openapi: 3.2.0 info: title: Aeris Events API x-refined-note: - x-api-id differs across the merged source definitions and was not carried - x-audience differs across the merged source definitions and was not carried version: '1.0' description: 'Operations tagged Events across 2 of this provider''s published API definitions: subscription-signalling-events-api.yaml, watchtower-api-openapi.yaml. Each path carries the servers of the definition it was published in.' servers: - url: https://iot-api.aeris.com/iot/api/xdr description: API server - url: https://watchtower-api-prd.aeriscloud.com tags: - name: Events description: Signalling events for subscriptions. paths: /events: get: tags: - Events summary: List subscription events description: 'This resource will return a list of signalling events registered for all the IMSIs that you supply in the request. ### NOTE: * Data is only available from 1 day prior to the current time. * The maximum interval to query is 1 day.' operationId: listSubscriptionEvents parameters: - $ref: '#/components/parameters/imsiParam' - $ref: '#/components/parameters/fromParam' - $ref: '#/components/parameters/toParam' - $ref: '#/components/parameters/limitParam' - $ref: '#/components/parameters/codeParam' - $ref: '#/components/parameters/sortParam' - $ref: '#/components/parameters/additionalFieldsParam' - $ref: '#/components/parameters/cursorParam' responses: '200': description: OK headers: X-RateLimit-Limit-Second: $ref: '#/components/headers/X-RateLimit-Limit-Second' X-RateLimit-Limit-Minute: $ref: '#/components/headers/X-RateLimit-Limit-Minute' X-RateLimit-Remaining-Second: $ref: '#/components/headers/X-RateLimit-Remaining-Second' X-RateLimit-Remaining-Minute: $ref: '#/components/headers/X-RateLimit-Remaining-Minute' content: application/json: schema: type: object properties: next: description: Opaque string returned within the meta object response on endpoints which support pagination. Indicates that more results are available and can be used as the 'cursor' parameter in the next request to return the next page of results. The last page of results will not have a 'next' present. type: string example: DFVSDB3434%DFB%EYY445 items: type: array items: $ref: '#/components/schemas/Event' '400': description: Bad reqeust. content: application/problem+json: schema: $ref: '#/components/schemas/400Response' '401': description: Authentication Failure content: application/problem+json: schema: $ref: '#/components/schemas/401Response' '404': description: No Found content: application/problem+json: schema: $ref: '#/components/schemas/404Response' '500': description: Internal server error content: application/problem+json: schema: $ref: '#/components/schemas/500Response' '503': description: Service Unavailable content: application/problem+json: schema: $ref: '#/components/schemas/503Response' '529': description: Service Overloaded content: application/problem+json: schema: $ref: '#/components/schemas/529Response' default: description: The standard http error codes will be given. 4XX for client errors and 5XX for server errors. content: application/problem+json: schema: $ref: '#/components/schemas/ErrorResponse' security: - OAuth2: - xdr-raw-api.read - subscription-signalling-events.read servers: - url: https://iot-api.aeris.com/iot/api/xdr description: API server /events/{event_id}: get: deprecated: false tags: - Events summary: Get subscription event details description: Get subscription event details for the specified event id. operationId: getSubscriptionEventDetails parameters: - $ref: '#/components/parameters/eventIdParam' - $ref: '#/components/parameters/fieldsParam' responses: '200': description: OK headers: X-RateLimit-Limit-Second: $ref: '#/components/headers/X-RateLimit-Limit-Second' X-RateLimit-Limit-Minute: $ref: '#/components/headers/X-RateLimit-Limit-Minute' X-RateLimit-Remaining-Second: $ref: '#/components/headers/X-RateLimit-Remaining-Second' X-RateLimit-Remaining-Minute: $ref: '#/components/headers/X-RateLimit-Remaining-Minute' content: application/json: schema: $ref: '#/components/schemas/Event' '400': description: Bad reqeust. content: application/problem+json: schema: $ref: '#/components/schemas/400Response' '401': description: Authentication Failure content: application/problem+json: schema: $ref: '#/components/schemas/401Response' '404': description: No Found content: application/problem+json: schema: $ref: '#/components/schemas/404Response' '500': description: Internal server error content: application/problem+json: schema: $ref: '#/components/schemas/500Response' '503': description: Service Unavailable content: application/problem+json: schema: $ref: '#/components/schemas/503Response' '529': description: Service Overloaded content: application/problem+json: schema: $ref: '#/components/schemas/529Response' default: description: The standard http error codes will be given. 4XX for client errors and 5XX for server errors. content: application/problem+json: schema: $ref: '#/components/schemas/ErrorResponse' security: - OAuth2: - xdr-raw-api.read - subscription-signalling-events.read servers: - url: https://iot-api.aeris.com/iot/api/xdr description: API server /watchtower/v1/events: put: summary: Update multiple Events description: This endpoint allows to update the status of one or more Events. operationId: updateEvents parameters: - $ref: '#/components/parameters/authorization' - $ref: '#/components/parameters/accountId' tags: - Events requestBody: content: application/json: schema: $ref: '#/components/schemas/EventsBulkUpdateRequest' responses: '200': description: Successfully updated '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' security: - oAuth2ClientCredentials: [] servers: - url: https://watchtower-api-prd.aeriscloud.com /watchtower/v1/events/search: post: summary: Search/Get Events description: This endpoint returns the list of Events. operationId: getEvents parameters: - $ref: '#/components/parameters/authorization' - $ref: '#/components/parameters/accountId' - $ref: '#/components/parameters/startTime' - $ref: '#/components/parameters/endTime' - $ref: '#/components/parameters/offset' - $ref: '#/components/parameters/limit' - $ref: '#/components/parameters/sort' tags: - Events requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/EventsQueryRequest' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PagedEventsTable' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '413': $ref: '#/components/responses/413' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' security: - oAuth2ClientCredentials: [] servers: - url: https://watchtower-api-prd.aeriscloud.com /watchtower/v1/events/{eventId}: get: summary: Get details of an Event description: This endpoint retrieves details about an Event. operationId: getEvent parameters: - $ref: '#/components/parameters/authorization' - $ref: '#/components/parameters/accountId' - $ref: '#/components/parameters/eventId' tags: - Events responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/Event_2' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' security: - oAuth2ClientCredentials: [] put: summary: Update a single Event (Lifecycle operation) description: This endpoint allows to update the status of an Event and provide a comment. operationId: updateEvent parameters: - $ref: '#/components/parameters/authorization' - $ref: '#/components/parameters/accountId' - $ref: '#/components/parameters/eventId' tags: - Events requestBody: content: application/json: schema: $ref: '#/components/schemas/EventsUpdateRequest' responses: '200': description: Successfully updated '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' security: - oAuth2ClientCredentials: [] servers: - url: https://watchtower-api-prd.aeriscloud.com /watchtower/v1/events/export: post: summary: Export Events description: Use this endpoint to export the Events report as CSV. operationId: exportEvents parameters: - $ref: '#/components/parameters/authorization' - $ref: '#/components/parameters/accountId' - $ref: '#/components/parameters/startTime' - $ref: '#/components/parameters/endTime' - $ref: '#/components/parameters/sort' tags: - Events requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/EventsQueryRequest' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ScheduledReport' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' security: - oAuth2ClientCredentials: [] servers: - url: https://watchtower-api-prd.aeriscloud.com /watchtower/v1/events/metrics/search: post: summary: Get Events Metrics description: This endpoint returns metrics about Events. Allows you to retrieve arbitrary metrics by supplying dimensions, metrics and filters. operationId: getEventsMetrics parameters: - $ref: '#/components/parameters/authorization' - $ref: '#/components/parameters/accountId' - $ref: '#/components/parameters/startTime' - $ref: '#/components/parameters/endTime' - $ref: '#/components/parameters/offset' - $ref: '#/components/parameters/limit' - $ref: '#/components/parameters/sort' tags: - Events requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/EventsMetricsRequest' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PagedSummaryTable' example: total: 4 limit: 10 offset: 0 schema: fields: - name: status type: STRING - name: cnt__event_id type: INTEGER data: - - New - 15 - - Saved For Review - 5 - - Dismissed - 6 - - Completed - 10 '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' security: - oAuth2ClientCredentials: [] servers: - url: https://watchtower-api-prd.aeriscloud.com /watchtower/v1/aggregate-events/metrics/search: post: summary: Get Aggregated Events Metrics description: This endpoint returns metrics about Aggregates events. operationId: getAggregatedEventsMetrics parameters: - $ref: '#/components/parameters/authorization' - $ref: '#/components/parameters/accountId' - $ref: '#/components/parameters/startTime' - $ref: '#/components/parameters/endTime' - $ref: '#/components/parameters/offset' - $ref: '#/components/parameters/limit' - $ref: '#/components/parameters/sort' tags: - Events requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AggregatedEventsQueryRequest' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/PagedSummaryTable' example: total: 4 limit: 10 offset: 0 lastEvaluatedDate: '2025-10-10' schema: fields: - name: status type: STRING - name: cnt__event_id type: INTEGER data: - - New - 15 - - Saved For Review - 5 - - Dismissed - 6 - - Completed - 10 '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' security: - oAuth2ClientCredentials: [] servers: - url: https://watchtower-api-prd.aeriscloud.com components: parameters: imsiParam: in: query name: imsi description: One or more imsi(s), comma separated, which identifies the subscription(s) to get events for, e.g. "238208000000001,238208000000002". The maximum imsi number is 15. required: true style: form explode: false schema: type: string allowReserved: true example: 238208000000001,238208000000002 toParam: in: query name: to description: The end time, UTC, for the time window processed to generate the response, e.g. "2019-06-28T00:00:00.000Z". If not input, will use default value "Now (UTC)". required: false schema: type: string format: date-time allowReserved: true example: '2019-06-28T01:00:00.000Z' additionalFieldsParam: name: additionalFields in: query description: "Parameter used to filter the response object, you can determine a subset of additional fields that you want to\ninclude in the response, e.g. \"lac,apn\".\n\n\n__Request__\n\n\nGET /events\n\n\n__Response__\n\n```json\n\n{\n \"next\": \"DFVSDB3434%DFB%EYY445\",\n \"items\": [\n {\n \"imsi\": \"238208000000001\",\n \"id\": \"WOh6LIABUqU6IY0JSVLK\",\n \"code\": \"m46-0\",\n \"occurred_at\": \"2017-06-27T15:47:03.000Z\",\n }\n ...\n ]\n}\n\n```\n\n\n__Request__\n\n\nGET /events?__additionalFields=lac,apn__\n\n\n__Response__\n\n```json\n\n{\n \"next\": \"DFVSDB3434%DFB%EYY445\",\n \"items\": [\n {\n \"imsi\": \"238208000000001\",\n \"id\": \"WOh6LIABUqU6IY0JSVLK\",\n \"code\": \"m46-0\",\n \"occurred_at\": \"2017-06-27T15:47:03.000Z\",\n \"lac\": \"2323\",\n \"apn\": \"ericsson.api.net\"\n }\n ...\n ]\n}\n\n```\n" required: false schema: type: string allowReserved: true sortParam: in: query name: sort description: Sort parameter containing sort field and sort mode used for getting the event data, e.g. "occurred_at:asc". If not input, will use default value "occurred_at:asc". schema: type: string enum: - code:asc - code:desc - occurred_at:asc - occurred_at:desc allowReserved: true fromParam: in: query name: from description: The start time, UTC, for the time window processed to generate the response, e.g. "2019-06-28T00:00:00.000Z". If not input, will use default value "One hour ago (UTC)". required: false schema: type: string format: date-time allowReserved: true example: '2019-06-28T00:00:00.000Z' codeParam: in: query name: code description: One or more codes, comma separated, filtering which events to retrieve, e.g. "l42,m56". required: false schema: type: string example: l42,m56 eventIdParam: in: path name: event_id description: An id which identifies a specific signalling event, which is the id field in response of /events. required: true schema: type: string limitParam: in: query name: limit description: Specifies the maximum number of events to be returned, allowed interval is 1-1000, if not input, will use default value "100". required: false schema: type: integer minimum: 1 maximum: 1000 example: 100 cursorParam: in: query name: cursor description: 'Parameter used for display the content of next page on pagination, cannot be used with other parameters in one request. Set to the value of ''next'' for the next page of results. ' schema: type: string allowReserved: true fieldsParam: name: fields in: query description: "Parameter used to filter the response object, you can determine a subset of fields that you want to\ninclude in the response, e.g. \"(imsi,lac)\".\n\n\n__Request__\n\n\nGET /events/WOh6LIABUqU6IY0JSVLK\n\n\n__Response__\n\n```json\n\n{\n \"imsi\": \"238208000000001\",\n \"id\": \"WOh6LIABUqU6IY0JSVLK\",\n \"code\": \"m46-0\",\n \"occurred_at\": \"2017-06-27T15:47:03.000Z\",\n \"rat_type\": 1,\n \"visited_nw\": \"France | Orange\",\n \"imei\": \"676767676767\",\n \"lac\": \"2323\",\n \"lai\": \"2323\",\n \"ggsn_ip\": \"8.8.8.8\",\n \"sgsn_ip\": \"8.8.4.4\",\n \"apn\": \"ericsson.api.net\"\n ...\n}\n\n```\n\n\n__Request__\n\n\nGET /events/WOh6LIABUqU6IY0JSVLK?__fields=(imsi,lac)__\n\n\n__Response__\n\n```json\n\n{\n \"imsi\": \"238208000000001\",\n \"lac\": \"2323\"\n}\n\n```\n" required: false schema: type: string allowReserved: true startTime: name: startTime in: query required: true description: The start timestamp. (inclusive) example: '2021-07-01T06:30:00Z' schema: $ref: '#/components/schemas/dateTime' endTime: name: endTime in: query required: true description: The end timestamp. (exclusive) example: '2021-07-05T06:30:00Z' schema: $ref: '#/components/schemas/dateTime' sort: name: sort in: query description: Use sort=comma-separated-fields[:asc|desc] to sort the result. example: deviceId,updateTime:desc schema: type: string accountId: name: X-Watchtower-Account-Id in: header description: Account Id required: true schema: $ref: '#/components/schemas/accountId' example: 1002000010 offset: name: offset in: query description: The position in pagination. Specifies the starting row offset into the result set returned. For example, if the page size (limit) is 10, then to select the second page, pass the offset as 10 to retrieve items 11 to 20.

Search parameters must be consistent across pages. schema: $ref: '#/components/schemas/offset' eventId: name: eventId in: path description: Event Id required: true schema: $ref: '#/components/schemas/EventId' authorization: name: Authorization in: header description: Bearer Token for authentication required: true schema: type: string pattern: ^Bearer [A-Za-z0-9-._~+/]+=*$ example: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ... limit: name: limit in: query description: The number of items to retrieve per page (10000 max). schema: $ref: '#/components/schemas/limit' schemas: 503Response: allOf: - $ref: '#/components/schemas/ErrorResponse' - type: object properties: title: example: Service Unavailable status: example: 503 404Response: allOf: - $ref: '#/components/schemas/ErrorResponse' - type: object properties: title: example: No Found status: example: 404 ErrorResponse: type: object properties: type: type: string format: uri description: 'An absolute URI that identifies the problem type. When dereferenced,it SHOULD provide human-readable documentation for the problem type (e.g., using HTML). ' example: http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html#sec10.5.4 title: type: string description: 'A short, summary of the problem type. Written in english and readable for engineers (usually not suited for non technical stakeholders and not localized. ' example: Service Unavailable status: type: integer format: int32 description: The HTTP status code generated by the origin server for this occurrence of the problem. minimum: 100 example: 503 exclusiveMaximum: 600 detail: type: string description: A human readable explanation specific to this occurrence of the problem. example: Connection to database timed out. instance: type: string description: An absolute URI that identifies the specific occurrence of the problem. It may or may not yield further information if dereferenced. example: https://api.documentation.url/request-id parameters: type: object additionalProperties: type: string Event: type: object allOf: - $ref: '#/components/schemas/ListEvent' properties: rat_type: type: integer format: int32 description: ' Radio Access Technology (RAT) type values.
