API reference · schema
WebhookRequest
5 fields · used by 1 operations
Last reviewed 2026-10-02
Fields
| Field | Type | Meaning |
|---|---|---|
url required | string | min length 8 · max length 2000 |
events | array of string | |
description | string or null | max length 200 |
format | string | cain (signed JSON envelope), splunk_hec or xsiam default "cain" |
auth_token | string or null | the SIEM collector's token (splunk_hec, xsiam); stored, never returned max length 512 |
Smallest valid example
{
"url": "url",
"format": "cain"
}Used by 1 operation
| POST | /fabric/webhooks | Get notified when an action is held, blocked or halted |
JSON Schema
Show the raw definition
{
"properties": {
"url": {
"type": "string",
"maxLength": 2000,
"minLength": 8,
"title": "Url"
},
"events": {
"items": {
"type": "string"
},
"type": "array",
"title": "Events"
},
"description": {
"anyOf": [
{
"type": "string",
"maxLength": 200
},
{
"type": "null"
}
],
"title": "Description"
},
"format": {
"type": "string",
"title": "Format",
"description": "cain (signed JSON envelope), splunk_hec or xsiam",
"default": "cain"
},
"auth_token": {
"anyOf": [
{
"type": "string",
"maxLength": 512
},
{
"type": "null"
}
],
"title": "Auth Token",
"description": "the SIEM collector's token (splunk_hec, xsiam); stored, never returned"
}
},
"type": "object",
"required": [
"url"
],
"title": "WebhookRequest"
}Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem