Skip to content

detectionSearch

QUERYdetectionSearch

Detections GraphQL API · Queries

Search alerts using Query Language. This is the same query language provided in Advanced Search page in Taegis XDR.

Arguments

Argument Type Description
in SearchRequestInput

Returns

AlertsResponse

Request samples

curl -X POST "https://api.taegis.sophos.com/graphql" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"query\": \"query DetectionSearch(\$in: SearchRequestInput) { detectionSearch(in: \$in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }\",
  \"variables\": {
    \"in\": {
      \"cql_query\": \"<cql_query>\"
    }
  }
}"

import requests

response = requests.post(
    "https://api.taegis.sophos.com/graphql",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'query': 'query DetectionSearch($in: SearchRequestInput) { '
             'detectionSearch(in: $in) { status reason alerts { total_results '
             'next_offset previous_offset last_offset first_offset total_parts '
             '} search_id queryId } }',
    'variables': {'in': {'cql_query': '<cql_query>'}}},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "query": "query DetectionSearch($in: SearchRequestInput) { detectionSearch(in: $in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }",
  "variables": {
    "in": {
      "cql_query": "<cql_query>"
    }
  }
}'
Invoke-RestMethod -Method POST -Uri "https://api.taegis.sophos.com/graphql" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api.taegis.sophos.com/graphql", strings.NewReader(`{
  "query": "query DetectionSearch($in: SearchRequestInput) { detectionSearch(in: $in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }",
  "variables": {
    "in": {
      "cql_query": "<cql_query>"
    }
  }
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api.taegis.sophos.com/graphql", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "query": "query DetectionSearch($in: SearchRequestInput) { detectionSearch(in: $in) { status reason alerts { total_results next_offset previous_offset last_offset first_offset total_parts } search_id queryId } }",
  "variables": {
    "in": {
      "cql_query": "<cql_query>"
    }
  }
}),
});
const data = await response.json();
console.log(data);