Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

L2 Linker

Hi CBarichello,


You are on the right path. You are missing a filter that would inform the API as to how far back to query for alerts. Here I am querying for resolved alerts from the last 3 hours via v2 POST:

# Get a 10 minute token
token=$(curl -X POST -H 'Content-Type: application/json' -d '{"username":"'$PRISMA_ACCESS_KEY_ID'","password":"'$PRISMA_SECRET_KEY'"}' | jq -r '.token')
# Body of the POST

curl -L -X POST '' -H 'Content-Type: application/json; charset=UTF-8' -H 'Accept: */*' -H 'x-redlock-auth: '$token --data-raw "$body"

# Same thing via v2 GET
curl -L -X GET '' -H 'Accept: */*' -H 'x-redlock-auth: '$token


All info can be found the developer documentation
Hope this helps.
Helping protect our customers' digital way of life.

View solution in original post

Who rated this post