Cisco AMP for Endpoints API

GET /v1/events

Description

This is a general query interface for events. This is analogous to the Events view on the FireAMP Console.

Events can be filtered by a variety of criteria. Each criteria type is logically ANDed with the other criteria; each selection of a criteria is logically ORed. For example: with the query string: connector_guid[]=ead39d47-93bd-4230-b692-454b433faf96&event_type[]=2164260868&event_type[]=1090519054, it will return any events that match the connector guid ad39d47-93bd-4230-b692-454b433faf96 AND any events with type (1090519054 OR 2164260868).

The arguments passed to the event_type and group_guid parameters can be retrieved from their respective endpoints.

Query Parameters

Name Type Example Values Description
limit Integer 2, 1, 10
detection_sha256 String f8a6a244138cb1e2f044f63f3dc42beeb555da892bbd7a121274498cbdfc9ad5
application_sha256 String 80ef843fa78c33b511394a9c7535a9cbace1deb2270e86ee4ad2faffa5b1e7d2
connector_guid[] GUID af73d9d5-ddc5-4c93-9c6d-d5e6b5c5eb01
group_guid[] GUID b077d6bc-bbdf-42f7-8838-a06053fbd98a
start_date String (Time ISO8601) 2015-10-01T00:00:00+00:00 Inclusive (The list will include events that match start_date)
offset Integer 10
event_type[] Array 1090519054, 1090519084

Show Response Fields

Name Type Description
version String
metadata.links.self String
metadata.links.prev String
metadata.links.next String
metadata.results.total Integer
metadata.results.current_item_count Integer
metadata.results.index Integer
metadata.results.items_per_page Integer
data Array
data[].id Integer
data[].timestamp Integer
data[].timestamp_nanoseconds Integer
data[].date String (Time ISO8601)
data[].event_type String
data[].event_type_id Integer
data[].detection String
data[].detection_id String
data[].group_guids Array
data[].group_guids[] GUID
data[].computer.connector_guid GUID
data[].computer.hostname String
data[].computer.external_ip String
data[].computer.user String
data[].computer.active Boolean
data[].computer.network_addresses Array
data[].computer.network_addresses[].ip String
data[].computer.network_addresses[].mac String
data[].computer.links.computer String
data[].computer.links.trajectory String
data[].computer.links.group String
data[].file.disposition String
data[].file.file_name String
data[].file.file_path String
data[].file.identity.sha256 String
data[].file.identity.sha1 String
data[].file.identity.md5 String
data[].file.parent.process_id Integer
data[].file.parent.disposition String
data[].file.parent.file_name String
data[].file.parent.identity.sha256 String
data[].file.parent.identity.sha1 String
data[].file.parent.identity.md5 String
Write
Preview

Examples

Fetch list of events sorted in descending order by timestamp
Fetch list of events filtered by connector_guid
Fetch list of events filtered by group_guid
Fetch list of events filtered by detection_sha256
Fetch list of events filtered by application_sha256
Fetch list of events filtered by detection_sha256 and application_sha256
Fetch list of events filtered by event_type
Fetch events that are newer than a given timestamp
Fetch list of events filtered by SCAN_STARTED event type

Fetch list of events sorted in descending order by timestamp

Request

Requires Authorization
GET /v1/events?limit=2
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/events?limit=2'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3552
x-ratelimit-remaining: 2730
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-09-30T15:59:05Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/events?limit=2",
      "next": "https://api.eu.amp.cisco.com/v1/events?limit=2&offset=2"
    },
    "results": {
      "total": 388,
      "current_item_count": 2,
      "index": 0,
      "items_per_page": 2
    }
  },
  "data": [
    {
      "id": 5832268414885822000,
      "timestamp": 1569589811,
      "timestamp_nanoseconds": 13000000,
      "date": "2019-09-27T13:10:11+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832268410590855181",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "user": "A@ZBOTTEST2",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3756858138.exe",
        "file_path": "\\\\?\\C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\2_3756858138.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        },
        "parent": {
          "process_id": 3020,
          "disposition": "Unknown",
          "file_name": "a.exe",
          "identity": {
            "sha256": "0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f",
            "sha1": "5df10f3387f7ff512e420240f81bde68a2b4c7aa",
            "md5": "9a2e18cb348feb772d02fb8f8728ab82"
          }
        }
      }
    },
    {
      "id": 5832268410590855000,
      "timestamp": 1569589810,
      "timestamp_nanoseconds": 810000000,
      "date": "2019-09-27T13:10:10+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832268410590855180",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "user": "A@ZBOTTEST2",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3756858138.exe",
        "file_path": "\\\\?\\C:\\Documents and Settings\\Administrator\\Local Settings\\Temp\\2_3756858138.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        },
        "parent": {
          "process_id": 3020,
          "disposition": "Unknown",
          "file_name": "a.exe",
          "identity": {
            "sha256": "0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f",
            "sha1": "5df10f3387f7ff512e420240f81bde68a2b4c7aa",
            "md5": "9a2e18cb348feb772d02fb8f8728ab82"
          }
        }
      }
    }
  ]
}

