This URL retrieves the top attack subcategories.
Resource URL
GET /alerts/TopN/attack_subcategories
Request Parameters
URL Parameters: None
Payload Request Parameters: None
Query Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| duration | Indicates the start time for the alerts. The default value is LAST_14_DAYS. Duration can be:
|
String | No |
Response Parameters
Following fields are returned.
| Field Name | Description | Data Type |
|---|---|---|
| TopAttackSubCategoriesList |
List of top attack subcategories |
Array |
Details of fields in TopAttackSubCategoriesList:
| Field Name | Description | Data Type |
|---|---|---|
| attackSubcategory | Subcategory of the attack | String |
| attackCount | Count of the attack | Number |
Example
Request
GET https://<NSM_IP>/sdkapi/alerts/TopN/attack_subcategories?duration=LAST_14_DAYS
Payload
None
Response
{
"TopAttackSubCategoriesList":
[{
"attackSubcategory":"restricted-application","attackCount":214910},
{"attackSubcategory":"protocol-violation","attackCount":151135},
{"attackSubcategory":"dos","attackCount":99870},
{"attackSubcategory":"audit","attackCount":62959},
{"attackSubcategory":"write-exposure","attackCount":40540},
{"attackSubcategory":"pup","attackCount":37059},
{"attackSubcategory":"botnet","attackCount":35194},
{"attackSubcategory":"privileged-access","attackCount":30411},
{"attackSubcategory":"code-execution","attackCount":30263},
{"attackSubcategory":"buffer-overflow","attackCount":24166
}]
}
Error Information
Following error codes are returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 500 | 1001 | Internal error |
| 2 | 400 | 3601 | Invalid duration |