The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Alert search request

Prev Next

Takes a list of parameters as a request and searches for an alert.

POST https://<etp_instance_addr>/api/v2/public/alerts/search

Required header

x-fireeye-api-key: <key>—Specifies your personal API key (For FireEye IAM users)

Authorization: Bearer xxxx - Specifies your API access token (For Trellix IAM users)

Content-Type: application/json—Specifies that the server's response body is expected to be in JSON format.

Parameters

Parameter

Description

ack

True/false filter if alert is acknowledged. Type: Boolean.

advanced_search

Documentation link for advanced search domain specific language. Type: String.

alert_id

Value of ID of an alert returned in Alert search result. Type: String.

custom : riskware_result

Riskware rule ID’s for an alert. Type: String.

date_range

Filter time range for alerts search. Accepts only RFC3339 formatted timestamp.

domain

Domain names associated with the alert. Type: String.

domain_group

Name of domain group which contains the associated domains. Type: String.

email-header - subject

Text to filter based on subject. Type: String.

malwarename

Names of malware. Type: String.

malwarestype

Malware type. Type: String.

md5

Md5sum of the malware which is hit. Type: String.

mta_msg_id

MTA message id assigned to the email of the specific alert. Type: String.

size

Size of email header ranges between 0-100.

smtp-message - from

Email sender. Type: String.

smtp-message - to

Email recipient. Type: String.

smtp-message - ip_address

IP address of the email’s sender. Type: String.

smtp-message - threat_type

Value of threat type of email. Type: String.

sort - order

Order in which the result should be sorted based on time. Type: string. Accepts asc/desc.

sort - search_before

Used for pagination. Contains text from previous search result to move to previous page. Type: String.

sort - search_after

Used for pagination. Contains text from previous search result to move to next page. Type: String.

traffic_type

Traffic type of alerts. Type: string. Accepts “inbound/outbound”.

verdict

Value verdict. Type: String.

Example request

curl - X POST --location 'https://<etp_instance_addr>/api/v2/public/alerts/search -d
'{ 
    "ack": boolean,
    "advanced_search": "string",
    "alert_id": [ "string" ],
    "custom": 
            {
                "is_custom_block": boolean,
                "is_other": boolean,
                "is_qr": boolean,
                "is_riskware": boolean,
                "is_yara": boolean,
                "riskware_result": [ "string" ]
            },
    "date_range": 
            {
                "from": "string",
                "to": "string"
            },
    "domain": [ "string" ],
    "domain_group": [ "string" ]
    "email-header": 
                {    
                "subject": [ "string" ]
                },
    "is_read": boolean,
    "is_retro": boolean,
    "malwarename": [ "string" ],  
    "malwarestype": [ "string" ],
    "md5": [ "string" ],
    "mta_msg_id": [ "string" ],
    "size": 100,
    "smtp-message":
                {
                    "from": [ "string" ],
                    "ip_address": [ "string" ],
                    "threat_type": [ "string"  ],
                    "to": [ "string" ]
                },
    "sort":
          {
               "order": "string",
               "search_after": "string",
               "search_before": "string"
          },
    "traffic_type": "string",
    "verdict": [ "string" ]
}'
 
\--header 'x-fireeye-api-key: xxxxx'

Example response

{    
    "data": [        
         {            
            "smtp-message": 
                        {                
                            "from": "rest_out@rest-alerts.etp-testdomain5.com",                
                            "ip_address": "127.0.0.1",                
                            "country": "us",                
                            "protocol": "attachment",                
                            "queue-id": "3z2GDyZ-0-q1gA1120281230CDA186e61ce2b",                
                            "last-malware": "Malware.Binary.pdf",                
                            "threat_type": "PDF Attachment Phish",                
                            "threat_type_description": "The PDF attachment in the email is serving potential phishing content",                
                            "to": [                    
                                    "usera@etp-testdomain.com"                
                                    ]            
                        },            
            "email-header": 
                        {                
                            "to": "usera@etp-testdomain5.com",                
                            "from": "rest_out@rest-alerts.etp-testdomain5.com",                
                            "cc": "",                
                            "subject": "ZYQHI Outbound Alerts Download Test",                
                            "message-id": "<20250507040523.000123@2263a84a90b0>"            
                        },            
            "malware": [                
                        {                    
                            "name": "Malware.Binary.pdf",                    
                            "stype": "Dynamic Analysis"                
                        },                
                        {                    
                            "name": "Malware.Binary.pdf.FEC2",                    
                            "stype": "UNITY"                
                        }            
                        ],            
            "sha256": "6da5d6e5ec6c5150b06b7b703c43ef665b8f523e2878e3b63cbea47e3cd2d8e7",            
            "domain": "rest-alerts.out.hyg2.etp-testdomain5.com",            
            "verdict": "malicious",            
            "mta_msg_id": "3z2GDyZ-0-q1gA11234560CDA186e61ce2b",            
            "original": "ihcpslvk.pdf",            
            "report_id": "a1334b22-1818-409e-a394-c234ec28f75d",            
            "id": "3z2GDyZ-0-41da1234-fa51-1234-8cdd-75f3b6b6be8e-f77a9e76",            
            "md5": "a147aaa0a1da4eea3155ab1a75f69d55",            
            "object_uuid": "41da6784-fa51-1234-8cdd-75f3b3n6rt8e",            
            "traffic_type": "outbound",            
            "alert_date": "2025-05-07T04:06:57Z",            
            "accepted_time": "2025-05-07T04:05:23Z",            
            "email_status": "quarantined",            
            "custom": 
                    {                
                        "riskware_action": "",                
                        "riskware_result": null,                
                        "is_yara": false,                
                        "is_riskware": false,                
                        "is_sc_imp": false,                
                        "is_custom_block": false,                
                        "is_qr": false,                
                        "is_other": true            
                    },            
            "client_id": 0,            
            "domain_id": 0,            
            "ack": false,            
            "is_retro": false,            
            "is_read": false        
        }    ],    
    "meta": 
        {        
            "total": 1,        
            "size": 1,        
            "search_before": "WzE3NDY1OTA4MTcwMDAsIjN6MkdEeVotMX12MRThNjc4NC1mYTUxLTQ1MjQtOGNkZC03NWYzYjZiNmJlOGUtZjc3YTllNzYiXQ==",        
            "search_after": "WzE3NDY1OTA4MTcwMDAsIjN6MkdEeVotMC12MCRTNjc4NC1mERUxLTQ1MjQtOGNkZC03NWYzYjZiNmJlOGUtZjc3YTllNzYiXQ=="    
        }
}

Example request for pagination

curl - X POST --location 'https://<etp_instance_addr>/api/v2/public/alerts/search' --header 'Content-Type: application/json' --header 'Authorization: Bearer xxx' 
    --data'{    
                "size":20,
                "date_range":
                        {         
                            "from":"2025-09-02T06:45:01Z",         
                            "to":"2025-09-02T07:45:01Z"     
                        },    
                "sort":
                        {         
                            "search_after":"WzE3NTY3OTgyODMwMDAsIjN6MlhkZHItMTEyNTcwOS0wNGJjNGUzOS0zZGI1LTQ3MWItOTYxNi1kYTkzYTAxNmE4MGItOWMwMWMxNTciXQ==",         
                            "order":"desc"     
                        }
            }'

You can use the sort fields search_before and search_after for pagination. You also need to mention the order to move forward or backward in the search. Order 'desc' is the default value used when the sort parameter is not passed.

To go to the next page add search_after along with order. To go to the previous page add search_before along with order.