Takes a list of parameters as a request and searches for an alert.
POST https://<etp_instance_addr>/api/v2/public/alerts/search
Required header
x-fireeye-api-key: <key>—Specifies your personal API key (For FireEye IAM users)
Authorization: Bearer xxxx - Specifies your API access token (For Trellix IAM users)
Content-Type: application/json—Specifies that the server's response body is expected to be in JSON format.
Parameters
Parameter | Description |
|---|---|
ack | True/false filter if alert is acknowledged. Type: Boolean. |
advanced_search | Documentation link for advanced search domain specific language. Type: String. |
alert_id | Value of ID of an alert returned in Alert search result. Type: String. |
custom : riskware_result | Riskware rule ID’s for an alert. Type: String. |
date_range | Filter time range for alerts search. Accepts only RFC3339 formatted timestamp. |
domain | Domain names associated with the alert. Type: String. |
domain_group | Name of domain group which contains the associated domains. Type: String. |
email-header - subject | Text to filter based on subject. Type: String. |
malwarename | Names of malware. Type: String. |
malwarestype | Malware type. Type: String. |
md5 | Md5sum of the malware which is hit. Type: String. |
mta_msg_id | MTA message id assigned to the email of the specific alert. Type: String. |
size | Size of email header ranges between 0-100. |
smtp-message - from | Email sender. Type: String. |
smtp-message - to | Email recipient. Type: String. |
smtp-message - ip_address | IP address of the email’s sender. Type: String. |
smtp-message - threat_type | Value of threat type of email. Type: String. |
sort - order | Order in which the result should be sorted based on time. Type: string. Accepts asc/desc. |
sort - search_before | Used for pagination. Contains text from previous search result to move to previous page. Type: String. |
sort - search_after | Used for pagination. Contains text from previous search result to move to next page. Type: String. |
traffic_type | Traffic type of alerts. Type: string. Accepts “inbound/outbound”. |
verdict | Value verdict. Type: String. |
Example request
curl - X POST --location 'https://<etp_instance_addr>/api/v2/public/alerts/search -d
'{
"ack": boolean,
"advanced_search": "string",
"alert_id": [ "string" ],
"custom":
{
"is_custom_block": boolean,
"is_other": boolean,
"is_qr": boolean,
"is_riskware": boolean,
"is_yara": boolean,
"riskware_result": [ "string" ]
},
"date_range":
{
"from": "string",
"to": "string"
},
"domain": [ "string" ],
"domain_group": [ "string" ]
"email-header":
{
"subject": [ "string" ]
},
"is_read": boolean,
"is_retro": boolean,
"malwarename": [ "string" ],
"malwarestype": [ "string" ],
"md5": [ "string" ],
"mta_msg_id": [ "string" ],
"size": 100,
"smtp-message":
{
"from": [ "string" ],
"ip_address": [ "string" ],
"threat_type": [ "string" ],
"to": [ "string" ]
},
"sort":
{
"order": "string",
"search_after": "string",
"search_before": "string"
},
"traffic_type": "string",
"verdict": [ "string" ]
}'
\--header 'x-fireeye-api-key: xxxxx'Example response
{
"data": [
{
"smtp-message":
{
"from": "rest_out@rest-alerts.etp-testdomain5.com",
"ip_address": "127.0.0.1",
"country": "us",
"protocol": "attachment",
"queue-id": "3z2GDyZ-0-q1gA1120281230CDA186e61ce2b",
"last-malware": "Malware.Binary.pdf",
"threat_type": "PDF Attachment Phish",
"threat_type_description": "The PDF attachment in the email is serving potential phishing content",
"to": [
"usera@etp-testdomain.com"
]
},
"email-header":
{
"to": "usera@etp-testdomain5.com",
"from": "rest_out@rest-alerts.etp-testdomain5.com",
"cc": "",
"subject": "ZYQHI Outbound Alerts Download Test",
"message-id": "<20250507040523.000123@2263a84a90b0>"
},
"malware": [
{
"name": "Malware.Binary.pdf",
"stype": "Dynamic Analysis"
},
{
"name": "Malware.Binary.pdf.FEC2",
"stype": "UNITY"
}
],
"sha256": "6da5d6e5ec6c5150b06b7b703c43ef665b8f523e2878e3b63cbea47e3cd2d8e7",
"domain": "rest-alerts.out.hyg2.etp-testdomain5.com",
"verdict": "malicious",
"mta_msg_id": "3z2GDyZ-0-q1gA11234560CDA186e61ce2b",
"original": "ihcpslvk.pdf",
"report_id": "a1334b22-1818-409e-a394-c234ec28f75d",
"id": "3z2GDyZ-0-41da1234-fa51-1234-8cdd-75f3b6b6be8e-f77a9e76",
"md5": "a147aaa0a1da4eea3155ab1a75f69d55",
"object_uuid": "41da6784-fa51-1234-8cdd-75f3b3n6rt8e",
"traffic_type": "outbound",
"alert_date": "2025-05-07T04:06:57Z",
"accepted_time": "2025-05-07T04:05:23Z",
"email_status": "quarantined",
"custom":
{
"riskware_action": "",
"riskware_result": null,
"is_yara": false,
"is_riskware": false,
"is_sc_imp": false,
"is_custom_block": false,
"is_qr": false,
"is_other": true
},
"client_id": 0,
"domain_id": 0,
"ack": false,
"is_retro": false,
"is_read": false
} ],
"meta":
{
"total": 1,
"size": 1,
"search_before": "WzE3NDY1OTA4MTcwMDAsIjN6MkdEeVotMX12MRThNjc4NC1mYTUxLTQ1MjQtOGNkZC03NWYzYjZiNmJlOGUtZjc3YTllNzYiXQ==",
"search_after": "WzE3NDY1OTA4MTcwMDAsIjN6MkdEeVotMC12MCRTNjc4NC1mERUxLTQ1MjQtOGNkZC03NWYzYjZiNmJlOGUtZjc3YTllNzYiXQ=="
}
}Example request for pagination
curl - X POST --location 'https://<etp_instance_addr>/api/v2/public/alerts/search' --header 'Content-Type: application/json' --header 'Authorization: Bearer xxx'
--data'{
"size":20,
"date_range":
{
"from":"2025-09-02T06:45:01Z",
"to":"2025-09-02T07:45:01Z"
},
"sort":
{
"search_after":"WzE3NTY3OTgyODMwMDAsIjN6MlhkZHItMTEyNTcwOS0wNGJjNGUzOS0zZGI1LTQ3MWItOTYxNi1kYTkzYTAxNmE4MGItOWMwMWMxNTciXQ==",
"order":"desc"
}
}'You can use the sort fields search_before and search_after for pagination. You also need to mention the order to move forward or backward in the search. Order 'desc' is the default value used when the sort parameter is not passed.
To go to the next page add search_after along with order. To go to the previous page add search_before along with order.