This URL retrieves all alerts.
Resource URL
GET /alerts? domainId=<domain_id>&includeChildDomain=<true/false>&alertstate=<state>&timeperiod=<timeperiod>&startime=<start_time>&endtime=<endBtime>&search=<search_string> &page=<page>&filter=<filterBvalue>
Request Parameters
Query Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Alert state, values allowed are, ANY/Acknowledged/Unacknowledged | String | No |
| Time period, allowed values are
| String | No |
| Start time | String | No |
| End time | String | No |
| Next/Previous | String | No |
| Domain ID. Default value is 0. | Number | Yes |
| Chooses to include child domain or not. Default value is true. | Boolean | Yes |
| Search | String | No |
| Filter on following column is allowed name, assignTo, application, layer7Data, result, attackCount, relevance, alertId, direction, device, domain, interface, attackSeverity, nspId, btp, attackCategory, malwarefileName, malwarefileHash, malwareName, malwareConfidence, malwareEngine ,executableName, executableHash, executableConfidenceName, attackerIPAddress, attackerPort, attackerRisk, attackerProxyIP, attackerHostname, targetIPAddress, targetPort, targetRisk, targetProxyIP, targetHostname, botnetFamily Ex: name:Malware;direction:Inbound,Outbound;attackcount:>3,<4 | String | No |
Response Parameters
Following fields are returned.
Field Name | Description | Data Type |
|---|---|---|
| Total alerts count | Number |
| Retrieved alerts count | Number |
| List of alerts | ObjectList |
Details of alerts:
Field Name | Description | Data Type |
|---|---|---|
| Alert name | String |
| Unique alert id | Number |
| List of alerts | Object |
| Assignment | String |
| Attack severity | String |
| Event details | Object |
| Attack details | Object |
| Attacker details | Object |
| Target details | Object |
| Malware file | Object |
| Endpoint executable | Object |
| Detection | Object |
| Application string | String |
| Layer 7 information | String |
Details of event:
Field Name | Description | Data Type |
|---|---|---|
| Time | String |
| Direction | Number |
| Result | String |
| Attack count | String |
| Relevance | String |
| Alert id | Number |
| NSP id | String |
| Btp | String |
| Attack category | String |
Details of attacker/target:
Field Name | Description | Data Type |
|---|---|---|
| IP address | String |
| Port | String |
| Host name | String |
| Country | String |
| OS | String |
| VM name | String |
| Proxy IP | String |
| User | String |
| Risk | String |
| Network object | String |
Details of malwareFile:
Field Name | Description | Data Type |
|---|---|---|
| File name | String |
| File hash | String |
| Malware name | String |
| Malware confidence | String |
| Engine | String |
| Size | String |
Details of EndpointExecutable:
Field Name | Description | Data Type |
|---|---|---|
| Name | String |
| Hash | String |
| Malware confidence | String |
Example
Request
Response
"totalAlertsCount": 824917,
"retrievedAlertsCount": 1000,
"alertsList":
[
{
"name": "DNS: New Dataloc Test Attack 8-3 (16 bytes)",
"uniqueAlertId": "6245941293374082717",
"alertState": "UnAcknowledged",
"assignTo": "",
"attackSeverity": "Medium",
"event":
{
"time": "Jan 04, 2016 16:24:4",
"direction": "Outbound",
"result": "Inconclusive",
"attackCount": 1,
"relevance": "Unknown",
"alertId": "1383009720294233669"
},
"attack":
{
"nspId": "0x40307a00",
"btp": "Low",
"attackCategory": "Exploit"
},
"attacker":
{
"ipAddrs": "1.1.1.10",
"port": 58719,
"hostName": "",
"country": null,
"os": null,
"vmName": null,
"proxyIP": "",
"user": null,
"risk": "Minimal Risk",
"networkObject": null
},
"target":
{
"ipAddrs": "1.1.1.9",
"port": 53,
"hostName": "",
"country": null,
"os": null,
"vmName": null,
"proxyIP": "",
"user": null,
"risk": "Minimal Risk",
"networkObject": null
},
"malwareFile":
{
"fileName": "",
"fileHash": "",
"malwareName": "",
"malwareConfidence": "",
"engine": "",
"size": null
},
"endpointExcutable":
{
"name": "",
"hash": "",
"malwareConfidence": ""
},
"detection":
{
"domain": "/My Company",
"device": "prabu-6050",
"interface": "5A-5B"
},
"application": "DNS",
"layer7Data": ""
},
{
"name": "DNS: New Dataloc Test Attack 8-3 (16 bytes)",
"uniqueAlertId": "6245941293374082716",
"alertState": "UnAcknowledged",
"assignTo": "",
"attackSeverity": "Medium",
"event":
{
"time": "Jan 04, 2016 16:24:4",
"direction": "Outbound",
"result": "Inconclusive",
"attackCount": 1,
"relevance": "Unknown",
"alertId": "1383009720294233668"
},
"attack":
{
"nspId": "0x40307a00",
"btp": "Low",
"attackCategory": "Exploit"
},
"attacker":
{
"ipAddrs": "1.1.1.10",
"port": 58719,
"hostName": "",
"country": null,
"os": null,
"vmName": null,
"proxyIP": "",
"user": null,
"risk": "Minimal Risk",
"networkObject": null
},
"target":
{
"ipAddrs": "1.1.1.9",
"port": 53,
"hostName": "",
"country": null,
"os": null,
"vmName": null,
"proxyIP": "",
"user": null,
"risk": "Minimal Risk",
"networkObject": null
},
"malwareFile":
{
"fileName": "",
"fileHash": "",
"malwareName": "",
"malwareConfidence": "",
"engine": "",
"size": null
},
"endpointExcutable":
{
"name": "",
"hash": "",
"malwareConfidence": ""
},
"detection":
{
"domain": "/My Company",
"device": "prabu-6050",
"interface": "5A-5B"
},
"application": "DNS",
"layer7Data": ""
}
]
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 3704 | Invalid filter value |
2 | 404 | 9803 | Sensor id is required |
3 | 404 | 9803 | Manager name is required |