Documentation Get help

Send security events to your SIEM

Send Flowstate’s security events to a collector you control, such as Splunk, Datadog, a Microsoft Sentinel Logic App, or any service that accepts JSON over HTTPS.

You need to be a Flowstate admin.

What Flowstate sends

EventWhen
Effort report history viewedSomeone opens a person’s effort report history
Allocation review viewedSomeone opens a team’s allocation review
Weekly allocations viewedSomeone opens a team’s weekly allocations
AI assistant access approved or deniedSomeone approves or denies an AI assistant’s access to their Flowstate account
AI assistant requestAn AI assistant connected to Flowstate makes a request, including requests that fail or are rate limited

The exact event names and severities are under For your technical team.

Before you start

  • An HTTPS address in your SIEM that accepts JSON sent by POST.
  • The credential that address needs, if any.

1. Add an endpoint

  1. Go to Settings → Organisation → SIEM Integration.

  2. Under Endpoints, select Add Endpoint.

  3. Enter a Name, such as “Splunk Production”.

  4. Enter the Endpoint URL. Use an https:// address.

  5. Choose an Endpoint Type. Every endpoint receives the same JSON over HTTPS.

  6. Choose an Auth Type and fill in Credential:

    Auth TypeEnter in Credential
    Bearer TokenThe token
    Basic Authusername:password
    Custom HeaderThe header name and value together, such as DD-API-KEY: <your key>
    NoneNothing
  7. Under Event Categories, tick at least Data Access, Authentication and API Activity.

  8. Leave Minimum Severity at Info (all events) unless you only want the more serious events.

  9. Select Create Endpoint.

2. Check events arrive

  1. In Flowstate, open a team’s weekly allocations.
  2. In your SIEM, search for effort.weekly_allocations_viewed.

Done when: the event is in your SIEM.

Pause, change or delete an endpoint

  • To pause sending, turn off the switch on the endpoint’s row. Turn it back on to start again.
  • To change an endpoint, open its menu and select Edit Endpoint. Leave Credential blank to keep the current one.
  • To delete an endpoint, open its menu, select Delete Endpoint, then select Delete. Events stop going to it straight away. Deleting can’t be undone, so pause the endpoint instead if you might need it again.

If something’s not right

Nothing arrives. Check the endpoint’s switch is on, its Event Categories include the event’s category, and Minimum Severity isn’t set higher than the event. Then check your collector accepts the credential you entered.

Splunk rejects the events. Use Splunk’s raw collector address, as described below.

For your technical team

Event names

CategoryEventSeverity
Data Accesseffort.report_history_viewedinfo
Data Accesseffort.allocation_review_viewedinfo
Data Accesseffort.weekly_allocations_viewedinfo
Authenticationmcp_consent_approvedinfo
Authenticationmcp_consent_deniedinfo
API Activitymcp_requestinfo
API Activitymcp_request_errorhigh
API Activitymcp_rate_limitedmedium

Event format

Each event is one JSON object, sent with Content-Type: application/json.

FieldContents
eventIdUnique ID for the event
timestampWhen it happened, ISO 8601
logTypeAlways siem
categoryauthentication, api_activity or data_access
eventTypeThe event name
descriptionA readable sentence
severityinfo, low, medium, high or critical
outcomesuccess, failure or unknown
actoruserId, email, ipAddress and userAgent, where known
targettype, id and name of what was acted on, where there is one
detailFields for that event, such as teamId and weekStart
organizationIdYour organisation’s ID, where known
tenantIdYour account’s ID
requestIdThe request ID, where known
servicename, version and environment of the Flowstate service that sent it

Example:

{
  "eventId": "<uuid>",
  "timestamp": "<ISO 8601 time>",
  "logType": "siem",
  "category": "data_access",
  "eventType": "effort.weekly_allocations_viewed",
  "description": "User viewed weekly team allocations",
  "severity": "info",
  "outcome": "success",
  "actor": { "userId": "<user id>", "email": "jane@example.com" },
  "target": { "type": "team", "id": "<team id>" },
  "detail": { "teamId": "<team id>", "weekStart": "<ISO 8601 time>" },
  "organizationId": "<organisation id>",
  "tenantId": "<account id>",
  "service": { "name": "flowstate-app", "version": "<release>", "environment": "production" }
}

Vendor set-up

Check your vendor’s current documentation too.

  • Splunk HTTP Event Collector: use the raw endpoint, /services/collector/raw. Set Auth Type to Custom Header and Credential to Authorization: Splunk <HEC token>.
  • Datadog: use Datadog’s HTTP log intake for your site. Set Auth Type to Custom Header and Credential to DD-API-KEY: <API key>.
  • Microsoft Sentinel: point Flowstate at an HTTP-triggered Logic App or Azure Function that forwards events to your Log Analytics workspace.

Manage endpoints from a script

The API Keys section on the same page creates keys for managing your SIEM endpoints from a script. They don’t read events.

  1. Select Create Key.
  2. Enter a Name and choose an Expiration.
  3. Select Create API Key and copy the key. It’s only shown once.

A SIEM key can manage everything on this page, including other SIEM keys, so store it as carefully as an admin password. Send it as Authorization: Bearer fs_siem_….

Method and pathDoes
GET /api/siem/configList endpoints
POST /api/siem/configCreate an endpoint
PUT /api/siem/config/{id}Change an endpoint, including switching it on or off
DELETE /api/siem/config/{id}Delete an endpoint
GET /api/siem/keysList SIEM keys
POST /api/siem/keysCreate a SIEM key
DELETE /api/siem/keys/{id}Revoke a SIEM key

Revoke a SIEM API key

Revoke a key when the script that uses it is retired, or if the key may have been seen by someone who shouldn’t have it.

  1. Go to Settings → Organisation → SIEM Integration.
  2. Under API Keys, open the key’s menu and select Revoke Key.
  3. Select Revoke.

Anything using the key loses access straight away, and the key leaves the list.