`GET /alerts/{id}/investigations` — the investigations an alert is linked to.
/alerts/{id}/investigationsThe investigations this alert is linked to that you may open, as
GET /investigations/{id} returns them, 100 links a page. Investigations
you may not open are left out and not counted. A link made a moment ago
can take a moment to appear. A hidden or unknown alert is a 404, a token
without alerts:read a 403.
Path Parameters
Alert id
Query Parameters
The previous page's next_cursor
Response Body
application/json
curl -X GET "https://example.com/alerts/string/investigations"{ "data": [ { "artifact_ids": [ "string" ], "assignee": null, "closed_at": "string", "closed_by": null, "created_at": "string", "created_by": "string", "description": "string", "folder_id": "string", "id": "string", "name": "string", "org_id": "string", "owner_team_id": "string", "status": "OPEN", "updated_at": "string" } ], "next_cursor": "string"}`POST /installations/{id}/permissions` — approve some of the permissions the App declares that this installation does not hold yet (ADR-0079). POST
The body is an install's: `(scope, target)` pairs, bounded the same way. Only the installing team, acting as it, approves.
Recent changes to this investigation, from the audit log: the last 20 in 90 days, newest first. Readable by whoever can read the investigation; IP addresses and the full-history query only for owners and admins. New changes can take a few minutes to appear. GET
Next Page