Vigilfield Docs
API referenceInvestigations

`GET /investigations/{id}/alerts` — the investigation's linked alerts.

GET/investigations/{id}/alerts

Newest alert first, 100 links a page. Each alert you may see comes as GET /alerts/{id} returns it, as it is now. not_shown counts the page's links to alerts you may not see or that no longer exist; nothing else about them is returned, the cursor included. A page may hold no alerts while next_cursor is set: follow it until it is null. The cursor is good only for you, on this investigation.

Path Parameters

id*string

Investigation id

Query Parameters

cursor?string

The previous page's next_cursor

Response Body

application/json

curl -X GET "https://example.com/investigations/string/alerts"
{  "data": [    {      "acknowledged_at": "string",      "acknowledged_by": null,      "deliveries": {        "complete": true,        "targets": [          {            "recipients": null,            "state": "sending",            "target": {              "destination_id": "string",              "kind": "destination"            }          }        ]      },      "delivery_failed": [        "string"      ],      "description": "string",      "first_seen": "string",      "hit_count": 0,      "id": "string",      "key": "string",      "last_seen": "string",      "latest_row": null,      "origin": "string",      "resolved_at": "string",      "resolved_by": null,      "severity": "informational",      "source": {        "class": "rule",        "result_table_id": "string",        "rule_id": "string",        "run_id": "string"      },      "status": "open",      "title": "string"    }  ],  "next_cursor": "string",  "not_shown": 0}