Google Cloud Chronicle Alerts API

Operations for managing security alerts

OpenAPI Specification

google-cloud-chronicle-alerts-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Google Cloud Chronicle Alerts API
  description: The Chronicle API provides programmatic access to Google Cloud's security analytics platform. It supports ingesting security telemetry, searching security data using UDM, managing detection rules, investigating alerts, and accessing threat intelligence.
  version: v1alpha
  contact:
    name: Google Cloud Support
    url: https://cloud.google.com/chronicle/docs/support
  termsOfService: https://cloud.google.com/terms
servers:
- url: https://chronicle.googleapis.com/v1alpha
  description: Production Server
security:
- oauth2: []
tags:
- name: Alerts
  description: Operations for managing security alerts
paths:
  /projects/{projectId}/locations/{location}/instances/{instanceId}/alerts:
    get:
      operationId: listAlerts
      summary: Google Cloud Chronicle List alerts
      description: Lists alerts in a Chronicle instance.
      tags:
      - Alerts
      parameters:
      - $ref: '#/components/parameters/projectId'
      - $ref: '#/components/parameters/location'
      - $ref: '#/components/parameters/instanceId'
      - $ref: '#/components/parameters/pageSize'
      - $ref: '#/components/parameters/pageToken'
      - name: filter
        in: query
        description: Filter expression for alerts
        schema:
          type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListAlertsResponse'
components:
  parameters:
    pageToken:
      name: pageToken
      in: query
      schema:
        type: string
    projectId:
      name: projectId
      in: path
      required: true
      schema:
        type: string
    pageSize:
      name: pageSize
      in: query
      schema:
        type: integer
    location:
      name: location
      in: path
      required: true
      schema:
        type: string
    instanceId:
      name: instanceId
      in: path
      required: true
      schema:
        type: string
  schemas:
    ListAlertsResponse:
      type: object
      properties:
        alerts:
          type: array
          items:
            $ref: '#/components/schemas/Alert'
        nextPageToken:
          type: string
    Alert:
      type: object
      properties:
        name:
          type: string
        ruleName:
          type: string
        severity:
          type: string
          enum:
          - INFORMATIONAL
          - LOW
          - MEDIUM
          - HIGH
          - CRITICAL
        state:
          type: string
          enum:
          - NEW
          - IN_PROGRESS
          - CLOSED
        createTime:
          type: string
          format: date-time
        feedback:
          type: string
          enum:
          - TRUE_POSITIVE
          - FALSE_POSITIVE
  securitySchemes:
    oauth2:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://accounts.google.com/o/oauth2/auth
          tokenUrl: https://oauth2.googleapis.com/token
          scopes:
            https://www.googleapis.com/auth/cloud-platform: Full access to Google Cloud
externalDocs:
  description: Chronicle API Documentation
  url: https://cloud.google.com/chronicle/docs/reference/rest