---
title: "[restSearch] Get a filtered and paginated list of events"
method: POST
path: "/events/restSearch"
tags: ["Events"]
---

# [restSearch] Get a filtered and paginated list of events

`POST /events/restSearch`

**This is the recommended endpoint for searching events.**

## Request body

- object
  - `page` integer, nullable
  - `limit` integer, nullable — Maximum number of results to be returned. Can't be greater than the one set for your role. 0 means maximum.
  - `value` string
  - `type` 'md5' | 'sha1' | 'sha256' | 'filename' | 'pdb' | 'filename|md5' | 'filename|sha1' | 'filename|sha256' | 'ip-src' | 'ip-dst' | 'hostname' | 'domain' | 'domain|ip' | 'email' | 'email-src' | 'eppn' | 'email-dst' | 'email-subject' | 'email-attachment' | 'email-body' | 'float' | 'git-commit-id' | 'url' | 'http-method' | 'user-agent' | 'ja3-fingerprint-md5' | 'jarm-fingerprint' | 'favicon-mmh3' | 'hassh-md5' | 'hasshserver-md5' | 'regkey' | 'regkey|value' | 'AS' | 'snort' | 'suricata' | 'bro' | 'zeek' | 'community-id' | 'pattern-in-file' | 'pattern-in-traffic' | 'pattern-in-memory' | 'pattern-filename' | 'pgp-public-key' | 'pgp-private-key' | 'yara' | 'stix2-pattern' | 'sigma' | 'gene' | 'kusto-query' | 'mime-type' | 'identity-card-number' | 'cookie' | 'vulnerability' | 'cpe' | 'weakness' | 'attachment' | 'malware-sample' | 'link' | 'comment' | 'text' | 'hex' | 'other' | 'named pipe' | 'mutex' | 'process-state' | 'target-user' | 'target-email' | 'target-machine' | 'target-org' | 'target-location' | 'target-external' | 'btc' | 'dash' | 'xmr' | 'iban' | 'bic' | 'bank-account-nr' | 'aba-rtn' | 'bin' | 'cc-number' | 'prtn' | 'phone-number' | 'threat-actor' | 'campaign-name' | 'campaign-id' | 'malware-type' | 'uri' | 'authentihash' | 'vhash' | 'ssdeep' | 'imphash' | 'telfhash' | 'pehash' | 'impfuzzy' | 'sha224' | 'sha384' | 'sha512' | 'sha512/224' | 'sha512/256' | 'sha3-224' | 'sha3-256' | 'sha3-384' | 'sha3-512' | 'tlsh' | 'cdhash' | 'filename|authentihash' | 'filename|vhash' | 'filename|ssdeep' | 'filename|imphash' | 'filename|impfuzzy' | 'filename|pehash' | 'filename|sha224' | 'filename|sha384' | 'filename|sha512' | 'filename|sha512/224' | 'filename|sha512/256' | 'filename|sha3-224' | 'filename|sha3-256' | 'filename|sha3-384' | 'filename|sha3-512' | 'filename|tlsh' | 'windows-scheduled-task' | 'windows-service-name' | 'windows-service-displayname' | 'whois-registrant-email' | 'whois-registrant-phone' | 'whois-registrant-name' | 'whois-registrant-org' | 'whois-registrar' | 'whois-creation-date' | 'x509-fingerprint-sha1' | 'x509-fingerprint-md5' | 'x509-fingerprint-sha256' | 'dns-soa-email' | 'size-in-bytes' | 'counter' | 'datetime' | 'port' | 'ip-dst|port' | 'ip-src|port' | 'hostname|port' | 'mac-address' | 'mac-eui-64' | 'email-dst-display-name' | 'email-src-display-name' | 'email-header' | 'email-reply-to' | 'email-x-mailer' | 'email-mime-boundary' | 'email-thread-index' | 'email-message-id' | 'github-username' | 'github-repository' | 'github-organisation' | 'jabber-id' | 'twitter-id' | 'dkim' | 'dkim-signature' | 'first-name' | 'middle-name' | 'last-name' | 'full-name' | 'date-of-birth' | 'place-of-birth' | 'gender' | 'passport-number' | 'passport-country' | 'passport-expiration' | 'redress-number' | 'nationality' | 'visa-number' | 'issue-date-of-the-visa' | 'primary-residence' | 'country-of-residence' | 'special-service-request' | 'frequent-flyer-number' | 'travel-details' | 'payment-details' | 'place-port-of-original-embarkation' | 'place-port-of-clearance' | 'place-port-of-onward-foreign-destination' | 'passenger-name-record-locator-number' | 'mobile-application-id' | 'chrome-extension-id' | 'edge-extension-id' | 'cortex' | 'boolean' | 'anonymised'
  - `category` 'Internal reference' | 'Targeting data' | 'Antivirus detection' | 'Payload delivery' | 'Artifacts dropped' | 'Payload installation' | 'Persistence mechanism' | 'Network activity' | 'Payload type' | 'Attribution' | 'External analysis' | 'Financial fraud' | 'Support Tool' | 'Social network' | 'Person' | 'Other'
  - `org` union
    - string
    - string
  - `tags` string[], nullable
  - `event_tags` string[], nullable
  - `searchall` string — Search events by matching any tag names, event descriptions, attribute values or attribute comments
  - `from` string, nullable — You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)
  - `to` string, nullable — You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)
  - `last` union — Events published within the last x amount of time, where x can be defined in days, hours, minutes (for example 5d or 12h or 30m), ISO 8601 datetime format or timestamp
    - integer
    - string
  - `eventid` string
  - `withAttachments` boolean — Extends the response with the base64 representation of the attachment, if there is one
  - `sharinggroup` string[], nullable — Sharing group ID(s), either as single string or list of IDs
  - `metadata` boolean, nullable — Will only return the metadata of the given query scope, contained data is omitted.
  - `uuid` string, uuid
  - `publish_timestamp` string
  - `timestamp` string
  - `published` boolean
  - `enforceWarninglist` boolean, nullable — Should the warning list be enforced. Adds blocked field for matching attributes
  - `sgReferenceOnly` boolean — Will only return the sharing group ID
  - `requested_attributes` string[] — List of properties that will be selected in the CSV export
  - `includeContext` boolean, nullable — Adds events context fields in the CSV export
  - `headerless` boolean, nullable — Removes header in the CSV export
  - `includeWarninglistHits` boolean, nullable
  - `attackGalaxy` string, nullable
  - `to_ids` boolean
  - `deleted` boolean — Whether to include soft-deleted attributes. Default value 0. If set to 1, only deleted attributes will be returned. If set to [0,1], both deleted and non-deleted attributes will be returned.
  - `excludeLocalTags` boolean, nullable — Exclude local tags from the export
  - `date` string, nullable — You can use any of the valid time related filters (examples: 7d, timestamps, [14d, 7d] for ranges, etc.)
  - `includeSightingdb` boolean, nullable — Extend response with Sightings DB results if the module is enabled
  - `tag` string
  - `object_relation` string, nullable — Filter by the attribute object relation value
  - `threat_level_id` '1' | '2' | '3' | '4' — Represents the threat level. * `1` - High * `2` - Medium * `3` - Low * `4` - Undefined
  - `extending` boolean — Whether to include events that are extending another one. If set to 1, only events extending another will be returned. If set to 0, only events that are not extending another will be returned. Omit or [0,1] to disregard extension state.
  - `extended` boolean — Whether to include events that are extended by another one. If set to 1, only events extended by another will be returned. If set to 0, only events that are not extended by another will be returned. Omit or [0,1] to disregard extension state.
  - `returnFormat` 'json' | 'xml' | 'csv' | 'text' | 'stix' | 'stix2' | 'stix-json' | 'attack' | 'attack-sightings' | 'cache' | 'count' | 'hashes' | 'netfilter' | 'opendata' | 'openioc' | 'rpz' | 'snort' | 'suricata' | 'yara' | 'yara-json' — Format of the response payload

## Response `200`

Rest search events response

- object
  - `response` object[]

## Other responses

- `403` — Authentication failed. Please make sure you pass the API key of an API enabled user along in the Authorization header.
- `default` — Unexpected API error

---

[API](https://skmtc.net/misp/apis/misp-automation-api.md) · [All operations](https://skmtc.net/misp/apis/misp-automation-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/misp/misp-automation-api/revisions/88b34ff032a1/schema)
