clients
Creates, updates, deletes, gets or lists a clients resource.
Overview
| Name | clients |
| Type | Resource |
| Id | sumologic.oauth.clients |
Fields
The following fields are returned by SELECT queries:
- get
- list
OAuth client object that was requested.
| Name | Datatype | Description |
|---|---|---|
id | string | Unique identifier of the OAuth client. (example: 0000000006743FDE) |
name | string | Name of the OAuth client. (example: My OAuth Client) |
client_id | string | Identifier of the OAuth client. Unique within each organization. Will be a URL for dynamically generated clients. (example: zVplCFHcpTDwtktBIQmFI2K6s9HEo4HAtcQD1f1M5eQ) (wire: clientId) |
created_at | string (date-time) | Creation timestamp in UTC in [RFC3339](https://tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt) |
created_by | string | Identifier of the user who created the OAuth client. (example: 0000000006743FDD) (wire: createdBy) |
description | string | Description of the OAuth client. (example: OAuth client for data ingestion) |
disabled | boolean | Whether the OAuth client is disabled. Disabled OAuth clients cannot be used to authenticate users. |
modified_at | string (date-time) | Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt) |
modified_by | string | Identifier of the user who modified the OAuth client. (example: 0000000006743FDD) (wire: modifiedBy) |
scopes | array | Scopes assigned to the client. MCP Server Required Scopes: For full access to all MCP Server tools, the following scopes are required. Each tool lists the scopes it needs. - alerts___alertsReadById — viewAlerts - alerts___alertsSearch — viewAlerts - dashboards___getDashboard — viewLibrary - dashboards___listDashboards — viewLibrary - dashboards___createDashboard — manageLibrary - dashboards___updateDashboard — manageLibrary - discovery___listPartitions — viewPartitions - discovery___listExtractionRules — viewFieldExtractionRules - discovery___listCustomFields — viewFields - log-search___runLogSearch — runLogSearch - insights___getAllInsights — viewCse - insights___getInsight — viewCse - insights___getInsights — viewCse - insights___updateInsightAssignee — viewCse, cseManageInsightAssignee - insights___updateInsightStatus — viewCse, cseManageInsightStatus - rules___getRule — viewCse, cseViewRules - rules___getRules — viewCse, cseViewRules - rules___createTemplatedMatchRule — viewCse, cseManageRules - rules___createThresholdRule — viewCse, cseManageRules ### Alerting - viewAlerts (MCP Server) - adminMonitorsV2 - viewMonitorsV2 - manageMonitorsV2 - viewMutingSchedules - manageMutingSchedules ### Audit Event Management - searchAuditIndex - dataVolumeIndex - auditEventIndex ### Cloud SIEM - viewCse (MCP Server) - cseViewRules (MCP Server) - cseManageRules (MCP Server) - cseManageInsightAssignee (MCP Server) - cseManageInsightStatus (MCP Server) - cseCommentOnInsights - cseCreateInsights - cseDeleteInsights - cseInvokeInsights - cseManageInsightPolicy - cseManageInsightSignals - cseManageInsightTags - cseViewThreatIntelligence - cseManageThreatIntelligence - cseViewMatchLists - cseManageMatchLists - cseViewFileAnalysis - cseManageFileAnalysis - cseViewCustomInsights - cseManageCustomInsights - cseViewNetworkBlocks - cseManageNetworkBlocks - cseViewSuppressedEntities - cseManageSuppressedEntities - cseViewMappings - cseManageMappings - cseManageArtifacts - cseViewCustomInsightStatuses - cseManageCustomInsightStatuses - cseViewContextActions - cseManageContextActions - cseViewActions - cseManageActions - cseViewEnrichments - cseManageEnrichments - cseViewCustomEntityType - cseManageCustomEntityType - cseViewEntity - cseManageEntity - cseViewEntityConfiguration - cseManageEntityConfiguration - cseViewEntityCriticality - cseManageEntityCriticality - cseViewTagSchemas - cseManageTagSchemas - cseManageFavoriteFields - cseViewEntityGroups - cseManageEntityGroups - cseViewAutomations - cseManageAutomations - cseExecuteAutomations ### Cloud SOAR - viewCloudSoar - cloudSoarAPIAdmin - cloudSoarAPIEmailEdit - cloudSoarAPIEmailRead - cloudSoarAPIUse - cloudSoarAppCentralAccess - cloudSoarAppCentralExport - cloudSoarAuditAndInformationAuditTrail - cloudSoarAuditAndInformationConfigureAuditTrail - cloudSoarAuditAndInformationLicenseInformation - cloudSoarAutomationRulesAccess - cloudSoarAutomationRulesConfigure - cloudSoarBridgeMonitoringAccess - cloudSoarCustomizationFields - cloudSoarCustomizationIncidentLabels - cloudSoarCustomizationLogo - cloudSoarDashboardAccess - cloudSoarDashboardAll - cloudSoarEntitiesAccess - cloudSoarEntitiesBulkPhysicalDelete - cloudSoarEntitiesManage - cloudSoarGeneralConfigure - cloudSoarIncidentAccess - cloudSoarIncidentAccessAll - cloudSoarIncidentAttachmentsAccess - cloudSoarIncidentAttachmentsEdit - cloudSoarIncidentBulkOperations - cloudSoarIncidentChangeOwnership - cloudSoarIncidentEdit - cloudSoarIncidentFoldersEdit - cloudSoarIncidentManageInvestigators - cloudSoarIncidentNotesAccess - cloudSoarIncidentNotesEdit - cloudSoarIncidentPlaybooksAccess - cloudSoarIncidentPlaybooksEdit - cloudSoarIncidentPlaybooksManage - cloudSoarIncidentTaskAccess - cloudSoarIncidentTaskAccessAll - cloudSoarIncidentTaskEdit - cloudSoarIncidentTaskReassign - cloudSoarIncidentTaskView - cloudSoarIncidentTemplatesAccess - cloudSoarIncidentTemplatesConfigure - cloudSoarIncidentTriageAccess - cloudSoarIncidentTriageAccessAll - cloudSoarIncidentTriageChangeOwnership - cloudSoarIncidentTriageEdit - cloudSoarIncidentTriageView - cloudSoarIncidentView - cloudSoarIncidentWarRoomUse - cloudSoarIntegrationsAccess - cloudSoarIntegrationsConfigure - cloudSoarNotificationConfigure - cloudSoarNotificationTriage - cloudSoarObservabilityAccess - cloudSoarObservabilityManagement - cloudSoarPlaybooksAccess - cloudSoarPlaybooksConfigure - cloudSoarReportAccess - cloudSoarReportAll - cloudSoarUserManagementGroups - cloudSoarWidgetsAll ### Dashboards - worldDashboards - whitelistDashboards - shareDashboardAllowlist - manageDashboardExecutionControls ### Data Management - manageApps - viewCollectors - manageCollectors - viewConnections - manageConnections - contentAdmin - viewFieldExtractionRules (MCP Server) - manageFieldExtractionRules - viewFields (MCP Server) - manageFields - manageBudgets - viewLibrary (MCP Server) - manageLibrary (MCP Server) - viewPartitions (MCP Server) - managePartitions - manageS3DataForwarding - viewScheduledViews - manageScheduledViews - manageTokens - viewPipelines - managePipelines - viewAccountOverview - dataVolume - downloadSearchResults - viewDeletionRules - manageDeletionRules - reviewDeletionRequest - viewEventExtractionRules - manageEventExtractionRules - viewParsers ### Data Masking - viewUnmaskedData - manageDataMasking ### Entity Management - manageEntityTypeConfig ### Logs - runLogSearch (MCP Server) ### Macros - manageMacros ### Metrics - runMetricsQuery - metricsTransformation - metricsExtraction - metricsRules ### Open Analytics - manageOpenAnalyticsEndpoint ### Organizations - viewOrganizations - createTrialOrganizations - createOrganizations - upgradeTrialOrganizations - changeCreditsAllocation - deactivateOrganizations - manageOrganizations ### Reliability Management - viewSlos - manageSlos ### Security - manageAccessKeys - viewPersonalAccessKeys - managePersonalAccessKeys - manageOAuthClients - changeDataAccessLevel - passwordPolicy - ipWhitelisting - ipAllowlisting - supportAccount - audit - saml - worldDashboardMaster - orgSettings ### Threat Intelligence - viewThreatIntelDataStore - manageThreatIntelDataStore ### Usage Management - viewUsageManagement - manageUsageManagement ### User Management - viewUsersAndRoles - manageUsersAndRoles |
type | string | Type of the object model. |
A list of all OAuth clients within the organization.
