The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Download alert case Files as ZIP request

Prev Next

Downloads all case files of the alert specified by alert ID, in a zip file.

GET https://<etp_instance_addr>/api/v2/public/alerts/<alert_id>/casefile

Use the alert ID from the alert search response (this is a part of the API endpoint URL).

Required header

x-fireeye-api-key: <key>—Specifies your personal API key. (For FireEye IAM users)

Authorization: Bearer xxxx - Specifies your API access token (For Trellix IAM users)

Example of an alert request

GET https://<etp_instance_addr>/api/v2/public/alerts/3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8/casefile

Download alert case files as ZIP response

The downloaded zip is password protected, and the password is "infected".

Zip File (Binary)
<num>-casefile.zip

cURL code sample: download alert case files as ZIP

curl - X GET --location '<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de/casefile' -o file.zip --header 'x-fireeye-api-key: xxxxx'

This cURL sample includes the following options:

  • --header 'x-fireeye-api-key: xxxxxxxxxxxxxxx'—This header specifies your personal API key. Use the access token if you are a Trellix IAM user.

  • https://<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de/casefile - The request URL

Results

This example downloads all case files of the specified alert in a zip file.