Skip to content

Developer portal

SIEM webhook v2

Field dictionary and signing headers for scan.complete notifications.

Sample payload

Download a signed example: webhook-v2-scan-complete.json. Configure signing in Monitor alert settings (webhookSigningSecret).

Field dictionary

FieldTypeNotes
schemaVersionstringAlways qtangl-webhook-v2
eventstringscan.complete
tenantIdstringTenant identifier
scanIdstringCompleted scan job ID
targetDomainstringScanned target
readinessScorenumber0–100 composite score
readinessBandstringHuman band label
verifyUrlstringPublic verify link for report signature
evidenceZipUrlstringDashboard or bundle export link
scanDiffobjectDelta vs previous scan when available
alertsarrayTriggered alert rules (readiness drop, new Q-vuln, cert expiry)
topFindingsarrayTop degraded or new quantum-vulnerable assets
messagestringPrimary human-readable summary

Splunk HEC (example)

curl -X POST "$SPLUNK_HEC_URL/services/collector" \
  -H "Authorization: Splunk $SPLUNK_TOKEN" \
  -d '{"event": <paste qtangl webhook JSON>, "sourcetype": "qtangl:scan"}'

See also Monitor setup and Trust center.