---
title: Creates bulk events
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Cloudforce One](https://developers.cloudflare.com/api/go/resources/cloudforce_one)

[Threat Events](https://developers.cloudflare.com/api/go/resources/cloudforce_one/subresources/threat_events)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Creates bulk events

client.CloudforceOne.ThreatEvents.BulkNew(ctx, params) (\*[ThreatEventBulkNewResponse](<https://developers.cloudflare.com/api/go/resources/cloudforce_one#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/cloudforce-one/events/create/bulk

The `datasetId` parameter must be defined. To list existing datasets (and their IDs) in your account, use the [`List Datasets`](https://developers.cloudflare.com/api/resources/cloudforce_one/subresources/threat_events/subresources/datasets/methods/list/) endpoint.

##### Security

API Token

The preferred authorization scheme for interacting with the Cloudflare API. [Create a token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/).

**Example:**`Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY`

##### Accepted Permissions (at least one required)

`Cloudforce One Write``Cloudforce One Read`

##### ParametersExpand Collapse

<details>

<summary>

params ThreatEventBulkNewParams

</summary>

AccountID param.Field\[string]

Path param: Account ID.

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20account_id">Link to this property</a>

<details>

<summary>

Data param.Field\[\[]ThreatEventBulkNewParamsData]

Body param

</summary>

Category string

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20category">Link to this property</a>

Date Time

formatdate-time

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20date">Link to this property</a>

Event string

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20event">Link to this property</a>

<details>

<summary>

Raw ThreatEventBulkNewParamsDataRaw

</summary>

Data map\[string, unknown]

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20raw%20%3E%20(property)%20data">Link to this property</a>

Source stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20raw%20%3E%20(property)%20source">Link to this property</a>

TLP stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20raw%20%3E%20(property)%20tlp">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20raw">Link to this property</a>

TLP string

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20tlp">Link to this property</a>

AccountID float64Optional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20accountId">Link to this property</a>

Attacker stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attacker">Link to this property</a>

AttackerCountry stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20attackerCountry">Link to this property</a>

DatasetID stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20datasetId">Link to this property</a>

Indicator stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicator">Link to this property</a>

<details>

<summary>

Indicators \[]ThreatEventBulkNewParamsDataIndicatorOptional

Array of indicators for this event. Supports multiple indicators per event for complex scenarios.

</summary>

IndicatorType string

The type of indicator (e.g., DOMAIN, IP, JA3, HASH)

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

Value string

The indicator value (e.g., domain name, IP address, hash)

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicators%20%3E%20(items)%20%3E%20(property)%20value">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicators">Link to this property</a>

IndicatorType stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20indicatorType">Link to this property</a>

Insight stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20insight">Link to this property</a>

Tags \[]stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20tags">Link to this property</a>

TargetCountry stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetCountry">Link to this property</a>

TargetIndustry stringOptional

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data%20%3E%20(schema)%20%3E%20(items)%20%3E%20(property)%20targetIndustry">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20data">Link to this property</a>

DatasetID param.Field\[string]

Body param

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20datasetId">Link to this property</a>

IncludeCreatedEvents param.Field\[bool]Optional

Body param: When true, response includes array of created event UUIDs and shard IDs. Useful for tracking which events were created and where.

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default%20%3E%20(param)%20includeCreatedEvents">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(method)%20bulk_create%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type ThreatEventBulkNewResponse struct{…}

Detailed result of bulk event creation with auto-tag management

</summary>

CreatedEventsCount float64

Number of events created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20createdEventsCount">Link to this property</a>

CreatedTagsCount float64

Number of new tags created in SoT

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20createdTagsCount">Link to this property</a>

ErrorCount float64

Number of errors encountered

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20errorCount">Link to this property</a>

QueuedIndicatorsCount float64

Number of indicators queued for async processing

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20queuedIndicatorsCount">Link to this property</a>

CreateBulkEventsRequestID stringOptional

Correlation ID for async indicator processing

formatuuid

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20createBulkEventsRequestId">Link to this property</a>

<details>

<summary>

CreatedEvents \[]ThreatEventBulkNewResponseCreatedEventOptional

Array of created events with UUIDs and shard locations. Only present when includeCreatedEvents=true

</summary>

EventIndex float64

Original index in the input data array

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20createdEvents%20%3E%20(items)%20%3E%20(property)%20eventIndex">Link to this property</a>

ShardID string

Dataset ID of the shard where the event was created

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20createdEvents%20%3E%20(items)%20%3E%20(property)%20shardId">Link to this property</a>

UUID string

UUID of the created event

formatuuid

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20createdEvents%20%3E%20(items)%20%3E%20(property)%20uuid">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20createdEvents">Link to this property</a>

<details>

<summary>

Errors \[]ThreatEventBulkNewResponseErrorOptional

Array of error details

</summary>

Error string

Error message

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20error">Link to this property</a>

EventIndex float64

Index of the event that caused the error

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20errors%20%3E%20(items)%20%3E%20(property)%20eventIndex">Link to this property</a>

</details>

<a href="#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)%20%3E%20(property)%20errors">Link to this property</a>

</details>

[Link to this property](<#(resource)%20cloudforce_one.threat_events%20%3E%20(model)%20ThreatEventBulkNewResponse%20%3E%20(schema)>)

### Creates bulk events

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"
  "time"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/cloudforce_one"
  "github.com/cloudflare/cloudflare-go/option"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  response, err := client.CloudforceOne.ThreatEvents.BulkNew(context.TODO(), cloudforce_one.ThreatEventBulkNewParams{
    AccountID: cloudflare.F("account_id"),
    Data: cloudflare.F([]cloudforce_one.ThreatEventBulkNewParamsData{cloudforce_one.ThreatEventBulkNewParamsData{
      Category: cloudflare.F("Domain Resolution"),
      Date: cloudflare.F(time.Now()),
      Event: cloudflare.F("An attacker registered the domain domain.com"),
      Raw: cloudflare.F(cloudforce_one.ThreatEventBulkNewParamsDataRaw{
        Data: cloudflare.F(map[string]interface{}{
        "foo": "bar",
        }),
      }),
      TLP: cloudflare.F("amber"),
    }}),
    DatasetID: cloudflare.F("durableObjectName"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", response.CreatedEventsCount)
}
```

200 example

```
{
  "createdEventsCount": 0,
  "createdTagsCount": 0,
  "errorCount": 0,
  "queuedIndicatorsCount": 0,
  "createBulkEventsRequestId": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
  "createdEvents": [
    {
      "eventIndex": 0,
      "shardId": "shardId",
      "uuid": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e"
    }
  ],
  "errors": [
    {
      "error": "error",
      "eventIndex": 0
    }
  ]
}
```

##### Returns Examples

200 example

```
{
  "createdEventsCount": 0,
  "createdTagsCount": 0,
  "errorCount": 0,
  "queuedIndicatorsCount": 0,
  "createBulkEventsRequestId": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
  "createdEvents": [
    {
      "eventIndex": 0,
      "shardId": "shardId",
      "uuid": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e"
    }
  ],
  "errors": [
    {
      "error": "error",
      "eventIndex": 0
    }
  ]
}
```