| Name | Datatype | Description |
|---|---|---|
id | string | Unique identifier of the OAuth client. (example: 0000000006743FDE) |
name | string | Name of the OAuth client. (example: My OAuth Client) |
client_id | string | Identifier of the OAuth client. Unique within each organization. Will be a URL for dynamically generated clients. (example: zVplCFHcpTDwtktBIQmFI2K6s9HEo4HAtcQD1f1M5eQ) (wire: clientId) |
created_at | string (date-time) | Creation timestamp in UTC in [RFC3339](https://tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt) |
created_by | string | Identifier of the user who created the OAuth client. (example: 0000000006743FDD) (wire: createdBy) |
description | string | Description of the OAuth client. (example: OAuth client for data ingestion) |
disabled | boolean | Whether the OAuth client is disabled. Disabled OAuth clients cannot be used to authenticate users. |
modified_at | string (date-time) | Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt) |
modified_by | string | Identifier of the user who modified the OAuth client. (example: 0000000006743FDD) (wire: modifiedBy) |
scopes | array | Scopes assigned to the client. MCP Server Required Scopes: For full access to all MCP Server tools, the following scopes are required. Each tool lists the scopes it needs. - alerts___alertsReadById — viewAlerts - alerts___alertsSearch — viewAlerts - dashboards___getDashboard — viewLibrary - dashboards___listDashboards — viewLibrary - dashboards___createDashboard — manageLibrary - dashboards___updateDashboard — manageLibrary - discovery___listPartitions — viewPartitions - discovery___listExtractionRules — viewFieldExtractionRules - discovery___listCustomFields — viewFields - log-search___runLogSearch — runLogSearch - insights___getAllInsights — viewCse - insights___getInsight — viewCse - insights___getInsights — viewCse - insights___updateInsightAssignee — viewCse, cseManageInsightAssignee - insights___updateInsightStatus — viewCse, cseManageInsightStatus - rules___getRule — viewCse, cseViewRules - rules___getRules — viewCse, cseViewRules - rules___createTemplatedMatchRule — viewCse, cseManageRules - rules___createThresholdRule — viewCse, cseManageRules ### Alerting - viewAlerts (MCP Server) - adminMonitorsV2 - viewMonitorsV2 - manageMonitorsV2 - viewMutingSchedules - manageMutingSchedules ### Audit Event Management - searchAuditIndex - dataVolumeIndex - auditEventIndex ### Cloud SIEM - viewCse (MCP Server) - cseViewRules (MCP Server) - cseManageRules (MCP Server) - cseManageInsightAssignee (MCP Server) - cseManageInsightStatus (MCP Server) - cseCommentOnInsights - cseCreateInsights - cseDeleteInsights - cseInvokeInsights - cseManageInsightPolicy - cseManageInsightSignals - cseManageInsightTags - cseViewThreatIntelligence - cseManageThreatIntelligence - cseViewMatchLists - cseManageMatchLists - cseViewFileAnalysis - cseManageFileAnalysis - cseViewCustomInsights - cseManageCustomInsights - cseViewNetworkBlocks - cseManageNetworkBlocks - cseViewSuppressedEntities - cseManageSuppressedEntities - cseViewMappings - cseManageMappings - cseManageArtifacts - cseViewCustomInsightStatuses - cseManageCustomInsightStatuses - cseViewContextActions - cseManageContextActions - cseViewActions - cseManageActions - cseViewEnrichments - cseManageEnrichments - cseViewCustomEntityType - cseManageCustomEntityType - cseViewEntity - cseManageEntity - cseViewEntityConfiguration - cseManageEntityConfiguration - cseViewEntityCriticality - cseManageEntityCriticality - cseViewTagSchemas - cseManageTagSchemas - cseManageFavoriteFields - cseViewEntityGroups - cseManageEntityGroups - cseViewAutomations - cseManageAutomations - cseExecuteAutomations ### Cloud SOAR - viewCloudSoar - cloudSoarAPIAdmin - cloudSoarAPIEmailEdit - cloudSoarAPIEmailRead - cloudSoarAPIUse - cloudSoarAppCentralAccess - cloudSoarAppCentralExport - cloudSoarAuditAndInformationAuditTrail - cloudSoarAuditAndInformationConfigureAuditTrail - cloudSoarAuditAndInformationLicenseInformation - cloudSoarAutomationRulesAccess - cloudSoarAutomationRulesConfigure - cloudSoarBridgeMonitoringAccess - cloudSoarCustomizationFields - cloudSoarCustomizationIncidentLabels - cloudSoarCustomizationLogo - cloudSoarDashboardAccess - cloudSoarDashboardAll - cloudSoarEntitiesAccess - cloudSoarEntitiesBulkPhysicalDelete - cloudSoarEntitiesManage - cloudSoarGeneralConfigure - cloudSoarIncidentAccess - cloudSoarIncidentAccessAll - cloudSoarIncidentAttachmentsAccess - cloudSoarIncidentAttachmentsEdit - cloudSoarIncidentBulkOperations - cloudSoarIncidentChangeOwnership - cloudSoarIncidentEdit - cloudSoarIncidentFoldersEdit - cloudSoarIncidentManageInvestigators - cloudSoarIncidentNotesAccess - cloudSoarIncidentNotesEdit - cloudSoarIncidentPlaybooksAccess - cloudSoarIncidentPlaybooksEdit - cloudSoarIncidentPlaybooksManage - cloudSoarIncidentTaskAccess - cloudSoarIncidentTaskAccessAll - cloudSoarIncidentTaskEdit - cloudSoarIncidentTaskReassign - cloudSoarIncidentTaskView - cloudSoarIncidentTemplatesAccess - cloudSoarIncidentTemplatesConfigure - cloudSoarIncidentTriageAccess - cloudSoarIncidentTriageAccessAll - cloudSoarIncidentTriageChangeOwnership - cloudSoarIncidentTriageEdit - cloudSoarIncidentTriageView - cloudSoarIncidentView - cloudSoarIncidentWarRoomUse - cloudSoarIntegrationsAccess - cloudSoarIntegrationsConfigure - cloudSoarNotificationConfigure - cloudSoarNotificationTriage - cloudSoarObservabilityAccess - cloudSoarObservabilityManagement - cloudSoarPlaybooksAccess - cloudSoarPlaybooksConfigure - cloudSoarReportAccess - cloudSoarReportAll - cloudSoarUserManagementGroups - cloudSoarWidgetsAll ### Dashboards - worldDashboards - whitelistDashboards - shareDashboardAllowlist - manageDashboardExecutionControls ### Data Management - manageApps - viewCollectors - manageCollectors - viewConnections - manageConnections - contentAdmin - viewFieldExtractionRules (MCP Server) - manageFieldExtractionRules - viewFields (MCP Server) - manageFields - manageBudgets - viewLibrary (MCP Server) - manageLibrary (MCP Server) - viewPartitions (MCP Server) - managePartitions - manageS3DataForwarding - viewScheduledViews - manageScheduledViews - manageTokens - viewPipelines - managePipelines - viewAccountOverview - dataVolume - downloadSearchResults - viewDeletionRules - manageDeletionRules - reviewDeletionRequest - viewEventExtractionRules - manageEventExtractionRules - viewParsers ### Data Masking - viewUnmaskedData - manageDataMasking ### Entity Management - manageEntityTypeConfig ### Logs - runLogSearch (MCP Server) ### Macros - manageMacros ### Metrics - runMetricsQuery - metricsTransformation - metricsExtraction - metricsRules ### Open Analytics - manageOpenAnalyticsEndpoint ### Organizations - viewOrganizations - createTrialOrganizations - createOrganizations - upgradeTrialOrganizations - changeCreditsAllocation - deactivateOrganizations - manageOrganizations ### Reliability Management - viewSlos - manageSlos ### Security - manageAccessKeys - viewPersonalAccessKeys - managePersonalAccessKeys - manageOAuthClients - changeDataAccessLevel - passwordPolicy - ipWhitelisting - ipAllowlisting - supportAccount - audit - saml - worldDashboardMaster - orgSettings ### Threat Intelligence - viewThreatIntelDataStore - manageThreatIntelDataStore ### Usage Management - viewUsageManagement - manageUsageManagement ### User Management - viewUsersAndRoles - manageUsersAndRoles |
type | string | Type of the object model. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | id, region | Get an OAuth client with the given identifier from the organization. | |
list | select | region | limit, token, run_as_id, client_id | List all OAuth clients. |
create | insert | region, scopes, type | Creates a new OAuth clientId and clientSecret. | |
update | update | id, region, disabled, scopes, type | Updates the properties of existing OAuth client by Id. | |
delete | delete | id, region | Deletes the OAuth client with the given Id. | |
rotate_secret | exec | id, region | Generates a new secret for the oauth client that is passed in the call, keeping the same client ID. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
id | string | The ID of the oauth client to rotate the secret for. |
region | string | Sumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT) |
client_id | string | Filter clients by exact client ID. When specified, returns only the client matching this ID. Supports URL-based client identifiers (URL-encode the value). (wire: clientId) |
limit | integer (int32) | Limit the number of OAuth clients returned in the response. The number of OAuth clients returned may be less than the limit. |
run_as_id | string | Identifier of the service account that the OAuth Client runs as. (wire: runAsId) |
token | string | Continuation token to get the next page of results. A page object with the next continuation token is returned in the response body. Subsequent GET requests should specify the continuation token to get the next page of results. token is set to null when no more pages are left. |
SELECT examples
- get
- list
Get an OAuth client with the given identifier from the organization.
SELECT
id,
name,
client_id,
created_at,
created_by,
description,
disabled,
modified_at,
modified_by,
scopes,
type
FROM sumologic.oauth.clients
WHERE id = '{{ id }}' -- required
AND region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
;
List all OAuth clients.
SELECT
id,
name,
client_id,
created_at,
created_by,
description,
disabled,
modified_at,
modified_by,
scopes,
type
FROM sumologic.oauth.clients
WHERE region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
AND limit = '{{ limit }}'
AND token = '{{ token }}'
AND run_as_id = '{{ run_as_id }}'
AND client_id = '{{ client_id }}'
;
INSERT examples
- create
- Manifest
Creates a new OAuth clientId and clientSecret.
INSERT INTO sumologic.oauth.clients (
type,
scopes,
region
)
SELECT
'{{ type }}' /* required */,
'{{ scopes }}' /* required */,
'{{ region }}'
RETURNING
id,
name,
client_id,
created_at,
created_by,
description,
disabled,
modified_at,
modified_by,
scopes,
type
;
# Description fields are for documentation purposes
- name: clients
props:
- name: region
value: "{{ region }}"
description: Required parameter for the clients resource.
- name: type
value: "{{ type }}"
description: |
Type of the object model.
- name: scopes
value:
- "{{ scopes }}"
description: |
Scopes assigned to the client.
**MCP Server Required Scopes:** For full access to all MCP Server tools, the following scopes are required. Each tool lists the scopes it needs.