0reserved 
1UTRAN3G
2GERAN2G
3WLAN 
4GAN 
5HSPA Evolution 
6EUTRANLTE/4G
7Virtual 
8-255spare 
' visited_nw: type: string description: Visited mobile network. imei: type: string description: ' Device identity. For IMEISV, the IMEI field include first 14 digit decimal and CD field, ignoring the SVN digits. For the detail about CD field calculation, please refer to https://www.etsi.org/deliver/etsi_ts/123000_123099/123003/16.06.00_60/ts_123003v160600p.pdf Annex B ' lac: type: string description: ' Location area code. LAC field is also used to store TAC (Tracking Area Code) in 4G case. ' lai: type: string description: Location area identifier. ggsn_ip: type: string description: ' IP of the Gateway GPRS support node. Follow raw events might include this field: l2-0,l42,g1-0,g2-0,l1-0,l4-0,g4-0,l6-0,l7-0,g4-3,g1-3,g2-3,l1-3,g6-0,l2-3,l2-2,l7-3,l6-3,g6-3,l6-2,l4-2,l11-0,l4-3,l7-2,g4-1,l1-2,g6-1 ' sgsn_ip: type: string description: ' IP of the Serving GPRS support node. Follow raw events might include this field: l42,g1-0,g2-0,g4-0,g4-3,g1-3,g2-3,g6-0,g6-3,g4-1,g6-1 ' apn: type: string description: Access point name. cell_id: type: string description: Identity of accessing cell. destination_msisdn: type: string description: 'Destination mobile subscription. The destination_msisdn field in SMS MT (m46-0) is empty. Could get the info by IMSI field from "Subscription Search API". ' source_msisdn: type: string description: Source mobile subscription. enterprise_id: type: string description: Internal identity of the enterprise. gtp_cause: type: string description: ' GTP cause v{0,1} from the analytics records - GPRS.
-1UNKNOWN 
0Request IMSI 
1Request IMEI 
2 Request IMSI and IMEI 
3No identity needed 
4MS Refuses 
5MS is not GPRS Responding 
6Reactivation Requested 
7PDP address inactivity timer expires 
8Network Failure 
9QoS parameter mismatch 
10-48For future use 
49-63Cause values reserved for GPRS charging protocol use 
64-127For future use 
128Request accepted 
129New PDP type due to network preference 
130New PDP type due to single address bearer only 
131-176For future use 
177-191Cause values reserved for GPRS charging protocol use 
192Non-existent 
193Invalid message format 
194IMSI/IMEI not known 
195MS is GPRS Detached 
196MS is not GPRS Responding 
197MS Refuses 
198Version not supported 
199No resources available 
200Service not supported 
201Mandatory IE incorrect 
202Mandatory IE missing 
203Optional IE incorrect 
204System failure 
205Roaming restriction 
206P-TMSI Signature mismatch 
207GPRS connection suspended 
208Authentication failure 
209User authentication failed 
210Context not found 
211All dynamic PDP addresses are occupied 
212No memory is available 
213Relocation failure 
214Unknown mandatory extension header 
215Semantic error in the TFT operation 
216Syntactic error in the TFT operation 
217Semantic errors in packet filter(s) 
218Syntactic errors in packet filter(s) 
219Missing or unknown APN 
220Unknown PDP addressor PDP type 
221PDP context without TFT already activated 
222APN accessdenied – no subscription 
223APN Restriction type incompatibility with currently active PDP Contexts 
224MS MBMS Capabilities Insufficient 
225Invalid Correlation-ID 
226MBMS Bearer Context Superseded 
227Bearer Control Mode violation 
228Collision with network initiated request 
229APN Congestion 
230Bearer handling not supported 
231Target access restricted for the subscriber 
232UE is temporarily not reachable due to power saving 
233Relocation failure due to NAS message redirection 
234-240For future use 
241-255Cause values reserved for GPRS charging protocol use 
GTP cause v2 from the analytics records - LTE.
-1UNKNOWN 
0ReservedShall not be sent and if received the Cause shall be treated as an invalid IE
1Reserved 
2 Local Detach 
3Complete Detach 
4RAT changed from 3GPP to Non-3GPP 
5ISR deactivation 
6Error Indication received from RNC/eNodeB/S4-SGSN 
7IMSI Detach Only 
8Reactivation Requested 
9PDN reconnection to this APN disallowed 
10Access changed from Non-3GPP to 3GPP 
11PDN connection inactivity timer expiresUsed by the PGW in Delete Bearer Request(s) to indicate that all the bearer(s) for the emergency PDN connection are deleted upon the inactivity timer expiry
12PGW not respondingUsed by the SGW in PGW Restart Notification to indicate that the peer PGW has failed and not restarted
13Network FailureUsed by the SGSN or MME in the Delete Session Request to indicate that the message is sent due to a network problem
14QoS parameter mismatchUsed by the SGSN or MME in the Delete Session Request to indicate that the PDN connection can not be established due to a QoS parameter mismatch
15SpareThis value range shall be used by Cause values in an initial/request message
16Request acceptedReturned when the GTPv2 entity has accepted a control plane request
17Request accepted partially 
18New PDN type due to network preference 
19New PDN type due to single address bearer only 
20-63SpareThis value range shall be used by Cause values in an acceptance response/triggered message
64Context Not Found 
65Invalid Message Format 
66Version not supported by next peer 
67Invalid length 
68Service not supportedUsed by the GTP entity when it receives a message, which corresponds to a feature or a service which is not supported by the node
69Mandatory IE incorrect 
70Mandatory IE missing 
71Shall not be used 
72System failure 
73No resources available 
74Semantic error in the TFT operation 
75Syntactic error in the TFT operation 
76Semantic errors in packet filter(s) 
77Syntactic errors in packet filter(s) 
78Missing or unknown APN 
79Shall not be used 
80GRE key not found 
81Relocation failure 
82Denied in RAT 
83Preferred PDN type not supported 
84All dynamic addresses are occupied 
85UE context without TFT already activated 
86Protocol type not supported 
87UE not responding 
88UE refuses 
89Service denied 
90Unable to page UE 
91No memory available 
92User authentication failed 
93APN access denied - no subscription 
94Request rejected (reason not specified) 
95P-TMSI Signature mismatch 
96IMSI/IMEI not known 
97Semantic error in the TAD operation 
98Syntactic error in the TAD operation 
99Shall not be used 
100Remote peer not respondingUsed by the SGW for the messages spanning through two interfaces
101Collision with network initiated request 
102Unable to page UE due to Suspension 
103Conditional IE missing 
104APN Restriction type incompatible with active PDN connection 
105Invalid overall length of the triggered response message and a piggybacked initial message 
106Data forwarding not supported 
107Invalid reply from remote peer 
108Fallback to GTPv1 
109Invalid peer 
110Temporarily rejected due to handover/TAU/RAU procedure in progress 
111Modifications not limited to S1-U bearers 
112Request rejected for a PMIPv6 reason 
113APN Congestion 
114Bearer handling not supported 
115UE already re-attached 
116Multiple PDN connections for a given APN not allowed 
117Target access restricted for the subscriber 
118Shall not be used 
119MME/SGSN refuses due to VPLMN Policy 
120GTP-C Entity Congestion 
121Late Overlapping Request  
122Timed out Request  
123UE is temporarily not reachable due to power saving 
124Relocation failure due to NAS message redirection 
125UE not authorised by OCS or external AAA Server 
126Multiple accesses to a PDN connection not allowed 
127Request rejected due to UE capability 
128-239SpareFor future use in a triggered/response message
240-255SpareFor future use in an initial/request message
' map_errorcode: type: integer format: int32 description: ' Map error code from the analytics records.
0No Error
1Unknown Subscriber
3Unknown MSC
5Unidentified Subscriber
6Absent Subscriber for SM
7Unknown Equipment
8Roaming Not Allowed
9Illegal Subscriber
10Bearer Service Not Provisione
11Teleservice Not Provisioned
12Illegal Equipment
13Call Barred
14Forwarding Violation
15CUG Reject
16Illegal SS Operation
17SS Error Status
18SS Not Available
19SS Subscription Violation
20SS Incompatibility
21Facility Not Supported
22Ongoing GroupCall
25No Handover Number Available
26Subsequent Handover Failure
27Absent Subscriber
28Incompatible Terminal
29ShortTerm Denial
30LongTerm Denial
31Subscriber Busy For MT SMS
32SM Delivery Failure
33Message Waiting List Full
34System failure
35Data Missing
36Unexpected Data Value
37PW Registration Failure
38Negative PW Check
39No Roaming Number Available
40tracingBufferFull
42Target Cell Outside GroupCall
43Number of PW Attempts Violati
45Busy Subscriber
46No Subscriber Reply
47Forwarding Failed
48OR Not Allowed
49ATI Not Allowed
50No GroupCall Number Available
51Resource Limitation
52Unauthorized Requesting Network
53Unauthorized LCS Client
54Position Method Failure
58Unknown or Unreachable LCS Cl
59MM Event Not Supported
60ATSI Not Allowed
61ATM Not Allowed
62Information Not Available
71Unknown Alphabet
72USSD Busy
144Number Changed
' map_status: type: string description: ' Map status from the analytics records.
0Normalmap_errorcode defines the result of the successfull map signal
1Setup 
3TimeoutThere was a signalling timeout
4AbortAn error occurred, causing a signalling abortion
' mcc: type: string description: Mobile country code. mnc: type: string description: Mobile network code. pdprx: type: integer format: int64 description: The amount of data received in bytes. pdptx: type: integer format: int64 description: The amount of data transmitted in bytes. terminal_ip: type: string description: IP of the device. result_code: type: integer format: int32 description: ' LTE control plane diameter signal.
0UNDEFINEDProbably experimental_resultcode is returned, instead of result_code, which is not part of the API.
1001DIAMETER_MULTI_ROUND_AUTHThis informational error is returned by a Diameter server to inform the access device that the authentication mechanism being used requires multiple round trips, and a subsequent request needs to be issued in order for access to be granted.
2001DIAMETER_SUCCESSThe Request was successfully completed.
2002DIAMETER_LIMITED_SUCCESSWhen returned, the request was successfully completed, but additional processing is required by the application in order to provide service to the user.
3001DIAMETER_COMMAND_UNSUPPORTEDThe Request contained a Command-Code that the receiver did not recognize or support. This MUST be used when a Diameter node receives an experimental command that it does not understand.
3002DIAMETER_UNABLE_TO_DELIVERThis error is given when Diameter can not deliver the message to the destination, either because no host within the realm supporting the required application was available to process the request, or because Destination-Host AVP was given without the associated Destination-Realm AVP.
3003DIAMETER_REALM_NOT_SERVEDThe intended realm of the request is not recognized.
3004DIAMETER_TOO_BUSYWhen returned, a Diameter node SHOULD attempt to send the message to an alternate peer. This error MUST only be used when a specific server is requested, and it cannot provide the requested service.
3005DIAMETER_LOOP_DETECTEDAn agent detected a loop while trying to get the message to the intended recipient. The message MAY be sent to an alternate peer, if one is available, but the peer reporting the error has identified a configuration problem.
3006DIAMETER_REDIRECT_INDICATIONA redirect agent has determined that the request could not be satisfied locally and the initiator of the request should direct the request directly to the server, whose contact information has been added to the response. When set, the Redirect-Host AVP MUST be present.
3007DIAMETER_APPLICATION_UNSUPPORTEDA request was sent for an application that is not supported.
3008DIAMETER_INVALID_HDR_BITSA request was received whose bits in the Diameter header were either set to an invalid combination, or to a value that is inconsistent with the command code''s definition.
3009DIAMETER_INVALID_AVP_BITSA request was received that included an AVP whose flag bits are set to an unrecognized value, or that is inconsistent with the AVP''s definition.
3010DIAMETER_UNKNOWN_PEERA CER was received from an unknown peer.
4001DIAMETER_AUTHENTICATION_REJECTEDThe authentication process for the user failed, most likely due to an invalid password used by the user. Further attempts MUST only be tried after prompting the user for a new password.
4002DIAMETER_OUT_OF_SPACEA Diameter node received the accounting request but was unable to commit it to stable storage due to a temporary lack of space.
4003ELECTION_LOSTThe peer has determined that it has lost the election process and has therefore disconnected the transport connection.
5001DIAMETER_AVP_UNSUPPORTEDThe peer received a message that contained an AVP that is not recognized or supported and was marked with the ''M'' (Mandatory) bit. A Diameter message with this error MUST contain one or more Failed-AVP AVPs containing the AVPs that caused the failure.
5002DIAMETER_UNKNOWN_SESSION_IDThe request contained an unknown Session-Id.
5003DIAMETER_AUTHORIZATION_REJECTEDA request was received for which the user could not be authorized. This error could occur if the service requested is not permitted to the user.
5004DIAMETER_INVALID_AVP_VALUEThe request contained an AVP with an invalid value in its data portion. A Diameter message indicating this error MUST include the offending AVPs within a Failed-AVP AVP.
5005DIAMETER_MISSING_AVPThe request did not contain an AVP that is required by the Command Code definition. If this value is sent in the Result-Code AVP, a Failed-AVP AVP SHOULD be included in the message. The Failed-AVP AVP MUST contain an example of the missing AVP complete with the Vendor-Id if applicable. The value field of the missing AVP should be of correct minimum length and contain zeroes.
5006DIAMETER_RESOURCES_EXCEEDEDA request was received that cannot be authorized because the user has already expended allowed resources. An example of this error condition is when a user that is restricted to one dial-up PPP port attempts to establish a second PPP connection.
5007DIAMETER_CONTRADICTING_AVPSThe Home Diameter server has detected AVPs in the request that contradicted each other, and it is not willing to provide service to the user. The Failed-AVP AVP MUST be present, which contain the AVPs that contradicted each other.
5008DIAMETER_AVP_NOT_ALLOWEDA message was received with an AVP that MUST NOT be present. The Failed-AVP AVP MUST be included and contain a copy of the offending AVP.
5009DIAMETER_AVP_OCCURS_TOO_MANY_TIMESA message was received that included an AVP that appeared more often than permitted in the message definition. The Failed-AVP AVP MUST be included and contain a copy of the first instance of the offending AVP that exceeded the maximum number of occurrences.
5010DIAMETER_NO_COMMON_APPLICATIONThis error is returned by a Diameter node that receives a CER whereby no applications are common between the CER sending peer and the CER receiving peer.
5011DIAMETER_UNSUPPORTED_VERSIONThis error is returned when a request was received, whose version number is unsupported.
5012DIAMETER_UNABLE_TO_COMPLYThis error is returned when a request is rejected for unspecified reasons.
