openapi: 3.2.0 info: title: Case Manager Alerts API version: 1.0.0 servers: - url: /airmdrapi tags: - name: Alerts paths: /alerts: post: tags: - Alerts operationId: createAlertsAPI summary: Create alerts parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string - name: skip_investigation in: query description: Flag indicating whether the investigation for the alert should be skipped. schema: type: boolean requestBody: description: Request body for creating alerts. required: true content: application/json: schema: $ref: '#/components/schemas/CreateAlertsRequest' security: - SessionCookie: [] responses: '200': description: Alerts created successfully content: application/json: schema: $ref: '#/components/schemas/GetAlertResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alerts/analyze: post: tags: - Alerts operationId: analyzeAlertAPI summary: Analyze alerts parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string - name: return_partial_data in: query description: If true, returns whatever fields were identified even if some are missing. If false, returns error if any field is missing. required: false schema: type: boolean default: false requestBody: description: Request body for analyzing alerts. required: true content: application/json: schema: $ref: '#/components/schemas/AnalyzeAlertRequest' security: - SessionCookie: [] responses: '200': description: Alerts analyzed successfully content: application/json: schema: $ref: '#/components/schemas/AnalyzeAlertResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alerts/export: post: tags: - Alerts operationId: exportAlertsAPI summary: Export alerts data parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string requestBody: description: Request body for list alerts with search and filter. required: true content: application/json: schema: $ref: '#/components/schemas/ListAlertsRequest' security: - SessionCookie: [] responses: '200': description: A CSV file containing the alerts data content: text/csv: schema: type: string format: binary default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alerts/{alert_id}: get: tags: - Alerts operationId: getAlertAPI summary: get the details of an alert parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string - name: alert_id in: path description: The ID associated with the alert schema: type: string security: - SessionCookie: [] responses: '200': description: Alert fetched successfully content: application/json: schema: $ref: '#/components/schemas/GetAlertResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' patch: tags: - Alerts operationId: updateAlertAPI summary: update the details of an alert parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string - name: alert_id in: path description: The ID associated with the alert schema: type: string requestBody: description: Request body for updating an alert. required: true content: application/json: schema: $ref: '#/components/schemas/UpdateAlertRequest' security: - SessionCookie: [] responses: '200': description: Alert updated successfully content: application/json: schema: $ref: '#/components/schemas/GetAlertResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alerts/{alert_id}/investigate: post: tags: - Alerts operationId: investigateAlertAPI summary: process or investigate the alert description: investigate or re-investigate the alert parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string - name: alert_id in: path description: The ID associated with the alert schema: type: string security: - SessionCookie: [] responses: '200': description: Alert submitted for investigation successfully content: application/json: schema: $ref: '#/components/schemas/InvestigateAlertResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alerts/{alert_id}/investigate/agentic-preview: post: tags: - Alerts operationId: investigateAlertAgenticPreviewAPI summary: run the agentic preview investigation for a single alert description: Fires the agentic investigation via the beta (preview) service asynchronously and returns immediately. Skips the playbook side entirely and does not create a case (create_case_in_airmdr is hardcoded to false). When the beta call completes successfully, the alert's is_investigated_with_agent flag is set to true. parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: alert_id in: path description: The ID associated with the alert required: true schema: type: string security: - SessionCookie: [] responses: '202': description: Alert accepted for agentic preview investigation content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alerts/bulk/hard_delete: delete: tags: - Alerts operationId: bulkHardDeleteAlertsAPI summary: delete alerts in bulk parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/BulkDeleteAlertsRequest' security: - SessionCookie: [] responses: '200': description: Alerts deleted successfully content: application/json: schema: $ref: '#/components/schemas/BulkDeleteAlertsResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alerts/{alert_id}/hard_delete: delete: tags: - Alerts operationId: hardDeleteAlertAPI summary: delete an alert parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string - name: alert_id in: path description: The ID associated with the alert schema: type: string security: - SessionCookie: [] responses: '200': description: Alert deleted successfully content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alert_types: get: tags: - Alerts operationId: listAlertTypesAPI summary: Get the list of Alert types parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string - name: alert_provider in: query description: alert provider filter schema: type: string security: - SessionCookie: [] responses: '200': description: List of alerts types fetched successfully content: application/json: schema: $ref: '#/components/schemas/ListAlertTypesResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alert_budget_overview: get: tags: - Alerts operationId: getAlertBudgetOverview summary: Per-organization alert budget vs. actual overview description: 'Returns one row per organization the caller can access via RBAC, showing the weekly alert budget (`weekly_investigation_limit`) against the actual weekly alert volume, whether the org is over budget, and a summary of its alert-skip list (how many types are already applied, pending, or awaiting approval, plus the next auto-apply date). Powers the overview tab of the alert-skip console. Actuals are derived from the same daily cost-trim snapshot that backs the skip-list detail view, so the two screens reconcile. The `stale` flag indicates the snapshot is older than the configured freshness window.' parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: organization_id in: query description: 'The organization (UUID) whose accessible org set the overview is computed for. The response includes one row per organization the caller can access from this org via RBAC. ' required: true schema: type: string - name: sort_by in: query required: false description: Field to order rows by. Defaults to organization_name. schema: type: string enum: - organization_name - organization_code - actual - budget - pct_of_budget default: organization_name - name: sort_order in: query required: false description: Sort direction. Defaults to asc. schema: type: string enum: - asc - desc default: asc - name: limit in: query required: false description: Maximum number of org rows to return. schema: type: integer minimum: 1 maximum: 500 default: 50 - name: offset in: query required: false description: Row offset for pagination. schema: type: integer minimum: 0 default: 0 security: - SessionCookie: [] responses: '200': description: Alert budget overview fetched successfully. content: application/json: schema: $ref: '#/components/schemas/AlertBudgetOverviewResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alert_skip_list: get: tags: - Alerts operationId: getAlertSkipList summary: Retrieve one organization's alert-skip list description: 'Returns the organization''s alert types as flat rows, each tagged with a status (not_skipped / recommended / skipped / excluded), along with the org''s weekly alert budget and actual weekly volume.' parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' - name: organization_id in: query required: true description: The organization (UUID) to load the skip list for. schema: type: string security: - SessionCookie: [] responses: '200': description: Alert skip list fetched successfully. content: application/json: schema: $ref: '#/components/schemas/AlertSkipListResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alert_skip_list/apply: post: tags: - Alerts operationId: applyAlertSkip summary: Apply pending alert-skip entries now (admin only) description: 'Immediately transitions the named `pending` skip entries to `applied`, bypassing the day-7 auto-apply wait. Restricted to admin/super-admin callers. Omitting `items` applies every pending entry for the org. The action is audited.' parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' security: - SessionCookie: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AlertSkipLifecycleRequest' responses: '200': description: Pending skip entries applied successfully. content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alert_skip_list/hold: post: tags: - Alerts operationId: holdAlertSkip summary: Hold pending alert-skip entries past auto-apply (admin only) description: 'Marks the named `pending` skip entries as `held`, preventing the day-7 auto-apply from promoting them until released. Restricted to admin/super-admin callers (a hold is also the contract-override lever). The action is audited; `reason` is recorded.' parameters: - $ref: '#/components/parameters/user-id' - $ref: '#/components/parameters/organization-id' - $ref: '#/components/parameters/x-request-id' security: - SessionCookie: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AlertSkipLifecycleRequest' responses: '200': description: Skip entries held successfully. content: application/json: schema: $ref: '#/components/schemas/Success' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alerts_list: post: tags: - Alerts operationId: listAlertsAPI summary: Get the list of alerts description: Get the list of alerts per org parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string - name: page in: query description: Page number for paginated results. schema: type: integer - name: size in: query description: Number of results per page. schema: type: integer requestBody: description: Request body for list alerts with search and filter. required: true content: application/json: schema: $ref: '#/components/schemas/ListAlertsRequest' security: - SessionCookie: [] responses: '200': description: List of alerts fetched successfully content: application/json: schema: $ref: '#/components/schemas/ListAlertsResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' /alerts/execution/{execution_id}: get: tags: - Alerts operationId: getAlertbyExecutionIDAPI summary: get the details of an alert given execution id parameters: - name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string - name: Organization-Hosturl in: header description: The host url of the organization. schema: type: string - name: execution_id in: path description: The ID associated with the execution for which alert is to be fetched. schema: type: string security: - SessionCookie: [] responses: '200': description: Alert fetched successfully content: application/json: schema: $ref: '#/components/schemas/GetAlertResponse' default: description: unexpected error content: application/json: schema: $ref: '#/components/schemas/Error' components: schemas: InvestigateAlertResponse: type: object required: - alert_id - message properties: alert_id: type: string message: type: string TimeRange: type: object properties: from_date: type: integer format: int64 to_date: type: integer format: int64 AlertBudgetOverviewResponse: type: object required: - orgs - totals - stale properties: computed_at: type: integer format: int64 description: Unix timestamp (seconds) when the newest matching snapshot row was computed. window_start: type: integer format: int64 window_end: type: integer format: int64 stale: type: boolean description: True when the newest snapshot is older than the configured freshness window. orgs: type: array items: $ref: '#/components/schemas/AlertBudgetOverviewRow' total: type: integer description: Total number of accessible org rows before pagination. limit: type: integer description: The page size applied to this response. offset: type: integer description: The row offset applied to this response. totals: $ref: '#/components/schemas/AlertBudgetTotals' ListAlertsFilter: type: object properties: global_search_query: type: string investigation_status: type: array description: possible values are created, submitted, inprogress, completed, failed items: type: string alert_id: type: string alert_provider: type: string alert_providers: type: array items: type: string alert_type: type: string alert_types: type: array items: type: string organization_code: type: string organization_codes: type: array items: type: string modified_at_time_range: $ref: '#/components/schemas/TimeRange' created_at_time_range: $ref: '#/components/schemas/TimeRange' connection_ids: type: array items: type: string fetched_playbook_names: type: array description: Filter alerts by source playbook names items: type: string investigation_playbook_names: type: array description: Filter alerts by investigator playbook names items: type: string unresolved: type: boolean description: Flag to filter alerts by unresolved status no_linked_cases: type: boolean description: Flag to filter alerts where there is no linked cases ProviderDetails: type: object properties: name: type: string icon: type: string provider_id: type: string ConnectionDetails: type: object properties: connection_id: type: string connection_name: type: string AlertSkipLifecycleRequest: type: object required: - organization_id properties: organization_id: type: string items: type: array description: 'Alert types to act on. At least one item is required; the request is rejected with 400 when empty. ' items: $ref: '#/components/schemas/AlertSkipItem' reason: type: string description: Optional free-text reason, recorded in the audit trail. UpdateAlertRequest: type: object properties: alert_provider: type: string investigation_status: $ref: '#/components/schemas/AlertInvestigationStatus' investigation_playbook_id: type: string investigation_playbook_name: type: string investigation_retry_count: type: integer execution_id: type: string linked_case_id: type: string alert_ioc: $ref: '#/components/schemas/AlertsIOC' resolved: type: boolean alert_summary: type: string description: Human-readable summary of the alert original_alert_id: type: string description: When setting investigation_status to Duplicate, the alert_id this alert duplicates AlertSkipItem: type: object required: - alert_provider - alert_type properties: alert_provider: type: string alert_type: type: string ListAlertsResponse: type: object required: - data - total properties: data: type: array items: $ref: '#/components/schemas/AlertMinimal' description: list of alerts total: type: integer LinkedCaseSummary: type: object properties: case_id: type: string description: Human-readable case ID disposition: type: integer description: Disposition of the case disposition_label: type: string description: Human-readable label for the case disposition disposition_summary: type: string description: Human-readable summary of the case disposition created_at: type: integer format: int64 description: Timestamp when the case was created is_agentic_case: type: boolean description: Flag indicating whether the case was created by agentic investigation agentic_investigation_id: type: string description: ID of the agentic investigation associated with this case AlertsIOC: type: object properties: ip_address: type: array items: type: string domain: type: array items: type: string username: type: array items: type: string location: type: array items: type: string hostname: type: array items: type: string url: type: array items: type: string ioc_fields: type: object BulkDeleteAlertsResponse: type: object required: - message - data properties: message: type: string data: type: array items: type: string AlertMinimal: type: object required: - alert_id - alert_uuid - alert_content - alert_provider - alert_ioc - organization_uuid - organization_code - created_at - created_by - created_at_source - fetched_playbook_id - fetched_playbook_name - investigation_status - alert_provider_details - linked_case_count - alert_link properties: alert_id: type: string alert_uuid: type: string alert_content: type: string alert_provider: type: string alert_type: type: string alert_ioc: $ref: '#/components/schemas/AlertsIOC' organization_uuid: type: string organization_code: type: string created_by: type: string created_at: type: integer format: int64 modified_at: type: integer format: int64 created_at_source: type: integer format: int64 fetched_playbook_id: type: string fetched_playbook_name: type: string fetched_execution_id: type: string investigation_playbook_id: type: string investigation_playbook_name: type: string investigation_status: $ref: '#/components/schemas/AlertInvestigationStatus' investigation_retry_count: type: integer investigation_completed_time: type: integer format: int64 execution_id: type: string linked_case_id: type: string description: ID of the latest case linked to the alert original_alert_id: type: string description: When investigation_status is Duplicate, the alert_id this alert was found to be a duplicate of alert_provider_details: $ref: '#/components/schemas/ProviderDetails' resolved: type: boolean linked_case_count: type: integer description: Count of the other cases that are also linked to the alert in addition to the latest case alert_link: type: string description: URL for the alert AlertSkipSummary: type: object properties: applied: type: integer description: Count of alert types currently applied (skipped). pending: type: integer description: Count of alert types proposed this week, not yet applied. needs_approval: type: integer description: Count of escalation-bearing types awaiting admin approval. next_auto_apply_at: type: integer format: int64 description: Unix timestamp (seconds) of the soonest pending auto-apply. Absent when none pending. Error: type: object required: - message properties: message: type: string description: user friendly error message AnalyzeAlertResponse: type: object required: - alert_content - alert_provider - alert_type properties: alert_content: type: string alert_provider: type: string alert_type: type: string created_at_source: type: integer format: int64 SortOrder: type: integer enum: - 0 - 1 x-enum-varnames: - Asc - Desc Success: type: object required: - message properties: message: type: string description: user friendly message CreateAlertsRequest: type: object required: - alert_content - alert_provider - organization_code properties: alert_content: type: string description: The content/body of the alert alert_provider: type: string description: The provider/source of the alert (e.g. aws, microsoft_graph, etc.) alert_type: type: string description: The type/category of the alert fetched_playbook_id: type: string description: ID of the playbook that fetched this alert fetched_playbook_name: type: string description: Name of the playbook that fetched this alert fetched_execution_id: type: string description: Execution ID of the playbook run that fetched this alert organization_code: type: string description: Code/identifier of the organization this alert belongs to alert_ioc: $ref: '#/components/schemas/AlertsIOC' description: Indicators of Compromise (IOCs) associated with this alert created_at_source: type: integer format: int64 description: Timestamp when the alert was created at the source/provider add_alert_definition: type: boolean description: Flag to add alert definition to the alert content, True for alerts creating airmdr detection playbooks is_test_alert: type: boolean description: Flag indicating whether this alert is a test alert and should be treated differently original_alert_id: type: string description: When creating with investigation_status Duplicate, the alert_id this alert duplicates SortFields: type: object required: - field - sort_order properties: field: type: string description: indicates which field will be used for sorting sort_order: $ref: '#/components/schemas/SortOrder' description: indicates sort order - asc or desc AnalyzeAlertRequest: type: object required: - alert_content properties: alert_content: type: string BulkDeleteAlertsRequest: type: object required: - alert_uuids properties: alert_uuids: type: array items: type: string ListAlertsRequest: type: object properties: filter: $ref: '#/components/schemas/ListAlertsFilter' sort: type: array items: $ref: '#/components/schemas/SortFields' ignore_alert_content: type: boolean description: Flag to indicate whether to ignore the alert content. If true, the alert content will not be fetched. AlertBudgetOverviewRow: type: object required: - organization_uuid - actual - over_budget properties: organization_uuid: type: string organization_code: type: string organization_name: type: string budget: type: integer format: int64 description: Weekly alert budget (weekly_investigation_limit). Absent when no budget is set. actual: type: integer format: int64 description: Actual weekly alert volume for the org. pct_of_budget: type: number format: double description: actual / budget (0..n). Absent when no budget is set. over_budget: type: boolean enforce_weekly_limit: type: boolean description: Whether the org's blind weekly cutoff is enforced (EnforceWeeklyInvestigationLimit). skip_summary: $ref: '#/components/schemas/AlertSkipSummary' CaseExecutionDetails: type: object properties: case_id: type: string investigation_status: $ref: '#/components/schemas/AlertInvestigationStatus' investigation_playbook_id: type: string investigation_playbook_name: type: string execution_id: type: string linked_manually: type: boolean description: Flag to indicate if the case was linked manually or through investigation playbook is_agentic_case: type: boolean description: whether the linked case was created by agentic investigation AlertInvestigationStatus: type: integer enum: - 0 - 5 - 10 - 12 - 15 - 20 - 25 - 30 - 35 - 40 x-enum-varnames: - AlertInvestigationStatusCreated - AlertInvestigationStatusSubmitted - AlertInvestigationStatusInProgress - AlertInvestigationStatusSuspended - AlertInvestigationStatusCompleted - AlertInvestigationStatusFailed - AlertInvestigationStatusInvestigationLimitReached - AlertInvestigationStatusStopped - AlertInvestigationStatusSkipped - AlertInvestigationStatusDuplicate AlertTypeSeverity: type: integer enum: - 10 - 20 - 30 - 40 x-enum-varnames: - AlertTypeSeverityLow - AlertTypeSeverityMedium - AlertTypeSeverityHigh - AlertTypeSeverityCritical AlertSkipRow: type: object required: - alert_provider - alert_type - alerts_per_week - status properties: alert_provider: type: string alert_type: type: string alerts_per_week: type: integer format: int64 cases_per_week: type: integer format: int64 escalations_30d: type: integer format: int64 status: type: string enum: - not_skipped - recommended - skipped - excluded source: type: string enum: - system_suggested - user requires_approval: type: boolean GetAlertResponse: type: object required: - alert_id - alert_uuid - alert_content - alert_provider - alert_ioc - organization_uuid - organization_code - created_at - created_by - created_at_source - fetched_playbook_id - fetched_playbook_name - investigation_status - alert_provider_details - alert_link properties: alert_id: type: string alert_uuid: type: string alert_content: type: string alert_provider: type: string alert_type: type: string alert_ioc: $ref: '#/components/schemas/AlertsIOC' organization_uuid: type: string organization_code: type: string created_by: type: string created_at: type: integer format: int64 modified_at: type: integer format: int64 created_at_source: type: integer format: int64 fetched_playbook_id: type: string fetched_playbook_name: type: string fetched_execution_id: type: string investigation_playbook_id: type: string investigation_playbook_name: type: string investigation_status: $ref: '#/components/schemas/AlertInvestigationStatus' investigation_retry_count: type: integer investigation_completed_time: type: integer format: int64 execution_id: type: string linked_case_id: type: string description: ID of the latest case linked to the alert original_alert_id: type: string description: When investigation_status is Duplicate, the alert_id this alert was found to be a duplicate of alert_provider_details: $ref: '#/components/schemas/ProviderDetails' resolved: type: boolean is_investigated_with_agent: type: boolean description: Flag indicating whether the alert was investigated by the agentic investigation service is_alert_reinvestigated: type: boolean description: Flag indicating whether the alert has been manually reinvestigated via the InvestigateAlert API alert_summary: type: string description: Human-readable summary of the alert linked_case_details: type: array items: $ref: '#/components/schemas/CaseExecutionDetails' description: Details of the all the cases that are linked to the alert linked_case_summary: $ref: '#/components/schemas/LinkedCaseSummary' description: Summary of the latest case linked to the alert connection_details: $ref: '#/components/schemas/ConnectionDetails' description: Details of the connection fetched the alert alert_type_details: $ref: '#/components/schemas/AlertTypeWithProperties' description: Details of the alert type alert_link: type: string description: URL for the alert AlertSkipListResponse: type: object required: - organization_uuid - rows - stale properties: budget: type: integer format: int64 description: Weekly alert budget (weekly_investigation_limit). Absent when no budget is set. allowed_pct_of_budget: type: number format: double description: Allowed percentage of budget for the org (0..1). Absent when no budget is set. actual: type: integer format: int64 description: Actual weekly alert volume for the org. organization_uuid: type: string organization_code: type: string computed_at: type: integer format: int64 window_start: type: integer format: int64 window_end: type: integer format: int64 stale: type: boolean rows: type: array items: $ref: '#/components/schemas/AlertSkipRow' AlertTypeWithProperties: type: object required: - alert_type - alert_provider - default_severity - categories - mitre_tactics properties: alert_type: type: string alert_provider: type: string default_severity: $ref: '#/components/schemas/AlertTypeSeverity' categories: type: array items: type: string mitre_tactics: type: array items: type: string ListAlertTypesResponse: type: array items: type: string AlertBudgetTotals: type: object required: - budget - actual properties: budget: type: integer format: int64 description: Sum of per-org weekly budgets (orgs with a budget set). actual: type: integer format: int64 description: Sum of per-org actual weekly alert volume. pct_of_budget: type: number format: double description: actual / budget across all orgs with a budget set. parameters: organization-id: name: Organization-ID in: header description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string x-request-id: name: X-Request-ID in: header description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled. schema: type: string user-id: name: User-ID in: header description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled. schema: type: string securitySchemes: SessionCookie: type: apiKey in: cookie name: Session x-tagGroups: - name: Included APIs tags: - Case Manager V2 - Dashboard - Alerts - Webhooks - Query DSL