Get Audit Management Log

Cortex Xpanse REST API

post /public_api/v1/audits/management_logs/

Get audit management logs.
- Response is concatenated using AND condition (OR is not supported).
- Maximum result set size is 100.
- Offset is the zero-based number of incidents from the start of the result set.

Request headers
authorization String required

api-key

Example: {{api_key}}
x-xdr-auth-id String required

api-key-id

Example: {{api_key_id}}
CLIENT REQUEST
curl -X 'POST'
-H 'Accept: application/json'
-H 'Content-Type: application/json'
-H 'authorization: {{api_key}}' -H 'x-xdr-auth-id: {{api_key_id}}'
'https://api-}/public_api/v1/audits/management_logs/'
-d '{ "request_data" : { "search_from" : 0, "filters" : [ { "field" : "email", "value" : 0, "operator" : "in" }, { "field" : "email", "value" : 0, "operator" : "in" } ], "sort" : { "field" : "timestamp", "keyword" : "desc" }, "search_to" : 0 } }'
import http.client conn = http.client.HTTPSConnection("api-") payload = "{\"request_data\":{\"filters\":[{\"field\":\"email\",\"operator\":\"in\",\"value\":0}],\"search_from\":0,\"search_to\":100,\"sort\":{\"field\":\"sub_type\",\"keyword\":\"ASC\"}}}" headers = { 'authorization': "{{api_key}}", 'x-xdr-auth-id': "{{api_key_id}}", 'content-type': "application/json" } conn.request("POST", "%7B%7Bfqdn%7D%7D/public_api/v1/audits/management_logs/", payload, headers) res = conn.getresponse() data = res.read() print(data.decode("utf-8"))
require 'uri' require 'net/http' require 'openssl' url = URI("https://api-/%7B%7Bfqdn%7D%7D/public_api/v1/audits/management_logs/") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true http.verify_mode = OpenSSL::SSL::VERIFY_NONE request = Net::HTTP::Post.new(url) request["authorization"] = '{{api_key}}' request["x-xdr-auth-id"] = '{{api_key_id}}' request["content-type"] = 'application/json' request.body = "{\"request_data\":{\"filters\":[{\"field\":\"email\",\"operator\":\"in\",\"value\":0}],\"search_from\":0,\"search_to\":100,\"sort\":{\"field\":\"sub_type\",\"keyword\":\"ASC\"}}}" response = http.request(request) puts response.read_body
const data = JSON.stringify({ "request_data": { "filters": [ { "field": "email", "operator": "in", "value": 0 } ], "search_from": 0, "search_to": 100, "sort": { "field": "sub_type", "keyword": "ASC" } } }); const xhr = new XMLHttpRequest(); xhr.withCredentials = true; xhr.addEventListener("readystatechange", function () { if (this.readyState === this.DONE) { console.log(this.responseText); } }); xhr.open("POST", "https://api-/%7B%7Bfqdn%7D%7D/public_api/v1/audits/management_logs/"); xhr.setRequestHeader("authorization", "{{api_key}}"); xhr.setRequestHeader("x-xdr-auth-id", "{{api_key_id}}"); xhr.setRequestHeader("content-type", "application/json"); xhr.send(data);
HttpResponse<String> response = Unirest.post("https://api-/%7B%7Bfqdn%7D%7D/public_api/v1/audits/management_logs/") .header("authorization", "{{api_key}}") .header("x-xdr-auth-id", "{{api_key_id}}") .header("content-type", "application/json") .body("{\"request_data\":{\"filters\":[{\"field\":\"email\",\"operator\":\"in\",\"value\":0}],\"search_from\":0,\"search_to\":100,\"sort\":{\"field\":\"sub_type\",\"keyword\":\"ASC\"}}}") .asString();
