alertsServiceSearch¶
QUERYalertsServiceSearch
Detections GraphQL API · Queries
Search alerts using Query Language. This is the same query language provided in Advanced Search page in Taegis XDR.
Request samples¶
curl -X POST "https://api.taegis.sophos.com/graphql" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
\"query\": \"query AlertsServiceSearch(\$in: SearchRequestInput) { alertsServiceSearch(in: \$in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }\",
\"variables\": {
\"in\": {
\"cql_query\": \"<cql_query>\"
}
}
}"
import requests
response = requests.post(
"https://api.taegis.sophos.com/graphql",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
json={ 'query': 'query AlertsServiceSearch($in: SearchRequestInput) { '
'alertsServiceSearch(in: $in) { status reason alerts { '
'total_results next_offset previous_offset last_offset '
'first_offset total_parts } search_id queryId } }',
'variables': {'in': {'cql_query': '<cql_query>'}}},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
"Content-Type" = "application/json"
}
$body = '{
"query": "query AlertsServiceSearch($in: SearchRequestInput) { alertsServiceSearch(in: $in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }",
"variables": {
"in": {
"cql_query": "<cql_query>"
}
}
}'
Invoke-RestMethod -Method POST -Uri "https://api.taegis.sophos.com/graphql" -Headers $headers -Body $body -ContentType "application/json"
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
req, err := http.NewRequest("POST", "https://api.taegis.sophos.com/graphql", strings.NewReader(`{
"query": "query AlertsServiceSearch($in: SearchRequestInput) { alertsServiceSearch(in: $in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }",
"variables": {
"in": {
"cql_query": "<cql_query>"
}
}
}`))
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api.taegis.sophos.com/graphql", {
method: "POST",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
body: JSON.stringify({
"query": "query AlertsServiceSearch($in: SearchRequestInput) { alertsServiceSearch(in: $in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }",
"variables": {
"in": {
"cql_query": "<cql_query>"
}
}
}),
});
const data = await response.json();
console.log(data);