Create a reference table in the authenticated organization.
items is a list of rows, each with a non-empty data array of
(field_name, value) entries. Entries are deduplicated within a row; two rows may
carry the same pair.
fields is read-only -- derived from the entries in first-seen order, so row and
entry order set the eventual SQL predicate order. operation and grouping are
accepted but ignored: the service always stores the current defaults, because the
SQL builder that will read them does not exist yet.
Each field_name must be a column of nocsf_unified_events that can be matched by
exact value, and each value must be a possible value for that column's type. Both
are 400s. The restriction is what stops a typo becoming a reference table that saves
cleanly and then breaks every rule using it at query time.
visibility is optional. public is accepted from any organization, but only
shares the table when Nebulock owns it -- on your own table it is recorded and
changes nothing, since cross-organization reads are gated on ownership. private is
a Nebulock-curated state and is a 400 for anyone else.
The items may arrive as a CSV instead. Send the request as multipart/form-data
with a payload field holding this JSON object and a file field holding the CSV;
the format and every rejection are the ones
POST /reference-tables/{id}/csv-upload documents. Sending both items and a file
is a 400 -- they are two spellings of one field. JSON callers are unaffected.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||