External DocumentationTo learn more, visit the Rapid7 InsightIDR documentation.
Basic Parameters
| Parameter | Description |
|---|---|
| End Time | The end of the timeframe to filter the results by. |
| Page | The number of the page to return results from (zero-based). |
| Page Size | The maximum number of results to return per page. Valid range is 1-1000. |
| Return All Pages | Automatically fetch all resources, page by page. |
| Start Time | The start of the timeframe to filter the results by. |
| Statuses | A comma-separated list of statuses of investigations to filter by. |
| Tags | A comma-separated list of tags to include in the response. Only investigations who have all specified tags will be included. For Example: Incident, Security Test, Reported to Customer. |
Advanced Parameters
| Parameter | Description |
|---|---|
| Assignee Email Address | The email address of the assignee to filter the results by. |
| Multi Customer | When selected, investigations will be returned from all organizations the connected user has access to. Note: This feature is available for multi-customer user keys only. |
| Priorities | A comma-separated list of investigation priorities to filter the results by. For Example - UNSPECIFIED, LOW, MEDIUM, HIGH, CRITICAL |
| Sort | An investigation field to filter the results by, concatenated with the direction of sorting. For Example: priority,DESCAvailable sorting parameters: - created_time - priority - rrn - alerts_most_recent_created_time - alerts_most_recent_detection_created_time Available sorting directions: - DESC - ASC |
| Sources | A comma-separated list of investigation sources to filter the results by. For Example - USER,ALERT |