Create an Observable
curl --request POST \
--url https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables \
--header 'BLINK-API-KEY: <api-key>' \
--header 'Content-Type: */*' \
--data '
{
"content": "1.1.1.1",
"description": "Suspicious IP address observed in network traffic",
"enrichment_data": "{\"VirusTotal-Score\":\"value\"}",
"name": "Suspicious IP Address",
"reputation": "Suspicious/Risky",
"type": "IP Address"
}
'import requests
url = "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables"
payload = {
"content": "1.1.1.1",
"description": "Suspicious IP address observed in network traffic",
"enrichment_data": "{\"VirusTotal-Score\":\"value\"}",
"name": "Suspicious IP Address",
"reputation": "Suspicious/Risky",
"type": "IP Address"
}
headers = {
"BLINK-API-KEY": "<api-key>",
"Content-Type": "*/*"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'BLINK-API-KEY': '<api-key>', 'Content-Type': '*/*'},
body: JSON.stringify({
content: '1.1.1.1',
description: 'Suspicious IP address observed in network traffic',
enrichment_data: '{"VirusTotal-Score":"value"}',
name: 'Suspicious IP Address',
reputation: 'Suspicious/Risky',
type: 'IP Address'
})
};
fetch('https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'content' => '1.1.1.1',
'description' => 'Suspicious IP address observed in network traffic',
'enrichment_data' => '{"VirusTotal-Score":"value"}',
'name' => 'Suspicious IP Address',
'reputation' => 'Suspicious/Risky',
'type' => 'IP Address'
]),
CURLOPT_HTTPHEADER => [
"BLINK-API-KEY: <api-key>",
"Content-Type: */*"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables"
payload := strings.NewReader("{\n \"content\": \"1.1.1.1\",\n \"description\": \"Suspicious IP address observed in network traffic\",\n \"enrichment_data\": \"{\\\"VirusTotal-Score\\\":\\\"value\\\"}\",\n \"name\": \"Suspicious IP Address\",\n \"reputation\": \"Suspicious/Risky\",\n \"type\": \"IP Address\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("BLINK-API-KEY", "<api-key>")
req.Header.Add("Content-Type", "*/*")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables")
.header("BLINK-API-KEY", "<api-key>")
.header("Content-Type", "*/*")
.body("{\n \"content\": \"1.1.1.1\",\n \"description\": \"Suspicious IP address observed in network traffic\",\n \"enrichment_data\": \"{\\\"VirusTotal-Score\\\":\\\"value\\\"}\",\n \"name\": \"Suspicious IP Address\",\n \"reputation\": \"Suspicious/Risky\",\n \"type\": \"IP Address\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["BLINK-API-KEY"] = '<api-key>'
request["Content-Type"] = '*/*'
request.body = "{\n \"content\": \"1.1.1.1\",\n \"description\": \"Suspicious IP address observed in network traffic\",\n \"enrichment_data\": \"{\\\"VirusTotal-Score\\\":\\\"value\\\"}\",\n \"name\": \"Suspicious IP Address\",\n \"reputation\": \"Suspicious/Risky\",\n \"type\": \"IP Address\"\n}"
response = http.request(request)
puts response.read_body{
"content": "1.1.1.1",
"description": "Suspicious IP address observed in network traffic",
"enrichment_data": "{\"VirusTotal-Score\":\"value\"}",
"name": "Suspicious IP Address",
"reputation": "Suspicious/Risky",
"type": "IP Address"
}{
"data": {},
"details": "<string>",
"identifier": "<string>",
"message": "<string>",
"status": 404,
"user_error": {}
}Case Management
Create an Observable
API endpoint to create a new observable in Blink’s case management system.
