Skip to content

alertsServiceSearch

QUERYalertsServiceSearch

Detections GraphQL API · Queries

Search alerts using Query Language. This is the same query language provided in Advanced Search page in Taegis XDR.

Arguments

Argument Type Description
in SearchRequestInput

Returns

AlertsResponse

Request samples

curl -X POST "https://api.taegis.sophos.com/graphql" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"query\": \"query AlertsServiceSearch(\$in: SearchRequestInput) { alertsServiceSearch(in: \$in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }\",
  \"variables\": {
    \"in\": {
      \"cql_query\": \"<cql_query>\"
    }
  }
}"

import requests

response = requests.post(
    "https://api.taegis.sophos.com/graphql",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'query': 'query AlertsServiceSearch($in: SearchRequestInput) { '
             'alertsServiceSearch(in: $in) { status reason alerts { '
             'total_results next_offset previous_offset last_offset '
             'first_offset total_parts } search_id queryId } }',
    'variables': {'in': {'cql_query': '<cql_query>'}}},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "query": "query AlertsServiceSearch($in: SearchRequestInput) { alertsServiceSearch(in: $in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }",
  "variables": {
    "in": {
      "cql_query": "<cql_query>"
    }
  }
}'
Invoke-RestMethod -Method POST -Uri "https://api.taegis.sophos.com/graphql" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api.taegis.sophos.com/graphql", strings.NewReader(`{
  "query": "query AlertsServiceSearch($in: SearchRequestInput) { alertsServiceSearch(in: $in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }",
  "variables": {
    "in": {
      "cql_query": "<cql_query>"
    }
  }
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api.taegis.sophos.com/graphql", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "query": "query AlertsServiceSearch($in: SearchRequestInput) { alertsServiceSearch(in: $in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }",
  "variables": {
    "in": {
      "cql_query": "<cql_query>"
    }
  }
}),
});
const data = await response.json();
console.log(data);