<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to pass a filter to the Alerts API call with a post in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-to-pass-a-filter-to-the-alerts-api-call-with-a-post/m-p/564175#M1088</link>
    <description>&lt;P&gt;Thanks for the detailed information.&amp;nbsp; &amp;nbsp;After reading your post, I changed my code from&lt;/P&gt;
&lt;P&gt;-d '{"limit":"3","filters":[{"status":"resolved"}]}'&lt;/P&gt;
&lt;P&gt;to&lt;/P&gt;
&lt;P&gt;d '{"limit":"3","filters":[{"name":"alert.status","operator":"=","value":"resolved"}]}'&lt;/P&gt;
&lt;P&gt;It works great now.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2023 20:26:56 GMT</pubDate>
    <dc:creator>CBarichello</dc:creator>
    <dc:date>2023-11-02T20:26:56Z</dc:date>
    <item>
      <title>How to pass a filter to the Alerts API call with a post</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-to-pass-a-filter-to-the-alerts-api-call-with-a-post/m-p/563952#M1085</link>
      <description>&lt;P&gt;I am attempting to get back a list of alerts with a status of resolved, but the filter is not working for me.&amp;nbsp; Any ideas?&amp;nbsp; &amp;nbsp;I get back items, but they don't always have a status of resolved.&amp;nbsp; Sometimes they do, sometimes the status is open, etc.&amp;nbsp; See code below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;url&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;A href="https://api2.prismacloud.io/alert?detailed=true" target="_blank"&gt;https://api2.prismacloud.io/alert?detailed=true&lt;/A&gt;"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;api_key=&lt;/SPAN&gt;&lt;SPAN&gt;"my token goes here"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;json_body='{&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"limit"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"3"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"filters"&lt;/SPAN&gt;&lt;SPAN&gt;: [&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"status"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"resolved"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; }&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; ]&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;}'&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;curl -X POST $url&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt; -H &lt;/SPAN&gt;&lt;SPAN&gt;"Content-Type: application/json"&lt;/SPAN&gt;&lt;SPAN&gt; -H &lt;/SPAN&gt;&lt;SPAN&gt;"Accept: */*"&lt;/SPAN&gt;&lt;SPAN&gt; -H &lt;/SPAN&gt;&lt;SPAN&gt;"x-redlock-auth: $api_key"&lt;/SPAN&gt;&lt;SPAN&gt; -d &lt;/SPAN&gt;&lt;SPAN&gt;"$json_body"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 01 Nov 2023 20:10:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-to-pass-a-filter-to-the-alerts-api-call-with-a-post/m-p/563952#M1085</guid>
      <dc:creator>CBarichello</dc:creator>
      <dc:date>2023-11-01T20:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass a filter to the Alerts API call with a post</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-to-pass-a-filter-to-the-alerts-api-call-with-a-post/m-p/564167#M1087</link>
      <description>&lt;P&gt;Hi CBarichello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are on the right path. You are missing a filter that would inform the API as to how far back to query for alerts. Here I am querying for resolved alerts from the last 3 hours via v2 POST:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;# Get a 10 minute token
token=$(curl -X POST https://api2.prismacloud.io/login -H 'Content-Type: application/json' -d '{"username":"'$PRISMA_ACCESS_KEY_ID'","password":"'$PRISMA_SECRET_KEY'"}' | jq -r '.token')
# Body of the POST
body='{"detailed":"true","timeRange":{"type":"relative","value":{"amount":3,"unit":"hour"}},"filters":[{"name":"alert.status","operator":"=","value":"resolved"}]}'

curl -L -X POST 'https://api2.prismacloud.io/v2/alert?detailed=true' -H 'Content-Type: application/json; charset=UTF-8' -H 'Accept: */*' -H 'x-redlock-auth: '$token --data-raw "$body"

# Same thing via v2 GET
curl -L -X GET 'https://api2.prismacloud.io/v2/alert?timeType=relative&amp;amp;timeAmount=3&amp;amp;timeUnit=hour&amp;amp;detailed=true&amp;amp;alert.status=resolved' -H 'Accept: */*' -H 'x-redlock-auth: '$token&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;All info can be found the developer documentation&amp;nbsp;&lt;A href="https://pan.dev/prisma-cloud/api/cspm/post-alerts-v-2/" target="_blank"&gt;https://pan.dev/prisma-cloud/api/cspm/post-alerts-v-2/&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;Hope this helps.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 02 Nov 2023 19:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-to-pass-a-filter-to-the-alerts-api-call-with-a-post/m-p/564167#M1087</guid>
      <dc:creator>JNeytchev</dc:creator>
      <dc:date>2023-11-02T19:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to pass a filter to the Alerts API call with a post</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-to-pass-a-filter-to-the-alerts-api-call-with-a-post/m-p/564175#M1088</link>
      <description>&lt;P&gt;Thanks for the detailed information.&amp;nbsp; &amp;nbsp;After reading your post, I changed my code from&lt;/P&gt;
&lt;P&gt;-d '{"limit":"3","filters":[{"status":"resolved"}]}'&lt;/P&gt;
&lt;P&gt;to&lt;/P&gt;
&lt;P&gt;d '{"limit":"3","filters":[{"name":"alert.status","operator":"=","value":"resolved"}]}'&lt;/P&gt;
&lt;P&gt;It works great now.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 20:26:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-to-pass-a-filter-to-the-alerts-api-call-with-a-post/m-p/564175#M1088</guid>
      <dc:creator>CBarichello</dc:creator>
      <dc:date>2023-11-02T20:26:56Z</dc:date>
    </item>
  </channel>
</rss>