5013DIAMETER_INVALID_BIT_IN_HEADERThis error is returned when a reserved bit in the Diameter header is set to one (1) or the bits in the Diameter header are set incorrectly.
5014DIAMETER_INVALID_AVP_LENGTHThe request contained an AVP with an invalid length. A Diameter message indicating this error MUST include the offending AVPs within a Failed-AVP AVP.
5015DIAMETER_INVALID_MESSAGE_LENGTHThis error is returned when a request is received with an invalid message length.
5016DIAMETER_INVALID_AVP_BIT_COMBOThe request contained an AVP with which is not allowed to have the given value in the AVP Flags field. A Diameter message indicating this error MUST include the offending AVPs within a Failed-AVP AVP.
5017DIAMETER_NO_COMMON_SECURITYThis error is returned when a CER message is received, and there are no common security mechanisms supported between the peers. A Capabilities-Exchange-Answer (CEA) message MUST be returned with the Result-Code AVP set to DIAMETER_NO_COMMON_SECURITY.
' exp_resultcode: type: integer format: int32 description: ' Experimental result codes are controlled in a vendor-specific manner. The present document lists the 3GPP specific Experimental result codes in 3GPP TS 29.230.
2001DIAMETER_FIRST_REGISTRATION
2002DIAMETER_SUBSEQUENT_REGISTRATION
2003DIAMETER_UNREGISTERED_SERVICE
2004DIAMETER_SUCCESS_SERVER_NAME_NOT_STORED
2005Deprecated value
2006 to 2020reserved for the TS 29.229
2021DIAMETER_PDP_CONTEXT_DELETION_INDICATION
2022 to 2040reserved for the TS 29.061
2401 to 2420reserved for the TS 29.109
4100DIAMETER_USER_DATA_NOT_AVAILABLE
4101DIAMETER_PRIOR_UPDATE_IN_PROGRESS
4102 to 4120reserved for the TS 29.329
4121DIAMETER_ERROR_OUT_OF_RESOURCES
4122 to 4140reserved for the TS 29.061
4141DIAMETER_PCC_BEARER_EVENT
4142DIAMETER_BEARER_EVENT
4143 to 4160reserved for the TS 29.212
4161 to 4180reserved for the TS 32.299
4181DIAMETER_AUTHENTICATION_DATA_UNAVAILABLE
4182 to 4200reserved for the TS 29.272
5001DIAMETER_ERROR_USER_UNKNOWN
5002DIAMETER_ERROR_IDENTITIES_DONT_MATCH
5003DIAMETER_ERROR_IDENTITY_NOT_REGISTERED
5004DIAMETER_ERROR_ROAMING_NOT_ALLOWED
5005DIAMETER_ERROR_IDENTITY_ALREADY_REGISTERED
5006DIAMETER_ERROR_AUTH_SCHEME_NOT_SUPPORTED
5007DIAMETER_ERROR_IN_ASSIGNMENT_TYPE
5008DIAMETER_ERROR_TOO_MUCH_DATA
5009DIAMETER_ERROR_NOT_SUPPORTED_USER_DATA
5010unassigned
5011DIAMETER_ERROR_FEATURE_UNSUPPORTED
5012 to 5020reserved for the TS 29.229
5021 to 5040reserved for the TS 32.299
5041DIAMETER_ERROR_USER_NO_WLAN_SUBSCRIPTION
5042DIAMETER_ERROR_W-APN_UNUSED_BY_USER
5043DIAMETER_ERROR_NO_ACCESS_INDEPENDENT_SUBSCRIPTION
5044DIAMETER_ERROR_USER_NO_W-APN_SUBSCRIPTION
5045DIAMETER_ERROR_UNSUITABLE_NETWORK
5046 to 5060reserved for the TS 29.234
5061INVALID_SERVICE_INFORMATION
5062FILTER_RESTRICTIONS
5063REQUESTED_SERVICE_NOT_AUTHORIZED
5064DUPLICATED_AF_SESSION
5065IP-CAN_SESSION_NOT_AVAILABLE
5066 to 5080reserved for TS 29.209, TS 29.211 and TS 29.214 [18]
5100DIAMETER_ERROR_USER_DATA_NOT_RECOGNIZED
5101DIAMETER_ERROR_OPERATION_NOT_ALLOWED
5102DIAMETER_ERROR_USER_DATA_CANNOT_BE_READ
5103DIAMETER_ERROR_USER_DATA_CANNOT_BE_MODIFIED
5104DIAMETER_ERROR_USER_DATA_CANNOT_BE_NOTIFIED
5105DIAMETER_ERROR_TRANSPARENT_DATAOUT_OF_SYNC
5106DIAMETER_ERROR_SUBS_DATA_ABSENT
5107DIAMETER_ERROR_NO_SUBSCRIPTION_TO_DATA
5108DIAMETER_ERROR_DSAI_NOT_AVAILABLE
5109 to 5119reserved for the TS 29.329
5120DIAMETER_ERROR_START_INDICATION
5121DIAMETER_ERROR_STOP_INDICATION
5122DIAMETER_ERROR_UNKNOWN_MBMS_BEARER_SERVICE
5123DIAMETER_ERROR_SERVICE_AREA
5124 to 5139reserved for the TS 29.061
5140DIAMETER_ERROR_INITIAL_PARAMETERS
5141DIAMETER_ERROR_TRIGGER_EVENT
5142DIAMETER_PCC_RULE_EVENT
5143DIAMETER_ERROR_BEARER_NOT_AUTHORIZED
5144DIAMETER_ERROR_TRAFFIC_MAPPING_INFO_REJECTED
5145DIAMETER_QOS_RULE_EVENT
5146reserved
5147DIAMETER_ERROR_CONFLICTING_REQUEST
5148 to 5159reserved for the TS 29.212
5401DIAMETER_ERROR_IDENTITY_UNKNOWN
5402DIAMETER_ERROR_NOT_AUTHORIZED
5403DIAMETER_ERROR_TRANSACTION_IDENTIFIER_INVALID
5404 to 5419reserved for the TS 29.109
5420DIAMETER_ERROR_UNKNOWN_EPS_SUBSCRIPTION
5421DIAMETER_ERROR_RAT_NOT_ALLOWED
5422DIAMETER_ERROR_EQUIPMENT_UNKNOWN
5423 to 5449reserved for the TS 29.272
5450DIAMETER_ERROR_USER_NO_NON_3GPP_SUBSCRIPTION
5451DIAMETER_ERROR_USER_NO_APN_SUBSCRIPTION
5452DIAMETER_ERROR_RAT_TYPE_NOT_ALLOWED
5453 to 5469reserved for the TS 29.273
5470DIAMETER_ERROR_SUBSESSION
5471 to 5489reserved for the TS 29.215
' ipv6_terminal_ip: type: string description: Internet Protocol Version 6 of the device. example: rat_type: 1 visited_nw: France | Orange imei: '676767676767' lac: '2323' lai: '2323' ggsn_ip: 8.8.8.8 sgsn_ip: 8.8.4.4 apn: ericsson.api.net cell_id: '34565' destination_msisdn: 0466498215 source_msisdn: 0466498216 enterprise_id: ericsson gtp_cause: Requestaccepted map_errorcode: 1 map_status: '0' mcc: '272' mnc: '06' pdprx: 1 pdptx: 1 terminal_ip: 1.2.3.4 result_code: 1 exp_resultcode: 2001 ipv6_terminal_ip: fd20:05b6:ef60:fd47:e614:85d2:cdf6:93ec 400Response: allOf: - $ref: '#/components/schemas/ErrorResponse' - type: object properties: title: example: Bad Request status: example: 400 500Response: allOf: - $ref: '#/components/schemas/ErrorResponse' - type: object properties: title: example: Internal server error status: example: 500 ListEvent: type: object required: - imsi - id - code - occurred_at properties: imsi: type: string description: The international mobile subscriber identity. An internationally standardized unique number to identify a mobile subscription. id: type: string description: Unique internal identity for the event. code: type: string description: ' Event type code from the analytics records.