import Foundation let headers = [ "authorization": "{{api_key}}", "x-xdr-auth-id": "{{api_key_id}}", "content-type": "application/json" ] let parameters = ["request_data": [ "filters": [ [ "field": "email", "operator": "in", "value": 0 ] ], "search_from": 0, "search_to": 100, "sort": [ "field": "sub_type", "keyword": "ASC" ] ]] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api-/%7B%7Bfqdn%7D%7D/public_api/v1/audits/management_logs/")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume()
<?php $curl = curl_init(); curl_setopt_array($curl, [ CURLOPT_URL => "https://api-/%7B%7Bfqdn%7D%7D/public_api/v1/audits/management_logs/", CURLOPT_RETURNTRANSFER => true, CURLOPT_ENCODING => "", CURLOPT_MAXREDIRS => 10, CURLOPT_TIMEOUT => 30, CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1, CURLOPT_CUSTOMREQUEST => "POST", CURLOPT_POSTFIELDS => "{\"request_data\":{\"filters\":[{\"field\":\"email\",\"operator\":\"in\",\"value\":0}],\"search_from\":0,\"search_to\":100,\"sort\":{\"field\":\"sub_type\",\"keyword\":\"ASC\"}}}", CURLOPT_HTTPHEADER => [ "authorization: {{api_key}}", "content-type: application/json", "x-xdr-auth-id: {{api_key_id}}" ], ]); $response = curl_exec($curl); $err = curl_error($curl); curl_close($curl); if ($err) { echo "cURL Error #:" . $err; } else { echo $response; }
CURL *hnd = curl_easy_init(); curl_easy_setopt(hnd, CURLOPT_CUSTOMREQUEST, "POST"); curl_easy_setopt(hnd, CURLOPT_URL, "https://api-/%7B%7Bfqdn%7D%7D/public_api/v1/audits/management_logs/"); struct curl_slist *headers = NULL; headers = curl_slist_append(headers, "authorization: {{api_key}}"); headers = curl_slist_append(headers, "x-xdr-auth-id: {{api_key_id}}"); headers = curl_slist_append(headers, "content-type: application/json"); curl_easy_setopt(hnd, CURLOPT_HTTPHEADER, headers); curl_easy_setopt(hnd, CURLOPT_POSTFIELDS, "{\"request_data\":{\"filters\":[{\"field\":\"email\",\"operator\":\"in\",\"value\":0}],\"search_from\":0,\"search_to\":100,\"sort\":{\"field\":\"sub_type\",\"keyword\":\"ASC\"}}}"); CURLcode ret = curl_easy_perform(hnd);
var client = new RestClient("https://api-/%7B%7Bfqdn%7D%7D/public_api/v1/audits/management_logs/"); var request = new RestRequest(Method.POST); request.AddHeader("authorization", "{{api_key}}"); request.AddHeader("x-xdr-auth-id", "{{api_key_id}}"); request.AddHeader("content-type", "application/json"); request.AddParameter("application/json", "{\"request_data\":{\"filters\":[{\"field\":\"email\",\"operator\":\"in\",\"value\":0}],\"search_from\":0,\"search_to\":100,\"sort\":{\"field\":\"sub_type\",\"keyword\":\"ASC\"}}}", ParameterType.RequestBody); IRestResponse response = client.Execute(request);
Body parameters
required
application/json
request_dataobject
filtersarray
[
fieldstring (Enum)
Allowed values:"email""type""sub_type""result""timestamp""audit_id"
operatorstring (Enum)
Allowed values:"in""neq""eq""lte""gte"
valueinteger
Free-Form object
]
search_frominteger
search_tointeger
Default:100
sortobject
fieldstring (Enum)
Default:"timestamp"
Allowed values:"sub_type""result""timestamp""audit_id""type"
keywordstring (Enum)
Default:"desc"
Allowed values:"ASC""asc""DESC""desc"
Free-Form object
Free-Form object
REQUEST
{ "request_data": { "filters": [ { "field": "email", "operator": "in", "value": 0 } ], "search_from": 0, "search_to": 0, "sort": { "field": "sub_type", "keyword": "ASC" } } }
Responses

Successful response

Body
application/json
replyobjectrequired
total_countinteger
result_countinteger
dataarray
[
AUDIT_IDinteger
AUDIT_OWNER_NAMEstring
AUDIT_OWNER_EMAILstring
AUDIT_ASSET_JSONobject
AUDIT_ASSET_NAMESstring
AUDIT_HOSTNAMEstring
AUDIT_RESULTstring
AUDIT_REASONstring
AUDIT_DESCRIPTIONstring
AUDIT_ENTITYstring (Enum)
Allowed values:"LIVE_TERMINAL""RULES""RULES_EXCEPTIONS""AUTH""RESPONSE""INCIDENT_MANAGEMENT""ALERT_MANAGEMENT""INCIDENT_TIMELINE_EVENT""ENDPOINT_MANAGEMENT""ENDPOINT_GROUPS""ALERT_WHITELIST""PUBLIC_API""DISTRIBUTIONS""STARRED_INCIDENTS""POLICY_PROFILES""DEVICE_CONTROL_PROFILES""DEVICE_CONTROL_POLICY""PROTECTION_PROFILES""DEVICE_CONTROL_PROFILE""HOST_FIREWALL_PROFILE""HOST_DISK_ENCRYPTION_PROFILE""POLICY_RULES""PROTECTION_POLICY""DEVICE_CONTROL_TEMP_EXCEPTIONS""DEVICE_CONTROL_GLOBAL_EXCEPTIONS""DEVICE_CONTROL_CUSTOM_DEVICE""GLOBAL_EXCEPTIONS""MSSP""REPORTING""DASHBOARD""BROKER_API""BROKER_VM""MTH""MDR""ALERT_NOTIFICATIONS""INTEGRATIONS""QUERY""SCRIPT_EXECUTION""ALERT_RULES""COLLECTION""API_KEY""EDL""VA_RESCAN_ENDPOINT""HI_RESCAN_ENDPOINT""REMEDIATION""INGEST_DATA""LICENSING""AGENT_CONFIGURATION""PERMISSIONS""SCORING_RULES""LAYOUT_RULES""PLAYBOOK_TRIGGERS""FEATURED_ALERT_FIELDS""SYSTEM""TENANT_TAKEOVER""SCOUTER_POLICY""SCOUTER_PROFILE""SCOUTER_GROUPS""ALLOWED_DOMAINS""QUERY_LIBRARY""TENANT_CONFIGURATION""SCOUTER_CONFIGURATION""HOST_FIREWALL""XIF""XDM""ACTION_CENTER""XCLOUD_INTEGRATION""DATASETS""XSOAR""SECURITY_SETTINGS""ALERT_EXCLUSION""INDICATOR_RULES""EVENT_FORWARDING""ASSET_INVENTORY""SERVER_SETTINGS""ASSET_ROLES""CUSTOM_FIELDS""AUTOMATION_RULES""AGENT_EXCEPTION_RULES""REMEDIATION_PATH_RULES"
AUDIT_ENTITY_SUBTYPEstring
AUDIT_SESSION_IDstring
AUDIT_CASE_IDstring
AUDIT_INSERT_TIMEinteger
AUDIT_SEVERITYstring
AUDIT_LINKstring
AUDIT_SOURCE_IPstring
AUDIT_USER_AGENTstring
AUDIT_USER_ROLESarray[string]
Free-Form object
]
Free-Form object
Free-Form object
RESPONSE
{ "reply": { "total_count": 0, "result_count": 0, "data": [ { "AUDIT_ID": 0, "AUDIT_OWNER_NAME": "example", "AUDIT_OWNER_EMAIL": "example", "AUDIT_ASSET_JSON": {}, "AUDIT_ASSET_NAMES": "example", "AUDIT_HOSTNAME": "example", "AUDIT_RESULT": "example", "AUDIT_REASON": "example", "AUDIT_DESCRIPTION": "example", "AUDIT_ENTITY": "LIVE_TERMINAL", "AUDIT_ENTITY_SUBTYPE": "example", "AUDIT_SESSION_ID": "example", "AUDIT_CASE_ID": "example", "AUDIT_INSERT_TIME": 0, "AUDIT_SEVERITY": "example", "AUDIT_LINK": "example", "AUDIT_SOURCE_IP": "example", "AUDIT_USER_AGENT": "example", "AUDIT_USER_ROLES": [ "example" ] } ] } }

Bad Request. Got an invalid JSON.

Body
application/json
replyobject

The query results upon error.

err_codestring

HTTP response code.

err_msgstring

Error message.

err_extrastring

Additional information describing the error.

Free-Form object
Free-Form object
RESPONSE
{ "reply": { "err_code": "example", "err_msg": "example", "err_extra": "example" } }

Unauthorized access. An issue occurred during authentication. This can indicate an incorrect key, id, or other invalid authentication parameters.

Body
application/json
replyobject

The query results upon error.

err_codestring

HTTP response code.

err_msgstring

Error message.

err_extrastring

Additional information describing the error.

Free-Form object
Free-Form object
RESPONSE
{ "reply": { "err_code": "example", "err_msg": "example", "err_extra": "example" } }

Unauthorized access. User does not have the required license type to run this API.

Body
application/json
replyobject

The query results upon error.

err_codestring

HTTP response code.

err_msgstring

Error message.

err_extrastring

Additional information describing the error.

Free-Form object
Free-Form object
RESPONSE
{ "reply": { "err_code": "example", "err_msg": "example", "err_extra": "example" } }

Forbidden access. The provided API Key does not have the required RBAC permissions to run this API.

Body
application/json
replyobject

The query results upon error.

err_codestring

HTTP response code.

err_msgstring

Error message.

err_extrastring

Additional information describing the error.

Free-Form object
Free-Form object
RESPONSE
{ "reply": { "err_code": "example", "err_msg": "example", "err_extra": "example" } }

Unprocessable Entity

Body
application/json
codeinteger

Error code

statusstring

Error name

messagestring

Error message

errorsobject

Errors

RESPONSE
{ "code": 0, "status": "example", "message": "example", "errors": {} }

Internal server error. A unified status for API communication type errors.

Body
application/json
replyobject

The query results upon error.

err_codestring

HTTP response code.

err_msgstring

Error message.

err_extrastring

Additional information describing the error.

Free-Form object
Free-Form object
RESPONSE
{ "reply": { "err_code": "example", "err_msg": "example", "err_extra": "example" } }