Get a list of alerts. - Response is concatenated using AND condition (OR is not supported). - Maximum result set size is 100. - Offset is the zero-based number of alerts from the start of the result set. Cortex XDR displays in the APIs response whether an PAN NGFW type alert contains a PCAP triggering packet. Use the Retrieve PCAP Packet API to retrieve a list of alert IDs and their associated PCAP data.
Note: You can send a request to retrieve either all or filtered results.
Required license: Cortex XDR Prevent, Cortex XDR Pro per Endpoint, or Cortex XDR Pro per GB
curl -X POST \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
"https://api-yourfqdn/public_api/v1/alerts/get_alerts/" \
-d '{
"request_data" : {
"search_from" : 0,
"filters" : [ {
"field" : "alert_id_list",
"value" : [ "", "" ],
"operator" : "in"
}, {
"field" : "alert_id_list",
"value" : [ "", "" ],
"operator" : "in"
} ],
"sort" : {
"field" : "field",
"keyword" : "keyword"
},
"search_to" : 6
}
}'
{"request_data":{}}
Identifies the alert field the filter is matching. Filters are based on the following keywords:
alert_id_list
: List of integers representing the Alert IDs.alert_source
: List of strings representing the Alert sources.severity
: List of strings representing the Alert severities.creation_time
: Timestamp of the alert creation time.
Identifies the comparison operator you want to use for this filter. Valid keywords are:
in
:
alert_id_list
,alert_source
, andseverity
gte
/lte
creation_time
.
Value that this filter must match. The contents of this field will differ depending on the alert field that you specified for this filter:
creation_time
: Integer representing the number of seconds or milliseconds after the Unix epoch, UTC timezone. The value is returned in the response under thedetection_timestamp
field, and represented in console under the TIMESTAMP field.alert_id_list
: Array of integers. Each item in the list must be an alert ID.severity
: Valid values arelow
,medium
,high
,critical
,informational
.