Documentation
Send events to your SIEM
Two ways to get governance events out of Ovyero: your collector pulls a feed, or Ovyero pushes an alert to a webhook. Both carry metadata only, never source code.
Pull: the event feed
curl -sS "https://ovyero.visnryentertainment.com/api/v1/siem/events?format=ndjson&limit=1000" \ -H "Authorization: Bearer $OVYERO_API_KEY"
| Parameter | Values |
|---|---|
format | ndjson (default), splunk (Splunk HEC) or json. |
after | An ISO timestamp. Only events after it are returned. Pass the X-Next-Cursor response header from the previous call. |
types | Comma-separated filter, for example verdict,forensic_access. |
limit | Default 1000, at most 10000. X-Event-Count reports how many came back. |
Each event has ts, event_type (verdict, security_event, forensic_access or admin_event), verdict, action, target, critics, violations, actor, actor_type, actor_verified, artifact_sha256 and ledger_hash (the entry’s hash in your tamper-evident ledger).
Push: alert webhook
- Save a destination:
curl -sS -X POST https://ovyero.visnryentertainment.com/api/v1/siem/config \ -H "Authorization: Bearer $OVYERO_API_KEY" -H "Content-Type: application/json" \ -d '{"enabled":true,"webhookUrl":"https://hooks.example.com/ovyero","format":"generic","alertOn":["GATE","SECURITY"],"secret":"a-long-random-string"}' - Send a test alert:
POST /api/v1/siem/test. The response says whether it was delivered.
| Field | Values |
|---|---|
format | generic (default), slack or pagerduty. |
alertOn | Any of GATE, WARN, SECURITY. Default: GATE and SECURITY. |
secret | Used to sign each delivery. Never returned; reads show secretSet only. |
webhookUrl | Must be https and publicly reachable. Loopback, private and link-local addresses are refused when you save and again when an alert is sent. Reads show the URL masked. |
Verify a delivery
When a secret is set, each request carries X-Ovyero-Signature: sha256=<hex>: the HMAC-SHA256 of the raw request body, keyed with your secret. Deliveries are JSON POSTs with User-Agent: Ovyero-SIEM/1 and a 4-second timeout.
Who can change it
- An API key, or the organization owner signed in within the last 10 minutes.
- Reading the configuration from a signed-in session needs the owner or an admin.
- Every change is written to your audit ledger.
Problems: Troubleshooting or contact us.