Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt

Use this file to discover all available pages before exploring further.

Get a list of forensic events. Required scope: investigation-workbench:read

Parameters

ParameterDescription
Company IDThe Mitiga client company ID. Required when acting on behalf of another company.
End TimeThe end time to filter results to.
EntityThe forensic entity ID to filter results by.
Entity Comparison TypeThe search operator for the Entity filter. Defaults to EqualsCaseInsensitive.
Entity TypeThe type of entity to filter results by.
Event TypeA comma-separated list of forensic event types to filter results by.
IP AddressA comma-separated list of IPv4, IPv6, or hostnames to filter forensic events by.
ImportanceA comma-separated list of importance levels to filter forensic events by.
Include Beta EventsSelect to include beta events in the results.
Is PublishedSelect to filter forensic events by whether they are published.
PlatformsA comma-separated list of platforms to filter by.

For example: AWS, M365, AzureAD, GCP, Okta, Github, and more.
Start TimeThe start time to filter results from.
StatusA comma-separated list of forensic event statuses to filter results by.
Suppression StatusSelect the suppression status to filter forensic events by. Defaults to Retained (non-suppressed) events only.
VerdictA comma-separated list of verdicts to filter forensic events by.

Workflow Library Example

List Forensic Events with Mitiga and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop