Demisto Reports API

The Reports API from Demisto — 4 operation(s) for reports.

OpenAPI Specification

demisto-reports-api-openapi.yml Raw ↑
swagger: '2.0'
info:
  description: 'This is the public REST API to integrate with the demisto server.

    HTTP request can be sent using any HTTP-client.


    For an example dedicated client take a look at: https://github.com/demisto/demisto-py.


    Requests must include API-key that can be generated in the Demisto web client under ''Settings'' -> ''Integrations'' -> ''API keys''



    Optimistic Locking and Versioning\:


    When using Demisto REST API, you will need to make sure to work on the latest version of the item (incident, entry, etc.), otherwise, you will get a DB version error (which not allow you to override a newer item).

    In addition, you can pass ''version\: -1'' to force data override (make sure that other users data might be lost).


    Assume that Alice and Bob both read the same data from Demisto server, then they both changed the data, and then both tried to write the new versions back to the server. Whose changes should be saved? Alice’s? Bob’s?

    To solve this, each data item in Demisto has a numeric incremental version.

    If Alice saved an item with version 4 and Bob trying to save the same item with version 3, Demisto will rollback Bob request and returns a DB version conflict error.

    Bob will need to get the latest item and work on it so Alice work will not get lost.


    Example request using ''curl''\:


    ```

    curl ''https://hostname:443/incidents/search'' -H ''content-type: application/json'' -H ''accept: application/json'' -H ''Authorization: <API Key goes here>'' --data-binary ''{"filter":{"query":"-status:closed -category:job","period":{"by":"day","fromValue":7}}}'' --compressed

