Returns a single alert by ID.
The alert identifier: its UUID or its numeric pretty_id. This property is required.
A successful response.
A security event ingested from an alert source and enriched with a triage verdict and context.
The unique identifier of the alert.
The unique identifier of the alert as displayed on the Alerts page.
The identifier of the organization.
The identifier of the workspace.
The alert name.
The type of alert. For example, "Endpoint Detection - ldt".
Contains information from the source security system that generated the alert.
The alert source vendor name. Deprecated: use integration_type_id instead.
A link to the alert in the source system console.
The severity from the source system. For example, "Critical", "High", "Medium", "Low", "Informational".
The mitigation action taken or available from the source system.
The timestamp when the alert was detected by the source system.
The alert source type identifier. For example, "crowdstrike_streaming", "sentinelone_data_connector".
The timestamp when the alert was acknowledged by Auto Triage.
The timestamp when Auto Triage completed the verdict assignment.
The timestamp when the alert was ingested into the workspace.
The triage verdict, severity, and confidence assigned by Auto Triage.
The verdict value. Possible values: "True Positive - Malicious", "True Positive - Benign", "False Positive".
The severity assigned by Auto Triage. Possible values: "Critical", "High", "Medium", "Low", "Info".
The Auto Triage's confidence level in the verdict. Possible values: "High", "Medium", "Low".
Contains the alert analysis summary and event timeline.
A detailed description of the alert.
The chronological sequence of events that occurred within the alert.
A single event in the alert timeline.
The timestamp of the event.
A description of what occurred.
The reasoning and supporting evidence behind the triage verdict.
An explanation of why the verdict was assigned.
Supporting evidence for the verdict.
Key indicators extracted from the alert.
A key indicator extracted from the alert.
The identifier of the observable.
The type of observable. For example, "IP Address", "Hash", "Hostname", "URL". Unrecognized types are reported as "Unknown".
The value of the observable.
Context about the observable.
The reputation status of the observable. Possible values: "Unknown", "Clean", "Suspicious", "Malicious".
A link to the observable in Torq.
Contains MITRE ATT&CK framework mappings.
The MITRE ATT&CK tactics associated with the alert.
A MITRE ATT&CK tactic.
The MITRE ATT&CK tactic ID. For example, "TA0011".
The tactic name.
A link to the MITRE ATT&CK tactic page.
The MITRE ATT&CK techniques associated with the alert.
A MITRE ATT&CK technique.
The MITRE ATT&CK technique ID. For example, "T1219", "T1059.004".
The technique name.
A link to the MITRE ATT&CK technique page.
The rules and guidance entries applied during triage.
The rule or guidance entry applied during triage.
The rule or guidance identifier.
The rule or guidance name.
The type of reference. Possible values: "Guidance", "Rule".
The description of the rule or guidance entry.
Recommended actions for the analyst based on the triage verdict.
The recommended action for the analyst.
The action identifier.
The name of the recommended action.
A detailed description of the recommended action.
The priority level of the action. Possible values: "Critical", "High", "Medium", "Low".
Contains information about the case associated with this alert.
The case pretty ID.
A link to the case in Torq.
The entity that performed the action.
The actor kind. Identifies which actor case is populated. One of:
USER, WORKFLOW, INTEGRATION, SERVICE_API_KEY, SOCRATES, TRIAGE, AGENT, BUILDER.
User identity information.
The actor's email address.
The user's full name.
Workflow execution details.
The workflow ID.
The workflow execution ID.
The workflow name.
Integration configuration.
The integration ID.
The integration type identifier.
Service account API token information.
The service account API token name.
The service account API token client ID.
Original actor information.
The entity that performed the action.
Triage system action.
Agent execution details.
The agent ID.
The agent execution ID.
Workflow Builder acting on behalf of a user.
The entity that performed the action.
Contains the manual verification status set by an analyst.
The verdict review action taken. Possible values: "Confirmed", "Changed".
The email address of the analyst who reviewed the verdict.
The timestamp when the verdict was reviewed.
Verdict and/or severity changes.
The new severity if changed. Possible values: "Critical", "High", "Medium", "Low", "Info". Empty if unchanged.
The new verdict if changed. Possible values: "True Positive - Malicious", "True Positive - Benign", "False Positive". Empty if unchanged.
The analyst's comment on the verdict review.
The security categories assigned to the alert, ordered by dominance — the first element is the primary category. Always has at least one value. Possible values: "Endpoint Security", "Identity and Access", "Cloud Security", "Data Security", "Email Security", "General". For natively supported sources the categories follow from the detection type; for universal sources Auto Triage classifies them.
Invalid bearer token. If you receive this message more than once try creating a new Client ID/Client Secret or generating a new bearer token.
You don't have permission to access this resource.