Export vulnerability events for authorized partner tenants.
curl --request GET \
--url https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events \
--header 'Authorization: Bearer <token>'import requests
url = "https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"root_tenant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"generated_at": "2023-11-07T05:31:56Z",
"from": "2023-11-07T05:31:56Z",
"to": "2023-11-07T05:31:56Z",
"format": "<string>",
"coverage": [
{
"tenant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"tenant_host": "<string>"
}
],
"items": [
{
"finding_event_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"tenant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"tenant_host": "<string>",
"event_type": "opened",
"occurred_at": "2023-11-07T05:31:56Z",
"cve_id": "<string>",
"description": "<string>",
"severity": "critical",
"cvss_score": 123,
"cvr_score": 123,
"epss_probability": 123,
"exploitability_label": "<string>",
"root_cause_key": "<string>",
"root_cause_label": "<string>",
"source_type": "endpoint",
"asset_id": "<string>",
"asset_display_name": "<string>",
"asset_type": "endpoint",
"os_family": "<string>",
"os_name": "<string>",
"agent_status": "<string>",
"tenant_name": "<string>",
"detected_while_offline": false,
"exploit_sources": [
"<string>"
]
}
]
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>"
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>"
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>"
}Reporting
Export vulnerability events for authorized partner tenants.
This endpoint returns a single-page export of live vulnerability detection events, within a
bounded time window, for the authorized partner’s tenant scope. The response is returned
with a Content-Disposition: attachment header naming a timestamped export file.
Notes:
tenant_ids(optional, comma-separated) restricts the export to specific tenants.from/to(optional, ISO-8601 timestamps) bound the detection window; defaults to the last 24 hours.frommust not be later thanto.source_type,severity,root_cause_type, andpatchabilityfilter the result set.format(optional, defaultjson) selects the export format; onlyjsonis currently supported; any other value returns 400.- The export is capped at the maximum page size (500 events) and is not cursor-paginated.
Required headers:
Authorization: Bearer {token}(requires thepulse.readscope)
GET
/
pulse
/
v1
/
partner
/
exports
/
vulnerability-events
Export vulnerability events for authorized partner tenants.
curl --request GET \
--url https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events \
--header 'Authorization: Bearer <token>'import requests
url = "https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://{instance}.cyrisma.com/app/pulse/v1/partner/exports/vulnerability-events")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"root_tenant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"generated_at": "2023-11-07T05:31:56Z",
"from": "2023-11-07T05:31:56Z",
"to": "2023-11-07T05:31:56Z",
"format": "<string>",
"coverage": [
{
"tenant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"tenant_host": "<string>"
}
],
"items": [
{
"finding_event_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"tenant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"tenant_host": "<string>",
"event_type": "opened",
"occurred_at": "2023-11-07T05:31:56Z",
"cve_id": "<string>",
"description": "<string>",
"severity": "critical",
"cvss_score": 123,
"cvr_score": 123,
"epss_probability": 123,
"exploitability_label": "<string>",
"root_cause_key": "<string>",
"root_cause_label": "<string>",
"source_type": "endpoint",
"asset_id": "<string>",
"asset_display_name": "<string>",
"asset_type": "endpoint",
"os_family": "<string>",
"os_name": "<string>",
"agent_status": "<string>",
"tenant_name": "<string>",
"detected_while_offline": false,
"exploit_sources": [
"<string>"
]
}
]
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>"
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>"
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>"
}Authorizations
A Tenant Authority machine-client token from POST /v1/auth/client-token, carrying subject_type=machine_client and the pulse.read scope.
Query Parameters
Comma-separated tenant UUIDs to scope the list to. Omit to use every tenant the caller is authorized for.
Start of the window, RFC 3339. Treated as UTC.
End of the window, RFC 3339. Treated as UTC.
Export encoding.
Available options:
json, csv 