How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

ThreatLocker Action Log API

The ActionLog API from ThreatLocker — 9 operation(s) for actionlog.

ThreatLocker Action Log API is one of 18 APIs that ThreatLocker publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Action Log. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, a getting-started guide, and authentication docs.

This API exposes 9 operations across 9 paths, and defines 32 schemas. It is described by OpenAPI 3.2.0, at version v1.0.0.

Requests are made against a single base URL, https://portalapi.threatlocker.com/portalapi/.

9 operations 9 paths 32 schemas 5 GET4 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
v1.0.0
Base URL
https://portalapi.threatlocker.com/portalapi/
Authentication
API Key, API Key, API Key
Resource Areas
1

Authentication & Security 3

ThreatLocker Action Log API declares 3 security schemes for authenticating requests. An API key is passed in the header as Authorization (Authorization). An API key is passed in the header as ManagedOrganizationId (ManagedOrganizationId). An API key is passed in the header as OverrideManagedOrganizationId (OverrideManagedOrganizationId). By default, every request must be authenticated.

  • Authorization — Please insert Standard Authorization header.
  • ManagedOrganizationId — Please insert Managed Organization Id.
  • OverrideManagedOrganizationId — Please insert Managed Organization Id.

Paths & Operations 9

Across 9 paths, the API surfaces 9 operations — 5 GET, 4 POST. Each is listed below with its method, path, parameters, and response codes.

ActionLog 9
POST
/portalapi/ActionLog/ActionLogGetByParametersV2
Get Action Logs By Parameters.
1 param body → 200
GET
/portalapi/ActionLog/ActionLogGetAllForFileHistory
Get All File History by hostname and fullpath
5 params → 200
GET
/portalapi/ActionLog/ActionLogGetAllForFileHistoryV2
Get All File History by hostname and fullpath
6 params → 200
GET
/portalapi/ActionLog/ActionLogGetById
Get Action Logs by Id.
3 params → 200
GET
/portalapi/ActionLog/ActionLogGetByIdV2
5 params → 200
POST
/portalapi/ActionLog/ActionLogGetTestingEnvironmentDetailsById
Get Testing Environment Details For VDI HyperV
body → 200
POST
/portalapi/ActionLog/ActionLogGetPolicyConditionsForPermitApplication
Get Policy Conditions For Permit Application
1 param body → 200
POST
/portalapi/ActionLog/ActionLogGetSearchString
Get Search String (This is for save search).
body → 200
GET
/portalapi/ActionLog/ActionLogGetFileDownloadDetailsById
2 params → 200

Schemas 32

The contract defines 32 schemas that model the data the API accepts and returns. The most detailed are ActionLogDto (96 properties), ApprovalRequestDto (63 properties), PermitApplicationDto (46 properties), ActionLogParamsDto (34 properties). Each schema is shown below with its type and property counts.

Certificate
object
4 properties
ComputerGroupItemDto
object
7 properties
FileDownloadDetailsDto
object
5 properties
SystemAuditDetails
object
4 properties
NetworkExclusionDto
object
3 properties
PermitApplicationDto
object
46 properties
NetworkPolicy
object
5 properties
ThreatLockerCertDto
object
4 properties
ActionLogParamsDto
object
34 properties
Int32ObjectKeyValuePair
object
2 properties
PermitFileDetails
object
18 properties
SystemAuditItem
object
14 properties
AdvRFPolicy
object
10 properties
ApprovalRequestDto
object
63 properties
PolicyManualOption
object
8 properties
AssociatedApplicationPolicy
object
3 properties
FileExclusionDto
object
4 properties
ThreatLockerActionDto
object
33 properties
PermitPolicyConditions
object
8 properties
PermitPolicyLevel
object
5 properties
ActionLogDto
object
96 properties
ApprovalRequestTimerDto
object
8 properties
RegistryPolicy
object
4 properties
OrganizationParentsDto
object
2 properties
PermitMatchingApplications
object
7 properties
EngineRating
object
2 properties
ApplicationOnlineDto
object
10 properties
FilePolicy
object
4 properties
PermitAdminNotes
object
3 properties
ThreatLockerItemDto
object
7 properties
ActionLogCreatedByProcessesDto
object
2 properties
ParamsFieldsDto
object
18 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

threatlocker-actionlog-api-openapi.yml Raw ↑

Other APIs ThreatLocker publishes across the network.

ThreatLocker Application API
ThreatLocker Approval Request API
ThreatLocker Computer API
ThreatLocker Computer Checkin API
ThreatLocker Computer Group API
ThreatLocker Maintenance Mode API
ThreatLocker Online Devices API
ThreatLocker Organization API
ThreatLocker Policy API
ThreatLocker Report API
ThreatLocker Save Search API
ThreatLocker Scheduled Agent Action API
Where this information came from

This is an independent, third-party profile of ThreatLocker Action Log API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.