Fetch IP Address risk list demo events

Get simulated Juniper NetScreen syslogs with risky IPs for testing SIEM integrations, refreshed every four hours.

What this endpoint does

This endpoint generates simulated Juniper NetScreen firewall syslog events containing destination IP addresses drawn from the Recorded Future IP risk list, designed for testing and demonstrating SIEM or firewall log integrations without requiring live network data. Each call returns a refreshed set of synthetic firewall traffic log entries (updated every four hours) that mimic permitted outbound connections to risky IP addresses, making it useful for validating detection pipelines, building demos, or developing log-parsing workflows. Similar demo event endpoints exist for domains, hashes, URLs, and vulnerabilities, each using a different log format appropriate to that entity type.

Response data

The response is plain text (not JSON), with one syslog entry per line in Juniper NetScreen firewall format. Each entry contains a timestamp, device identifier, traffic notification type, start time, duration, policy ID, service type, protocol number, source and destination zones, firewall action, bytes sent and received, a destination IP address (the risky indicator from the IP risk list), and a simulated internal source IP address. Use the IP Risk List endpoint to download the full set of scored IP indicators that these demo events reference.

Query Params
int32
≤ 1000

Maximum number of records returned,

Response

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
text/plain