Fetch list of events filtered by connector_guid

Request

Requires Authorization
GET /v1/events?connector_guid[]=803e8de1-dfe8-4733-b685-0657fd9e02ae&limit=1
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/events?connector_guid[]=803e8de1-dfe8-4733-b685-0657fd9e02ae&limit=1'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3544
x-ratelimit-remaining: 2667
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-09-30T15:59:05Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/events?connector_guid[]=803e8de1-dfe8-4733-b685-0657fd9e02ae&limit=1",
      "next": "https://api.eu.amp.cisco.com/v1/events?connector_guid%5B%5D=803e8de1-dfe8-4733-b685-0657fd9e02ae&limit=1&offset=1"
    },
    "results": {
      "total": 40,
      "current_item_count": 1,
      "index": 0,
      "items_per_page": 1
    }
  },
  "data": [
    {
      "id": 5832268414885822000,
      "timestamp": 1569589811,
      "timestamp_nanoseconds": 13000000,
      "date": "2019-09-27T13:10:11+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832268410590855181",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "user": "A@ZBOTTEST2",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3756858138.exe",
        "file_path": "\\\\?\\C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\2_3756858138.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        },
        "parent": {
          "process_id": 3020,
          "disposition": "Unknown",
          "file_name": "a.exe",
          "identity": {
            "sha256": "0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f",
            "sha1": "5df10f3387f7ff512e420240f81bde68a2b4c7aa",
            "md5": "9a2e18cb348feb772d02fb8f8728ab82"
          }
        }
      }
    }
  ]
}

Fetch list of events filtered by group_guid

Request

Requires Authorization
GET /v1/events?group_guid[]=6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03&limit=1
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/events?group_guid[]=6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03&limit=1'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3534
x-ratelimit-remaining: 2604
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-09-30T15:59:05Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/events?group_guid[]=6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03&limit=1",
      "next": "https://api.eu.amp.cisco.com/v1/events?group_guid%5B%5D=6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03&limit=1&offset=1"
    },
    "results": {
      "total": 40,
      "current_item_count": 1,
      "index": 0,
      "items_per_page": 1
    }
  },
  "data": [
    {
      "id": 5832268414885822000,
      "timestamp": 1569589811,
      "timestamp_nanoseconds": 13000000,
      "date": "2019-09-27T13:10:11+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832268410590855181",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "user": "A@ZBOTTEST2",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3756858138.exe",
        "file_path": "\\\\?\\C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\2_3756858138.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        },
        "parent": {
          "process_id": 3020,
          "disposition": "Unknown",
          "file_name": "a.exe",
          "identity": {
            "sha256": "0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f",
            "sha1": "5df10f3387f7ff512e420240f81bde68a2b4c7aa",
            "md5": "9a2e18cb348feb772d02fb8f8728ab82"
          }
        }
      }
    }
  ]
}

Fetch list of events filtered by detection_sha256

Request

Requires Authorization
GET /v1/events?detection_sha256=8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a&limit=1
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/events?detection_sha256=8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a&limit=1'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3524
x-ratelimit-remaining: 2541
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-09-30T15:59:05Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/events?detection_sha256=8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a&limit=1",
      "next": "https://api.eu.amp.cisco.com/v1/events?detection_sha256=8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a&limit=1&offset=1"
    },
    "results": {
      "total": 30,
      "current_item_count": 1,
      "index": 0,
      "items_per_page": 1
    }
  },
  "data": [
    {
      "id": 5832268414885822000,
      "timestamp": 1569589811,
      "timestamp_nanoseconds": 13000000,
      "date": "2019-09-27T13:10:11+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832268410590855181",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "user": "A@ZBOTTEST2",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3756858138.exe",
        "file_path": "\\\\?\\C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\2_3756858138.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        },
        "parent": {
          "process_id": 3020,
          "disposition": "Unknown",
          "file_name": "a.exe",
          "identity": {
            "sha256": "0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f",
            "sha1": "5df10f3387f7ff512e420240f81bde68a2b4c7aa",
            "md5": "9a2e18cb348feb772d02fb8f8728ab82"
          }
        }
      }
    }
  ]
}