    ```'
  title: Demisto Apikeys Reports API
  version: 2.0.0
host: hostname:443
schemes:
- https
consumes:
- application/json
- application/xml
produces:
- application/json
security:
- api_key: []
- csrf_token: []
- x-xdr-auth-id: []
tags:
- name: Reports
paths:
  /reports:
    get:
      description: Get all of the reports
      summary: Get all reports
      operationId: getAllReports
      responses:
        '200':
          description: Return array of reports
          schema:
            type: array
            items:
              $ref: '#/definitions/Report'
      tags:
      - Reports
  /reports/{id}:
    get:
      description: Get a report by its ID
      summary: Get report by ID
      operationId: getReportByID
      parameters:
      - type: string
        description: the ID of the report to get
        name: id
        in: path
        required: true
      responses:
        '200':
          description: Return a report
          schema:
            $ref: '#/definitions/Report'
      tags:
      - Reports
  /reports/{id}/latest:
    get:
      description: Get the latest report by its ID
      produces:
      - application/octet-stream
      summary: Get latest report by ID
      operationId: downloadLatestReport
      parameters:
      - type: string
        description: the ID of the report to get
        name: id
        in: path
        required: true
      responses:
        '200':
          description: Return a report file
          schema:
            type: file
      tags:
      - Reports
  /reports/upload:
    post:
      description: Upload report file to Demisto
      consumes:
      - multipart/form-data
      produces:
      - application/json
      summary: Upload report file to Demisto
      operationId: uploadReport
      parameters:
      - type: file
        description: file
        name: file
        in: formData
        required: true
      responses:
        '200':
          description: A list of all the reports in the instance
          schema:
            type: array
            items:
              $ref: '#/definitions/Report'
      tags:
      - Reports
definitions:
  ModuleArgs:
    description: ModuleArgs represents module args
    type: object
    additionalProperties:
      type: object
    x-go-package: github.com/demisto/server/domain
  EndingType:
    description: EndingType holds the type of schedule Ending
    type: string
    x-go-package: github.com/demisto/server/domain
  Dashboard:
    type: object
    title: Dashboard ...
    properties:
      commitMessage:
        type: string
        x-go-name: CommitMessage
      fromDate:
        type: string
        format: date-time
        x-go-name: FromDate
      fromDateLicense:
        type: string
        format: date-time
        x-go-name: FromDateLicenseVal
      id:
        type: string
        x-go-name: ID
      isCommon:
        type: boolean
        x-go-name: IsCommon
      layout:
        $ref: '#/definitions/WidgetCells'
      modified:
        type: string
        format: date-time
        x-go-name: Modified
      name:
        type: string
        x-go-name: Name
      owner:
        type: string
        x-go-name: Owner
      period:
        $ref: '#/definitions/Period'
      prevName:
        type: string
        x-go-name: PrevName
      shared:
        type: boolean
        x-go-name: Shared
      shouldCommit:
        type: boolean
        x-go-name: ShouldCommit
      sortValues:
        type: array
        items:
          type: string
        x-go-name: SortValues
      system:
        type: boolean
        x-go-name: System
      toDate:
        type: string
        format: date-time
        x-go-name: ToDate
      vcShouldIgnore:
        type: boolean
        x-go-name: VCShouldIgnore
      version:
        type: integer
        format: int64
        x-go-name: Versn
    x-go-package: github.com/demisto/server/domain
  ReportQuery:
    type: object
    title: ReportQuery ...
    properties:
      filter:
        $ref: '#/definitions/RawMessage'
      groupBy:
        type: array
        items:
          type: string
        x-go-name: GroupBy
      keys:
        type: array
        items:
          type: string
