Vulnerabilities API - GET vulnerability events
Lists the events of a specific vulnerability.
The request produces an application/json
payload.
GET | ManagedDynatrace for Government | https://{your-domain}/e/{your-environment-id}/api/v2/securityProblems/{id}/events |
SaaS | https://{your-environment-id}.live.dynatrace.com/api/v2/securityProblems/{id}/events | |
Environment and Cluster ActiveGate (default port 9999) | https://{your-activegate-domain}:9999/e/{your-environment-id}/api/v2/securityProblems/{id}/events |
Authentication
To execute this request, you need an access token with securityProblems.read
scope.
To learn how to obtain and use it, see Tokens and authentication.
Parameters
Parameter | Type | Description | In | Required |
---|---|---|---|---|
id | string | The ID of the requested security problem. | path | required |
from | string | The start of the requested timeframe. You can use one of the following formats:
If not set, the relative timeframe of thirty days is used ( | query | optional |
to | string | The end of the requested timeframe. You can use one of the following formats:
If not set, the current timestamp is used. | query | optional |
Response
Response codes
Code | Type | Description |
---|---|---|
200 | SecurityProblemEventsList | Success. The response contains the list of security problem events. |
Response body objects
The SecurityProblemEventsList
object
A list of events for a security problem.
Element | Type | Description |
---|---|---|
events | SecurityProblemEvent[] | A list of events for a security problem. |
nextPageKey | string | The cursor for the next page of results. Has the value of Use it in the nextPageKey query parameter to obtain subsequent pages of the result. |
pageSize | integer | The number of entries per page. |
totalCount | integer | The total number of entries in the result. |
The SecurityProblemEvent
object
The event of a security problem.
Element | Type | Description |
---|---|---|
muteState | MuteState | Metadata of the muted state of a security problem in relation to an event. |
reason | string | The reason of the event creation.
|
riskAssessmentSnapshot | RiskAssessmentSnapshot | A snapshot of the risk assessment of a security problem. |
timestamp | integer | The timestamp when the event occurred. |
The MuteState
object
Metadata of the muted state of a security problem in relation to an event.
Element | Type | Description |
---|---|---|
comment | string | A user's comment. |
reason | string | The reason for the mute state change.
|
user | string | The user who has muted or unmuted the problem. |
The RiskAssessmentSnapshot
object
A snapshot of the risk assessment of a security problem.
Element | Type | Description |
---|---|---|
baseRiskScore | number | The risk score (1-10) from the CVSS score. |
changes | RiskAssessmentChanges | All changes of the risk assessment. |
exposure | string | The level of exposure of affected entities.
|
numberOfAffectedEntities | integer | The number of currently affected entities. |
numberOfAffectedNodes | integer | The number of currently affected nodes. |
numberOfAffectedProcessGroups | integer | The number of currently affected process groups. |
numberOfReachableDataAssets | integer | The number of data assets that are currently reachable by affected entities. |
numberOfRelatedAttacks | integer | The number of related attacks. |
publicExploit | string | The availability status of public exploits.
|
riskLevel | string | The Davis risk level. It is calculated by Dynatrace on the basis of CVSS score.
|
riskScore | number | The Davis risk score (1-10). It is calculated by Dynatrace on the basis of CVSS score. |
vulnerableFunctionUsage | string | The state of vulnerable code execution.
|
The RiskAssessmentChanges
object
All changes of the risk assessment.
Element | Type | Description |
---|---|---|
deltaBaseRiskScore | number | The delta of the risk score. |
deltaNumberOfAffectedNodes | integer | The delta of the number of currently affected nodes. |
deltaNumberOfAffectedProcessGroups | integer | The delta of the number of currently affected process groups. |
deltaNumberOfReachableDataAssets | integer | The delta of the number of data assets that are currently reachable by affected entities. |
deltaNumberOfRelatedAttacks | integer | The delta of the number of related attacks. |
deltaRiskScore | number | The delta of the Davis risk score. |
previousExposure | string | The previous level of exposure of affected entities.
|
previousPublicExploit | string | The previous availability status of public exploits.
|
previousVulnerableFunctionUsage | string | The previous state of vulnerable code execution.
|
Response body JSON model
1{2 "events": [3 {4 "muteState": {5 "comment": "string",6 "reason": "AFFECTED",7 "user": "string"8 },9 "reason": "ASSESSMENT_CHANGED",10 "riskAssessmentSnapshot": {11 "baseRiskScore": 1,12 "changes": {13 "deltaBaseRiskScore": 1,14 "deltaNumberOfAffectedNodes": 1,15 "deltaNumberOfAffectedProcessGroups": 1,16 "deltaNumberOfReachableDataAssets": 1,17 "deltaNumberOfRelatedAttacks": 1,18 "deltaRiskScore": 1,19 "previousExposure": "NOT_AVAILABLE",20 "previousPublicExploit": "AVAILABLE",21 "previousVulnerableFunctionUsage": "IN_USE"22 },23 "exposure": "NOT_AVAILABLE",24 "numberOfAffectedEntities": 1,25 "numberOfAffectedNodes": 1,26 "numberOfAffectedProcessGroups": 1,27 "numberOfReachableDataAssets": 1,28 "numberOfRelatedAttacks": 1,29 "publicExploit": "AVAILABLE",30 "riskLevel": "CRITICAL",31 "riskScore": 1,32 "vulnerableFunctionUsage": "IN_USE"33 },34 "timestamp": 135 }36 ],37 "nextPageKey": "AQAAABQBAAAABQ==",38 "pageSize": 1,39 "totalCount": 140}