page | null | integer (int32) | >= 1 | 1 |
limit | null | integer (int32) | >= 0 | 10 |
quickFilter | | string | Olayları herhangi bir etiket adı, olay açıklamaları, öznitelik değerleri veya öznitelik yorumlarıyla eşleştirmek için arama yapar. | "malware" |
searchall | | string | Olayları herhangi bir etiket adı, olay açıklamaları, öznitelik değerleri veya öznitelik yorumlarıyla eşleştirmek için arama yapar. | "ransomware" |
timestamp | | string (Timestamp) | ^\\d+$ | "1617613315" |
object\_name | | string | <= 131071 karakter | "malicious\_file.exe" |
object\_template\_uuid | | string <uuid> | <= 36 karakter | "6f3c0d71-5b7a-46a9-a78b-29a146b5e3c7" |
object\_template\_version | | string | ^\\d+$ | "1" |
eventid | | string | <= 10 karakter ^\\d+$ | "12345" |
eventinfo | | string | <= 65535 karakter | "Malware infection" |
ignore | | boolean | false | true |
from | | string veya null (DateRestSearchFilter) | | |
to | | string veya null (DateRestSearchFilter) | | |
date | | string veya null (DateRestSearchFilter) | | |
tags | | Array of strings | veya null (TagsRestSearchFilter) | |
last | | integer veya string | veya null (LastRestSearchFilter) | |
event\_timestamp | | string (Timestamp) | ^\\d+$ | "1617613315" |
publish\_timestamp | | string (Timestamp) | ^\\d+$ | "1617613315" |
org | | OrganisationId veya OrganisationName | | |
uuid | | string <uuid> | <= 36 karakter | "6f3c0d71-5b7a-46a9-a78b-29a146b5e3c7" |
value | | string | <= 131071 karakter | "1.2.3.4" |
type | | string | <= 100 karakter | "ip-src" |
category | | string | <= 255 karakter | "Network activity" |
object\_relation | | string | veya null (ObjectRelationRestSearchFilter) | |
attribute\_timestamp | | string (Timestamp) | ^\\d+$ | "1617613315" |
first\_seen | | string veya null (NullableMicroTimestamp) | ^\\d+$ veya null | "1617613315" |
last\_seen | | string veya null (NullableMicroTimestamp) | ^\\d+$ veya null | "1617613315" |
comment | | string | <= 65535 karakter | "Malicious activity" |
to\_ids | | boolean veya null (ToIDSRestSearchFlag) | | |
published | | boolean | false | true |
deleted | | boolean | false | false |
withAttachments | | boolean | false | true |
enforceWarninglist | | boolean veya null (EnforceWarninglistRestSearchFilter) | | |
includeAllTags | | boolean | false | true |
includeEventUuid | | boolean | false | true |
include\_event\_uuid | | boolean | false | true |
includeEventTags | | boolean | false | true |
includeProposals | | boolean | false | true |
includeWarninglistHits | | boolean veya null | false | true |
includeContext | | boolean veya null (IncludeContextRestSearchFlag) | | |
includeSightings | | boolean veya null (IncludeContextRestSearchFlag) | | |
includeSightingdb | | boolean veya null (IncludeSightingDbRestSearchFlag) | | |
includeCorrelations | | boolean veya null (IncludeCorrelationsRestSearchFlag) | | |
includeDecayScore | | boolean | false | true |
includeFullModel | | boolean | false | true |
allow\_proposal\_blocking | | boolean | false | true |
metadata | | boolean veya null (MetadataRestSearchFilter) | | |
attackGalaxy | | string veya null (AttackGalaxyRestSearchFilter) | | |
excludeDecayed | | boolean | false | true |
decayingModel | | string | | |
modelOverrides | | object | | |
returnFormat | | string | "json" | "json" |