-protobuf") |
| from | integer Default: 0 Pagination offset (number of items to skip) |
| size | integer <= 200 Default: 50 Number of items to return (max 200) |
[- {
- "@id": "string",
- "filenames": [
- "string"
], - "dateCreated": "2019-08-24T14:15:22Z",
- "size": 0,
- "messageTypes": [
- "string"
]
}
]Retrieves the full schema document including all file contents (base64-encoded bytes). Used by parsers and the Web-Read-Go transcoder at runtime to fetch schema bundles by their content-addressed id.
| id required | string Content-addressed @id of the schema (SHA-256 hex hash of the file bundle) |
{- "@id": "string",
- "@type": "Schema",
- "creator": "string",
- "dateCreated": "2019-08-24T14:15:22Z",
- "contentType": "string",
- "files": [
- {
- "filename": "string",
- "content": "string"
}
], - "size": 0,
- "messageTypes": [
- "string"
]
}Create a new whisperer, and associate it to the owner customer.
Whisperer creation request
| customer required | string System Id of the customer. |
| name required | string Name of the whisperer to create. |
{- "customer": "YOD66VZ54Jih",
- "name": "Upload"
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Search for whisperers
Also available by GET method on the collection
If client is not admin, the search will be limited to the Whisperers owned by this customer or shared with him.
If client is using public link,
users and teams are omitted in responseSearch parameters
| query | string Free query, using Elasticsearch query string DSL. |
| aggs | object Aggregation request, using Elasticsearch aggregation DSL. |
Array of objects Sorting option. Sorting by @id is automaticaly added. | |
| next | Array of strings Aggregation request, using Elasticsearch aggregation DSL. |
| size required | integer Page size. |
| avoidTotalHits | boolean Tells if response should include total hits count. |
| includeETags | boolean Tells if response should include _eTags fields for update. |
{- "query": "string",
- "aggs": { },
- "sort": [
- {
- "key": "string",
- "order": "asc"
}
], - "next": [
- "string"
], - "size": 0,
- "avoidTotalHits": true,
- "includeETags": true
}{- "total": 0,
- "items": [
- {
- "@id": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "@type": "Packet",
- "version": "2.0",
- "commonId": "ROlrqlFhTY2ayXIxTV2uZA.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931-5",
- "name": "456285.172.16.102.72-43118-172.16.102.125-8080#5",
- "whisperer": "ROlrqlFhTY2ayXIxTV2uZA",
- "instanceId": "rd-srv508-bes",
- "tcpSession": "ROlrqlFhTY2ayXIxTV2uZA.rd-srv508-bes.456285.172.16.102.72-43118-172.16.102.125-8080.1682747931",
- "timestamp": 1642625100.188968,
- "length": 229,
- "rawPacket": {
- "link_type": "LINKTYPE_LINUX_SLL",
- "buf": [ ],
- "header": [ ]
}, - "protocols": {
- "Linux SLL": {
- "src": "50:6b:8d:3a:97:undefined",
- "dst": null
}, - "IPv4": {
- "src": "172.16.102.125",
- "dst": "172.16.102.72"
}, - "TCP": {
- "src": "8080",
- "dst": "43118",
- "direction": "in",
- "packetLot": 1,
- "index": 5,
- "relativeSeq": 1,
- "relativeAck": 0,
- "hasData": true
}
}, - "date": "2022-01-19T20:45:00.188Z",
- "minute": "2022-01-19T20:45:00.000Z",
- "protocolsList": [
- "Linux SLL",
- "IPv4",
- "TCP"
]
}
], - "aggs": { },
- "nextPage": {
- "@type": "SearchAction",
- "query": { }
}, - "asyncResults": {
- "@type": "SearchAction",
- "query": { }
}
}Get a whisperer's details.
Only admins can see DELETED whisperers.
customers or links applicationsResponse varies depending on client:
users and teams fields for public links users| id required | string Internal id of Whisperer |
{- "@id": "string",
- "@type": "Whisperer",
- "version": "string",
- "name": "string",
- "customer": "string",
- "team": "string",
- "dns": "string",
- "apikey": "string",
- "config": {
- "@id": "string",
- "@type": "string",
- "version": "string",
- "dateCreated": "2019-08-24",
- "dateModified": "2019-08-24",
- "editor": "string",
- "creator": "string",
- "client": {
- "capture": {
- "mode": "FILE",
- "file": "string",
- "interface": "string",
- "filter": "string",
- "slowItDown": 0,
- "captureBufferkB": 0
}, - "packets": {
- "sendBufferSizekB": 0,
- "sendBufferDelay": "string",
- "maxSendingInParallel": 0,
- "maxSendingBufferLength": 0,
- "vxlan": {
- "decapsulate": true,
- "keepOriginal": true
}, - "filterHosts": {
- "hostsToTrack": [
- "string"
], - "hostsToIgnore": [
- "string"
], - "trackByDefault": true,
- "waitForNameResolvingToTrack": true,
- "trackUnresolvedIp": true
}
}, - "dumpPackets": {
- "dumpToFile": true,
- "fileBufferSizekB": 0,
- "outputPath": "string"
}, - "dnsCache": {
- "customDnsServer": true,
- "host": "string",
- "port": 0,
- "trackIp": true,
- "ttl": "string",
- "refreshRate": "string",
- "sendFullDelay": "string",
- "sendUpdateDelay": "string",
- "purgeDelay": "string"
}, - "tcpSessions": {
- "track": true,
- "sendSessionDelay": "string",
- "sessionTimeOut": "string",
- "maxSendingInParallel": 0,
- "maxSendingBufferLength": 0
}, - "circuitBreakers": {
- "breakOnHighCpu": true,
- "maxCpu": 0,
- "breakOnHighRam": true,
- "maxRam": 0
}
}, - "server": {
- "dns": {
- "ttl": "string",
- "purgeDelay": "string",
- "maxDelta": "string",
- "customNamePatterns": [
- "string"
]
}, - "pack": {
- "savePackets": true
}, - "tcpStreams": {
- "saveTcpSession": true,
- "parseHTTP": true,
- "parseHTTPOptions": {
- "portsToParse": [
- 0
], - "portsToIgnore": [
- 0
], - "parseByDefault": true
}
}, - "webstreams": {
- "saveContent": true,
- "headersToFilter": [
- "string"
], - "urisToFilter": [
- "string"
], - "urisToFilterReqContent": [
- "string"
], - "urisToFilterResContent": [
- "string"
], - "saveRawHeaders": true,
- "urisToFilterReqRawHeaders": [
- "string"
], - "urisToFilterResRawHeaders": [
- "string"
], - "reqTemplates": [
- {
- "name": "string",
- "pattern": "string",
- "toParse": {
- "verb": true,
- "uri": true,
- "headers": true,
- "body": true
}
}
], - "reqTags": [
- {
- "name": "string",
- "pattern": "string",
- "toParse": {
- "verb": true,
- "uri": true,
- "headers": true,
- "body": true
}
}
], - "resTags": [
- {
- "name": "string",
- "pattern": "string",
- "toParse": {
- "status": true,
- "headers": true,
- "body": true
}
}
], - "saveHttpParsingLogs": true
}
}
}, - "users": [
- {
- "@id": "string",
- "email": "string",
- "rights": {
- "record": true,
- "share": true,
- "publish": true,
- "rights": true,
- "config": true,
- "delete": true
}
}
], - "creator": "string",
- "dateCreated": "2019-08-24",
- "editor": "string",
- "dateModified": "2019-08-24"
}Updates a customer. You can:
| id required | string Internal id of Whisperer |
| If-Match required | string eTag of previous state of the whisperer |
Json patch with the changes
| op required | string Enum: "test" "remove" "add" "replace" "move" "copy" |
| path required | string |
| value | string |
| from | string |
[- {
- "op": "test",
- "path": "string",
- "value": "string",
- "from": "string"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Delete a whisperer.
| id required | string Internal id of Whisperer |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Create/Replace the whisperer API key used for whisperer connection to Spider.
The API key is a public/private key pair.
Any call to this API (if authorized) will overwrite the previous API key, and the whisperer will not be able to use the previous one. A connected whisperer will be disconnected when its current JWT token will expire. The API key is taken as a configuration AT START of whisperers, and need a restart to be changed.
The API can supports two outputs:
| id required | string System id of Whisperer |
{- "whisperer": "abcdefghijklmnopqrstuv",
- "privatePem": "-----BEGIN RSA PRIVATE KEY-----\nline1\nline2\nline3\n...\n-----END RSA PRIVATE KEY-----\n"
}This endpoint is for testing purposes only:
| id required | string System id of Whisperer |
| timeStamp required | string <date-time> Timestamp to use in signature |
| instanceId required | string InstanceId to use in signature |
The whisperer RSA private key, as a PEM
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Initialize the configuration of the whisperer
| id required | string System id of Whisperer |
| version required | string |
required | object Settings used client side - the Sniffer |
required | object Settings used server side, for parsing |
{- "version": "0.1",
- "client": {
- "capture": {
- "mode": "INTERFACE",
- "interface": "any",
