Please run the below command using the access token extracted in Step1 Output to extract Netwitness Respond Incident INC-36.
#curl 'https://<NODE_ZEROIP>/rest/api/incidents/INC-36' -i -k -X GET -H 'Accept: application/json;charset=UTF-8' -H 'NetWitness-Token: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MjkzMDA2NzMzMjksImlzcyI6InNlY3VyaXR5LXNlcnZlci1lOWFmMzdhZC0yNWRmLTQzMjYtODVkMy1hYTA5N2FjZGVjZjUiLCJpYXQiOjE2MjkyNzE4NzMzMjksImF1dGhvcml0aWVzIjpbIkFkbWluaXN0cmF0b3JzIl0sInVzZXJfbmFtZSI6ImFkbWluIn0.drqzIDyf2YSwQX4o1VEP5VNnsXUjtQ-WZGFRO0l5cjZXK63xs4dBLrQTs9J6Odn0YctWEMBB2IOi0TGwhYneizboqnob3rfRgUkpYqaCK42R2FWU4UP2qAgH44XpIjsCpNZf997uFyqsuRAUMt1rF4jENZQpE2IB6WOiomRWS10Cmn--7b-Ll61tuce5nv-MFQUz6Y3mbnXlAMDTsapuDaubxS93xIcHaOORNlk0ekysN6tpBTdLRvM448vQvDcJDQ5skhjOhKTgL1z6bKQaJ4wnA8UFJ0w-p8GNahcurePHngaToUib15hg352cMDhJHB_vY3VR0KH8fAjhXvKtqA'
Sample output:
HTTP/1.1 200
Server: nginx
Date: Wed, 18 Aug 2021 07:33:09 GMT
Content-Type: application/json;charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
X-NW-UI-PRIMARY: true
X-NW-CBA-ENABLED: false
{"id":"INC-36","title":"High Risk User for jsheppard","summary":null,"priority":"High","riskScore":70,"status":"New","alertCount":1,"averageAlertRiskScore":70,"sealed":true,"totalRemediationTaskCount":0,"openRemediationTaskCount":0,"created":"2021-08-09T03:05:27.565Z","lastUpdated":"2021-08-09T03:05:27.565Z","lastUpdatedBy":null,"assignee":null,"sources":["Reporting Engine"],"ruleId":"5f509ffb8d167917599c7129","firstAlertTime":"2021-08-09T03:05:24Z","categories":[],"journalEntries":null,"createdBy":"High Risk User","deletedAlertCount":0,"eventCount":2,"alertMeta":{"SourceIp":["1.1.0.7"],"DestinationIp":[""]}}
Please run the below command using the access token extracted in Step1 Output to extract Netwitness Respond INC-36 alerts.
#curl 'https://<NODE_ZEROIP>/rest/api/incidents/INC-36/alerts?pageSize=10&pageNumber=0' -i -k -X GET -H 'Accept: application/json;charset=UTF-8' -H 'NetWitness-Token: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MjkzMDA2NzMzMjksImlzcyI6InNlY3VyaXR5LXNlcnZlci1lOWFmMzdhZC0yNWRmLTQzMjYtODVkMy1hYTA5N2FjZGVjZjUiLCJpYXQiOjE2MjkyNzE4NzMzMjksImF1dGhvcml0aWVzIjpbIkFkbWluaXN0cmF0b3JzIl0sInVzZXJfbmFtZSI6ImFkbWluIn0.drqzIDyf2YSwQX4o1VEP5VNnsXUjtQ-WZGFRO0l5cjZXK63xs4dBLrQTs9J6Odn0YctWEMBB2IOi0TGwhYneizboqnob3rfRgUkpYqaCK42R2FWU4UP2qAgH44XpIjsCpNZf997uFyqsuRAUMt1rF4jENZQpE2IB6WOiomRWS10Cmn--7b-Ll61tuce5nv-MFQUz6Y3mbnXlAMDTsapuDaubxS93xIcHaOORNlk0ekysN6tpBTdLRvM448vQvDcJDQ5skhjOhKTgL1z6bKQaJ4wnA8UFJ0w-p8GNahcurePHngaToUib15hg352cMDhJHB_vY3VR0KH8fAjhXvKtqA'
Sample output:
HTTP/1.1 200
Server: nginx
Date: Wed, 18 Aug 2021 07:35:39 GMT
Content-Type: application/json;charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
X-NW-UI-PRIMARY: true
X-NW-CBA-ENABLED: false
{"items":[{"id":"61109b75be89bb34907df698","title":"High Risk User","detail":null,"created":"2021-08-09T03:05:24Z","source":"Reporting Engine","riskScore":null,"type":"Log","events":[{"source":{"device":{"ipAddress":"1.1.0.7","port":null,"macAddress":null,"dnsHostname":null,"dnsDomain":null},"user":{"username":null,"emailAddress":null,"adUsername":null,"adDomain":null}},"destination":{"device":{"ipAddress":null,"port":null,"macAddress":null,"dnsHostname":null,"dnsDomain":null},"user":{"username":"jsheppard","emailAddress":null,"adUsername":"jsheppard","adDomain":null}},"domain":"lt-us-jsheppard.prymida.com,LT-US-JSHEPPARD","eventSource":"5.5.5.5:56005","eventSourceId":"3107765"},{"source":{"device":{"ipAddress":"1.1.0.7","port":null,"macAddress":null,"dnsHostname":null,"dnsDomain":null},"user":{"username":null,"emailAddress":null,"adUsername":null,"adDomain":null}},"destination":{"device":{"ipAddress":null,"port":null,"macAddress":null,"dnsHostname":null,"dnsDomain":null},"user":{"username":"jsheppard","emailAddress":null,"adUsername":"jsheppard","adDomain":null}},"domain":"lt-us-jsheppard.prymida.com,LT-US-JSHEPPARD","eventSource":"5.5.5.5:56005","eventSourceId":"3107772"}]}],"pageNumber":0,"pageSize":10,"totalPages":1,"totalItems":1,"hasNext":false,"hasPrevious":false}