filescom-siem-http-destinations

SkillFiles & storage

A SIEM HTTP Destination defines where Files.com sends the log types you select.

Use filescom-siem-http-destinations in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add filescom-siem-http-destinations and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the filescom-siem-http-destinations skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

filescom-siem-http-destinationsStart free

What this skill tells your AI

The instructions your AI receives, as published by files-com/files-cli in skills/filescom-siem-http-destinations/SKILL.md and read by Ahel’s review.

A SIEM HTTP Destination defines where Files.com sends the log types you select. For HTTP destinations, Files.com sends JSON to the configured endpoint. For file destinations, Files.com writes JSON or CSV files to the configured folder.

All subcommands also accept the flags documented in CONTEXT.md (--api-key, --format, --workspace-id, --debug, and the pagination flags --cursor / --per-page / --max-pages on list). Those are not repeated below.

Commands

files-cli siem-http-destinations list

List SIEM HTTP Destinations.

No flags beyond the global ones.

files-cli siem-http-destinations find

Show SIEM HTTP Destination.

FlagTypeDescription
--idint64Siem Http Destination ID. Required.

files-cli siem-http-destinations create

Create SIEM HTTP Destination.

FlagTypeDescription
--namestringName for this Destination
--additional-headersobjectAdditional HTTP Headers included in calls to the destination URL
--sending-activeboolWhether this SIEM HTTP Destination is currently being sent to or not
--generic-payload-typeenumApplicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. One of: json_newline, json_array.
--file-destination-pathstringApplicable only for destination type: file. Destination folder path on Files.com.
--file-formatenumApplicable only for destination type: file. Generated file format. One of: json, csv.
--file-interval-minutesint64Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
--splunk-tokenstringApplicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
--crowdstrike-tokenstringApplicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
--azure-dcr-immutable-idstringApplicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
--azure-stream-namestringApplicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
--azure-oauth-client-credentials-tenant-idstringApplicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
--azure-oauth-client-credentials-client-idstringApplicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
--azure-oauth-client-credentials-client-secretstringApplicable only for destination type: azure. Client Credentials OAuth Client Secret.
--qradar-usernamestringApplicable only for destination type: qradar. Basic auth username provided by QRadar.
--qradar-passwordstringApplicable only for destination type: qradar. Basic auth password provided by QRadar.
--solar-winds-tokenstringApplicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
--new-relic-api-keystringApplicable only for destination type: new_relic. API key provided by New Relic.
--datadog-api-keystringApplicable only for destination type: datadog. API key provided by Datadog.
--action-send-enabledboolWhether or not sending is enabled for action logs.
--sftp-action-send-enabledboolWhether or not sending is enabled for sftp_action logs.
--ftp-action-send-enabledboolWhether or not sending is enabled for ftp_action logs.
--web-dav-action-send-enabledboolWhether or not sending is enabled for web_dav_action logs.
--sync-send-enabledboolWhether or not sending is enabled for sync logs.
--outbound-connection-send-enabledboolWhether or not sending is enabled for outbound_connection logs.
--automation-send-enabledboolWhether or not sending is enabled for automation logs.
--api-request-send-enabledboolWhether or not sending is enabled for api_request logs.
--public-hosting-request-send-enabledboolWhether or not sending is enabled for public_hosting_request logs.
--email-send-enabledboolWhether or not sending is enabled for email logs.
--exavault-api-request-send-enabledboolWhether or not sending is enabled for exavault_api_request logs.
--settings-change-send-enabledboolWhether or not sending is enabled for settings_change logs.
--destination-typeenumDestination Type. One of: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible. Required.
--destination-urlstringDestination Url

files-cli siem-http-destinations send-test-entry

send_test_entry SIEM HTTP Destination.

FlagTypeDescription
--siem-http-destination-idint64SIEM HTTP Destination ID
--destination-typeenumDestination Type. One of: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible.
--destination-urlstringDestination Url
--namestringName for this Destination
--additional-headersobjectAdditional HTTP Headers included in calls to the destination URL
--sending-activeboolWhether this SIEM HTTP Destination is currently being sent to or not
--generic-payload-typeenumApplicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. One of: json_newline, json_array.
--file-destination-pathstringApplicable only for destination type: file. Destination folder path on Files.com.
--file-formatenumApplicable only for destination type: file. Generated file format. One of: json, csv.
--file-interval-minutesint64Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
--splunk-tokenstringApplicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
--crowdstrike-tokenstringApplicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
--azure-dcr-immutable-idstringApplicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
--azure-stream-namestringApplicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
--azure-oauth-client-credentials-tenant-idstringApplicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
--azure-oauth-client-credentials-client-idstringApplicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
--azure-oauth-client-credentials-client-secretstringApplicable only for destination type: azure. Client Credentials OAuth Client Secret.
--qradar-usernamestringApplicable only for destination type: qradar. Basic auth username provided by QRadar.
--qradar-passwordstringApplicable only for destination type: qradar. Basic auth password provided by QRadar.
--solar-winds-tokenstringApplicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
--new-relic-api-keystringApplicable only for destination type: new_relic. API key provided by New Relic.
--datadog-api-keystringApplicable only for destination type: datadog. API key provided by Datadog.
--action-send-enabledboolWhether or not sending is enabled for action logs.
--sftp-action-send-enabledboolWhether or not sending is enabled for sftp_action logs.
--ftp-action-send-enabledboolWhether or not sending is enabled for ftp_action logs.
--web-dav-action-send-enabledboolWhether or not sending is enabled for web_dav_action logs.
--sync-send-enabledboolWhether or not sending is enabled for sync logs.
--outbound-connection-send-enabledboolWhether or not sending is enabled for outbound_connection logs.
--automation-send-enabledboolWhether or not sending is enabled for automation logs.
--api-request-send-enabledboolWhether or not sending is enabled for api_request logs.
--public-hosting-request-send-enabledboolWhether or not sending is enabled for public_hosting_request logs.
--email-send-enabledboolWhether or not sending is enabled for email logs.
--exavault-api-request-send-enabledboolWhether or not sending is enabled for exavault_api_request logs.
--settings-change-send-enabledboolWhether or not sending is enabled for settings_change logs.