- "filter": "(udp port 4789) and not host spider.streetsmart.global"
}, - "packets": {
- "vxlan": {
- "decapsulate": true,
- "keepOriginal": false
}, - "filterHosts": {
- "hostsToTrack": [ ],
- "hostsToIgnore": [
- ".*_poller[\\._]",
- "^itproduction_context_repository",
- "^security_authorization_service"
], - "trackByDefault": true
}
}, - "dnsCache": {
- "trackIp": true
}, - "tcpSessions": {
- "track": true
}
}, - "server": {
- "tcpStreams": {
- "parseHTTP": true,
- "parseHTTPOptions": {
- "portsToParse": [
- 80,
- 9200,
- [
- 3000,
- 3200
], - [
- 5000,
- 5100
]
], - "portsToIgnore": [
- 5432
], - "parseByDefault": true
}
}
}
}{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}Get the configuration of this Whisperer Usages:
The first call from whisperers is made by:
const timeStamp = moment().toISOString();
const info = {
timeStamp,
whispererId,
instanceId
};
const privKey = new NodeRSA(privatePem);
const signature = privKey.sign(Buffer.from(JSON.stringify(info)), 'base64');
Spider-TimeStamp: timeStamp
Spider-InstanceId: instanceId,
Spider-Signature: signature //base 64 encoded
The view parameter allows to modulate the output:
| id required | string System id of Whisperer |
| view | string Enum: "server" "client" "full" Type of configuration to get |
| Spider-Signature | string <base64> Signature of the call by the Whisperer, with its API key |
| Spider-Timestamp | string <date-time> Provided with API key in first Whisperer call to get its JWT token with the config |
| Spider-InstanceId | string Provided with API key in first Whisperer call to get its JWT token with the config |
{- "@id": "string",
- "@type": "string",
- "version": "string",
- "dateCreated": "2019-08-24",
- "dateModified": "2019-08-24",
- "editor": "string",
- "creator": "string",
- "client": {
- "capture": {
- "mode": "FILE",
- "file": "string",
- "interface": "string",
- "filter": "string",
- "slowItDown": 0,
- "captureBufferkB": 0
}, - "packets": {
- "sendBufferSizekB": 0,
- "sendBufferDelay": "string",
- "maxSendingInParallel": 0,
- "maxSendingBufferLength": 0,
- "vxlan": {
- "decapsulate": true,
- "keepOriginal": true
}, - "filterHosts": {
- "hostsToTrack": [
- "string"
], - "hostsToIgnore": [
- "string"
], - "trackByDefault": true,
- "waitForNameResolvingToTrack": true,
- "trackUnresolvedIp": true
}
}, - "dumpPackets": {
- "dumpToFile": true,
- "fileBufferSizekB": 0,
- "outputPath": "string"
}, - "dnsCache": {
- "customDnsServer": true,
- "host": "string",
- "port": 0,
- "trackIp": true,
- "ttl": "string",
- "refreshRate": "string",
- "sendFullDelay": "string",
- "sendUpdateDelay": "string",
- "purgeDelay": "string"
}, - "tcpSessions": {
- "track": true,
- "sendSessionDelay": "string",
- "sessionTimeOut": "string",
- "maxSendingInParallel": 0,
- "maxSendingBufferLength": 0
}, - "circuitBreakers": {
- "breakOnHighCpu": true,
- "maxCpu": 0,
- "breakOnHighRam": true,
- "maxRam": 0
}
}, - "server": {
- "dns": {
- "ttl": "string",
- "purgeDelay": "string",
- "maxDelta": "string",
- "customNamePatterns": [
- "string"
]
}, - "pack": {
- "savePackets": true
}, - "tcpStreams": {
- "saveTcpSession": true,
- "parseHTTP": true,
- "parseHTTPOptions": {
- "portsToParse": [
- 0
], - "portsToIgnore": [
- 0
], - "parseByDefault": true
}
}, - "webstreams": {
- "saveContent": true,
- "headersToFilter": [
- "string"
], - "urisToFilter": [
- "string"
], - "urisToFilterReqContent": [
- "string"
], - "urisToFilterResContent": [
- "string"
], - "saveRawHeaders": true,
- "urisToFilterReqRawHeaders": [
- "string"
], - "urisToFilterResRawHeaders": [
- "string"
], - "reqTemplates": [
- {
- "name": "string",
- "pattern": "string",
- "toParse": {
- "verb": true,
- "uri": true,
- "headers": true,
- "body": true
}
}
], - "reqTags": [
- {
- "name": "string",
- "pattern": "string",
- "toParse": {
- "verb": true,
- "uri": true,
- "headers": true,
- "body": true
}
}
], - "resTags": [
- {
- "name": "string",
- "pattern": "string",
- "toParse": {
- "status": true,
- "headers": true,
- "body": true
}
}
], - "saveHttpParsingLogs": true
}
}
}Updates a Whisperer configuration.
| id required | string System id of Whisperer |
| If-Match required | string eTag of previous state of the whisperer's config |
Json patch with the changes
| op required | string Enum: "test" "remove" "add" "replace" "move" "copy" |
| path required | string |
| value | string |
| from | string |
[- {
- "op": "test",
- "path": "string",
- "value": "string",
- "from": "string"
}
]{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}From a list of Whisperers, provide their TLS configuration
{- "@id": "string",
- "@type": "string",
- "version": "string",
- "whisperer": "string",
- "requiredState": "string",
- "tlsKeys": { }
}Called by ephemeral Whisperers (only) to renew their token (they do not have an API key).
If the Whisperer has a Time to Live associated to attachment, it won't renew.
| id required | string System id of Whisperer |
{- "@type": "Error",
- "title": "Error title",
- "message": "Error details"
}