API Evangelist API Evangelist
API Learnings
Toolbox
API Evangelist LLC

Chronicle API

The Chronicle API provides programmatic access to Chronicle's security analytics platform. Developers can use the API to ingest security telemetry, search across normalized security data using UDM (Unified Data Model), manage detection rules, investigate alerts, and retrieve threat intelligence. The API supports creating and managing detection rules, running retrohunts, and accessing curated threat detections.

Documentation

Specifications

Schemas & Data

OpenAPI

chronicle-api-openapi.yml Raw ↑