-
When I compare the data available from the DetectionSummaryEvent within the Event Streaming API versus what's available from the Incident and Detection Monitoring APIs, there seems to be some pretty big gaps -- specifically:
Where is this equivalent data located within the body.resources[] output from the Incident and Detection Monitoring APIs? Do you have to query the Threat Graph APIs with the corresponding body.resources[].behaviors[].control_graph_id to somehow find this information...? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
Hi @dkindlund - These fields will be part of the Event Stream if they are in scope of the event and are called out in the event data dictionary. In all other scenarios these fields will not be present. Let us know if you have any more questions! 😁 |
Beta Was this translation helpful? Give feedback.
Hi @dkindlund -
These fields will be part of the Event Stream if they are in scope of the event and are called out in the event data dictionary. In all other scenarios these fields will not be present.
Let us know if you have any more questions! 😁