Skip to main content
Send a DELETE request to /api/sessions to wipe log data from one or more SIEM indexes. ThreatLab clears the data from each target SIEM and automatically re-fires any noise jobs configured to repopulate the SIEM after a wipe. Method: DELETE
Path: /api/sessions
Auth: Session cookie with manage_exercises capability
This permanently deletes data from your SIEM indexes. Use carefully in production environments — wiped data cannot be recovered through ThreatLab.

Query Parameters

string
required
The SIEM name to wipe, exactly as configured in Admin > Resources. Repeat the parameter to wipe multiple SIEMs simultaneously: ?siem=Splunk&siem=Elastic

Wipe Behavior per Driver

ThreatLab handles each driver type differently during a wipe: SIEMs that are skipped appear in the skipped array of the response rather than the wiped array.

Noise Job Re-fire

After wiping, ThreatLab automatically re-fires any noise jobs that have propagate_on_wipe = true and target one or more of the wiped SIEMs. This repopulates background noise data so the SIEM is not left empty after the wipe. Re-fired job IDs are returned per SIEM in the re_fired array.

Response Fields

boolean
true on success.
array
List of SIEM names that were successfully wiped.
array
List of SIEM names that were skipped (for example, syslog_tcp destinations with no wipe mechanism).
array
Array of objects describing noise jobs re-fired after the wipe.
array
Array of error messages for any noise jobs that failed to re-fire. An empty array means all re-fires succeeded.

Example