---
title: "Alert Details"
method: GET
path: "/api/v2/Alerts/{alertId}"
tags: ["Alerts"]
---

# Alert Details

`GET /api/v2/Alerts/{alertId}`

Get details about an alert by invoking the following endpoint:
 
 > `GET https://YourAccount.lacework.net/api/v2/Alerts/{alertId}?scope={scope}` 

  You must specify a scope, as one of these options: `Details`, `Investigation`, `Events`, `RelatedAlerts`, `Integrations`, or `Timeline` or `ObservationTimeline`.

## Path parameters

- `alertId` string, required

## Query parameters

- `scope` 'Details' | 'Investigation' | 'Events' | 'RelatedAlerts' | 'Integrations' | 'Timeline' | 'ObservationTimeline', required

## Headers

- `Authorization` string, required
- `Content-Type` string, required

## Response `200`

No Error (Alert Details)

- union
  - AlertsDetailsResponseSchemaFinalized
    - `scope` 'Details' — This field is used for the response schema option; it will not be in the response.
    - `data` object
      - `alertId` integer — Alert ID
      - `alertType` string — The alert type
      - `alertName` string — The alert name such as `Service called GCP API`
      - `alertInfo` object — Details of the alert
        - `description` string — The alert description provides why the potential threat occurred
        - `subject` string — The alert subject. In some cases, the alert subject can be the same as the alert name.
        - `customerCount` number — Number of customers with similar behavior. While this event occurred for the first time in this FortiCNAPP account, it may be considered less risky if it represents common behavior observed in other customer cloud deployments.
        - `isExpectedLWBehavior` boolean — Whether the alert results from activity related to your FortiCNAPP integration, such as connections between FortiCNAPP agents and the FortiCNAPP platform.
        - `supportingFacts` object[] — List of supporting facts of a [composite alert](https://docs.fortinet.com/document/forticnapp/latest/administration-guide?cshid=INTRODUCTION_TO_COMPOSITE_ALERTS).
          - `supportingFactText` string — The supporting fact indicates why the potential threat occurred.
          - `subElements` object[] — Sub elements provide more details of supporting facts in a recursive format.
      - `severity` string — The alert's severity level. See [Alert Severity](https://docs.fortinet.com/document/forticnapp/latest/administration-guide?cshid=ALERT_SEVERITY).
      - `internetExposure` string — Whether any entity involved in the alert is exposed to the internet: yes, no, or unknown.
      - `reachability` string — Whether any entity in the alert is reachable.
      - `derivedFields` object — The alert category, subcategory, and source.
        - `category` string — The alert category. See [Alert Categories](https://docs.fortinet.com/document/forticnapp/latest/administration-guide?cshid=ALERT_CATEGORIES).
        - `subCategory` string — The alert subcategory. See [Alert Subcategories](https://docs.fortinet.com/document/forticnapp/latest/administration-guide?cshid=ALERT_CATEGORIES#alert-subcategories).
        - `source` string — The origin of the alert: AWS, Azure, GCP, Agent, or K8s.
      - `startTime` string — The time and date when the potential threat started
      - `endTime` string — The time and date when the potential threat ended
      - `lastUserUpdatedTime` string — The timestamp for when a user selected a [primary integration](https://docs.fortinet.com/document/forticnapp/latest/administration-guide?cshid=JIRA#bidirectional-integration) or updated the alert status
      - `status` string — The current status of the alert
      - `entityMap` object
  - AlertsInvestigationResponseSchemaFinalized
    - `scope` 'Investigation' — This field is used for the response schema option; it will not be in the response.
    - `data` object[]
      - `question` string — FortiCNAPP-defined investigative questions that may help uncover unexpected behaviors relevant to the event.
      - `answer` string — The answer to the investigative question, `Yes` or `No`.
  - AlertsEventsResponseSchemaFinalized
    - `scope` 'Events' — This field is used for the response schema option; it will not be in the response.
    - `data` object[]
      - `awsRegion` string — The AWS region where the event occurred.
      - `eventName` string — The name of the event.
      - `eventSource` string — The source domain of the event or where the event occurred, such as `rds.amazonaws.com`.
      - `sourceIpAddress` string — The IP address from which a request associated with the event was made.
      - `recipientAccountId` string — The account ID that received the event.
      - `mfa` boolean — Whether MFA is enabled.
      - `eventTime` string — A timestamp reflecting when the event occurred.
