Get enrichments¶
GET/
Live Discover API · Live Discover
Get enrichments.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
Request samples¶
curl -X GET "https://api-<data-region>.central.sophos.com/live-discover/v1/enrichment-pivots" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>"
import requests
response = requests.get(
"https://api-<data-region>.central.sophos.com/live-discover/v1/enrichment-pivots",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
}
Invoke-RestMethod -Method GET -Uri "https://api-<data-region>.central.sophos.com/live-discover/v1/enrichment-pivots" -Headers $headers
package main
import (
"fmt"
"io"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://api-<data-region>.central.sophos.com/live-discover/v1/enrichment-pivots", nil)
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/live-discover/v1/enrichment-pivots", {
method: "GET",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
},
});
const data = await response.json();
console.log(data);
Responses¶
200 — Enrichments.¶
Response fields
itemsarray of objectrequiredArray of enrichments.
Enrichment.
Show child attributesHide child attributes
idstring (uuid)Enrichment ID.
tenantobjectTenant these resources belong to.
Show child attributesHide child attributes
idstring (uuid)requirednamestringsourceTypestring (enum)requiredEnrichment source type.
Must be one of:
Must be one of:
canned, custom.namestringrequiredEnrichment name.
descriptionstringrequiredEnrichment description.
typestring (enum)requiredEnrichment type.
Must be one of:
Must be one of:
ipAddress, md5, sha256, dns, port, geolocation.urlstringrequiredEnrichment URL.
createdAtstring (datetime)When the enrichment was created.
createdByobjectPrincipal reference.
Show child attributesHide child attributes
idstring (uuid)requiredPrincipal ID. This is the client ID for service principals.
typestring (enum)requiredPrincipal type.
Must be one of:
Must be one of:
user, service.namestringPrincipal name. This doesn't apply to service principals.
accountTypestringAccount type.
Must be one of:
Must be one of:
partner, tenant, organization.updatedAtstring (datetime)When the enrichment was last updated.
updatedByobjectPrincipal reference.
Show child attributesHide child attributes
idstring (uuid)requiredPrincipal ID. This is the client ID for service principals.
typestring (enum)requiredPrincipal type.
Must be one of:
Must be one of:
user, service.namestringPrincipal name. This doesn't apply to service principals.
accountTypestringAccount type.
Must be one of:
Must be one of:
partner, tenant, organization.Errors¶
| Status | Meaning |
|---|---|
403 | Forbidden. |
500 | Unexpected error. |
All error responses share the same shape — see the error response object.
Response examples¶
200¶
{
"items": [
{
"id": "00000000-0000-0000-0000-000000000000",
"tenant": {
"id": "00000000-0000-0000-0000-000000000000",
"name": "string"
},
"sourceType": "canned",
"name": "string",
"description": "string",
"type": "ipAddress",
"url": "string",
"createdAt": "string",
"createdBy": {
"id": "00000000-0000-0000-0000-000000000000",
"type": "user",
"name": "string",
"accountType": "partner"
},
"updatedAt": "string",
"updatedBy": {
"id": "00000000-0000-0000-0000-000000000000",
"type": "user",
"name": "string",
"accountType": "partner"
}
}
]
}
See the guide for a narrative walkthrough of this API.