External DocumentationTo learn more, visit the Vectra Detect documentation.
Basic Parameters
| Parameter | Description |
|---|---|
| Destination | Filter detections by the destination in the detection details set. |
| Fields | The fields to include in the response. |
| Page | The page number to return. |
| Page Size | The maximum number of results to return. |
| Protocol | Filter detections by the protocol in the detection details set. |
| Return All Pages | Automatically fetch all resources, page by page. |
| Sort | Order results by a specific attribute. Note: Results are sorted in ascending order by default. Add a leading - (minus sign) to sort in descending order instead. |
| State | Filter detections by their state. |
Advanced Parameters
| Parameter | Description |
|---|---|
| C-Score | Filter detections by their c_score field. |
| C-Score Greater Than or Equal To | Only return detections with a c_score field value greater than or equal to the specified value. |
| Category | Filter detections by their category field. |
| Certainty | Filter detections by their certainty field. |
| Certainty Greater Than or Equal To | Only return detections with a certainty field value greater than or equal to the specified value. |
| Detection Category | Filter detections by their detection_category field. |
| Detection Type | Filter detections by their detection_type field. |
| Host ID | Filter detections by the ID of the host object the detection is attributed to. |
| Is Targeting Key Asset | Filters on detections targeting key assets. |
| Last Timestamp | Filter detections by their last_timestamp field. |
| Last Timestamp Greater Than or Equal To | Only return detections with a last_timestamp field value greater than or equal to the specified value. |
| Maximum ID | Return only detections whose ID is less than or equal to the specified value. |
| Minimum ID | Return only detections whose ID is greater than or equal to the specified value. |
| Note Modified Timestamp Greater Than or Equal To | Only return detections with a note_modified_timestamp field value greater than or equal to the specified value. |
| Source IP | Filter detections by their source IP address. |
| T-Score | Filter detections by their t_score field. |
| T-Score Greater Than or Equal To | Only return detections with a t_score field value greater than or equal to the specified value. |
| Tags | Filter detections based on their tags. Note: Detections that match any of the specified tags will be returned. |
| Threat | Filter detections by their threat field. |
| Threat Greater Than or Equal To | Only return detections with a threat field value greater than or equal to the specified value. |