Obtain Evidence
curl --request GET \
--url http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId} \
--header 'Authorization: Bearer <token>'import requests
url = "http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"_links": {
"self": {
"href": "<string>"
}
},
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"urn": "<string>",
"summary": "<string>",
"created": {
"by": "jsmith@example.com",
"on": "2023-11-07T05:31:56Z"
}
}{
"errorId": "<string>",
"message": "<string>",
"variables": [
"<string>"
],
"errorUrl": "<string>"
}Evidence
Obtain Evidence
Returns a piece of evidence associated with an investigation.
GET
/
investigations
/
{investigationId}
/
evidence
/
{evidenceId}
Obtain Evidence
curl --request GET \
--url http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId} \
--header 'Authorization: Bearer <token>'import requests
url = "http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("http://investigations.{region}.alienvault.cloud/investigations/v3/investigations/{investigationId}/evidence/{evidenceId}")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"_links": {
"self": {
"href": "<string>"
}
},
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"urn": "<string>",
"summary": "<string>",
"created": {
"by": "jsmith@example.com",
"on": "2023-11-07T05:31:56Z"
}
}{
"errorId": "<string>",
"message": "<string>",
"variables": [
"<string>"
],
"errorUrl": "<string>"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
The unique identifier of an investigation.
The unique identifier of an evidence.
Response
OK
Returns an evidence.
Show child attributes
Show child attributes
Unique identifier of the resource.
Uniform Resource Name (URN) of the evidence. It may contain an alarm, event, user, asset, or other information as edidence for the investigation.
Summary information from the source object providing the evidence. Such information is not subject to change or modified by a user.
Specifies when the resource was created and by whom.
Show child attributes
Show child attributes
⌘I