`PUT /investigations/{id}/alerts/{alertId}` — link an alert.
/investigations/{id}/alerts/{alertId}Link an alert to this investigation. You need to be able to edit the
investigation and see the alert; apps cannot. Linking a linked pair
succeeds and changes nothing. Neither the investigation nor the alert
changes. The answer is the two ids. A token without alerts:read is a 403
before anything is read; an alert you cannot see, or that does not exist,
is the 404 GET /alerts/{id} gives; a missing investigation is a 404; one
you may not edit is a 403.
Path Parameters
Investigation id
Alert id
Response Body
application/json
curl -X PUT "https://example.com/investigations/string/alerts/string"{ "alert_id": "string", "investigation_id": "string"}Recent changes to this investigation, from the audit log: the last 20 in 90 days, newest first. Readable by whoever can read the investigation; IP addresses and the full-history query only for owners and admins. New changes can take a few minutes to appear. GET
Previous Page
`GET /investigations/{id}/alerts` — the investigation's linked alerts. GET
Newest alert first, 100 links a page. Each alert you may see comes as `GET /alerts/{id}` returns it, as it is now. `not_shown` counts the page's links to alerts you may not see or that no longer exist; nothing else about them is returned, the cursor included. A page may hold no alerts while `next_cursor` is set: follow it until it is null. The cursor is good only for you, on this investigation.