- HTTP request
- Path parameters
- Query parameters
- Request body
- Response body
- Authorization scopes
- IAM Permissions
- ListBasis
- Try it!
Full name: projects.locations.instances.legacy.legacySearchDetections
Legacy endpoint for searching detections for a rule version.
HTTP request
GET https://chronicle.googleapis.com/v1alpha/{instance}/legacy:legacySearchDetections
Path parameters
Parameters | |
---|---|
instance |
Required. Chronicle instance this request is sent to. Format: projects/{project}/locations/{location}/instances/{instance} |
Query parameters
Parameters | |
---|---|
rule |
Required. The specific rule revision to search detections for. There are four acceptable formats: - |
alert |
Optional. An enum that filters which detections are returned by their AlertState. |
start |
Optional. The time to start search detections from, inclusive. Uses RFC 3339, where generated output will always be Z-normalized and uses 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted.Examples: |
end |
Optional. The time to end searching detections to, exclusive. Uses RFC 3339, where generated output will always be Z-normalized and uses 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted.Examples: |
list |
Optional. Basis for determining whether to apply start_time and end_time filters for detection time or creation time of the detection. |
page |
Optional. Maximum number of detections to return. |
page |
Optional. A page token, received from a previous When paginating, all other parameters provided to |
max |
Optional. The maximum size of response in bytes. If it is set to 0 (or is omitted), the server will not enforce any max response size limit. |
include |
Optional. If true, include one level of nested detections in the response. |
Request body
The request body must be empty.
Response body
LegacySearchDetections response message.
If successful, the response body contains data with the following structure:
JSON representation |
---|
{ "detections": [ { object ( |
Fields | |
---|---|
detections[] |
Either detections or nested_detections will be populated, but not both. List of detections in Collection protos corresponding to the rule_id. Only returned if |
nested_ |
Detections generated by the rule named by |
next_ |
A token that can be sent as |
resp_ |
This is related to the max_resp_size_bytes field in the request. If the original response size is larger than the max_resp_size_bytes, we will truncate detections so that the response size is smaller than max_resp_size_bytes, and this field will be set to true. |
Authorization scopes
Requires the following OAuth scope:
https://www.googleapis.com/auth/cloud-platform
For more information, see the Authentication Overview.
IAM Permissions
Requires the following IAM permission on the instance
resource:
chronicle.legacies.legacySearchDetections
For more information, see the IAM documentation.
ListBasis
Type of Timestamp to use for listing detections.
Enums | |
---|---|
LIST_BASIS_UNSPECIFIED |
Unspecified list basis. |
DETECTION_TIME |
List detections by detection time. |
CREATED_TIME |
List detections by created time. |