This URL gets the events information.
Resource URL
GET /<nbaid>/endpointintelligence/<hash>/events? duration=<duration>
Request Parameters
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| duration | Duration
|
String | No |
| hash | Hash | String | Yes |
| nbaId | NTBA monitors id | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| eventList | List of events | Array |
Details of eventList:
| Field Name | Description | Data Type |
|---|---|---|
| time | Attack time | String |
| attack | Attack | String |
| result | Result | String |
| direction | Direction | String |
| attackerIpAddress | Attacker ip address | String |
| attackerCountry | Attacker country | String |
| victimIpAddress | Victim ip address | String |
| victimPort | Victim port | Int |
| victimCountry | Victim country | String |
Example
Request
GET https://%3CNSM_IP%3E/sdkapi/1001/endpointintelligence/aaaaaaaa16/events?duration=LAST_14_DAYS
Response
{
{"eventList":[{"time":"Tue Sep 10 17:16:26 IST 2013","attack":"MALWARE: High-confidence malware executable detected by Endpoint Intelligence Agent engine","result":"Inconclusive","direction":"Unknown","attackerCountry":"---","victimIpAddress":"0.1.138.146","victimPort":0,"victimCountry}]
}
Error Information
Following error codes are returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 400 | 3601 | Invalid duration |
| 2 | 400 | 4901 | Invalid hash/failed retrieve |