curl --request POST \
--url https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts \
--header 'BLINK-API-KEY: <api-key>' \
--header 'Content-Type: */*' \
--data '
{
"description": "Malware detected and blocked by CrowdStrike Falcon",
"event": "{\"process\": \"malware.exe\", \"action\": \"blocked\"}",
"name": "CrowdStrike Falcon Detection",
"processing_status": "Missing Template",
"severity": 3,
"type": "Endpoint Detection and Response (EDR)",
"vendor": "CrowdStrike"
}
'import requests
url = "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts"
payload = {
"description": "Malware detected and blocked by CrowdStrike Falcon",
"event": "{\"process\": \"malware.exe\", \"action\": \"blocked\"}",
"name": "CrowdStrike Falcon Detection",
"processing_status": "Missing Template",
"severity": 3,
"type": "Endpoint Detection and Response (EDR)",
"vendor": "CrowdStrike"
}
headers = {
"BLINK-API-KEY": "<api-key>",
"Content-Type": "*/*"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'BLINK-API-KEY': '<api-key>', 'Content-Type': '*/*'},
body: JSON.stringify({
description: 'Malware detected and blocked by CrowdStrike Falcon',
event: '{"process": "malware.exe", "action": "blocked"}',
name: 'CrowdStrike Falcon Detection',
processing_status: 'Missing Template',
severity: 3,
type: 'Endpoint Detection and Response (EDR)',
vendor: 'CrowdStrike'
})
};
fetch('https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'description' => 'Malware detected and blocked by CrowdStrike Falcon',
'event' => '{"process": "malware.exe", "action": "blocked"}',
'name' => 'CrowdStrike Falcon Detection',
'processing_status' => 'Missing Template',
'severity' => 3,
'type' => 'Endpoint Detection and Response (EDR)',
'vendor' => 'CrowdStrike'
]),
CURLOPT_HTTPHEADER => [
"BLINK-API-KEY: <api-key>",
"Content-Type: */*"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts"
payload := strings.NewReader("{\n \"description\": \"Malware detected and blocked by CrowdStrike Falcon\",\n \"event\": \"{\\\"process\\\": \\\"malware.exe\\\", \\\"action\\\": \\\"blocked\\\"}\",\n \"name\": \"CrowdStrike Falcon Detection\",\n \"processing_status\": \"Missing Template\",\n \"severity\": 3,\n \"type\": \"Endpoint Detection and Response (EDR)\",\n \"vendor\": \"CrowdStrike\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("BLINK-API-KEY", "<api-key>")
req.Header.Add("Content-Type", "*/*")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts")
.header("BLINK-API-KEY", "<api-key>")
.header("Content-Type", "*/*")
.body("{\n \"description\": \"Malware detected and blocked by CrowdStrike Falcon\",\n \"event\": \"{\\\"process\\\": \\\"malware.exe\\\", \\\"action\\\": \\\"blocked\\\"}\",\n \"name\": \"CrowdStrike Falcon Detection\",\n \"processing_status\": \"Missing Template\",\n \"severity\": 3,\n \"type\": \"Endpoint Detection and Response (EDR)\",\n \"vendor\": \"CrowdStrike\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["BLINK-API-KEY"] = '<api-key>'
request["Content-Type"] = '*/*'
request.body = "{\n \"description\": \"Malware detected and blocked by CrowdStrike Falcon\",\n \"event\": \"{\\\"process\\\": \\\"malware.exe\\\", \\\"action\\\": \\\"blocked\\\"}\",\n \"name\": \"CrowdStrike Falcon Detection\",\n \"processing_status\": \"Missing Template\",\n \"severity\": 3,\n \"type\": \"Endpoint Detection and Response (EDR)\",\n \"vendor\": \"CrowdStrike\"\n}"
response = http.request(request)
puts response.read_body{
"description": "Malware detected and blocked by CrowdStrike Falcon",
"event": "{\"process\": \"malware.exe\", \"action\": \"blocked\"}",
"name": "CrowdStrike Falcon Detection",
"processing_status": "Missing Template",
"severity": 3,
"type": "Endpoint Detection and Response (EDR)",
"vendor": "CrowdStrike"
}{
"data": {},
"details": "<string>",
"identifier": "<string>",
"message": "<string>",
"status": 404,
"user_error": {}
}Create an Alert
API endpoint to create a new alert in Blink’s case management system.
