Skip to main content
The SOC Defenders CEF endpoint returns your filtered IOCs as Common Event Format log lines — one line per indicator. You can pipe the output directly into your syslog daemon or log collector, making it straightforward to ingest threat intelligence into ArcSight, QRadar, Splunk, or any other SIEM with a syslog input.
CEF/Syslog export requires a Pro subscription. Upgrade at socdefenders.ai.

Endpoint

GET /api/v1/iocs/cef The response body is plain text — one CEF log line per IOC, with no JSON envelope. This makes it suitable for direct piping into standard Unix log utilities.

Authentication

Pass your API key as a Bearer token in the Authorization header.

Query parameters

Example request

Fetch high-confidence IPv4 indicators and pipe them directly into your local syslog:
To write to a file instead:

CEF field mapping

Each response line follows the CEF standard format:
A sample line for a malicious IPv4 indicator looks like this: