This URL gets the events information.
Resource URL
GET /<nbaid>/endpointintelligence/<hash>/events? duration=<duration>
Request Parameters
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Duration
| String | No |
| Hash | String | Yes |
| NTBA monitors id | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| List of events | Array |
Details of eventList:
Field Name | Description | Data Type |
|---|---|---|
| Attack time | String |
| Attack | String |
| Result | String |
| Direction | String |
| Attacker ip address | String |
| Attacker country | String |
| Victim ip address | String |
| Victim port | Int |
| Victim country | String |
Example
Request
GET https://<NSM_IP>/sdkapi/1001/endpointintelligence/aaaaaaaa16/events?duration=LAST_14_DAYS
Response
{
{"eventList":[{"time":"Tue Sep 10 17:16:26 IST 2013","attack":"MALWARE: High-confidence malware executable detected by Endpoint Intelligence Agent engine","result":"Inconclusive","direction":"Unknown","attackerCountry":"---","victimIpAddress":"0.1.138.146","victimPort":0,"victimCountry}]
}
Error Information
Following error codes are returned by this URL:
S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 400 | 3601 | Invalid duration |
2 | 400 | 4901 | Invalid hash/failed retrieve |