curl --request POST \
--url https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts \
--header 'BLINK-API-KEY: <api-key>' \
--header 'Content-Type: */*' \
--data '
{
"description": "Malware detected and blocked by CrowdStrike Falcon",
"event": "{\"process\": \"malware.exe\", \"action\": \"blocked\"}",
"name": "CrowdStrike Falcon Detection",
"processing_status": "Missing Template",
"severity": 3,
"type": "Endpoint Detection and Response (EDR)",
"vendor": "CrowdStrike"
}
'import requests
url = "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts"
payload = {
"description": "Malware detected and blocked by CrowdStrike Falcon",
"event": "{\"process\": \"malware.exe\", \"action\": \"blocked\"}",
"name": "CrowdStrike Falcon Detection",
"processing_status": "Missing Template",
"severity": 3,
"type": "Endpoint Detection and Response (EDR)",
"vendor": "CrowdStrike"
}
headers = {
"BLINK-API-KEY": "<api-key>",
"Content-Type": "*/*"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'BLINK-API-KEY': '<api-key>', 'Content-Type': '*/*'},
body: JSON.stringify({
description: 'Malware detected and blocked by CrowdStrike Falcon',
event: '{"process": "malware.exe", "action": "blocked"}',
name: 'CrowdStrike Falcon Detection',
processing_status: 'Missing Template',
severity: 3,
type: 'Endpoint Detection and Response (EDR)',
vendor: 'CrowdStrike'
})
};
fetch('https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'description' => 'Malware detected and blocked by CrowdStrike Falcon',
'event' => '{"process": "malware.exe", "action": "blocked"}',
'name' => 'CrowdStrike Falcon Detection',
'processing_status' => 'Missing Template',
'severity' => 3,
'type' => 'Endpoint Detection and Response (EDR)',
'vendor' => 'CrowdStrike'
]),
CURLOPT_HTTPHEADER => [
"BLINK-API-KEY: <api-key>",
"Content-Type: */*"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts"
payload := strings.NewReader("{\n \"description\": \"Malware detected and blocked by CrowdStrike Falcon\",\n \"event\": \"{\\\"process\\\": \\\"malware.exe\\\", \\\"action\\\": \\\"blocked\\\"}\",\n \"name\": \"CrowdStrike Falcon Detection\",\n \"processing_status\": \"Missing Template\",\n \"severity\": 3,\n \"type\": \"Endpoint Detection and Response (EDR)\",\n \"vendor\": \"CrowdStrike\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("BLINK-API-KEY", "<api-key>")
req.Header.Add("Content-Type", "*/*")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts")
.header("BLINK-API-KEY", "<api-key>")
.header("Content-Type", "*/*")
.body("{\n \"description\": \"Malware detected and blocked by CrowdStrike Falcon\",\n \"event\": \"{\\\"process\\\": \\\"malware.exe\\\", \\\"action\\\": \\\"blocked\\\"}\",\n \"name\": \"CrowdStrike Falcon Detection\",\n \"processing_status\": \"Missing Template\",\n \"severity\": 3,\n \"type\": \"Endpoint Detection and Response (EDR)\",\n \"vendor\": \"CrowdStrike\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.blinkops.com/api/v1/workspace/{ws_id}/case_management/table/alerts")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["BLINK-API-KEY"] = '<api-key>'
request["Content-Type"] = '*/*'
request.body = "{\n \"description\": \"Malware detected and blocked by CrowdStrike Falcon\",\n \"event\": \"{\\\"process\\\": \\\"malware.exe\\\", \\\"action\\\": \\\"blocked\\\"}\",\n \"name\": \"CrowdStrike Falcon Detection\",\n \"processing_status\": \"Missing Template\",\n \"severity\": 3,\n \"type\": \"Endpoint Detection and Response (EDR)\",\n \"vendor\": \"CrowdStrike\"\n}"
response = http.request(request)
puts response.read_body{
"description": "Malware detected and blocked by CrowdStrike Falcon",
"event": "{\"process\": \"malware.exe\", \"action\": \"blocked\"}",
"name": "CrowdStrike Falcon Detection",
"processing_status": "Missing Template",
"severity": 3,
"type": "Endpoint Detection and Response (EDR)",
"vendor": "CrowdStrike"
}{
"data": {},
"details": "<string>",
"identifier": "<string>",
"message": "<string>",
"status": 404,
"user_error": {}
}Authorizations
Use your API key to access BlinkOps API. To generate an API key, please log in to your BlinkOps account and navigate to the API Keys section in the user settings page. Add the generated key to your request headers as BLINK-API-KEY.
Path Parameters
Workspace ID
Body
Alert Data
"Malware detected and blocked by CrowdStrike Falcon"
"{\"process\": \"malware.exe\", \"action\": \"blocked\"}"
"CrowdStrike Falcon Detection"
Unprocessed, Missing Template, Mid-processing, Bad Template, Processed "Missing Template"
3
Malware, Ransomware, Adware, Spyware, Crypto Miner, Data Exfiltration, Insider Threat, Network Intrusion, DoS, DDoS, MITM, SQL Injection, Email Spoofing, DNS Spoofing, C2 Communications, Rogue Device, Brute Force, Phishing, Compromised Credentials, Account Takeover, Physical, Vulnerability, Reconnaissance, Domain Takeover, Lateral Movement, Network Exposure, Data Exposure, Credential Exposure, Suspicious User Activity, Suspicious Login, Suspicious Network Activity, Suspicious USB Device, Security Policy Violation, Security Compliance Violation "Endpoint Detection and Response (EDR)"
CrowdStrike, Checkpoint, Delinea, Securonix, Falcon LogScale, Splunk, ArcSight, SolarWinds Service Desk, Datadog, SentinelOne, Microsoft Defender For Cloud, Microsoft Defender For Cloud Apps, Microsoft Defender For Endpoints "CrowdStrike"
Response
OK
"Malware detected and blocked by CrowdStrike Falcon"
"{\"process\": \"malware.exe\", \"action\": \"blocked\"}"
"CrowdStrike Falcon Detection"
Unprocessed, Missing Template, Mid-processing, Bad Template, Processed "Missing Template"
3
Malware, Ransomware, Adware, Spyware, Crypto Miner, Data Exfiltration, Insider Threat, Network Intrusion, DoS, DDoS, MITM, SQL Injection, Email Spoofing, DNS Spoofing, C2 Communications, Rogue Device, Brute Force, Phishing, Compromised Credentials, Account Takeover, Physical, Vulnerability, Reconnaissance, Domain Takeover, Lateral Movement, Network Exposure, Data Exposure, Credential Exposure, Suspicious User Activity, Suspicious Login, Suspicious Network Activity, Suspicious USB Device, Security Policy Violation, Security Compliance Violation "Endpoint Detection and Response (EDR)"
CrowdStrike, Checkpoint, Delinea, Securonix, Falcon LogScale, Splunk, ArcSight, SolarWinds Service Desk, Datadog, SentinelOne, Microsoft Defender For Cloud, Microsoft Defender For Cloud Apps, Microsoft Defender For Endpoints "CrowdStrike"
Was this page helpful?