This URL retrieves the top attack subcategories.
Resource URL
GET /alerts/TopN/attack_subcategories
Request Parameters
URL Parameters: None
Payload Request Parameters: None
Query Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Indicates the start time for the alerts. The default value is LAST_14_DAYS. Duration can be:
| String | No |
Response Parameters
Following fields are returned.
Field Name | Description | Data Type |
|---|---|---|
| List of top attack subcategories | Array |
Details of fields in TopAttackSubCategoriesList:
Field Name | Description | Data Type |
|---|---|---|
attackSubcategory | Subcategory of the attack | String |
attackCount | Count of the attack | Number |
Example
Request
GET https://<NSM_IP>/sdkapi/alerts/TopN/attack_subcategories?duration=LAST_14_DAYS
Payload
None
Response
{
"TopAttackSubCategoriesList":
[{
"attackSubcategory":"restricted-application","attackCount":214910},
{"attackSubcategory":"protocol-violation","attackCount":151135},
{"attackSubcategory":"dos","attackCount":99870},
{"attackSubcategory":"audit","attackCount":62959},
{"attackSubcategory":"write-exposure","attackCount":40540},
{"attackSubcategory":"pup","attackCount":37059},
{"attackSubcategory":"botnet","attackCount":35194},
{"attackSubcategory":"privileged-access","attackCount":30411},
{"attackSubcategory":"code-execution","attackCount":30263},
{"attackSubcategory":"buffer-overflow","attackCount":24166
}]
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 500 | 1001 | Internal error |
2 | 400 | 3601 | Invalid duration |