Signal Injection
Accepts XML, JSON, query-string, key/value or plain-text payloads and injects the parsed result into the SBN Immediate Queue so it is processed as an alarm. The parse route returns the same parsed structure without injecting, for testing. Use SBN program 1685 for XML, JSON and query-string translations, and program 1876 for plain text.
Setup
- No signal-injection settings are required.
- The default receiver source ID is
88883; override it per request with the{sousid}route segment. - SMART SBN: when
UseSmartSBNis on in the APIEngine settings and the local insert succeeds, APIEngine repeats the insert on every non-Primary datasource. Other Primary servers are skipped so Active/Active sites do not get duplicate signals. - A file attached to a multipart request is saved to the APIEngine file store, and its saved file name is added to the parsed JSON as
apiengine_filename. If the file cannot be saved, the error is logged and the signal is still injected.
Auth
The signal-injection routes take no APIEngine user token, and they are not listed in the API catalog. Restrict access to them at the network level (firewall, IIS IP and domain restrictions, or a reverse-proxy ACL).
Endpoints
Every inject and parse route accepts GET, POST and PUT. The payload is read from the multipart body field, then the raw request body, then the query string.
Parse (preview only, does not inject)
| Verb | Route | Versions |
|---|---|---|
| GET/POST/PUT | /api/v1/signal/parse | All |
| GET/POST/PUT | /v1/signal/parse | All |
| GET/POST/PUT | /api/v1/signalinjection/parse | v96 and later |
Inject (writes to the Immediate Queue)
| Verb | Route | Versions |
|---|---|---|
| GET/POST/PUT | /api/v1/signal/inject/{receiver} | All |
| GET/POST/PUT | /api/v1/signal/inject/{receiver?}/{form?}/{id?} | All |
| GET/POST/PUT | /api/v1/signal/inject/{sousid}/{receiver?} | All |
| GET/POST/PUT | /v1/signal/inject/{receiver?}/{form?}/{id?} | All |
| GET/POST/PUT | /api/v1/signalinjection/inject/{receiver} | v96 and later |
| GET/POST/PUT | /api/v1/signalinjection/inject/{receiver?}/{form?}/{id?} | v96 and later |
| GET/POST/PUT | /api/v1/signalinjection/inject/{sousid}/{receiver?} | v96 and later |
Route parameters:
receiver: alarm-translation receiver ID. If omitted, APIEngine uses the caller's IP address (see Operational notes).sousid: receiver source ID written to the Immediate Queue row; default88883.form,id: alarm-translation form and ID.
The response is the parsed structure, including Rows (one entry per queued row), Rows_Stamps, TranslationPrefix and Error.
Translations
Translation records are maintained in SBN. APIEngine writes a translation prefix followed by the receiver ID into each queued row:
| Payload | Prefix written |
|---|---|
| JSON, XML or a query string | ##ZZ |
| Anything else (plain text) | ##RW |
The receiver must match an SBN translation set up for the same prefix.
Operational notes
- IP-based receiver matching: when
receiveris empty, APIEngine uses the left-mostX-Forwarded-Foraddress, otherwise the connection's remote address.::1becomes127.0.0.1, and IPv4 octets are zero-padded to three digits (for example192.168.1.10becomes192.168.001.010) to match the padded form used in SBN translations. If a reverse proxy fronts APIEngine, make sure it setsX-Forwarded-For, or every receiver resolves to the proxy's address. - Per-row stamps:
Rows_Stampshas one entry per datasource and row. A stamp above-1means the row was accepted;-1means the insert failed. With SMART SBN there is one stamp from the local server plus one from each non-Primary datasource. - Long input: payload rows longer than 128 characters are injected in full.
Direct-Inject Receiver Width
Direct-inject alarms accept the full 12-character receiver.
SQL Injection Hardening
Immediate Queue inserts pass the payload as procedure parameters.