Get a list of issue to import into your SIEM. Issues are one or more incidents that have been grouped by the Issue Keys. To receive a stream of the latest issues, save the issue id as bookmark and query on some interval for the latest issues that > this bookmark, ie the latest issue id you have previously queried. For additional details about each issue, you can query the GetIssueDetails API for the specific issue id
Endpoint: GET /v1/getIssues. Authentication: requires AuthorizationHeader bearer token unless this operation's security is changed. Required AuthMind permission/scope: issues (grant this scope on the API token in Admin > API Tokens; a token without it receives 403 Forbidden). Documented parameters: issue_type, issue_id_gt, issue_time_gt, sort_order, sort_by, from, size. Pagination: use from and/or size as documented. Pagination convention for this endpoint: from is a zero-based row offset (default 0), size is the row limit (default 1000). Sorting: use only documented sort fields and sort-order enum values. Response parsing: inspect success; on failure inspect error, errors, or message depending on the referenced schema.
Used to retrieve only a specific issue type. If left empty, the issues will be retrieved for all the types.(recommended)
Allowed values: Access from Anonymous IP, Access from Public VPN, Access from Unauthorized Countries, Access to Anonymous IP, Access to Public VPN, Access to Unauthorized Countries, Auth Hash Quality, Auth Hash Security, Auth Protocol Quality, Compromised Password, Compromised User, Deviation in Daily Asset Activity, Enumeration of AD Admins, Enumeration of AD Users, Exposed Assets, Lack of MFA, Identity No MFA, Asset No MFA, Shadow Access, Shadow Assets, Shadow Identity Systems, Suspected AD NTLM Relay Attack, Suspected Attack on Disabled AD Account, Suspected Attack on Expired AD Account, Suspected Attack on Locked AD Account, Suspected AD Brute-force Attack, Suspected Identity Brute-force Attack, Suspected Directory/IdP Bot Attack, Suspected Directory/IdP Password Spray Attack, Suspicious Inbound Access, Suspicious Outbound Access, Unauthorized Asset Access, Unknown SaaS Access, Weak Password, Unauthorized Identity Access, Impossible Travel, Suspected Access Token Sharing.
Used to retrieve latest issues by Date / Time. All issues > this parameter will be returnedIf neither the issue_id_gt parameter field or this field is provided as parameter, the returns will default to the last 7 days. e.g. '2024-01-02 15:04:05'
Use the timestamp format stated in this endpoint (YYYY-MM-DD HH:MM:SS), interpreted as UTC.
- Mock serverhttps://apidoc.authmind.com/_mock/v1/docs/v1/getIssues
- https://apidoc.authmind.com/{{.Host}}/amapihttps://apidoc.authmind.com/{{.Host}}/amapi/v1/getIssues
curl -i -X GET \
'https://apidoc.authmind.com/_mock/v1/docs/v1/getIssues?issue_type=Access%20from%20Anonymous%20IP&issue_id_gt=string&issue_time_gt=2019-08-24T14%3A15%3A22Z&sort_order=ASC&sort_by=issue_id&from=0&size=0' \
-H 'Authorization: Bearer <YOUR_JWT_HERE>'{ "success": true, "results": [ { … } ], "metadata": { "from": 1, "size": 10, "total": 1 } }