v1

latestOpenAPI 3.0.0Apache 2.0 License2026-07-142381,278956.3 KB

Lists the active violations for a given Device Defender security profile.

Requires permission to access the ListActiveViolations action.

get/active-violations

Query parameters

thingNamestring

The name of the thing whose active violations are listed.

securityProfileNamestring

The name of the Device Defender security profile for which violations are listed.

behaviorCriteriaType'STATIC' | 'STATISTICAL' | 'MACHINE_LEARNING'

The criteria for a behavior.

listSuppressedAlertsboolean

A list of all suppressed alerts.

verificationState'FALSE_POSITIVE' | 'BENIGN_POSITIVE' | 'TRUE_POSITIVE' | 'UNKNOWN'

The verification state of the violation (detect alarm).

nextTokenstring

The token for the next set of results.

maxResultsinteger

The maximum number of results to return at one time.

Response

Success

nextTokenstring

A token that can be used to retrieve the next set of results, or <code>null</code> if there are no additional results.