g1-0PDP context active 
g1-1PDP context smAbort 
g1-2PDP context error 
g1-3PDP context timeout 
g2-0PDP context terminate 
g2-1PDP context terminate smAbort 
g2-2PDP context teminate error 
g2-3PDP context terminate timeout 
g3-0SGSN Context Request 
g4-0Modify PDP 
g4-1Modify PDP smAbort 
g4-3Modify PDP timeout 
g5-0Peak Report 
g6-0Error Indication 
g6-1Error Indication Abort 
g6-2Error Indication Error 
g6-3Error Indication Timeout 
m2GSM Location Update 
m3GSM Location Update cancelTriggered by Device Reconnect
m4Provide Roaming Number 
m7Insert Subscriber Data 
m8Delete Subscriber Data 
m9Send Parameters 
m12Activate SSSuppl services
m13Deactivate SSSuppl services
m14Interrogate SSSuppl services
m15Authentication Failure Report 
m22Send Routing InfoNo available currently
m23GPRS Location Update 
m25GPRS failure 
m26GPRS attachMobile station ready for 2G/3G
m44MT Forward SMForward Mobile Terminated SMS
m45Send Routing Info For SMNo available currently
m46-0SMS MT DeliverSM-TL(carried in mt-ForwardSM)
m46-1SMS MT Submit ReportSM-TL(carried in mo-ForwardSM Ack)
m46-2SMS MT Status ReportSM-TL (carried in mo-ForwardSM Ack)
m46-4SMS MO Deliver ReportSM-TL (carried in mt-ForwardSM Ack)
m46-5SMS MO SubmitSM-TL (carried in mo-ForwardSM)
m46-6SMS MO CommandSM-TL
m47Report SM-Delivery StatusShort message alert MAP procedure
m56Send Authentication Info 
m57Restore Data 
m59Process Unstructured SS-Request 
m63Inform Service Center 
m64Alert Service CenterShort message alert MAP procedure
m66Ready for SM 
m67Purge MSNo available currently
m70Provide Subscriber Info 
m71Any Time Interrogation 
m99Duplicated TcapId For Sms 
l1-0Create Session OK 
l1-1Create Session SM Abort 
l1-2Create Session Error 
l1-3Create Session Timeout 
l2-0Modify Bearer OK 
l2-1Modify Bearer SM Abort 
l2-2Modify Bearer Error 
l2-3Modify Bearer Timeout 
l3-0Release Access Bearers OK 
l3-1Release Access Bearers SM Abort 
l3-2Release Access Bearers Error 
l3-3Release Access Bearers Timeout 
l4-0Delete Session OK 
l4-1Delete Session SM Abort 
l4-2Delete Session Error 
l4-3Delete Session Timeout 
l5-0Create Bearer OK 
l5-1Create Bearer SM Abort 
l5-2Create Bearer Error 
l5-3Create Bearer Timeout 
l6-0Update Bearer OK 
l6-1Update Bearer SM Abort 
l6-2Update Bearer Error 
l6-3Update Bearer Timeout 
l7-0Delete Bearer Request OK 
l7-1Delete Bearer Request SM Abort 
l7-2Delete Bearer Request Error 
l7-3Delete Bearer Request Timeout 
l8-0Downlink Data Notification OK 
l8-1Downlink Data Notification SM Abort 
l8-2Downlink Data Notification Error 
l8-3Downlink Data Notification Timeout 
l9-0Downlink Data Notification Failure OK 
l9-1Downlink Data Notification Failure SM Abort 
l9-2Downlink Data Notification Failure Error 
l9-3Downlink Data Notification Failure Timeout 
l10-0Bearer Resource Failure OK 
l10-1Bearer Resource Failure SM Abort 
l10-2Bearer Resource Failure Error 
l10-3Bearer Resource Failure Timeout 
l11-0Modify Bearer Failure OK 
l11-1Modify Bearer Failure SM Abort 
l11-2Modify Bearer Failure Error 
l11-3Modify Bearer Failure Timeout 
l12-0Delete Bearer Failure OK 
l12-1Delete Bearer Failure SM Abort 
l12-2Delete Bearer Failure Error 
l12-3Delete Bearer Failure Timeout 
l42Throughput Data 
d300User Authorization Request 
d300-0User Authorization Success 
d300-1User Authorization Failure 
d301Server Assignment Request 
d301-0Server Assignment Success 
d301-1Server Assignment Failure 
d302Location Info Request 
d302-0Location Info Success 
d302-1Location Info Failure 
d303Multimedia Auth Request 
d303-0Multimedia Auth Success 
d303-1Multimedia Auth Failure 
d304Registration Termination Request 
d304-0Registration Termination Success 
d304-1Registration Termination Failure 
d305Push Profile Request 
d305-0Push Profile Success 
d305-1Push Profile Failure 
d306User Data Request 
d306-0User Data Success 
d306-1User Data Failure 
d307Profile Update Request 
d307-0Profile Update Success 
d307-1Profile Update Failure 
d308Subscribe Notifications Request 
d308-0Subscribe Notifications Success 
d308-1Subscribe Notifications Failure 
d316Update Location Request 
d316-0Update Location Success 
d316-1Update Location Failure 
d317Cancel Location Request 
d317-0Cancel Location Success 
d317-1Cancel Location Failure 
d318Authentication Information Request 
d318-0Authentication Information Success 
d318-1Authentication Information Failure 
d319Insert Subscriber Data Request 
d319-0Insert Subscriber Data Success 
d319-1Insert Subscriber Data Failure 
d320Delete Subscriber Data Request 
d320-0Delete Subscriber Data Success 
d320-1Delete Subscriber Data Failure 
d321Purge UE Request 
d321-0Purge UE Success 
d321-1Purge UE Failure 
d322Reset Mobile Station Request 
d322-0Reset Mobile Station Success 
d322-1Reset Mobile Station Failure 
d323Notify Home Subscriber Server Request 
d323-0Notify Home Subscriber Server Success 
d323-1Notify Home Subscriber Server Failure 
x42-0Change notification 
x42-2Bearer notification 
x42-4Session deletion 
' occurred_at: type: string format: date-time description: The time at which an activity on the subscription was recorded (RFC 3339 date-time) example: imsi: '238208000000001' id: WOh6LIABUqU6IY0JSVLK code: m46-0 occurred_at: '2019-06-27T15:47:03.000Z' 401Response: allOf: - $ref: '#/components/schemas/ErrorResponse' - type: object properties: title: example: Authentication Failure status: example: 401 529Response: allOf: - $ref: '#/components/schemas/ErrorResponse' - type: object properties: title: example: Service Overloaded status: example: 529 SummaryDataRows: type: array items: type: array items: {} PagedSummaryTable: allOf: - type: object properties: lastEvaluatedDate: type: string - $ref: '#/components/schemas/Pagination' - $ref: '#/components/schemas/PagedSummaryTableData' AggregateEventSecurityItem: description: Aggregate Event Security Item type: string example: Malicious Endpoint enum: - Unclassified - Address Scan - Malicious IP - New IP - New Port - Port Scan - SIM Misuse - TCP Bad Flags - TCP Max Flows - Traffic Spike - Malicious Endpoint - Botnet and C&C - Cryptocurrency - Data Exfiltration - Suspicious Endpoint - Phishing - Ransomware - Devices located according to expectations - Non IoT devices in use - Unencrypted data flow to private apps - Unencrypted data flow to public apps - Use of untrusted DNS servers - Data Sovereignty - Devices communicating using VPN - Non compliant communication - OFAC - Public applications - Removable devices in use - Blocked Flows - Devices utilizing private APN - Devices utilizing internet APN - 'Anomalous Mobility Event: Moving Outside a Location List' - 'Anomalous Mobility Event: Impossible Mobility' - High Frequency Reconnect - High Cell Disconnect Rate x-enum-varnames: - Unclassified - AddressScan - MaliciousIP - NewIP - NewPort - PortScan - SIMMisuse - TCPBadFlags - TCPMaxFlows - TrafficSpike - MaliciousEndpoint - BotnetAndCnC - Cryptocurrency - DataExfiltration - SuspiciousEndpoint - Phishing - Ransomware - DevicesLocatedAccordingToExpectations - NonIoTDevicesInUse - UnencryptedDataFlowToPrivateApps - UnencryptedDataFlowToPublicApps - UseOfUntrustedDNSServers - DataSovereignty - DevicesCommunicatingUsingVPN - NonCompliantCommunicationOFAC - PublicApplications - RemovableDevicesInUse - BlockedFlows - DevicesUtilizingPrivateAPN - DevicesUtilizingInternetAPN - AnomalousMobilityEventMovingOutsideLocationList - AnomalousMobilityEventImpossibleMobility - HighFrequencyReconnect - HighCellDisconnectRate SummaryDataSchema: type: object properties: fields: type: array items: $ref: '#/components/schemas/Field' total: type: integer format: int64 description: Total number of items available. example: 1 minimum: 0 PagedEventsTable: allOf: - $ref: '#/components/schemas/Pagination' - type: object properties: data: type: array items: $ref: '#/components/schemas/Event_2' AggregateEventRiskCategory: description: Aggregate Event Category type: string example: 'Device Security: Anomalous' enum: - 'Device Security: Anomalous' - 'Device Security: Suspicious' - 'Device Security: Malicious' - Inventory and Control of Devices - Data Protection - Network Security - Application Security - 'Device Security: Traffic' offset: description: Position in pagination. type: integer format: int32 default: 0 minimum: 0 limit: type: integer format: int32 description: Number of items to retrieve (10000 max). minimum: 1 maximum: 10000 default: 20 EventDeviceGroup: type: object properties: id: type: integer format: int32 name: type: string example: Group1 colorCode: type: string example: '#123aaff' domain: description: FQDN type: string example: abc.xyz.com malwareProtectionLevel: type: string enum: - NONE - ESSENTIAL - AGGRESSIVE - COMPREHENSIVE EventType: type: string description: Type of the Event example: Malicious Endpoint enum: - Address Scan - Botnet and C&C - Cryptocurrency - Data Exfiltration - Malicious Endpoint - New IP - New Port - Phishing - Port Scan - Ransomware - SIM Misuse - Suspicious Endpoint - TCP Bad Flags - TCP Max Flows - Traffic Spike - Unclassified - 'Anomalous Mobility: Moving Outside Location List' - 'Anomalous Mobility: Impossible Mobility' - High Frequency Reconnect - High Cell Disconnect Rate x-enum-varnames: - AddressScan - BotnetAndCnC - Cryptocurrency - DataExfiltration - MaliciousEndpoint - NewIP - NewPort - Phishing - PortScan - Ransomware - SIMMisuse - SuspiciousEndpoint - TCPBadFlags - TCPMaxFlows - TrafficSpike - Unclassified - AnomalousMobilityMovingOutsideLocationList - AnomalousMobilityImpossibleMobility - HighFrequencyReconnect - HighCellDisconnectRate accountId: description: Account Id. type: integer format: int32 example: 10407 minimum: 0 EventsBulkUpdateRequest: allOf: - type: object properties: eventIds: type: array items: type: string description: Event Id example: v1_1652823856823_6b71e284b63a527caa6296a66e9fdd0c maxLength: 128 minLength: 1 - $ref: '#/components/schemas/EventsUpdateRequest' port: type: integer description: Port number minimum: 0 maximum: 65536 example: 8080 EventSeverity: description: Severity of the Event type: string example: Critical enum: - Critical - High - Medium - Low x-enum-varnames: - Critical - High - Medium - Low Event_2: type: object properties: eventId: $ref: '#/components/schemas/EventId' eventTime: $ref: '#/components/schemas/dateTime' category: description: Category of the Event (example, Billing Events, Security Events etc) type: string example: Security type: description: Type of the Event type: string example: Sim Fraud severity: $ref: '#/components/schemas/EventSeverity' status: $ref: '#/components/schemas/EventStatus' statusReason: type: string description: Additional Reasoning about status/status change. description: description: Description about the Event type: string example: IMEI change, TAC change, minimal change in data consumption. eventTypeDescription: description: Description about the Event type. type: string example: Detected anomalous communication(s). notes: description: Notes entered by a human user while taking an action on Event. type: string iccid: $ref: '#/components/schemas/iccid' imsi: $ref: '#/components/schemas/imsi' deviceProfileId: $ref: '#/components/schemas/deviceProfileId' productId: description: Product Id associated with the device. type: integer format: int32 example: 41 eventConfigId: type: integer description: Event Config Id example: 134242 lastActionTime: $ref: '#/components/schemas/dateTime' lastActionUser: description: User who took some action on this Event. type: string format: email example: john.doe@example.com eventSource: type: string description: Source system of this Event example: Security Center context: type: object description: Context of Event. This is specific to each type of Event. additionalProperties: true deviceIp: $ref: '#/components/schemas/ip' devicePort: $ref: '#/components/schemas/port' serverIp: $ref: '#/components/schemas/ip' serverPort: $ref: '#/components/schemas/port' serverFqdn: $ref: '#/components/schemas/domain' deviceName: description: Name of the device. type: string maxLength: 30 example: Lawn Mower 007 eventTypeId: description: Event Type Id type: integer example: 5 severityId: description: Severity Id. Lower values means higher severity. type: integer example: 5 confidenceLevel: description: Indicates the system's certainty about the accuracy of the detected event. type: string example: 85 threatClass: description: Categorizes the type of threat. type: string example: APT threatLevel: description: Shows the severity of the identified threat. type: integer example: 100 threatDiagnostic: description: Provides detailed analysis and detection information of the threat. type: string example: The threat diagnostic identifies unusual login attempts from multiple locations. protectionLevel: description: This column will store the protection level with possible values. type: string example: Essential, Aggressive, Comprehensive. requestId: description: This column will store the request ID. type: string example: REQ201043380628 deviceGroups: type: array items: $ref: '#/components/schemas/EventDeviceGroup' apnNames: type: array items: type: string description: Access Point Names (APN) associated with this event. example: - apn1 - apn2 apnTypes: type: array items: type: string description: Types of Access Point Names (APN) associated with this event. example: - type2 - type1 imei: type: string description: Current International Mobile Equipment Identity of the device. example: '867157040972691' prevImei: type: string description: Previous International Mobile Equipment Identity of the device (sim misuse). example: '867157040972690' deviceType: type: string description: Type of the device. example: smartphone country: type: string description: Country associated with the device location. example: US postalCode: type: string description: Postal code associated with the device location. example: '94105' postalTown: type: string description: Postal town associated with the device location. example: San Francisco EventStatus: description: Status of the Event type: string example: Saved For Review enum: - New - Saved For Review - In Process - Resolved - Dismissed x-enum-varnames: - New - SavedForReview - InProcess - Resolved - Dismissed deviceProfileId: description: Device Profile ID assigned to the device. type: string maxLength: 30 example: AER0000007087071 ip: type: string description: IP Address example: 172.16.1.3 EventId: type: string description: Event Id example: v1_1652823856823_6b71e284b63a527caa6296a66e9fdd0c maxLength: 128 minLength: 1 Field: type: object properties: name: description: The field name. type: string type: description: The data type of the field. type: string enum: - BOOLEAN - DATE - TIMESTAMP - STRING - INTEGER - FLOAT - DOUBLE - ARRAY required: - name - type EventCategory: type: string description: Category of the Event example: Malicious enum: - Malicious - Suspicious - Anomalous msisdn: description: Mobile Station International Subscriber Directory Number. type: string maxLength: 15 example: '8801500121121' AggregateEventAssessedSeverity: description: Aggregate Event Severity type: string example: High enum: - Critical - High - Medium - Low Error: type: object properties: code: type: integer description: HTTP code example: 500 message: type: string description: Error message example: An error encountered in processing the request timestamp: type: string description: ISO DateTime example: '2025-06-02 09:01:53.678' path: type: string description: Endpoint path at which the error occured example: /watchtower/v1/events traceId: type: string description: Trace Id example: ed81f29f-ea9b-4099-aa00-f8ed40b7a567 PagedSummaryTableData: type: object properties: schema: $ref: '#/components/schemas/SummaryDataSchema' data: $ref: '#/components/schemas/SummaryDataRows' EventsMetricsRequest: allOf: - $ref: '#/components/schemas/EventsQueryRequest' - type: object properties: interval: type: string description: Time interval in ISO8601 duration format (e.g. P1D for daily, PT1H for hourly) example: PT1H dimensions: type: string description: Comma-separated list of dimensions example: type,status metrics: type: string description: Comma-separated list of metrics. use cnt__ to get count aggregate. example: cnt__event_id iccid: description: Integrated Circuit Card Identifier. type: string minLength: 18 maxLength: 22 example: '891004234814455936' dateTime: description: ISO 8601 date time type: string format: date-time example: '2021-07-04T17:36:47Z' Pagination: type: object properties: total: $ref: '#/components/schemas/total' offset: $ref: '#/components/schemas/offset' limit: $ref: '#/components/schemas/limit' endpointFQDN: description: Fully qualified domain name of the endpoint type: string maxLength: 253 minLength: 1 ScheduledReport: type: object properties: reportId: description: Report Id type: string example: 7ae9e22d-8ad4-4a69-950a-6b13d75f0c74 status: $ref: '#/components/schemas/ReportStatus' statusEndpoint: description: Report Status URL type: string example: /watchtower/v1/scheduled-reports/7ae9e22d-8ad4-4a69-950a-6b13d75f0c74 EventsUpdateRequest: type: object description: Object representing an event update request. properties: status: description: Status of the Event type: string example: Saved For Review enum: - New - Saved For Review - In Process - Resolved - Dismissed x-enum-varnames: - New - SavedForReview - InProcess - Resolved - Dismissed notes: description: Notes entered by a human user while taking an action on event. type: string example: Acknowledging the event. Starting investigation of IMEI change. reason: description: Additional Reasoning about status/status change. type: string example: False Positive email: type: string format: email description: Email id of the user requestId: description: This column will store the request ID. type: string example: REQ201043380628 ReportStatus: description: Report status type: string example: Processing enum: - Success - Processing - Error - NotStarted imsi: description: International Mobile Subscriber Identifier of the device. type: string maxLength: 15 example: '310009133100012' AggregatedEventsQueryRequest: type: object properties: securityItems: type: array items: $ref: '#/components/schemas/AggregateEventSecurityItem' assessedSeverities: type: array items: $ref: '#/components/schemas/AggregateEventAssessedSeverity' riskCategories: type: array items: $ref: '#/components/schemas/AggregateEventRiskCategory' EventsQueryRequest: type: object properties: imsi: $ref: '#/components/schemas/imsi' iccid: $ref: '#/components/schemas/iccid' msisdn: $ref: '#/components/schemas/msisdn' statuses: type: array items: $ref: '#/components/schemas/EventStatus' types: type: array items: $ref: '#/components/schemas/EventType' categories: type: array items: $ref: '#/components/schemas/EventCategory' confidentLevel: type: integer threatLevel: type: integer threatClass: type: string threatDiagnostic: type: string deviceIp: $ref: '#/components/schemas/ip' endpointIp: $ref: '#/components/schemas/ip' endpointPort: $ref: '#/components/schemas/port' matchingProtectionLevels: type: array items: $ref: '#/components/schemas/malwareProtectionLevel' fqdn: $ref: '#/components/schemas/endpointFQDN' requestId: type: string deviceGroupIds: type: array items: type: integer format: int32 description: Device Group Ids apnNames: type: array items: type: string description: Filter by APN names. All specified values must match (AND logic). example: - apn1 - apn2 apnTypes: type: array items: type: string description: Filter by APN types. All specified values must match (AND logic). example: - type1 - type2 imei: type: string description: Filter by device IMEI. example: '867157040972691' deviceType: type: string description: Filter by device type. example: smartphone countries: type: array items: type: string description: Country name. example: United States description: Filter by countries of device location (multi-value, OR logic). example: - United States - Germany postalCode: type: string description: Filter by postal code of device location. example: '94105' postalTown: type: string description: Filter by postal town of device location. example: San Francisco headers: X-RateLimit-Remaining-Second: description: The number of requests remaining in a second. schema: type: integer format: int32 X-RateLimit-Limit-Second: description: The maximum number of requests allowed in a second. schema: type: integer format: int32 X-RateLimit-Remaining-Minute: description: The number of requests remaining in a minute. schema: type: integer format: int32 X-RateLimit-Limit-Minute: description: The maximum number of requests allowed in a minute. schema: type: integer format: int32 responses: '429': description: Too many requests. content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 429 message: 'Rate Limit Exceeded (XX) for clientId: XXXXXX. Please retry after XXX seconds' timestamp: 2025-06-01 13:28:03.967000 path: /watchtower/v1/... traceId: c3db9d7a432317363c8bc5ddb5aadf4b '401': description: Not authorized. content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 401 message: Unauthorized timestamp: 2025-06-01 13:28:03.967000 path: /watchtower/v1/... traceId: c3db9d7a432317363c8bc5ddb5aadf4b '403': description: Forbidden. content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 403 message: Forbidden timestamp: 2025-06-01 13:28:03.967000 path: /watchtower/v1/... traceId: c3db9d7a432317363c8bc5ddb5aadf4b '400': description: Bad Request. content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 400 message: Bad Request timestamp: 2025-06-01 13:28:03.967000 path: /watchtower/v1/... traceId: c3db9d7a432317363c8bc5ddb5aadf4b '404': description: Not found. content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 404 message: Not found timestamp: 2025-06-01 13:28:03.967000 path: /watchtower/v1/... traceId: c3db9d7a432317363c8bc5ddb5aadf4b '413': description: Requested data too large content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 413 message: Requested data too large. Please use /watchtower/v1/.../export for requesting larger amounts of data timestamp: 2025-06-01 13:28:03.967000 path: /watchtower/v1/... traceId: c3db9d7a432317363c8bc5ddb5aadf4b '500': description: Internal Server Error. content: application/json: schema: $ref: '#/components/schemas/Error' example: code: 500 message: Internal Server Error timestamp: 2025-06-01 13:28:03.967000 path: /watchtower/v1/... traceId: c3db9d7a432317363c8bc5ddb5aadf4b securitySchemes: OAuth2: type: oauth2 description: The resources in the API are protected using the OAuth 2.0 protocol with the password grant flow. flows: password: tokenUrl: /iot/api/auth/token scopes: xdr-raw-api.read: Grant read access to listing signalling events. subscription-signalling-events.read: Grant read access to listing subscription signalling events. oAuth2ClientCredentials: type: oauth2 description: This API uses OAuth 2 with the Client Credentials flow. flows: clientCredentials: tokenUrl: /watchtower/v1/auth/token scopes: {} x-refined-from: - subscription-signalling-events-api.yaml - watchtower-api-openapi.yaml