files-cli siem-http-destinations update

Update SIEM HTTP Destination.

FlagTypeDescription
--idint64Siem Http Destination ID. Required.
--namestringName for this Destination
--additional-headersobjectAdditional HTTP Headers included in calls to the destination URL
--sending-activeboolWhether this SIEM HTTP Destination is currently being sent to or not
--generic-payload-typeenumApplicable only for destination type: generic. Indicates the type of HTTP body. Can be json_newline or json_array. json_newline is multiple log entries as JSON separated by newlines. json_array is a single JSON array containing multiple log entries as JSON. One of: json_newline, json_array.
--file-destination-pathstringApplicable only for destination type: file. Destination folder path on Files.com.
--file-formatenumApplicable only for destination type: file. Generated file format. One of: json, csv.
--file-interval-minutesint64Applicable only for destination type: file. Interval, in minutes, between file deliveries. Valid values are 5, 10, 15, 20, 30, 60, 90, 180, 240, 360.
--splunk-tokenstringApplicable only for destination types: splunk, splunk_compatible. Authentication token for the destination.
--crowdstrike-tokenstringApplicable only for destination type: crowdstrike. Authentication token provided by Crowdstrike.
--azure-dcr-immutable-idstringApplicable only for destination types: azure, azure_legacy. Immutable ID of the Data Collection Rule.
--azure-stream-namestringApplicable only for destination type: azure. Name of the stream in the DCR that represents the destination table.
--azure-oauth-client-credentials-tenant-idstringApplicable only for destination types: azure, azure_legacy. Client Credentials OAuth Tenant ID.
--azure-oauth-client-credentials-client-idstringApplicable only for destination types: azure, azure_legacy. Client Credentials OAuth Client ID.
--azure-oauth-client-credentials-client-secretstringApplicable only for destination type: azure. Client Credentials OAuth Client Secret.
--qradar-usernamestringApplicable only for destination type: qradar. Basic auth username provided by QRadar.
--qradar-passwordstringApplicable only for destination type: qradar. Basic auth password provided by QRadar.
--solar-winds-tokenstringApplicable only for destination type: solar_winds. Authentication token provided by Solar Winds.
--new-relic-api-keystringApplicable only for destination type: new_relic. API key provided by New Relic.
--datadog-api-keystringApplicable only for destination type: datadog. API key provided by Datadog.
--action-send-enabledboolWhether or not sending is enabled for action logs.
--sftp-action-send-enabledboolWhether or not sending is enabled for sftp_action logs.
--ftp-action-send-enabledboolWhether or not sending is enabled for ftp_action logs.
--web-dav-action-send-enabledboolWhether or not sending is enabled for web_dav_action logs.
--sync-send-enabledboolWhether or not sending is enabled for sync logs.
--outbound-connection-send-enabledboolWhether or not sending is enabled for outbound_connection logs.
--automation-send-enabledboolWhether or not sending is enabled for automation logs.
--api-request-send-enabledboolWhether or not sending is enabled for api_request logs.
--public-hosting-request-send-enabledboolWhether or not sending is enabled for public_hosting_request logs.
--email-send-enabledboolWhether or not sending is enabled for email logs.
--exavault-api-request-send-enabledboolWhether or not sending is enabled for exavault_api_request logs.
--settings-change-send-enabledboolWhether or not sending is enabled for settings_change logs.
--destination-typeenumDestination Type. One of: generic, splunk, azure_legacy, qradar, sumo, rapid7, solar_winds, new_relic, datadog, azure, file, crowdstrike, splunk_compatible.
--destination-urlstringDestination Url

files-cli siem-http-destinations delete

Delete SIEM HTTP Destination.

FlagTypeDescription
--idint64Siem Http Destination ID. Required.

Signals

GitHub stars
46
Forks
4
Last commit
Oct 2026
Advanced
Item type
skill
Key
filescom-siem-http-destinations
Source
github.com/files-com/files-cli