openapi: 3.2.0
info:
version: 0.7.0
title: Aeris IoT Watchtower™ Security Report API
description: '## Introduction
The Aeris IoT Watchtower™ API provides access to resources such as real-time events, aggregated events, risk assessment reports, and device group operations.'
termsOfService: https://www.aeris.com/services-terms-of-use/
contact:
email: support@aeris.net
url: https://www.aeris.com/support/
license:
name: Aeris License
url: https://www.aeris.com/services-terms-of-use/
x-audience: external-public
servers:
- url: https://watchtower-api-prd.aeriscloud.com
security:
- oAuth2ClientCredentials: []
tags:
- name: Security Report
description: Endpoints for Security Reports
paths:
/watchtower/v1/security-report/export:
get:
tags:
- Security Report
summary: Get Monthly Security Report PDF
operationId: getSecurityReportPDF
parameters:
- $ref: '#/components/parameters/authorization'
- $ref: '#/components/parameters/accountId'
- $ref: '#/components/parameters/year'
- $ref: '#/components/parameters/month'
responses:
'200':
description: Successful Response
content:
application/json:
schema:
$ref: '#/components/schemas/ScheduledReport'
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'429':
$ref: '#/components/responses/429'
'500':
$ref: '#/components/responses/500'
/watchtower/v1/security-report/summary:
get:
tags:
- Security Report
summary: Get Security Report Summary
description: Get Summary section from Security Report
operationId: getSecurityReportSummary
parameters:
- $ref: '#/components/parameters/authorization'
- $ref: '#/components/parameters/accountId'
- $ref: '#/components/parameters/year'
- $ref: '#/components/parameters/month'
responses:
'200':
description: Successful Response
content:
application/json:
schema:
$ref: '#/components/schemas/SecurityReportSummary'
example:
total_low: 19
total_medium: 3
total_high: 3
overall_severity: High
summary_text: During the month of April 2025, Aeris IoT Watchtower™ conducted a security assessment of your 105,899 provisioned devices, of which 5 were active, on the Aeris network. We encountered a total of 25 issues with 3 considered to be high risk, 3 medium risk, and 19 low risks across the categories below. In this summary, we list only the most important in each category.
disclaimer: The results presented in this report are a point-in-time risk assessment and represent the state of security on the date it was produced. Aeris makes no representation on the completeness of the risks assessed. The risks analyzed in the section titled Security Risk Assessment Details constitute the entire analysis performed. This report is prepared for the intended recipient only and no other parties may rely on it for any purposes.
disclaimer_no2: ICMP, DNS and NTP protocols are excluded from endpoint locations map.
sections:
application_security:
high: 1
medium: 1
low: 0
highest_severity: High
recommended_action: Verify the legitimacy of traffic for devices communicating in non-designated / OFAC countries.
data_protection:
high: 2
medium: 0
low: 2
highest_severity: High
recommended_action: We recommend configuring your IoT devices to use encrypted protocols (HTTPS and SFTP) rather than unencrypted protocols (HTTP and FTP).
device_security:
high: 0
medium: 0
low: 15
highest_severity: Low
recommended_action: No action required at this time.
inventory_control_devices:
high: 0
medium: 0
low: 2
highest_severity: Low
recommended_action: No action required at this time.
net_work_security:
high: 0
medium: 2
low: 0
highest_severity: Medium
recommended_action: We recommend an end-to-end encrypted channel to be used for data flow between IOT devices and the customer’s application server.
device_activated_summary:
- - Unknown
- 5
- 462612618
trend_low:
content: +18.75%
direction: trend_up
current_value: 19
previous_value: 16
trend_medium:
content: 0%
direction: trend_flat
current_value: 3
previous_value: 3
trend_high:
content: -50%
direction: trend_down
current_value: 3
previous_value: 6
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'429':
$ref: '#/components/responses/429'
'500':
$ref: '#/components/responses/500'
/watchtower/v1/security-report/detail:
get:
tags:
- Security Report
summary: Get Security Report Detail
description: Get Details section from Security Report
operationId: getSecurityReportDetail
parameters:
- $ref: '#/components/parameters/authorization'
- $ref: '#/components/parameters/accountId'
- $ref: '#/components/parameters/year'
- $ref: '#/components/parameters/month'
responses:
'200':
description: Successful Response
content:
application/json:
schema:
$ref: '#/components/schemas/SecurityReportDetail'
example:
sections:
inventory_control_devices:
- sec_no: '90'
tds:
- content: 1.1 Devices located according to expectations
column: security_item
- content: Number of devices outside their designated home location
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices outside of designated home country: Low < 5%; Medium 5% to 10%; High > 10%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '95'
tds:
- content: 1.2 Non-IoT devices in use
column: security_item
- content: Use of Non-IoT devices
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% of non-IoT devices: Low < 5%; Medium 5% to 10%; High > 10%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
data_protection:
- sec_no: '100'
tds:
- content: 2.1 Encrypt Data flow to private applications
column: security_item
- content: Number of enterprise cellular connections towards applications deployed in the enterprise’s private network not using encrypted channels (ex- https or TLS)?
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% of devices using unencrypted channels: Low < 5%; Medium 5% to 10%; High > 10%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '105'
tds:
- content: 2.2 Encrypt Data flow to public applications
column: security_item
- content: Number of enterprise cellular connections towards applications deployed in the enterprise’s public network not using encrypted channels (ex- https or TLS)?
column: description
- content: +100%
direction: trend_up
current_value: 1
previous_value: 0
column: trend
- content: '1'
column: occurrence_count
- content: '1'
column: device_impacted
- content: '% of devices using unencrypted channels: Low < 5%; Medium 5% to 10%; High > 10%'
column: assessment_criteria
- content: High
column: assessed_severity
- content: We recommend configuring your IoT devices to use encrypted protocols (HTTPS and SFTP) rather than unencrypted protocols (HTTP and FTP).
column: recommended_action
- sec_no: '110'
tds:
- content: 2.3 Use of untrusted DNS servers
column: security_item
- content: Number of devices connecting to a recursive DNS that is public or untrusted
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% of devices using a public recursive DNS: Low < 5%; Medium 5% to 10%; High > 10%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '115'
tds:
- content: 2.4 Data Sovereignty
column: security_item
- content: Number of devices communicating with applications located outside the home country
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% of devices communicating with applications outside their home country: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
net_work_security:
- sec_no: '120'
tds:
- content: 3.1 Devices utilizing a secure connection
column: security_item
- content: Devices utilizing VPN to connect to enterprise’s servers
column: description
- content: +100%
direction: trend_up
current_value: 1
previous_value: 0
column: trend
- content: '1'
column: occurrence_count
- content: '1'
column: device_impacted
- content: '% devices use VPN:
Low > 30%
Medium Otherwise'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '160'
tds:
- content: 3.2 Devices utilizing private APN
column: security_item
- content: The devices are using a private APN to connect to private applications, private cloud hosted applications or to internet.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices utilizing private APN: Low ≥ 0%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '165'
tds:
- content: 3.3 Devices utilizing internet APN
column: security_item
- content: The devices are using an Internet APN to connect to public cloud hosted applications or to internet.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices utilizing internet APN: Low ≥ 0%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '1200'
tds:
- content: 3.4 Manage security access controls
column: security_item
- content: Number of enforcement security policies for device traffic
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: Low if any network policy configured, Medium otherwise
column: assessment_criteria
- content: Medium
column: assessed_severity
- content: No action required at this time.
column: recommended_action
application_security:
- sec_no: '125'
tds:
- content: '4.1 Non-compliant communications: OFAC'
column: security_item
- content: Devices communicating to endpoints in OFAC countries.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: 'Devices communicating to endpoints in OFAC countries: Low = 0; High > 0'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '130'
tds:
- content: 4.2 Public applications
column: security_item
- content: Applications reachable via the public Internet
column: description
- content: +100%
direction: trend_up
current_value: 54
previous_value: 0
column: trend
- content: '54'
column: occurrence_count
- content: '0'
column: device_impacted
- content: 'Number of applications reachable on the public Internet: Low = 0; Medium > 0'
column: assessment_criteria
- content: Medium
column: assessed_severity
- content: We recommend secure VPN communication instead of public internet for application communication.
column: recommended_action
device_security:
- sec_no: '55'
tds:
- content: 5.1 Malicious Endpoint
column: security_item
- content: Devices communicating with well-known malicious endpoints identified by their IP address
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% of devices communicating with Malicious endpoints by IP: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '60'
tds:
- content: 5.2 Botnet and C&C
column: security_item
- content: Devices communicated with an endpoint related to a malicious bot, infecting the hosts and connecting them to a central server or servers that act as a command and control (C&C) center.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices showing Botnet and C&C: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '65'
tds:
- content: 5.3 Cryptocurrency
column: security_item
- content: Devices communicated with an endpoint related to cryptocurrencies.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices showing Cryptocurrency: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '70'
tds:
- content: 5.4 Data Exfiltration
column: security_item
- content: Devices communicated with an endpoint participating in data exfiltration.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices showing Data Exfiltration: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '80'
tds:
- content: 5.5 Phishing
column: security_item
- content: Devices communicated with email messages that look like they are from a trusted business but are actually connected to phishing websites.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices showing Phishing: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '85'
tds:
- content: 5.6 Ransomware
column: security_item
- content: Devices communicated with an endpoint known to have ransomware.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices showing Ransomware: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '10'
tds:
- content: 5.7 Suspicious device behavior - Address Scan
column: security_item
- content: Devices scanning the addresses of other devices in their subnet
column: description
- content: +100%
direction: trend_up
current_value: 1
previous_value: 0
column: trend
- content: '1'
column: occurrence_count
- content: '1'
column: device_impacted
- content: '% devices showing address scan events: Low = 0%; Medium 0% to 0.1%; High > 0.1%'
column: assessment_criteria
- content: High
column: assessed_severity
- content: Verify the integrity of these devices that have been performing unusual address scans.
column: recommended_action
- sec_no: '30'
tds:
- content: 5.8 Suspicious device behavior - Port Scan
column: security_item
- content: Devices scanning ports beyond their normal connection to the endpoint
column: description
- content: +100%
direction: trend_up
current_value: 1
previous_value: 0
column: trend
- content: '1'
column: occurrence_count
- content: '1'
column: device_impacted
- content: '% devices showing port scan events: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: High
column: assessed_severity
- content: Verify the integrity of these devices that have been performing unusual port scans.
column: recommended_action
- sec_no: '35'
tds:
- content: 5.9 Suspicious Behavior - SIM misuse
column: security_item
- content: Devices having their SIM swapped
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices showing SIM misuse alarm: Low = 0%; Medium 0% to 0.1%; High > 0.1%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '75'
tds:
- content: 5.10 Suspicious Endpoint
column: security_item
- content: Devices communicated with a domain that has not been established and is serving temporary content on its base page (a parked domain).
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices showing Suspicious Endpoint: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '20'
tds:
- content: 5.11 Anomalous Behavior - New destination IPs
column: security_item
- content: Devices attached to unexpected new destination IP addresses on the network
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices showing new IP addresses: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '40'
tds:
- content: 5.12 Anomalous Behavior - TCP Bad Flags
column: security_item
- content: Devices having unexpected use of TCP flags.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: 'Frequency of TCP bad flag events per week: Low < 10; Medium 10 to 100; High > 100'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '45'
tds:
- content: 5.13 Anomalous Behavior - TCP large flow count
column: security_item
- content: Devices having unexpected large count of TCP flows.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices showing large TCP flow count: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '50'
tds:
- content: 5.14 Anomalous Behavior - Traffic Spike
column: security_item
- content: Devices having unexpected large occurrence of traffic spike.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% devices showing traffic spike: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '175'
tds:
- content: 5.15 Anomalous Mobility Event - Moving Outside a Location List
column: security_item
- content: The device has been identified outside the location list associated with one of the device groups this device belongs to.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% anomalous mobility events - moving outside location list: Low < 0.1%; Medium 0.1% to 0.5%; Critical > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '180'
tds:
- content: 5.16 Anomalous Mobility Event - Impossible Mobility
column: security_item
- content: The device has been moving across different locations at a speed that is beyond reasonable (900 km/h).
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% anomalous mobility events - impossible mobility: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
- sec_no: '140'
tds:
- content: 5.17 Blocked Flows
column: security_item
- content: Blocked Flows by a security policy.
column: description
- content: 0%
direction: trend_flat
current_value: 0
previous_value: 0
column: trend
- content: '0'
column: occurrence_count
- content: '0'
column: device_impacted
- content: '% showing Blocked Flows: Low < 0.1%; Medium 0.1% to 0.5%; High > 0.5%'
column: assessment_criteria
- content: Low
column: assessed_severity
- content: No action required at this time.
column: recommended_action
category:
inventory_control_devices: 1. Inventory and Control of Devices
data_protection: 2. Data Protection
net_work_security: 3. Network Security
application_security: 4. Application Security
device_security: 5. Device Security
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'429':
$ref: '#/components/responses/429'
'500':
$ref: '#/components/responses/500'
/watchtower/v1/security-report/device-location:
get:
tags:
- Security Report
summary: Get Security Report Device Location Tables
description: Get Device Location section from Security Report
operationId: getSecurityReportDevice
parameters:
- $ref: '#/components/parameters/authorization'
- $ref: '#/components/parameters/accountId'
- $ref: '#/components/parameters/year'
- $ref: '#/components/parameters/month'
responses:
'200':
description: Successful Response
content:
application/json:
schema:
$ref: '#/components/schemas/SecurityReportDeviceUsage'
example:
total: 1
data:
- - active_devices: 0
device_country: string
data_usage_bytes: 0
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'429':
$ref: '#/components/responses/429'
'500':
$ref: '#/components/responses/500'
/watchtower/v1/security-report/endpoint-location:
get:
tags:
- Security Report
summary: Get Security Report Endpoint Location Tables
description: Get Endpoint Location section from Security Report
operationId: getSecurityReportEndpoint
parameters:
- $ref: '#/components/parameters/authorization'
- $ref: '#/components/parameters/accountId'
- $ref: '#/components/parameters/year'
- $ref: '#/components/parameters/month'
responses:
'200':
description: Successful Response
content:
application/json:
schema:
$ref: '#/components/schemas/SecurityReportEndpoint'
example:
total: 1
data:
- - endpoint_country: United States
device_count: 5
endpoint_count: 385
data_usage_bytes: 12131923
ip_flows: 8320
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'429':
$ref: '#/components/responses/429'
'500':
$ref: '#/components/responses/500'
/watchtower/v1/security-report/appendix/search:
post:
tags:
- Security Report
summary: Get Security Report Appendix
description: Get Appendix report of an account for a specific month
operationId: getSecurityReportAppendix
parameters:
- $ref: '#/components/parameters/authorization'
- $ref: '#/components/parameters/accountId'
- $ref: '#/components/parameters/year'
- $ref: '#/components/parameters/month'
- $ref: '#/components/parameters/offset'
- $ref: '#/components/parameters/limit'
- $ref: '#/components/parameters/sort'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/SecurityReportAppendixRequest'
responses:
'200':
description: Successful Response
content:
application/json:
schema:
$ref: '#/components/schemas/PagedSecurityReportAppendix'
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'413':
$ref: '#/components/responses/413'
'429':
$ref: '#/components/responses/429'
'500':
$ref: '#/components/responses/500'
/watchtower/v1/security-report/appendix/export:
post:
summary: Export Security Report Appendix
tags:
- Security Report
operationId: exportSecurityReportAppendix
parameters:
- $ref: '#/components/parameters/authorization'
- $ref: '#/components/parameters/accountId'
- $ref: '#/components/parameters/year'
- $ref: '#/components/parameters/month'
- $ref: '#/components/parameters/sort'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/SecurityReportAppendixTrigger'
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/ScheduledReport'
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'429':
$ref: '#/components/responses/429'
'500':
$ref: '#/components/responses/500'
components:
schemas:
Severity:
type: string
enum:
- High
- Medium
- Low
title: Severity
example: High
EndpointData:
properties:
endpoint_country:
type: string
title: Endpoint Country
device_count:
type: integer
title: Device Count
endpoint_count:
type: integer
title: Endpoint Count
data_usage_bytes:
type: integer
title: Data Usage Bytes
ip_flows:
type: integer
title: Ip Flows
type: object
required:
- endpoint_country
- device_count
- endpoint_count
- data_usage_bytes
- ip_flows
title: EndpointData
total:
type: integer
format: int64
description: Total number of items available.
example: 1
minimum: 0
SecurityReportDetail:
properties:
sections:
$ref: '#/components/schemas/SecurityReportSections'
category:
$ref: '#/components/schemas/SecurityReportCategory'
type: object
required:
- sections
- category
title: SecurityReportDetail
offset:
description: Position in pagination.
type: integer
format: int32
default: 0
minimum: 0
limit:
type: integer
format: int32
description: Number of items to retrieve (10000 max).
minimum: 1
maximum: 10000
default: 20
DeviceUsageData:
properties:
active_devices:
type: integer
title: Active Devices
device_country:
type: string
title: Device Country
data_usage_bytes:
type: integer
title: Data Usage Bytes
type: object
required:
- active_devices
- device_country
- data_usage_bytes
title: DeviceUsageData
accountId:
description: Account Id.
type: integer
format: int32
example: 10407
minimum: 0
SecurityReportAppendixRequest:
title: SecurityReportAppendixRequest
type: object
required:
- year
- month
properties:
year:
type: integer
title: Year
month:
type: integer
title: Month
category:
type: string
title: Category
security_item:
type: string
title: Security Item
iccid:
type: string
title: Iccid
imsi:
type: string
title: Imsi
start_ts:
type: string
title: Start Ts
end_ts:
type: string
title: End Ts
device_location:
type: string
title: Device Location
device_type:
type: string
title: Device Type
network_protocol:
type: string
title: Network Protocol
protocol:
type: string
title: Protocol
unencrypted_protocol:
type: string
title: Unencrypted Protocol
server_port:
type: string
title: Server Port
endpoint_location:
type: string
title: Endpoint Location
fqdn:
type: string
title: Fqdn
dns_server_ip:
type: string
title: Dns Server Ip
scanned_subnet_port:
type: string
title: Scanned Subnet Port
apn:
type: array
title: Apn
items:
type: string
apn_type:
type: array
title: Apn Type
items:
type: string
device_group_id:
items:
type: string
type: array
title: Device Group Id
SecurityReportSectionItem:
properties:
sec_no:
type: string
title: Sec No
tds:
items:
$ref: '#/components/schemas/TdsItem'
type: array
title: Tds
alert_type:
type: string
title: Event Type
type: object
required:
- sec_no
- tds
title: SectionItem
SecurityEventData:
type: object
title: SecurityEventData
properties:
account_id:
type: string
title: Account Id
report_date:
type: string
format: date
title: Report Date
security_item:
type: string
title: Security Item
iccid:
type: string
title: Iccid
category:
type: string
title: Category
current_ts:
type: string
format: date-time
title: Current Ts
imsi:
type: string
title: Imsi
device_location:
type: string
title: Device Location
device_type:
type: string
title: Device Type
network_protocol:
type: string
title: Network Protocol
protocol:
type: string
title: Protocol
server_port:
type: string
title: Server Port
endpoint_location:
type: string
title: Endpoint Location
fqdn:
type: string
title: Fqdn
dns_server_ip:
type: string
title: Dns Server Ip
scanned_subnet_port:
type: string
title: Scanned Subnet Port
unencrypted_protocol:
type: string
title: Unencrypted Protocol
occurrence_count:
type: integer
title: Occurrence Count
apn:
type: array
title: Apn
items:
type: string
apn_type:
type: array
title: Apn Type
items:
type: string
device_groups:
type: array
title: Device Groups
items:
type: object
properties:
group_id:
type: string
title: Group Id
name:
type: string
title: Name
color_code:
type: string
title: Color Code
device_assigning_type:
type: string
title: Device Assigning Type
required:
- account_id
- report_date
- security_item
- iccid
- category
- current_ts
- imsi
- device_location
- device_type
- network_protocol
- protocol
- server_port
- endpoint_location
- fqdn
- dns_server_ip
- scanned_subnet_port
- unencrypted_protocol
- device_groups
SecurityReportSections:
properties:
inventory_control_devices:
items:
$ref: '#/components/schemas/SecurityReportSectionItem'
type: array
title: Inventory Control Devices
data_protection:
items:
$ref: '#/components/schemas/SecurityReportSectionItem'
type: array
title: Data Protection
net_work_security:
items:
$ref: '#/components/schemas/SecurityReportSectionItem'
type: array
title: Net Work Security
application_security:
items:
$ref: '#/components/schemas/SecurityReportSectionItem'
type: array
title: Application Security
device_security:
items:
$ref: '#/components/schemas/SecurityReportSectionItem'
type: array
title: Device Security
type: object
required:
- inventory_control_devices
- data_protection
- net_work_security
- application_security
- device_security
title: Sections
TdsItem:
properties:
content:
type: string
title: Content
column:
type: string
title: Column
direction:
type: string
title: Direction
current_value:
type: number
title: Current Value
previous_value:
type: number
title: Previous Value
type: object
required:
- content
- column
title: TdsItem
SecurityReportDeviceUsage:
properties:
total:
type: integer
title: Total
data:
items:
items:
$ref: '#/components/schemas/DeviceUsageData'
type: array
type: array
title: Rows
type: object
required:
- total
- data
title: DeviceUsageResponse
SecurityReportEndpoint:
properties:
total:
type: integer
title: Total
data:
items:
items:
$ref: '#/components/schemas/EndpointData'
type: array
type: array
title: Data
type: object
required:
- total
- data
title: EndpointResponse
SecurityReportCategory:
properties:
inventory_control_devices:
type: string
title: Inventory Control Devices
data_protection:
type: string
title: Data Protection
net_work_security:
type: string
title: Net Work Security
application_security:
type: string
title: Application Security
device_security:
type: string
title: Device Security
type: object
required:
- inventory_control_devices
- data_protection
- net_work_security
- application_security
- device_security
title: Category
Error:
type: object
properties:
code:
type: integer
description: HTTP code
example: 500
message:
type: string
description: Error message
example: An error encountered in processing the request
timestamp:
type: string
description: ISO DateTime
example: '2025-06-02 09:01:53.678'
path:
type: string
description: Endpoint path at which the error occured
example: /watchtower/v1/events
traceId:
type: string
description: Trace Id
example: ed81f29f-ea9b-4099-aa00-f8ed40b7a567
SectionSummary:
properties:
high:
type: integer
title: High
medium:
type: integer
title: Medium
low:
type: integer
title: Low
highest_severity:
$ref: '#/components/schemas/Severity'
recommended_action:
type: string
title: Recommended Action
type: object
required:
- high
- medium
- low
- highest_severity
- recommended_action
title: SectionSummary
SecurityReportAppendixTrigger:
properties:
request_by:
type: string
title: Request By
account_name:
type: string
title: Account Name
type: object
title: SecurityReportAppendixTrigger
TrendDirection:
type: string
enum:
- trend_up
- trend_down
- trend_flat
title: TrendDirection
SecurityReportSummary:
properties:
total_low:
type: integer
title: Total Low
total_medium:
type: integer
title: Total Medium
total_high:
type: integer
title: Total High
overall_severity:
$ref: '#/components/schemas/Severity'
summary_text:
type: string
title: Summary Text
disclaimer:
type: string
title: Disclaimer
disclaimer_no2:
type: string
title: Disclaimer No2
sections:
$ref: '#/components/schemas/SectionsSummary'
device_activated_summary:
title: Device Activated Summary
type: array
items:
type: array
minItems: 3
maxItems: 3
items: {}
trend_low:
$ref: '#/components/schemas/TrendData'
trend_medium:
$ref: '#/components/schemas/TrendData'
trend_high:
$ref: '#/components/schemas/TrendData'
type: object
required:
- total_low
- total_medium
- total_high
- overall_severity
- summary_text
- disclaimer
- disclaimer_no2
- sections
- device_activated_summary
- trend_low
- trend_medium
- trend_high
title: SecurityReportSummary
Pagination:
type: object
properties:
total:
$ref: '#/components/schemas/total'
offset:
$ref: '#/components/schemas/offset'
limit:
$ref: '#/components/schemas/limit'
SectionsSummary:
properties:
application_security:
$ref: '#/components/schemas/SectionSummary'
data_protection:
$ref: '#/components/schemas/SectionSummary'
device_security:
$ref: '#/components/schemas/SectionSummary'
inventory_control_devices:
$ref: '#/components/schemas/SectionSummary'
net_work_security:
$ref: '#/components/schemas/SectionSummary'
type: object
required:
- application_security
- data_protection
- device_security
- inventory_control_devices
- net_work_security
title: SectionsSummary
ScheduledReport:
type: object
properties:
reportId:
description: Report Id
type: string
example: 7ae9e22d-8ad4-4a69-950a-6b13d75f0c74
status:
$ref: '#/components/schemas/ReportStatus'
statusEndpoint:
description: Report Status URL
type: string
example: /watchtower/v1/scheduled-reports/7ae9e22d-8ad4-4a69-950a-6b13d75f0c74
PagedSecurityReportAppendix:
allOf:
- $ref: '#/components/schemas/Pagination'
- type: object
properties:
data:
type: array
items:
$ref: '#/components/schemas/SecurityEventData'
ReportStatus:
description: Report status
type: string
example: Processing
enum:
- Success
- Processing
- Error
- NotStarted
TrendData:
properties:
content:
type: string
title: Content
direction:
$ref: '#/components/schemas/TrendDirection'
current_value:
type: integer
title: Current Value
previous_value:
type: integer
title: Previous Value
type: object
required:
- content
- direction
- current_value
- previous_value
title: TrendData
description: Schema for a trend object.
responses:
'429':
description: Too many requests.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
example:
code: 429
message: 'Rate Limit Exceeded (XX) for clientId: XXXXXX. Please retry after XXX seconds'
timestamp: 2025-06-01 13:28:03.967000
path: /watchtower/v1/...
traceId: c3db9d7a432317363c8bc5ddb5aadf4b
'401':
description: Not authorized.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
example:
code: 401
message: Unauthorized
timestamp: 2025-06-01 13:28:03.967000
path: /watchtower/v1/...
traceId: c3db9d7a432317363c8bc5ddb5aadf4b
'403':
description: Forbidden.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
example:
code: 403
message: Forbidden
timestamp: 2025-06-01 13:28:03.967000
path: /watchtower/v1/...
traceId: c3db9d7a432317363c8bc5ddb5aadf4b
'400':
description: Bad Request.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
example:
code: 400
message: Bad Request
timestamp: 2025-06-01 13:28:03.967000
path: /watchtower/v1/...
traceId: c3db9d7a432317363c8bc5ddb5aadf4b
'413':
description: Requested data too large
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
example:
code: 413
message: Requested data too large. Please use /watchtower/v1/.../export for requesting larger amounts of data
timestamp: 2025-06-01 13:28:03.967000
path: /watchtower/v1/...
traceId: c3db9d7a432317363c8bc5ddb5aadf4b
'500':
description: Internal Server Error.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
example:
code: 500
message: Internal Server Error
timestamp: 2025-06-01 13:28:03.967000
path: /watchtower/v1/...
traceId: c3db9d7a432317363c8bc5ddb5aadf4b
parameters:
month:
name: month
description: Month
in: query
required: true
schema:
type: integer
maximum: 12
minimum: 1
year:
name: year
description: Year
in: query
required: true
schema:
type: integer
maximum: 2099
minimum: 2000
sort:
name: sort
in: query
description: Use sort=comma-separated-fields[:asc|desc] to sort the result.
example: deviceId,updateTime:desc
schema:
type: string
accountId:
name: X-Watchtower-Account-Id
in: header
description: Account Id
required: true
schema:
$ref: '#/components/schemas/accountId'
example: 1002000010
offset:
name: offset
in: query
description: The position in pagination. Specifies the starting row offset into the result set returned. For example, if the page size (limit) is 10, then to select the second page, pass the offset as 10 to retrieve items 11 to 20.
Search parameters must be consistent across pages.
schema:
$ref: '#/components/schemas/offset'
authorization:
name: Authorization
in: header
description: Bearer Token for authentication
required: true
schema:
type: string
pattern: ^Bearer [A-Za-z0-9-._~+/]+=*$
example: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ...
limit:
name: limit
in: query
description: The number of items to retrieve per page (10000 max).
schema:
$ref: '#/components/schemas/limit'
securitySchemes:
oAuth2ClientCredentials:
type: oauth2
description: This API uses OAuth 2 with the Client Credentials flow.
flows:
clientCredentials:
tokenUrl: /watchtower/v1/auth/token
scopes: {}