This URL retrieves the host analysis summary for given IP address for the time frame.
Resource URL
GET /networkforensics/<ipaddress>?startime=<start_time>&&duration=<duration>&&ntba=<ntba_id>
URL Parameters: ipaddress
Query Parameter1: starttime=
Date in the format yyyy-MM-dd HH:mm
Query Parameter 2: duration=
NEXT_60_SECONDS
NEXT_5_MINUTES
NEXT_60_MINUTES
NEXT_30_MINUTES
Query Parameter 3: ntba id
Request Parameters
Query Request Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Start time for analysis | String | No |
| Duration | String | No |
| NTBA id | Number | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
NetworkForensicsSummary | Summary of IP address | Object |
Details of fields in NetworkForensicsSummary:
Field Name | Description | Data Type |
|---|---|---|
| Endpoint summary | Object |
| Client connections | Object |
| Server connections | Object |
Details of fields in endpointSummary:
Field Name | Description | Data Type |
|---|---|---|
ipAddress | IP address | String |
analysisWindow | Analysis window | String |
zone | Zone | String |
country | Country | String |
etf | Etf | String |
dataSource | Data source | String |
Details of fields in ClientConnections:
Field Name | Description | Data Type |
|---|---|---|
| Connections | String |
| Applications | String |
| Endpoint executables | String |
| Server connections | String |
| TCP high ports | String |
| UDP services | String |
| UDP high ports | String |
Details of ServerConnections:
Field Name | Description | Data Type |
|---|---|---|
| Connections | String |
| Applications | String |
| TCP services | String |
| TCP high ports | String |
| UDP services | String |
| UDP high ports | String |
Example
Request
Response
{
" endpointSummary ":
{
" analysisWindow ": "",
" zone ": "South",
" country ": "India",
" dataSource ": "Allowed",
" ipAddress ": “”
}
" ClientConnections ":
{
" connections ": "10-Aug-2014 12:00",
" applications ": "",
" endpointExecutables ": "BitTorrent.exe"
}
" ServerConnections ":
{
" connections ": "10-Aug-2014 12:00",
" applications ": "",
}
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 400 | 4301 | Invalid duration |
2 | 400 | 4302 | Invalid time format |
3 | 400 | 5000 | Invalid IP address |