- `alerts___alertsReadById` — viewAlerts
- `alerts___alertsSearch` — viewAlerts
- `dashboards___getDashboard` — viewLibrary
- `dashboards___listDashboards` — viewLibrary
- `dashboards___createDashboard` — manageLibrary
- `dashboards___updateDashboard` — manageLibrary
- `discovery___listPartitions` — viewPartitions
- `discovery___listExtractionRules` — viewFieldExtractionRules
- `discovery___listCustomFields` — viewFields
- `log-search___runLogSearch` — runLogSearch
- `insights___getAllInsights` — viewCse
- `insights___getInsight` — viewCse
- `insights___getInsights` — viewCse
- `insights___updateInsightAssignee` — viewCse, cseManageInsightAssignee
- `insights___updateInsightStatus` — viewCse, cseManageInsightStatus
- `rules___getRule` — viewCse, cseViewRules
- `rules___getRules` — viewCse, cseViewRules
- `rules___createTemplatedMatchRule` — viewCse, cseManageRules
- `rules___createThresholdRule` — viewCse, cseManageRules
### Alerting
- viewAlerts *(MCP Server)*
- adminMonitorsV2
- viewMonitorsV2
- manageMonitorsV2
- viewMutingSchedules
- manageMutingSchedules
### Audit Event Management
- searchAuditIndex
- dataVolumeIndex
- auditEventIndex
### Cloud SIEM
- viewCse *(MCP Server)*
- cseViewRules *(MCP Server)*
- cseManageRules *(MCP Server)*
- cseManageInsightAssignee *(MCP Server)*
- cseManageInsightStatus *(MCP Server)*
- cseCommentOnInsights
- cseCreateInsights
- cseDeleteInsights
- cseInvokeInsights
- cseManageInsightPolicy
- cseManageInsightSignals
- cseManageInsightTags
- cseViewThreatIntelligence
- cseManageThreatIntelligence
- cseViewMatchLists
- cseManageMatchLists
- cseViewFileAnalysis
- cseManageFileAnalysis
- cseViewCustomInsights
- cseManageCustomInsights
- cseViewNetworkBlocks
- cseManageNetworkBlocks
- cseViewSuppressedEntities
- cseManageSuppressedEntities
- cseViewMappings
- cseManageMappings
- cseManageArtifacts
- cseViewCustomInsightStatuses
- cseManageCustomInsightStatuses
- cseViewContextActions
- cseManageContextActions
- cseViewActions
- cseManageActions
- cseViewEnrichments
- cseManageEnrichments
- cseViewCustomEntityType
- cseManageCustomEntityType
- cseViewEntity
- cseManageEntity
- cseViewEntityConfiguration
- cseManageEntityConfiguration
- cseViewEntityCriticality
- cseManageEntityCriticality
- cseViewTagSchemas
- cseManageTagSchemas
- cseManageFavoriteFields
- cseViewEntityGroups
- cseManageEntityGroups
- cseViewAutomations
- cseManageAutomations
- cseExecuteAutomations
### Cloud SOAR
- viewCloudSoar
- cloudSoarAPIAdmin
- cloudSoarAPIEmailEdit
- cloudSoarAPIEmailRead
- cloudSoarAPIUse
- cloudSoarAppCentralAccess
- cloudSoarAppCentralExport
- cloudSoarAuditAndInformationAuditTrail
- cloudSoarAuditAndInformationConfigureAuditTrail
- cloudSoarAuditAndInformationLicenseInformation
- cloudSoarAutomationRulesAccess
- cloudSoarAutomationRulesConfigure
- cloudSoarBridgeMonitoringAccess
- cloudSoarCustomizationFields
- cloudSoarCustomizationIncidentLabels
- cloudSoarCustomizationLogo
- cloudSoarDashboardAccess
- cloudSoarDashboardAll
- cloudSoarEntitiesAccess
- cloudSoarEntitiesBulkPhysicalDelete
- cloudSoarEntitiesManage
- cloudSoarGeneralConfigure
- cloudSoarIncidentAccess
- cloudSoarIncidentAccessAll
- cloudSoarIncidentAttachmentsAccess
- cloudSoarIncidentAttachmentsEdit
- cloudSoarIncidentBulkOperations
- cloudSoarIncidentChangeOwnership
- cloudSoarIncidentEdit
- cloudSoarIncidentFoldersEdit
- cloudSoarIncidentManageInvestigators
- cloudSoarIncidentNotesAccess
- cloudSoarIncidentNotesEdit
- cloudSoarIncidentPlaybooksAccess
- cloudSoarIncidentPlaybooksEdit
- cloudSoarIncidentPlaybooksManage