      - `userIdentity` object — The user associated with the event.
      - `firstTime` string — The earliest timestamp when a similar event was first seen.
      - `eventTimes` string — The timestamp of the original event in Pacific Time.
      - `userName` string — The user name involved in the event.
      - `additionalEventInfo` object — Additional information associated with the event, if available.
      - `requestParameters` object — Type-specific request parameters associated with the event.
      - `region` string — The region where the event occurred.
      - `projectId` string — The GCP project ID involved in the event.
      - `serviceName` string — The service name involved in the event.
      - `methodName` string — The method name.
      - `principalEmail` string — The principal email address.
      - `organizationName` string — The GCP organization name.
      - `callerSuppliedUserAgent` string — The caller supplied user agent.
      - `request` string — The request info.
      - `tenantId` string — The tenant ID.
      - `resourceId` string — The resource ID.
      - `callerIpAddress` string — The source IP address.
      - `identity` string — The identity.
      - `operationName` string — The API (operation name).
      - `resultType` string — The result type.
      - `subscriptionId` string — The subscription ID.
      - `providerName` string — The provider name.
      - `eventCategory` string — The event category for the original event.
      - `tenantName` string — The tenant name.
      - `subscriptionName` string — The subscription name.
      - `startTime` string — The start time of the event, related alert, or the composite observation.
      - `endTime` string — The end time of the event, related alert, or the composite observation.
      - `srcIpAddrPort` string — The source IP address and port for the connection.
      - `dstIpAddrPort` string — The destination IP address and port for the connection.
      - `machine` string — The hostname of the machine.
      - `container` string — The name of the container.
      - `processIdHash` string — The hash of the process ID.
      - `processId` string — The ID of the process.
      - `fileExePath` string — The execution path of the file.
      - `bytes` string — The number of bytes transferred.
      - `compositeEventId` number — The ID of the composite alert.
      - `id` string — The ID of the related alert or the composite observation.
      - `name` string — The name of the related alert or the composite observation.
      - `descriptionText` string — The description of the related alert or the composite observation.
      - `compositeStartTime` string — The start time of the composite alert.
      - `compositeEndTime` string — The end time of the composite alert.
      - `entityKeys` object[] — The list of focal entities of the related alert or composite observation.
      - `tagMetadata` object[] — The list of MITRE tags tagged to an alert.
        - `tagMetadata` object — Detailed MITRE tag information tagged to an alert.
          - `customerFacingId` string — Customer facing ID for MITRE tag.
          - `id` string — MITRE tag ID.
          - `name` string — MITRE tag name.
          - `orderIndex` string — Priority of the MITRE tag.
          - `parentId` string — ID representing the parent tag (MITRE Technique ID for a given sub-technique).
          - `type` string — Type of MITRE tag.
          - `url` string — URL to redirect to MITRE tag information on the MITRE tag website.
          - `version` string — Version of MITRE tag.
  - AlertsRelatedAlertsResponseSchemaFinalized
    - `scope` 'RelatedAlerts' — This field is used for the response schema option; it will not be in the response.
    - `data` object[]
      - `eventType` string — The event type of the related alert.
      - `eventId` string — The ID of the related alert.
      - `severity` string — The Severity of the related alert.
      - `startTime` string — The start time of the alert time range in which the related alert occurred.
      - `endTime` string — The end time of the alert time range in which the related alert occurred.
      - `eventModel` string — The event model of the related alert.
      - `eventProps` object — The event properties of the related alert.
      - `keys` object — The related alert event keys.
      - `rank` number — The rank of the related alert based on a similarity score.
      - `eventInfo` object — Information associated with the related event, such as its description.
      - `eventName` string — The name of the related alert.
  - AlertsIntegrationsResponseSchemaFinalized
    - `scope` 'Integrations' — This field is used for the response schema option; it will not be in the response.
