`GET /investigations/{id}/alerts` — the investigation's linked alerts.
/investigations/{id}/alertsNewest alert first, 100 links a page. Each alert you may see comes as
GET /alerts/{id} returns it, as it is now. not_shown counts the page's
links to alerts you may not see or that no longer exist; nothing else about
them is returned, the cursor included. A page may hold no alerts while
next_cursor is set: follow it until it is null. The cursor is good only
for you, on this investigation.
Path Parameters
Investigation id
Query Parameters
The previous page's next_cursor
Response Body
application/json
curl -X GET "https://example.com/investigations/string/alerts"{ "data": [ { "acknowledged_at": "string", "acknowledged_by": null, "deliveries": { "complete": true, "targets": [ { "recipients": null, "state": "sending", "target": { "destination_id": "string", "kind": "destination" } } ] }, "delivery_failed": [ "string" ], "description": "string", "first_seen": "string", "hit_count": 0, "id": "string", "key": "string", "last_seen": "string", "latest_row": null, "origin": "string", "resolved_at": "string", "resolved_by": null, "severity": "informational", "source": { "class": "rule", "result_table_id": "string", "rule_id": "string", "run_id": "string" }, "status": "open", "title": "string" } ], "next_cursor": "string", "not_shown": 0}`PUT /investigations/{id}/alerts/{alertId}` — link an alert. PUT
Link an alert to this investigation. You need to be able to edit the investigation and see the alert; apps cannot. Linking a linked pair succeeds and changes nothing. Neither the investigation nor the alert changes. The answer is the two ids. A token without `alerts:read` is a 403 before anything is read; an alert you cannot see, or that does not exist, is the 404 `GET /alerts/{id}` gives; a missing investigation is a 404; one you may not edit is a 403.
`DELETE /investigations/{id}/alerts/{alertId}` — unlink an alert. DELETE
The same checks as linking. Unlinking a pair that is not linked succeeds. Neither the investigation nor the alert changes. The answer is the two ids.