API Request for a Search
Table of Contents
Expand all | Collapse all
-
- New Features October 2020
- New Features September 2020
- New Features: August 2020
- New Features: April 2020
- New Features: November 2019
- New Features: May 2019
- New Features: March 2019
- New Features: February 2019
- New Features: November 2018
- New Features: October 2018
- New Features: September 2018
- New Features: August 2018
- New Features: July 2018
- New Features: June 2018
API Request for a Search
You can now view the API request for initiating
an AutoFocus Search directly
from the AutoFocus interface. The API request is for retrieving
samples, sessions, or statistics that meet the conditions of the
current AutoFocus search. This feature is useful for quickly generating
API requests for complex searches to use with your external application.
Note that the API request provided by this feature is only to start
an AutoFocus search; a different API request is required to view
the search results.
- Start or continue an AutoFocus search.
- View the API request for initiating the search.
- View (>_ API) the API request forSamplesorSessionsthat have been filtered according to the current search condition(s).
- View (>_) the API request in any of theStatisticswidgets for artifacts that meet the conditions of the current search and widget. In the following example, the API request forTop Malwareis only for retrieving the ten most prevalent malware samples in your network.
- Toggle betweenPythonandCurlto select the format of the API request that you want tocopy to clipboard.The API request reflects the parameters of the search you performed. For example, the sample Curl URL Request Library (cURL) API request above is from theTop Firewallswidget (Statistics). We can tell from the code that the API request:
- Retrieves the top ten firewalls ("size":10) with the most sessions that use theweb-browsingapplication ("field":"device.serial","operator":"is","value":"web-browsing").
- Retrieves theSerialnumbers of the firewalls ("field":"device.serial").
- Limits the scope of the request to private samples only ("scope":"private").
- Next steps:
- Refer to the AutoFocus API Reference Guide for more information on how to view the results of an API request.
- Learn more about how to use cURL and Python to integrate the AutoFocus API with your application. To use the AutoFocus API with Python, install the pan-python package, which provides a Python and command line interface for AutoFocus.