Fetch list of events filtered by application_sha256

Request

Requires Authorization
GET /v1/events?application_sha256=0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f&limit=1
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/events?application_sha256=0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f&limit=1'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3515
x-ratelimit-remaining: 2478
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-09-30T15:59:05Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/events?application_sha256=0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f&limit=1",
      "next": "https://api.eu.amp.cisco.com/v1/events?application_sha256=0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f&limit=1&offset=1"
    },
    "results": {
      "total": 16,
      "current_item_count": 1,
      "index": 0,
      "items_per_page": 1
    }
  },
  "data": [
    {
      "id": 5832268414885822000,
      "timestamp": 1569589811,
      "timestamp_nanoseconds": 13000000,
      "date": "2019-09-27T13:10:11+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832268410590855181",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "user": "A@ZBOTTEST2",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3756858138.exe",
        "file_path": "\\\\?\\C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\2_3756858138.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        },
        "parent": {
          "process_id": 3020,
          "disposition": "Unknown",
          "file_name": "a.exe",
          "identity": {
            "sha256": "0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f",
            "sha1": "5df10f3387f7ff512e420240f81bde68a2b4c7aa",
            "md5": "9a2e18cb348feb772d02fb8f8728ab82"
          }
        }
      }
    }
  ]
}

Fetch list of events filtered by detection_sha256 and application_sha256

Request

Requires Authorization
GET /v1/events?detection_sha256=8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a&application_sha256=0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f&limit=1
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/events?detection_sha256=8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a&application_sha256=0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f&limit=1'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3507
x-ratelimit-remaining: 2415
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-09-30T15:59:05Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/events?detection_sha256=8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a&application_sha256=0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f&limit=1",
      "next": "https://api.eu.amp.cisco.com/v1/events?detection_sha256=8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a&application_sha256=0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f&limit=1&offset=1"
    },
    "results": {
      "total": 16,
      "current_item_count": 1,
      "index": 0,
      "items_per_page": 1
    }
  },
  "data": [
    {
      "id": 5832268414885822000,
      "timestamp": 1569589811,
      "timestamp_nanoseconds": 13000000,
      "date": "2019-09-27T13:10:11+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832268410590855181",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "user": "A@ZBOTTEST2",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3756858138.exe",
        "file_path": "\\\\?\\C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\2_3756858138.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        },
        "parent": {
          "process_id": 3020,
          "disposition": "Unknown",
          "file_name": "a.exe",
          "identity": {
            "sha256": "0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f",
            "sha1": "5df10f3387f7ff512e420240f81bde68a2b4c7aa",
            "md5": "9a2e18cb348feb772d02fb8f8728ab82"
          }
        }
      }
    }
  ]
}

Fetch list of events filtered by event_type

Request

Requires Authorization
GET /v1/events?event_type[]=1090519054&event_type[]=1090519084&offset=10&limit=10
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/events?event_type[]=1090519054&event_type[]=1090519084&offset=10&limit=10'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3506
x-ratelimit-remaining: 2414
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-09-30T15:59:05Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/events?event_type[]=1090519054&event_type[]=1090519084&offset=10&limit=10",
      "prev": "https://api.eu.amp.cisco.com/v1/events?event_type%5B%5D=1090519054&event_type%5B%5D=1090519084&limit=10&offset=0",
      "next": "https://api.eu.amp.cisco.com/v1/events?event_type%5B%5D=1090519054&event_type%5B%5D=1090519084&limit=10&offset=20"
    },
    "results": {
      "total": 189,
      "current_item_count": 10,
      "index": 10,
      "items_per_page": 10
    }
  },
  "data": [
    {
      "id": 5832266490740474000,
      "timestamp": 1569589363,
      "timestamp_nanoseconds": 404000000,
      "date": "2019-09-27T13:02:43+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832266490740473860",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3564327093.exe",
        "file_path": "\\\\?\\C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\2_3564327093.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        }
      }
    },
    {
      "id": 5832266490740474000,
      "timestamp": 1569589363,
      "timestamp_nanoseconds": 201000000,
      "date": "2019-09-27T13:02:43+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832266490740473859",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "user": "",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3564327093.exe",
        "file_path": "\\\\?\\C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\2_3564327093.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        },
        "parent": {
          "process_id": 2084,
          "disposition": "Unknown",
          "file_name": "a.exe",
          "identity": {
            "sha256": "0723932d68702a59c4c8bf6a670a098cd55c39f4a3037fa8c2e6d2641fbfe85f",
            "sha1": "5df10f3387f7ff512e420240f81bde68a2b4c7aa",
            "md5": "9a2e18cb348feb772d02fb8f8728ab82"
          }
        }
      }
    }
  ]
}

