SpecifyDocs

Security events

/v1/security/events

Signed-in sessionLaunch key product.securityOperation security_events

People see the devices that run their agents, their security posture and the events those devices report.

Query parameters

organizationfalse | true
actorIdstring
fromnumber
eventType"decision" | "health" | "outcome"
deviceIdstring
decision"allow" | "deny" | "observe"
toolNamestring
coverageState"degraded" | "enforced" | "invalid_policy" | "missing_policy" | "observed"
asOfnumber
expectedAuthorizationVersionstring
cursorstring | null
limitinteger

Returns

itemsobject[]Required
nextCursorstring | nullRequired

Errors

400, 401, 403, 404, 409, 429 and 503 return {"error": {"code", "message", "correlationId"}}.