        x-go-name: Keys
      type:
        type: string
        x-go-name: Type
    x-go-package: github.com/demisto/server/domain
  Report:
    description: Report - represents report
    type: object
    properties:
      commitMessage:
        type: string
        x-go-name: CommitMessage
      createdBy:
        type: string
        x-go-name: CreatedBy
      cron:
        type: string
        x-go-name: Cron
      cronView:
        type: boolean
        x-go-name: CronView
      dashboard:
        $ref: '#/definitions/Dashboard'
      decoder:
        type: object
        additionalProperties:
          $ref: '#/definitions/ReportFieldsDecoder'
        x-go-name: Decoder
      description:
        type: string
        x-go-name: Description
      disableHeader:
        type: boolean
        x-go-name: DisableHeader
      endingDate:
        type: string
        format: date-time
        x-go-name: EndingDate
      endingType:
        $ref: '#/definitions/EndingType'
      humanCron:
        $ref: '#/definitions/HumanCron'
      id:
        type: string
        x-go-name: ID
      latestReportName:
        type: string
        x-go-name: LatestReportName
      latestReportTime:
        type: string
        format: date-time
        x-go-name: LatestReportTime
      latestReportUsername:
        type: string
        x-go-name: LatestReportUsername
      latestScheduledReportTime:
        type: string
        format: date-time
        x-go-name: LatestScheduledReportTime
      locked:
        type: boolean
        x-go-name: Locked
      modified:
        type: string
        format: date-time
        x-go-name: Modified
      name:
        type: string
        x-go-name: Name
      nextScheduledTime:
        type: string
        format: date-time
        x-go-name: NextScheduledTime
      orientation:
        type: string
        x-go-name: Orientation
      paperSize:
        type: string
        x-go-name: PaperSize
      prevName:
        type: string
        x-go-name: PrevName
      prevType:
        type: string
        x-go-name: PrevType
      recipients:
        type: array
        items:
          type: string
        x-go-name: Recipients
      recurrent:
        type: boolean
        x-go-name: Recurrent
      reportType:
        type: string
        x-go-name: ReportType
      runOnce:
        type: boolean
        x-go-name: RunOnce
      runningUser:
        type: string
        x-go-name: RunningUser
      scheduled:
        description: is it scheduled
        type: boolean
        x-go-name: Scheduled
      sections:
        type: array
        items:
          $ref: '#/definitions/Section'
        x-go-name: Sections
      sensitive:
        type: boolean
        x-go-name: Sensitive
      shouldCommit:
        type: boolean
        x-go-name: ShouldCommit
      sortValues:
        type: array
        items:
          type: string
        x-go-name: SortValues
      startDate:
        type: string
        format: date-time
        x-go-name: StartDate
      system:
        type: boolean
        x-go-name: System
      tags:
        type: array
        items:
          type: string
        x-go-name: Tags
      times:
        type: integer
        format: int64
        x-go-name: Times
      timezoneOffset:
        type: integer
        format: int64
        x-go-name: TimezoneOffset
      type:
        type: string
        x-go-name: Type
      userAPIKey:
        type: string
        x-go-name: UserAPIKey
      userAPIKeyID:
        type: string
        x-go-name: UserAPIKeyID
      vcShouldIgnore:
        type: boolean
        x-go-name: VCShouldIgnore
      version:
        type: integer
        format: int64
        x-go-name: Versn
    x-go-package: github.com/demisto/server/domain
  Order:
    description: Order struct holds a sort field and the direction of sorting
    type: object
    properties:
      asc:
        type: boolean
        x-go-name: Asc
      field:
        type: string
        x-go-name: Field
      fieldType:
        type: string
        x-go-name: FieldType
    x-go-package: github.com/demisto/server/domain
  RawMessage:
    description: 'It implements Marshaler and Unmarshaler and can

