Get Alerts by Id
GET/v1/alerts
List and filter Detection and Response (DDR) alerts to triage and prioritize real-time data security threats. This call returns a list of alerts with the necessary data to triage and assign for investigation
Request
Query Parameters
Possible values: [AWS
, AZURE
, GCP
, SNOWFLAKE
, FILE_SHARE
, O365
]
Possible values: [AWS
, AZURE
, GCP
, SNOWFLAKE
, FILE_SHARE
, O365
]
Possible values: [UNKNOWN
, DEVELOPMENT
, STAGING
, TESTING
, PRODUCTION
]
Possible values: [UNKNOWN
, DEVELOPMENT
, STAGING
, TESTING
, PRODUCTION
]
Possible values: [HIGH
, MEDIUM
, LOW
]
Possible values: [HIGH
, MEDIUM
, LOW
]
Possible values: [FIRST_MOVE
, ATTACK
, COMPLIANCE
, ASSET_AT_RISK
, RECONNAISSANCE
]
Possible values: [FIRST_MOVE
, ATTACK
, COMPLIANCE
, ASSET_AT_RISK
, RECONNAISSANCE
]
Possible values: [OPEN
, UNIMPORTANT
, WRONG
, HANDLED
, INVESTIGATING
]
Possible values: [OPEN
, UNIMPORTANT
, WRONG
, HANDLED
, INVESTIGATING
]
Sorting criteria in the format: property,(asc|desc). Default sort order is ascending. Multiple sort criteria are supported.
Default value: 0
Possible values: <= 50
Default value: 20
Header Parameters
Dig token header
Responses
- 200
Returns a list of alerts
Response Headers
X-Total-Count integer
The total number of items in the page
- application/json
- Schema
- Example (from schema)
Schema
- Array [
- Array [
- ]
- ]
assetLabels object[]
label object
Possible values: [SYSTEM
, USER
]
Possible values: [AWS
, AZURE
, GCP
, SNOWFLAKE
, FILE_SHARE
, O365
]
destinationProjects object
Possible values: [UNKNOWN
, DEVELOPMENT
, STAGING
, TESTING
, PRODUCTION
]
Possible values: [HIGH
, MEDIUM
, LOW
]
Possible values: [FIRST_MOVE
, ATTACK
, COMPLIANCE
, ASSET_AT_RISK
, RECONNAISSANCE
]
Possible values: [OPEN
, UNIMPORTANT
, WRONG
, HANDLED
, INVESTIGATING
]
Possible values: [CONSOLE
, SDK
, CLI
, SYSTEM
]
[
{
"id": "string",
"detectionTime": "2024-07-29T15:51:28.071Z",
"policyName": "string",
"assetName": "string",
"assetLabels": [
{
"label": {
"id": 0,
"name": "string",
"description": "string",
"color": "string",
"prettyName": "string"
},
"connectedBy": "SYSTEM"
}
],
"cloudProvider": "AWS",
"destinationProjects": {},
"cloudEnvironment": "UNKNOWN",
"policySeverity": "HIGH",
"policyCategoryType": "FIRST_MOVE",
"status": "OPEN",
"eventActor": "string",
"eventUserAgent": "string",
"eventActionMedium": "CONSOLE",
"eventSource": "string",
"policyFrameWorks": [
"string"
],
"eventRawData": "string"
}
]