The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alert details request

Prev Next

Retrieves detailed information for a specific alert. Alerts more than 90 days old are not available.

This API should be called after calling the /alerts/search API that returns a list of alert JSONs. Subsequently, this API should be called with the id value returned in those JSONs, for example, "id": "3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8" in the /alerts response example.

GET https://<etp_instance_addr>/api/v2/public/alerts/<alert_id>

Use the alert ID from the alert search response (this is a part of the API endpoint URL).

Required header

x-fireeye-api-key: <key>—Specifies your personal API key (For FireEye IAM users)

Authorization: Bearer xxxx - Specifies your API access token (For Trellix IAM users)

Options

url_screenshot=true-Retrieves a base64 encoded string of a FAUDE screenshot image. Values accepted are true and false.

Note

To retrieve Base64-encoded screenshot data for an Alert, include the query parameter url_screenshot in your request.

In the API response, the url_screenshot field returns the value ""(an empty string) if the url_screenshot query parameter was not included in the request or if screenshot data is not available for the alert.

Example of an alert request

Values for ID and other fields are for illustration purposes only.

Request for alert details: GET https://<etp_instance_addr>/api/v2/public/alerts/3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8

Request for alert details with screenshot data: GET https://<etp_instance_addr>/api/v2/public/alerts/3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8?url_screenshot=true

Alert details request response

{    
     "id": "3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8",
     "domain": "faas-stage.email.fireeyecloud.com",
     "msg": "extended",
     "traffic_type": "inbound",
     "mta_msg_id": "3yINFWA-1111152-q1b0CD10803434A4EF765d49e4a",
     "parent_uuid": "",
     "verdict": "MALICIOUS",
     "report_id": "e4cbe6e5-adce-43a7-bcd6-c074de68cf22",
     "alert_date": "2025-04-15T12:00:10Z",
     "product": "ETP",
     "sc_version": "1564.164",
     "version": "3.0",
     "accepted_time": "20250415120005",
     "object_uuid": "654e95de-7d13-46f2-9de9-ab2b0e8a45f4",
     "alert":
            {       
                "email-header": 
                            {
                                "to": "faas-stage-email-fireeyecloud-com@stage.bcc.email.fireeyecloud.com",
                                "from": "noreply@fireeye.com",
                                "subject": "ETP Test email SQS Alert Ingestion Tue Apr 15 12:00:00 UTC 2025",
                                "message-id": "<20250415120003.028455@etp-aws-tools-0.etp-aws-tools.etp-dev.svc.cluster.local>"        
                            },        
                "occurred": "2025-04-15T12:00:09.000000",
                "name": "malware-object",
                "uuid": "e4cbe6e5-adce-43a7-bcd6-c074de68cf22",
                "attack-time": "2025-04-15T12:00:09.000000",
                "sc-version": "1564.164",
                "severity": "majr",
                "smtp-message":
                            {
                                "from": "noreply@fireeye.com",
                                "ip_address": "18.210.87.193",
                                "country": "us",
                                "protocol": "url",
                                "queue-id": "3yINFWA-1111152-q1b0CD10803434A4EF765d49e4a",
                                "last-malware": "FETestEvent",
                                "threat_type": "Others",
                                "threat_type_description": "No description available",
                                "to":
                                    [ "faas-stage-email-fireeyecloud-com@stage.bcc.email.fireeyecloud.com" ]
                            },
                "explanation":
                            {
                                "analysis": "binary",
                                "malware-detected":
                                                {
                                                    "malware": [ {                        
                                                                    "stype": "210",
                                                                    "name": "FETestEvent",
                                                                    "md5sum": "271c1bcd28d01c6863fdb5b5c5d94e73",
                                                                    "original": "hxxp://fedeploycheck.fireeye.com/appliance-test/alert.html",
                                                                    "sha256": "abebb5862eea61a3d0a1c75bf5a2e2abcd6c4ee6a6ad086e1d518445594970fc",
                                                                    "profile": "",
                                                                    "downloaded-at": "2025-04-15T12:00:09.000000",
                                                                    "submitted-at": "2025-04-15T12:00:09.000000",
                                                                    "executed-at": "2025-04-15T12:00:09.000000",
                                                                    "application": "",
                                                                    "type": "url",
                                                                    "domain": "fedeploycheck.fireeye.com"
                                                                  }  ] 
                                                }
                            },
                 "src":
                            {
                                "smtp-mail-from": "noreply@fireeye.com",
                                "domain": "fireeye.com",
                                "url": "hxxp://fedeploycheck.fireeye.com/appliance-test/alert.html"
                            },
                 "dst":
                            {
                                "smtp-to": "faas-stage-email-fireeyecloud-com@stage.bcc.email.fireeyecloud.com"
                            }
               },    
     "mitre_mapping": [],
     "custom":
               {
                  "is_yara": false,
                  "is_riskware": false,
                  "is_sc_imp": false,
                  "is_custom_block": false,
                  "is_qr": false,
                  "is_other": true
                },
     "domain_id": 20265,
     "client_id": 7055,
     "is_retro": false,
     "url_screenshot": "iVBORw0KGgoAAAANSUhEUgAABAAAAAMACAIAAAA12IJaAAAAAXNSR0IArs4c6QAAIABJREFUeJ
                        zs3XecXVd57//nWXvv06Y3tVGzJMuWLPcGtgGbYkJxAd+Em4TQEmroplx+AUJIbojpgSTkJiaU
                        VAIJoRoHAjHGRpFciLutZktWHUmj6eecvdd6fn/s0VjYklxie2a0P++XypxdznnOvF4zZ333Xk
                        XNTAAAAAAUg5vuAgAAAAA8fQgAAAAAQIEQAAAAAIACIQAAAAAABUIAAAAAAAqEAAAAAAAUCAEA
                        AAAAKBACAAAAAFAgBAAAAACgQAgAAAAAQIEQAAAAAIACIQAAAAAABUIAAAAAAAqEAAAAAAAUCA
                        EAAAAAKBACAAAAAFAgBAAAAACgQAgAAAAAQIEQAAAAAIACIQAAAAAABUIAAAAAAAqEAA=="
}

cURL code sample: alert details

curl -X GET --location 'https://<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de'--header 'x-fireeye-api-key: xxxxx'

This cURL sample includes the following options:

  • --header 'x-fireeye-api-key: xxxxxxxxxxxxxxx'—This header specifies your personal API key. Use the access token if you are a Trellix IAM user.

  • https:/<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de - The request URL

Results

This example returns details of the specified alert.