      be used to delay JSON decoding or precompute a JSON encoding.'
    type: array
    title: RawMessage is a raw encoded JSON value.
    items:
      type: integer
      format: uint8
    x-go-package: encoding/json
  WidgetCells:
    type: array
    title: WidgetCells ...
    items:
      $ref: '#/definitions/WidgetCell'
    x-go-package: github.com/demisto/server/domain
  WidgetCell:
    type: object
    title: WidgetCell ...
    properties:
      forceRange:
        type: boolean
        x-go-name: ForceRange
      h:
        type: integer
        format: int64
        x-go-name: Height
      i:
        type: string
        x-go-name: Key
      id:
        type: string
        x-go-name: ID
      w:
        type: integer
        format: int64
        x-go-name: Width
      widget:
        $ref: '#/definitions/Widget'
      x:
        type: integer
        format: int64
        x-go-name: Xs
      y:
        type: integer
        format: int64
        x-go-name: Ys
    x-go-package: github.com/demisto/server/domain
  Widget:
    description: 'Widget describe a widget component used to get statistics requests, based on parameters such as

      dataType and widgetType. A widget can be a part of widgets collection inside a dashboard.'
    type: object
    required:
    - name
    - widgetType
    properties:
      category:
        description: Category the widget is related to. Used to display in widget library under category or dataType if empty.
        type: string
        x-go-name: Category
      commitMessage:
        type: string
        x-go-name: CommitMessage
      dataType:
        description: Data type of the widget. Describes what data does the widget query. supporting data types "incidents","messages","system","entries","tasks", "audit".
        type: string
        x-go-name: DataType
      dateRange:
        $ref: '#/definitions/DateRange'
      description:
        description: The description of the widget's usage and data representation.
        type: string
        x-go-name: Description
      id:
        type: string
        x-go-name: ID
      isPredefined:
        description: Is the widget a system widget.
        type: boolean
        x-go-name: IsPredefined
      locked:
        description: Is the widget locked for editing.
        type: boolean
        x-go-name: Locked
      modified:
        type: string
        format: date-time
        x-go-name: Modified
      name:
        description: Default name of the widget.
        type: string
        x-go-name: Name
      params:
        description: Additional parameters for this widget, depends on widget type and data.
        type: object
        additionalProperties:
          type: object
        x-go-name: AdditionalParams
      prevName:
        description: The previous name of the widget.
        type: string
        x-go-name: PrevName
      query:
        description: Query to search on the dataType.
        type: string
        x-go-name: Query
      shouldCommit:
        type: boolean
        x-go-name: ShouldCommit
      size:
        description: Maximum size for this widget data returned.
        type: integer
        format: int64
        x-go-name: Size
      sort:
        description: Sorting array to sort the data received by the given Order parameters.
        type: array
        items:
          $ref: '#/definitions/Order'
        x-go-name: Sort
      sortValues:
        type: array
        items:
          type: string
        x-go-name: SortValues
      vcShouldIgnore:
        type: boolean
        x-go-name: VCShouldIgnore
      version:
        type: integer
        format: int64
        x-go-name: Versn
      widgetType:
        description: 'Widget type describes how does the widget should recieve the data, and display it. Supporting types: "bar", "column", "pie", "list", "number", "trend", "text", "duration", "image", "line", and "table".'
        type: string
        x-go-name: WidgetType
    x-go-package: github.com/demisto/server/domain
  DateRange:
    description: DateRange provides common fields for date filtering
    type: object
    properties:
      fromDate:
        type: string
        format: date-time
        x-go-name: FromDate
      fromDateLicense:
        type: string
        format: date-time
        x-go-name: FromDateLicenseVal
      period:
        $ref: '#/definitions/Period'
      toDate:
        type: string
        format: date-time
        x-go-name: ToDate
    x-go-package: github.com/demisto/server/domain
  Section:
    type: object
    title: Section ...
    properties:
      automation:
        $ref: '#/definitions/ReportAutomation'
      data:
        type: object
        x-go-name: Data
      description:
        type: string
        x-go-name: Description
      displayType:
        type: string
        x-go-name: DisplayType
      emptyNotification:
        type: string
        x-go-name: EmptyNotification
      fromDate:
        type: string
        x-go-name: FromDate
      layout:
        type: object
        x-go-name: Layout
      query:
        $ref: '#/definitions/ReportQuery'
      title:
        type: string
        x-go-name: Title
      titleStyle:
        type: object
        additionalProperties:
          type: object
        x-go-name: TitleStyle
      toDate:
        type: string
        x-go-name: ToDate
      type:
        type: string
        x-go-name: Type
    x-go-package: github.com/demisto/server/domain
  HumanCron:
    type: object
    title: HumanCron ...
    properties:
      atTimeHour:
        type: string
        x-go-name: AtTimeHour
      atTimeMinute:
        type: string
        x-go-name: AtTimeMinute
      days:
        type: array
        items:
          type: string
        x-go-name: Days
      hoursPeriod:
        type: string
        x-go-name: HoursPeriod
      schedulingType:
        description: the following fields are deprecated. do not use them.
        type: string
        x-go-name: SchedulingType
      timePeriod:
        type: integer
        format: int64
        x-go-name: TimePeriod
      timePeriodType:
        type: string
        x-go-name: TimePeriodType
    x-go-package: github.com/demisto/server/domain
  ReportAutomation:
    type: object
    title: ReportAutomation ...
    properties:
      args:
        $ref: '#/definitions/ModuleArgs'
      id:
        type: string
        x-go-name: ID
      name:
        type: string
        x-go-name: Name
      noEvent:
        type: boolean
        x-go-name: NoEvent
    x-go-package: github.com/demisto/server/domain
  Period:
    type: object
    title: Period holds the 'Period' query, such as last 3 days, last 6 hours, between 6 days from now until 3 days from now.
    properties:
      by:
        description: By is used for legacty, and if exists it will override ByTo and ByFrom
        type: string
        x-go-name: By
      byFrom:
        type: string
        x-go-name: ByFrom
      byTo:
        type: string
        x-go-name: ByTo
      field:
        type: string
        x-go-name: Field
      fromValue:
        type: string
        format: duration
        x-go-name: FromValue
      toValue:
        type: string
        format: duration
        x-go-name: ToValue
    x-go-package: github.com/demisto/server/domain
  ReportFieldsDecoder:
    type: object
    title: ReportFieldsDecoder ...
    properties:
      type:
        type: string
        x-go-name: Type
      value:
        type: string
        x-go-name: Value
    x-go-package: github.com/demisto/server/domain
securityDefinitions:
  api_key:
    type: apiKey
    name: Authorization
    in: header
  csrf_token:
    type: apiKey
    name: X-XSRF-TOKEN
    in: header
  x-xdr-auth-id:
    type: apiKey
    name: x-xdr-auth-id
    in: header