Skip to main content
GET
/
api
/
v2
/
workspaces
/
{workspaceId}
/
incidents
/
{source}
/
by-entity
Get incidents by entity
curl --request GET \
  --url https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/by-entity
{
  "data": {
    "incidents": [
      {
        "creationTime": "2023-11-07T05:31:56Z",
        "number": 123,
        "title": "<string>",
        "description": "<string>",
        "severity": "Informational",
        "status": "Active",
        "id": "<string>",
        "source": "Sentinel",
        "workspaceId": "<string>",
        "classificationComment": "<string>",
        "classification": "BenignPositive"
      }
    ]
  },
  "meta": {
    "requestId": "<string>",
    "timestamp": "<string>"
  }
}

Documentation Index

Fetch the complete documentation index at: https://docs.contraforce.com/llms.txt

Use this file to discover all available pages before exploring further.

Path Parameters

workspaceId
string<uuid>
required
source
enum<string>
required
Available options:
Sentinel,
DefenderXDR,
QRadar,
Splunk,
CrowdStrike,
SentinelOne

Query Parameters

IncidentId
string
EntityKind
string
EntityFilter
string
TimeFilteringType
any
Available options:
ThreeHours,
SixHours,
TwelveHours,
TwentyFourHours,
FourtyEightHours,
Custom,
null
StartDate
string<date-time>
EndDate
string<date-time>
EntityName
string
EntityType
enum<string>
Available options:
User,
IP,
File,
Process,
Device,
Malware,
CloudApplication,
DomainName,
AzureResource,
FileHash,
RegistryKey,
RegistryValue,
SecurityGroup,
URL,
IoTDevice,
Mailbox,
MailCluster,
MailMessage,
Submission,
SentinelEntities,
DnsResolution,
Registry,
OAuthApplication,
AmazonResource,
BlobContainer,
Blob,
Container,
ContainerRegistry,
ContainerImage,
GoogleCloudResource,
KubernetesCluster,
KubernetesController,
KubernetesNamespace,
KubernetesPod,
KubernetesService,
KubernetesSecret,
KubernetesServiceAccount,
AnalyzedMessage,
DNS,
Unknown

Response

OK

Standard v2 API response envelope for single-item responses.

data
object
meta
object