Request a focus view
Request a focus view from a specified device.
|
Service endpoint |
/foci/v2 |
|
Optional query string parameters |
— |
|
Example |
https://protectapi.cylance.com/foci/v2 |
|
Method |
HTTP/1.1 POST |
|
Request headers |
|
Request
{
"device_id": "E378DACB9324453AB8C65A8406952195",
"artifact_type": "Process",
"artifact_subtype": "Uid",
"value": "59F849F29BBE4F1F889AAF50F9153618",
"threat_type": "THREAT",
"description": "Focus View Example"
}
Response
Please see the Response status codes for more information.
Request JSON schema
| Field Name | Description |
|---|---|
|
device_id |
This is the unique device ID that the lockdown command was issued to. See About device ID for device ID formatting. |
|
artifact_type |
This is the type of artifact for the focus view.
|
|
artifact_subtype |
This field should always be "Uid" at this time. |
|
value |
This is the UID of the artifact to gather a focus view about. This can be obtained from InstaQuery results, another focus view, the details/associated artifacts of a detection event, or anywhere else an artifact is referenced. |
|
threat_type |
This is an optional field to use with a "Protect" artifact_type to denote the type of threat that a focus view is being generated for. |
|
description |
This is the human-readable description for the focus view. |
Response JSON schema
| Field Name | Description |
|---|---|
|
device_id |
This is the unique device ID that the lockdown command was issued to. See About device ID for device ID formatting. |
|
artifact_type |
This is the type of artifact for the focus view.
|
|
artifact_subtype |
This field should always be "Uid" at this time. |
|
value |
This is the UID of the artifact to gather a focus view about. This can be obtained from InstaQuery results, another focus view, the details/associated artifacts of a detection event, or anywhere else an artifact is referenced. |
|
threat_type |
This is an optional field to use with a "Protect" artifact_type to denote the type of threat that a focus view is being generated for. |
|
description |
This is the human-readable description for the focus view. |
|
id |
This is the unique ID of the focus view. |
|
tenant_id |
This is the unique ID of the tenant associated with the focus view. |
|
create_at |
This is the timestamp (in UTC) of when the focus view was created. |
|
hostname |
This is the hostname of the device that the focus view was requested from. |
|
status |
This is the status of the focus view result or request. Possible values are:
|
|
relations |
This is a list of objects that are related to this focus view. The following fields can be contained:
|