Get Policies

Cortex XSIAM Platform APIs

get /api/v2/policies

Gets all policy instances from a list of given policy types. Default behavior is all.

Query parameters
types array[PolicyType]

Policy types to fetch

disableVerbose Boolean

Flag to bypass calling platform for asset groups data when fetching policies. Note that this means asset groups will not be updated when fetching policies.

Example: true
CLIENT REQUEST
curl -X 'GET'
-H 'Accept: application/json; charset=UTF-8'
'https://api-yourfqdn/api/v2/policies?types=&disableVerbose=true'
import http.client conn = http.client.HTTPSConnection("api-yourfqdn") conn.request("GET", "/api/v2/policies?types=null&disableVerbose=false") res = conn.getresponse() data = res.read() print(data.decode("utf-8"))
require 'uri' require 'net/http' require 'openssl' url = URI("https://api-yourfqdn/api/v2/policies?types=null&disableVerbose=false") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true http.verify_mode = OpenSSL::SSL::VERIFY_NONE request = Net::HTTP::Get.new(url) response = http.request(request) puts response.read_body
const data = null; const xhr = new XMLHttpRequest(); xhr.withCredentials = true; xhr.addEventListener("readystatechange", function () { if (this.readyState === this.DONE) { console.log(this.responseText); } }); xhr.open("GET", "https://api-yourfqdn/api/v2/policies?types=null&disableVerbose=false"); xhr.send(data);
HttpResponse<String> response = Unirest.get("https://api-yourfqdn/api/v2/policies?types=null&disableVerbose=false") .asString();
import Foundation let request = NSMutableURLRequest(url: NSURL(string: "https://api-yourfqdn/api/v2/policies?types=null&disableVerbose=false")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume()
<?php $curl = curl_init(); curl_setopt_array($curl, [ CURLOPT_URL => "https://api-yourfqdn/api/v2/policies?types=null&disableVerbose=false", CURLOPT_RETURNTRANSFER => true, CURLOPT_ENCODING => "", CURLOPT_MAXREDIRS => 10, CURLOPT_TIMEOUT => 30, CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1, CURLOPT_CUSTOMREQUEST => "GET", ]); $response = curl_exec($curl); $err = curl_error($curl); curl_close($curl); if ($err) { echo "cURL Error #:" . $err; } else { echo $response; }
CURL *hnd = curl_easy_init(); curl_easy_setopt(hnd, CURLOPT_CUSTOMREQUEST, "GET"); curl_easy_setopt(hnd, CURLOPT_URL, "https://api-yourfqdn/api/v2/policies?types=null&disableVerbose=false"); CURLcode ret = curl_easy_perform(hnd);
var client = new RestClient("https://api-yourfqdn/api/v2/policies?types=null&disableVerbose=false"); var request = new RestRequest(Method.GET); IRestResponse response = client.Execute(request);
Responses

Success

Body
application/json; charset=UTF-8

The response you get when calling the get policies V2 path

[
actionstring (Enum)

One of the supported policy actions

Example:"ISSUE"
Allowed values:"ISSUE""PREVENT"null
assetGroupsarray[string]
assetGroupsIDsarray[integer]
assetScopestringbyte
conditionstringbyte
createdAtstringdate-time
createdBystring
descriptionstring
disabledboolean
evaluationModesarray[string]
evaluationStagestring (Enum)

Lists supported evaluation stages

Example:"CI"
Allowed values:"CI""RUNTIME""DEPLOY"
exceptionstringbyte
idstring
missingInformationActionstring (Enum)

One of the supported policy actions

Example:"ISSUE"
Allowed values:"ISSUE""PREVENT"null
modifiedAtstringdate-time
namestring
policyRulesarray

Array of policy_rule objects related to the policy

[
actionstring (Enum)

One of the supported policy actions

Example:"ISSUE"
Allowed values:"ISSUE""PREVENT"null
idstring
policy_idstring
policy_revisioninteger
remediation_guidancestring
rule_idstring
rule_namestring
severitystring (Enum)

One of the supported policy severities

Example:"CRITICAL"
Allowed values:"INFO""LOW""MEDIUM""HIGH""CRITICAL"null
user_remediation_guidancestring

Additional remediation guidance that can be added to the rule’s predefined guidance.

]
remediationGuidancestring
revisioninteger
severitystring (Enum)

One of the supported policy severities

Example:"CRITICAL"
Allowed values:"INFO""LOW""MEDIUM""HIGH""CRITICAL"null
typestring (Enum)

One of the supported policy types

Example:"MALWARE"
Allowed values:"COMPLIANCE""MALWARE""SECRET""TRUSTED_IMAGES"null
usingSystemAssetGroupsboolean
]
RESPONSE
[application/json; charset=UTF-8 content]

Client error

Body
application/json; charset=UTF-8
errorstring
RESPONSE
[application/json; charset=UTF-8 content]

Service encountered an unexpected internal error