POST
/
workspace
/
{ws_id}
/
case_management
/
table
/
observables
Create an Observable
curl --request POST \
--url https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables \
--header 'BLINK-API-KEY: <api-key>' \
--header 'Content-Type: */*' \
--data '
{
"content": "1.1.1.1",
"description": "Suspicious IP address observed in network traffic",
"enrichment_data": "{\"VirusTotal-Score\":\"value\"}",
"name": "Suspicious IP Address",
"reputation": "Suspicious/Risky",
"type": "IP Address"
}
'import requests
url = "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables"
payload = {
"content": "1.1.1.1",
"description": "Suspicious IP address observed in network traffic",
"enrichment_data": "{\"VirusTotal-Score\":\"value\"}",
"name": "Suspicious IP Address",
"reputation": "Suspicious/Risky",
"type": "IP Address"
}
headers = {
"BLINK-API-KEY": "<api-key>",
"Content-Type": "*/*"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'BLINK-API-KEY': '<api-key>', 'Content-Type': '*/*'},
body: JSON.stringify({
content: '1.1.1.1',
description: 'Suspicious IP address observed in network traffic',
enrichment_data: '{"VirusTotal-Score":"value"}',
name: 'Suspicious IP Address',
reputation: 'Suspicious/Risky',
type: 'IP Address'
})
};
fetch('https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'content' => '1.1.1.1',
'description' => 'Suspicious IP address observed in network traffic',
'enrichment_data' => '{"VirusTotal-Score":"value"}',
'name' => 'Suspicious IP Address',
'reputation' => 'Suspicious/Risky',
'type' => 'IP Address'
]),
CURLOPT_HTTPHEADER => [
"BLINK-API-KEY: <api-key>",
"Content-Type: */*"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables"
payload := strings.NewReader("{\n \"content\": \"1.1.1.1\",\n \"description\": \"Suspicious IP address observed in network traffic\",\n \"enrichment_data\": \"{\\\"VirusTotal-Score\\\":\\\"value\\\"}\",\n \"name\": \"Suspicious IP Address\",\n \"reputation\": \"Suspicious/Risky\",\n \"type\": \"IP Address\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("BLINK-API-KEY", "<api-key>")
req.Header.Add("Content-Type", "*/*")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables")
.header("BLINK-API-KEY", "<api-key>")
.header("Content-Type", "*/*")
.body("{\n \"content\": \"1.1.1.1\",\n \"description\": \"Suspicious IP address observed in network traffic\",\n \"enrichment_data\": \"{\\\"VirusTotal-Score\\\":\\\"value\\\"}\",\n \"name\": \"Suspicious IP Address\",\n \"reputation\": \"Suspicious/Risky\",\n \"type\": \"IP Address\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/observables")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["BLINK-API-KEY"] = '<api-key>'
request["Content-Type"] = '*/*'
request.body = "{\n \"content\": \"1.1.1.1\",\n \"description\": \"Suspicious IP address observed in network traffic\",\n \"enrichment_data\": \"{\\\"VirusTotal-Score\\\":\\\"value\\\"}\",\n \"name\": \"Suspicious IP Address\",\n \"reputation\": \"Suspicious/Risky\",\n \"type\": \"IP Address\"\n}"
response = http.request(request)
puts response.read_body{
"content": "1.1.1.1",
"description": "Suspicious IP address observed in network traffic",
"enrichment_data": "{\"VirusTotal-Score\":\"value\"}",
"name": "Suspicious IP Address",
"reputation": "Suspicious/Risky",
"type": "IP Address"
}{
"data": {},
"details": "<string>",
"identifier": "<string>",
"message": "<string>",
"status": 404,
"user_error": {}
}Authorizations
Use your API key to access BlinkOps API. To generate an API key, please log in to your BlinkOps account and navigate to the API Keys section in the user settings page. Add the generated key to your request headers as BLINK-API-KEY.
Path Parameters
Workspace ID
Body
*/*
Observable Data
Example:
"1.1.1.1"
Example:
"Suspicious IP address observed in network traffic"
Example:
"{\"VirusTotal-Score\":\"value\"}"
Example:
"Suspicious IP Address"
Available options:
Unknown, Very Safe, Safe, Probably Safe, Leans Safe, May not be Safe, Exercise Caution, Suspicious/Risky, Possibly Malicious, Probably Malicious, Malicious, Other Example:
"Suspicious/Risky"
Available options:
Unknown, Hostname, IP Address, MAC Address, User Name, Email Address, URL String, File Name, Hash, Process Name, Resource UID, Port, Subnet, Command Line, Country, Process ID, HTTP User-Agent, CWE Object: uid, CVE Object: uid, User Credential ID, Endpoint, User, Email, Uniform Resource Locator, File, Process, Geo Location, Container, Registry Key, Registry Value, Fingerprint, Other Example:
"IP Address"
Response
OK
Example:
"1.1.1.1"
Example:
"Suspicious IP address observed in network traffic"
Example:
"{\"VirusTotal-Score\":\"value\"}"
Example:
"Suspicious IP Address"
Available options:
Unknown, Very Safe, Safe, Probably Safe, Leans Safe, May not be Safe, Exercise Caution, Suspicious/Risky, Possibly Malicious, Probably Malicious, Malicious, Other Example:
"Suspicious/Risky"
Available options:
Unknown, Hostname, IP Address, MAC Address, User Name, Email Address, URL String, File Name, Hash, Process Name, Resource UID, Port, Subnet, Command Line, Country, Process ID, HTTP User-Agent, CWE Object: uid, CVE Object: uid, User Credential ID, Endpoint, User, Email, Uniform Resource Locator, File, Process, Geo Location, Container, Registry Key, Registry Value, Fingerprint, Other Example:
"IP Address"
Was this page helpful?