Skip to content

Security Events Aggregation Query.

POST
/api/data/namespaces/{namespace}/app_security/events/aggregation
curl --request POST \
--url https://example-corp.console.ves.volterra.io/api/v1/api/production/us-east-1/namespaces/default/api/data/namespaces/example/app_security/events/aggregation \
--header 'Authorization: <Authorization>' \
--header 'Content-Type: application/json' \
--data '{ "aggs": {}, "end_time": "example", "namespace": "example", "query": "example", "start_time": "example" }'

GET summary/aggregation data for security events in the given namespace. For system namespace, all security events for the tenant matching the query specified in the request will be considered for aggregation. User may query security events that matches various fields such as vh_name, sec_event_type, src_site, city, country.

Examples of this operation.

namespace
required
string

Namespace

fetch security events for a given namespace.

Media typeapplication/json
Security Events Aggregation Request

Request to GET only aggregation data for security events.

object
aggs
aggregations

Aggregations provide summary/analytics data over the security events response. If the number of security events that matched the query is large and cannot be returned in a single response message, user can GET helpful insights/summary using aggregations. The aggregations are key’ed by user-defined aggregation name. The response will be key’ed with the same name. Optional.

object
end_time
end time

Fetch security events whose timestamp <= end_time format: unix_timestamp|RFC 3339

Optional: If not specified, then the end_time will be evaluated to start_time+10m If start_time is not specified, then the end_time will be evaluated to

string
<= 1024 characters
namespace
namespace

Fetch security events for a given namespace.

string
>= 6 characters <= 1024 characters
query
query

Query is used to specify the list of matchers syntax for query := {[]} := <field_name>"" <field_name> := string One or more of these fields in the security event may be specified in the query. Vh_name - name of the virtual host src_site - source site city - name of the city country - country code := string := [”=”|”!=”|”=”|”!”] = : equal to != : not equal to =~ : regex match !~ : not regex match When more than one matcher is specified in the query, then security events matching ALL the matchers will be returned in the response. Example: query={country=“United States”, city=“California”} will return all security events originating from California, United States.

Optional: If not specified, all the security events matching the given tenant and namespace will be returned in the response.

string
<= 1024 characters
start_time
start time

Fetch security events whose timestamp >= start_time format: unix_timestamp|RFC 3339

Optional: If not specified, then the start_time will be evaluated to end_time-10m If end_time is not specified, then the start_time will be evaluated to -10m.

string
<= 1024 characters
Examplegenerated
{
"aggs": {},
"end_time": "example",
"namespace": "example",
"query": "example",
"start_time": "example"
}

A successful response.

Media typeapplication/json
Security Events Aggregation Response

Response message for SecurityEventsAggregationRequest.

object
aggs
aggregations

Aggregations provide summary/analytics data over the security events response. If the number of security events that matched the query is large and cannot be returned in a single response message, user can GET helpful insights/summary using aggregations. The aggregation data is key’ed with the aggregation name specified in the request.

object
total_hits
total hits

Total number of security events that matched the query.

string format: uint64
<= 1024 characters
Examplegenerated
{
"aggs": {},
"total_hits": "example"
}

Returned when operation is not authorized.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when there is no permission to access resource.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when resource is not found.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when operation on resource is conflicting with current value.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when operation has been rejected as it is happening too frequently.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when server encountered an error in processing API.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when service is unavailable temporarily.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when server timed out processing request.

Media typeapplication/json
string format: string
Examplegenerated
example