Interacting with LEQL Variables via the API

Tested this over the weekend, and I was able to successfully get a list of existing variables in my IDR lab, create a new one, modify it, and ultimate deleting it. I did this using the free program “Postman” on a Macbook, and using the Get, Post, Put, and Delete calls. Here is a link to the video and the documentation I used to get started:

  1. Managing Platform API Keys | Insight Platform Documentation
  2. InsightIDR REST API | InsightIDR Documentation
  3. https://docs.rapid7.com/insightidr/log-search-api/
  4. https://docs.rapid7.com/insightidr/log-search-api/#operation/listVariables

Link to the video:


External_Variable_API

3 Likes