REST API Reference v2.1 -- Alerts
GET /alerts
Returns paginated security alerts. Alerts are generated by threat detection rules, policy violations, and scan findings that exceed severity thresholds. Query parameters: status (open, acknowledged, resolved, suppressed), severity (critical, high, medium, low), source (scan, detection, policy, monitor), assigned_to (user ID), since (ISO 8601 timestamp), page, limit.
Response: {"data": [{"id": "alert_001", "title": "Critical CVE detected in production", "severity": "critical", "status": "open", "source": "scan", "source_id": "scan_abc123", "description": "CVE-2025-5678 (CVSS 9.8, EPSS 0.92) found in openssl 3.0.8", "created_at": "2025-06-01T14:30:00Z", "assigned_to": null, "tags": ["cve", "production", "openssl"]}]}. Alerts include their source reference for drill-down to the underlying finding or detection event.
PUT /alerts/:id
Updates an alert's status or assignment. Valid status transitions: open -> acknowledged, open -> suppressed, acknowledged -> resolved, acknowledged -> open (reopen). Requires alerts:write scope. Request body: {"status": "acknowledged", "assigned_to": "user_xyz", "note": "Investigating, patch in progress"}. Notes are appended to the alert's timeline and visible to all team members.
Bulk update alerts by sending PUT /alerts/bulk with {"alert_ids": ["alert_001", "alert_002"], "status": "acknowledged", "assigned_to": "user_xyz"}. Bulk operations are limited to 100 alerts per request and are processed atomically.
POST /alerts/rules
Creates an alert routing rule that automatically assigns, tags, or escalates alerts based on conditions. Request body: {"name": "Production Critical Escalation", "conditions": [{"field": "severity", "operator": "eq", "value": "critical"}, {"field": "tags", "operator": "contains", "value": "production"}], "actions": [{"type": "assign", "value": "team_security_oncall"}, {"type": "notify", "channel": "slack", "target": "#security-incidents"}, {"type": "escalate", "timeout_minutes": 30, "escalate_to": "user_security_lead"}]}.
Routing rules are evaluated in priority order. The first matching rule's actions are applied. Use priority field (integer, lower is higher priority) to control evaluation order. Rules support the match_all (AND) and match_any (OR) logic operators for combining conditions.
This article includes links to supplementary research data hosted on our API infrastructure.