This URL retrieves the host analysis summary for given IP address for the time frame.
Resource URL
GET /networkforensics/<ipaddress>?startime=<start_time>&&duration=<duration>&&ntba=<ntba_id>
URL Parameters: ipaddress
Query Parameter1: starttime=
Date in the format yyyy-MM-dd HH:mm
Query Parameter 2: duration=
- NEXT_60_SECONDS
- NEXT_5_MINUTES
- NEXT_60_MINUTES
- NEXT_30_MINUTES
Query Parameter 3: ntba id
Request Parameters
Query Request Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| starttime | Start time for analysis | String | No |
| duration | Duration | String | No |
| Ntba_id | NTBA id | Number | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| NetworkForensicsSummary | Summary of IP address | Object |
Details of fields in NetworkForensicsSummary:
| Field Name | Description | Data Type |
|---|---|---|
| endpointSummary | Endpoint summary | Object |
| ClientConnections | Client connections | Object |
| ServerConnections | Server connections | Object |
Details of fields in endpointSummary:
| Field Name | Description | Data Type |
|---|---|---|
| ipAddress | IP address | String |
| analysisWindow | Analysis window | String |
| zone | Zone | String |
| country | Country | String |
| etf | Etf | String |
| dataSource | Data source | String |
Details of fields in ClientConnections:
| Field Name | Description | Data Type |
|---|---|---|
| connections | Connections | String |
| applications | Applications | String |
| endpointExecutables | Endpoint executables | String |
| tcpServices | Server connections | String |
| tcpHighPorts | TCP high ports | String |
| udpServices | UDP services | String |
| udpHighPorts | UDP high ports | String |
Details of ServerConnections:
| Field Name | Description | Data Type |
|---|---|---|
| connections | Connections | String |
| applications | Applications | String |
| tcpServices | TCP services | String |
| tcpHighPorts | TCP high ports | String |
| udpServices | UDP services | String |
| udpHighPorts | UDP high ports | String |
Example
Request
Response
{
" endpointSummary ":
{
" analysisWindow ": "",
" zone ": "South",
" country ": "India",
" dataSource ": "Allowed",
" ipAddress ": “”
}
" ClientConnections ":
{
" connections ": "10-Aug-2014 12:00",
" applications ": "",
" endpointExecutables ": "BitTorrent.exe"
}
" ServerConnections ":
{
" connections ": "10-Aug-2014 12:00",
" applications ": "",
}
}
Error Information
Following error codes are returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 400 | 4301 | Invalid duration |
| 2 | 400 | 4302 | Invalid time format |
| 3 | 400 | 5000 | Invalid IP address |