Recent changes to this investigation, from the audit log: the last 20 in 90 days, newest first. Readable by whoever can read the investigation; IP addresses and the full-history query only for owners and admins. New changes can take a few minutes to appear.
/investigations/{id}/activityPath Parameters
The investigation's id
Response Body
application/json
curl -X GET "https://example.com/investigations/string/activity"{ "audit_query": "string", "data": [ { "action": "string", "actor": { "kind": "person", "name": "string", "user_id": "string" }, "ip": "string", "outcome": "ok", "time": "string" } ]}`GET /alerts/{id}/investigations` — the investigations an alert is linked to. GET
The investigations this alert is linked to that you may open, as `GET /investigations/{id}` returns them, 100 links a page. Investigations you may not open are left out and not counted. A link made a moment ago can take a moment to appear. A hidden or unknown alert is a 404, a token without `alerts:read` a 403.
`PUT /investigations/{id}/alerts/{alertId}` — link an alert. PUT
Link an alert to this investigation. You need to be able to edit the investigation and see the alert; apps cannot. Linking a linked pair succeeds and changes nothing. Neither the investigation nor the alert changes. The answer is the two ids. A token without `alerts:read` is a 403 before anything is read; an alert you cannot see, or that does not exist, is the 404 `GET /alerts/{id}` gives; a missing investigation is a 404; one you may not edit is a 403.