This URL retrieves the top suspicious flows for the given IP address.
Resource URL
GET /networkforensics/<ipaddress>/suspiciousflows ?startime=<start_time>&&duration=<duration>&&ntba=<ntba_id>
URL Parameters: ipaddress
Query Parameter1: starttime=
Date in the format yyyy-MM-dd HH:mm
Query Parameter 2: duration=
- NEXT_60_SECONDS
- NEXT_5_MINUTES
- NEXT_60_MINUTES
- NEXT_30_MINUTES
Query Parameter 3: ntba id
Request Parameters
Query Request Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| starttime | Start time for analysis | String | No |
| duration | Duration | String | No |
| Ntba_id | NTBA id | Number | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| TopConversations | Top conversations | Object |
Details of fields in TopConversations:
| Field Name | Description | Data Type |
|---|---|---|
| time | Time | String |
| suspciousActivity | Suspicious activity | String |
| sourceEndpoint | Source host | String |
| sourcePort | Source port | Number |
| sourceEcecutable | Source executable name | String |
| destinationEndpoint | Destination endpoint | String |
| destinationPort | Destination port | Number |
| applications | Application names | String |
| attackName | Attack name | String |
| attackResult | Attack result | String |
| fileOrUrlAccessed | File or URL accessed | String |
Example
Request
Response
{
"suspciousFlows":
[
{
" time ": "10-Aug-2014 12:00",
" suspciousActivity ": "",
" sourceEcecutable ": "BitTorrent.exe",
"executableClassification": "Allowed",
"attackName": “”
}
]
}
Error Information
Following error codes are returned by this URL:
| No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 400 | 4301 | Invalid duration |
| 2 | 400 | 4302 | Invalid time format |
| 3 | 400 | 5000 | Invalid IP address |