This URL retrieves the top suspicious flows for the given IP address.
Resource URL
GET /networkforensics/<ipaddress>/suspiciousflows ?startime=<start_time>&&duration=<duration>&&ntba=<ntba_id>
URL Parameters: ipaddress
Query Parameter1: starttime=
Date in the format yyyy-MM-dd HH:mm
Query Parameter 2: duration=
NEXT_60_SECONDS
NEXT_5_MINUTES
NEXT_60_MINUTES
NEXT_30_MINUTES
Query Parameter 3: ntba id
Request Parameters
Query Request Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Start time for analysis | String | No |
| Duration | String | No |
| NTBA id | Number | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Top conversations | Object |
Details of fields in TopConversations:
Field Name | Description | Data Type |
|---|---|---|
| Time | String |
| Suspicious activity | String |
| Source host | String |
| Source port | Number |
| Source executable name | String |
| Destination endpoint | String |
| Destination port | Number |
| Application names | String |
| Attack name | String |
| Attack result | String |
| File or URL accessed | String |
Example
Request
Response
{
"suspciousFlows":
[
{
" time ": "10-Aug-2014 12:00",
" suspciousActivity ": "",
" sourceEcecutable ": "BitTorrent.exe",
"executableClassification": "Allowed",
"attackName": “”
}
]
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 400 | 4301 | Invalid duration |
2 | 400 | 4302 | Invalid time format |
3 | 400 | 5000 | Invalid IP address |