- cloudSoarIncidentTaskAccess
- cloudSoarIncidentTaskAccessAll
- cloudSoarIncidentTaskEdit
- cloudSoarIncidentTaskReassign
- cloudSoarIncidentTaskView
- cloudSoarIncidentTemplatesAccess
- cloudSoarIncidentTemplatesConfigure
- cloudSoarIncidentTriageAccess
- cloudSoarIncidentTriageAccessAll
- cloudSoarIncidentTriageChangeOwnership
- cloudSoarIncidentTriageEdit
- cloudSoarIncidentTriageView
- cloudSoarIncidentView
- cloudSoarIncidentWarRoomUse
- cloudSoarIntegrationsAccess
- cloudSoarIntegrationsConfigure
- cloudSoarNotificationConfigure
- cloudSoarNotificationTriage
- cloudSoarObservabilityAccess
- cloudSoarObservabilityManagement
- cloudSoarPlaybooksAccess
- cloudSoarPlaybooksConfigure
- cloudSoarReportAccess
- cloudSoarReportAll
- cloudSoarUserManagementGroups
- cloudSoarWidgetsAll
### Dashboards
- worldDashboards
- whitelistDashboards
- shareDashboardAllowlist
- manageDashboardExecutionControls
### Data Management
- manageApps
- viewCollectors
- manageCollectors
- viewConnections
- manageConnections
- contentAdmin
- viewFieldExtractionRules *(MCP Server)*
- manageFieldExtractionRules
- viewFields *(MCP Server)*
- manageFields
- manageBudgets
- viewLibrary *(MCP Server)*
- manageLibrary *(MCP Server)*
- viewPartitions *(MCP Server)*
- managePartitions
- manageS3DataForwarding
- viewScheduledViews
- manageScheduledViews
- manageTokens
- viewPipelines
- managePipelines
- viewAccountOverview
- dataVolume
- downloadSearchResults
- viewDeletionRules
- manageDeletionRules
- reviewDeletionRequest
- viewEventExtractionRules
- manageEventExtractionRules
- viewParsers
### Data Masking
- viewUnmaskedData
- manageDataMasking
### Entity Management
- manageEntityTypeConfig
### Logs
- runLogSearch *(MCP Server)*
### Macros
- manageMacros
### Metrics
- runMetricsQuery
- metricsTransformation
- metricsExtraction
- metricsRules
### Open Analytics
- manageOpenAnalyticsEndpoint
### Organizations
- viewOrganizations
- createTrialOrganizations
- createOrganizations
- upgradeTrialOrganizations
- changeCreditsAllocation
- deactivateOrganizations
- manageOrganizations
### Reliability Management
- viewSlos
- manageSlos
### Security
- manageAccessKeys
- viewPersonalAccessKeys
- managePersonalAccessKeys
- manageOAuthClients
- changeDataAccessLevel
- passwordPolicy
- ipWhitelisting
- ipAllowlisting
- supportAccount
- audit
- saml
- worldDashboardMaster
- orgSettings
### Threat Intelligence
- viewThreatIntelDataStore
- manageThreatIntelDataStore
### Usage Management
- viewUsageManagement
- manageUsageManagement
### User Management
- viewUsersAndRoles
- manageUsersAndRoles
default:
UPDATE examples
- update
Updates the properties of existing OAuth client by Id.
UPDATE sumologic.oauth.clients
SET
type = '{{ type }}',
disabled = {{ disabled }},
scopes = '{{ scopes }}'
WHERE
id = '{{ id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
AND disabled = {{ disabled }} --required
AND scopes = '{{ scopes }}' --required
AND type = '{{ type }}' --required
RETURNING
id,
name,
client_id,
created_at,
created_by,
description,
disabled,
modified_at,
modified_by,
scopes,
type;
DELETE examples
- delete
Deletes the OAuth client with the given Id.
DELETE FROM sumologic.oauth.clients
WHERE id = '{{ id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;
Lifecycle Methods
EXEC variables use wire (API) names.
- rotate_secret
Generates a new secret for the oauth client that is passed in the call, keeping the same client ID.
EXEC sumologic.oauth.clients.rotate_secret
@id='{{ id }}' --required,
@region='{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;