    - `data` object[]
      - `alertChannel` object — The name of the alert channel.
      - `alertIntegrationId` string — The integration identifier.
      - `createdTime` string — A timestamp representing the time the alert channel integration was created.
      - `alertId` number — The alert identifier.
      - `integrationType` string — The integration type, such as Jira or ServiceNow.
      - `integrationContext` object — Arbitrary fields needed for the specific integration type.
      - `intgGuid` string — The unique global identifier for the integration.
      - `lastSyncTime` string — The last time FortiCNAPP synchronized data with the integrated system.
      - `alertIntegrationStatus` string — Status specific to the integration type, such as a Jira issue status.
      - `status` string — The integration status.
      - `isBidirectional` boolean — Whether the integration supports bidirectional events.
  - AlertsTimelineResponseSchemaFinalized
    - `scope` 'Timeline' — This field is used for the response schema option; it will not be in the response.
    - `data` object[]
      - `alertChannel` object — The name of the alert channel.
      - `id` number — The timeline item identifier.
      - `alertId` number — The alert identifier.
      - `createdTime` string — The created time of the timeline item.
      - `entryType` string — The type of timeline item.
      - `entryAuthorType` string — The timeline item author type, among `SystemUpdate`, `UserUpdate`, or `Integration`.
      - `intgGuid` string — The integration's globally unique identifier.
      - `message` object — The message associated with the timeline item.
      - `externalTime` string — The timestamp when the timeline item was generated according to the external alert platform.
      - `user` object — The user who created the timeline item.
      - `external` boolean — Whether the timeline item was externally generated.
      - `updateContext` object — Context information associated with the timeline item.
      - `alertIntegration` object — Information about the alert channel integration.
  - AlertsObservationTimelineResponseSchemaFinalized
    - `scope` 'ObservationTimeline' — This field is used for the response schema option; it will not be in the response.
    - `data` object[]
      - `recordUuid` string — Unique identifier for a record in the observation timeline.
      - `observationPivotEntityUuids` unknown[] — A list of unique identifiers for the primary or 'pivot' entities that this record describes.
        - unknown
      - `observationType` string — The observation type corresponds to the kind of suspicious activity detected.
      - `description` string — A description of the suspicious activity detected.
      - `entities` object[]
        - `isDetail` boolean — Boolean flag denoting if the entity has special relevance to the observation to which it belongs.
        - `isSubject` boolean — Boolean flag denoting if the entity is the focus of the observation to which it belongs.
        - `entityType` string — The type of the entity.
        - `entityKey` object — A list of key-value pairs that identify the entity.
        - `entityText` string — Display text for the entity.
        - `entityUuid` string — Unique identifier for the entity.
      - `relationships` object[]
        - `relationshipId` string — Unique identifier for a specific instance of a relationship.
        - `srcEntityType` string — The type of the source entity.
        - `dstEntityType` string — The type of the destination entity.
        - `srcEntityKey` object — A list of key-value pairs that identify the source entity.
        - `dstEntityKey` object — A list of key-value pairs that identify the destination entity.
        - `srcEntityText` string — Display text for the source entity.
        - `dstEntityText` string — Display text for the destination entity.
        - `srcEntityUuid` string — Unique identifier for the source entity.
        - `dstEntityUuid` string — Unique identifier for the destination entity.
      - `startEpoch` number — The start timestamp in epoch seconds of the interval the observation was detected.
      - `endEpoch` number — The end timestamp in epoch seconds of the interval the observation was detected.
      - `formalTags` object[] — A list of tags that describe each group of observations in the observation timeline.

## Other responses

- `204` — No Data
- `4XX` — Client Error
- `5XX` — Internal Server Error

---

[API](https://skmtc.net/lacework/apis/forticnapp-api-2-0-documentation.md) · [All operations](https://skmtc.net/lacework/apis/forticnapp-api-2-0-documentation/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/lacework/forticnapp-api-2-0-documentation/revisions/7015f76895f2/schema)