Fetch events that are newer than a given timestamp

Request

Requires Authorization
GET /v1/events?start_date=2015-10-01T00%3A00%3A00%2B00%3A00&offset=10&limit=10
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/events?start_date=2015-10-01T00%3A00%3A00%2B00%3A00&offset=10&limit=10'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3506
x-ratelimit-remaining: 2413
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-09-30T15:59:05Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/events?start_date=2015-10-01T00%3A00%3A00%2B00%3A00&offset=10&limit=10",
      "prev": "https://api.eu.amp.cisco.com/v1/events?start_date=2015-10-01T00%3A00%3A00%2B00%3A00&limit=10&offset=0",
      "next": "https://api.eu.amp.cisco.com/v1/events?start_date=2015-10-01T00%3A00%3A00%2B00%3A00&limit=10&offset=20"
    },
    "results": {
      "total": 388,
      "current_item_count": 10,
      "index": 10,
      "items_per_page": 10
    }
  },
  "data": [
    {
      "id": 5832266490740474000,
      "timestamp": 1569589363,
      "timestamp_nanoseconds": 607000000,
      "date": "2019-09-27T13:02:43+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832266490740473862",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3564327093.exe",
        "file_path": "\\\\?\\C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\2_3564327093.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        }
      }
    },
    {
      "id": 5832266490740474000,
      "timestamp": 1569589363,
      "timestamp_nanoseconds": 544000000,
      "date": "2019-09-27T13:02:43+00:00",
      "event_type": "Threat Detected",
      "event_type_id": 1090519054,
      "detection": "ZBot:FakeAlert-tpd",
      "detection_id": "5832266490740473861",
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "severity": "Medium",
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "file": {
        "disposition": "Malicious",
        "file_name": "2_3564327093.exe",
        "file_path": "\\\\?\\C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\2_3564327093.exe",
        "identity": {
          "sha256": "8db0d7f3a27291f197173a1e3a3a7242fc49deb2d06f90598475c919417a1c7a",
          "sha1": "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5",
          "md5": "e74f1b3fffc4ae61e077bbdec3230e95"
        }
      }
    }
  ]
}

Fetch list of events filtered by SCAN_STARTED event type

Request

Requires Authorization
GET /v1/events?event_type[]=554696714&limit=10
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/events?event_type[]=554696714&limit=10'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3506
x-ratelimit-remaining: 2412
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-09-30T15:59:05Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/events?event_type[]=554696714&limit=10"
    },
    "results": {
      "total": 7,
      "current_item_count": 7,
      "index": 0,
      "items_per_page": 10
    }
  },
  "data": [
    {
      "id": 5832266988956680000,
      "timestamp": 1569589479,
      "timestamp_nanoseconds": 544000000,
      "date": "2019-09-27T13:04:39+00:00",
      "event_type": "Scan Started",
      "event_type_id": 554696714,
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "scan": {
        "description": "C:\\Program Files\\Mozilla Firefox"
      }
    },
    {
      "id": 5832265790660805000,
      "timestamp": 1569589200,
      "timestamp_nanoseconds": 44000000,
      "date": "2019-09-27T13:00:00+00:00",
      "event_type": "Scan Started",
      "event_type_id": 554696714,
      "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
      "group_guids": [
        "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      ],
      "computer": {
        "connector_guid": "803e8de1-dfe8-4733-b685-0657fd9e02ae",
        "hostname": "Demo_Zbot",
        "external_ip": "173.91.174.56",
        "active": false,
        "network_addresses": [
          {
            "ip": "79.196.182.171",
            "mac": "b6:7b:1e:95:b7:cc"
          }
        ],
        "links": {
          "computer": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae",
          "trajectory": "https://api.eu.amp.cisco.com/v1/computers/803e8de1-dfe8-4733-b685-0657fd9e02ae/trajectory",
          "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
        }
      },
      "scan": {
        "description": "Flash Scan"
      }
    }
  ]
}