Retrieves detailed information for a specific alert. Alerts more than 90 days old are not available.
This API should be called after calling the /alerts/search API that returns a list of alert JSONs. Subsequently, this API should be called with the id value returned in those JSONs, for example, "id": "3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8" in the /alerts response example.
GET https://<etp_instance_addr>/api/v2/public/alerts/<alert_id>
Use the alert ID from the alert search response (this is a part of the API endpoint URL).
Required header
x-fireeye-api-key: <key>—Specifies your personal API key (For FireEye IAM users)
Authorization: Bearer xxxx - Specifies your API access token (For Trellix IAM users)
Options
url_screenshot=true-Retrieves a base64 encoded string of a FAUDE screenshot image. Values accepted are true and false.
Note
To retrieve Base64-encoded screenshot data for an Alert, include the query parameter url_screenshot in your request.
In the API response, the
url_screenshotfield returns the value""(an empty string) if the url_screenshot query parameter was not included in the request or if screenshot data is not available for the alert.
Example of an alert request
Values for ID and other fields are for illustration purposes only.
Request for alert details: GET https://<etp_instance_addr>/api/v2/public/alerts/3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8
Request for alert details with screenshot data: GET https://<etp_instance_addr>/api/v2/public/alerts/3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8?url_screenshot=true
Alert details request response
{
"id": "3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8",
"domain": "faas-stage.email.fireeyecloud.com",
"msg": "extended",
"traffic_type": "inbound",
"mta_msg_id": "3yINFWA-1111152-q1b0CD10803434A4EF765d49e4a",
"parent_uuid": "",
"verdict": "MALICIOUS",
"report_id": "e4cbe6e5-adce-43a7-bcd6-c074de68cf22",
"alert_date": "2025-04-15T12:00:10Z",
"product": "ETP",
"sc_version": "1564.164",
"version": "3.0",
"accepted_time": "20250415120005",
"object_uuid": "654e95de-7d13-46f2-9de9-ab2b0e8a45f4",
"alert":
{
"email-header":
{
"to": "faas-stage-email-fireeyecloud-com@stage.bcc.email.fireeyecloud.com",
"from": "noreply@fireeye.com",
"subject": "ETP Test email SQS Alert Ingestion Tue Apr 15 12:00:00 UTC 2025",
"message-id": "<20250415120003.028455@etp-aws-tools-0.etp-aws-tools.etp-dev.svc.cluster.local>"
},
"occurred": "2025-04-15T12:00:09.000000",
"name": "malware-object",
"uuid": "e4cbe6e5-adce-43a7-bcd6-c074de68cf22",
"attack-time": "2025-04-15T12:00:09.000000",
"sc-version": "1564.164",
"severity": "majr",
"smtp-message":
{
"from": "noreply@fireeye.com",
"ip_address": "18.210.87.193",
"country": "us",
"protocol": "url",
"queue-id": "3yINFWA-1111152-q1b0CD10803434A4EF765d49e4a",
"last-malware": "FETestEvent",
"threat_type": "Others",
"threat_type_description": "No description available",
"to":
[ "faas-stage-email-fireeyecloud-com@stage.bcc.email.fireeyecloud.com" ]
},
"explanation":
{
"analysis": "binary",
"malware-detected":
{
"malware": [ {
"stype": "210",
"name": "FETestEvent",
"md5sum": "271c1bcd28d01c6863fdb5b5c5d94e73",
"original": "hxxp://fedeploycheck.fireeye.com/appliance-test/alert.html",
"sha256": "abebb5862eea61a3d0a1c75bf5a2e2abcd6c4ee6a6ad086e1d518445594970fc",
"profile": "",
"downloaded-at": "2025-04-15T12:00:09.000000",
"submitted-at": "2025-04-15T12:00:09.000000",
"executed-at": "2025-04-15T12:00:09.000000",
"application": "",
"type": "url",
"domain": "fedeploycheck.fireeye.com"
} ]
}
},
"src":
{
"smtp-mail-from": "noreply@fireeye.com",
"domain": "fireeye.com",
"url": "hxxp://fedeploycheck.fireeye.com/appliance-test/alert.html"
},
"dst":
{
"smtp-to": "faas-stage-email-fireeyecloud-com@stage.bcc.email.fireeyecloud.com"
}
},
"mitre_mapping": [],
"custom":
{
"is_yara": false,
"is_riskware": false,
"is_sc_imp": false,
"is_custom_block": false,
"is_qr": false,
"is_other": true
},
"domain_id": 20265,
"client_id": 7055,
"is_retro": false,
"url_screenshot": "iVBORw0KGgoAAAANSUhEUgAABAAAAAMACAIAAAA12IJaAAAAAXNSR0IArs4c6QAAIABJREFUeJ
zs3XecXVd57//nWXvv06Y3tVGzJMuWLPcGtgGbYkJxAd+Em4TQEmroplx+AUJIbojpgSTkJiaU
VAIJoRoHAjHGRpFciLutZktWHUmj6eecvdd6fn/s0VjYklxie2a0P++XypxdznnOvF4zZ333Xk
XNTAAAAAAUg5vuAgAAAAA8fQgAAAAAQIEQAAAAAIACIQAAAAAABUIAAAAAAAqEAAAAAAAUCAEA
AAAAKBACAAAAAFAgBAAAAACgQAgAAAAAQIEQAAAAAIACIQAAAAAABUIAAAAAAAqEAAAAAAAUCA
EAAAAAKBACAAAAAFAgBAAAAACgQAgAAAAAQIEQAAAAAIACIQAAAAAABUIAAAAAAAqEAA=="
}cURL code sample: alert details
curl -X GET --location 'https://<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de'--header 'x-fireeye-api-key: xxxxx'
This cURL sample includes the following options:
--header 'x-fireeye-api-key: xxxxxxxxxxxxxxx'—This header specifies your personal API key. Use the access token if you are a Trellix IAM user.https:/<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de- The request URL
Results
This example returns details of the specified alert.