anorcross
(anorcross)
January 30, 2024, 6:39pm
1
I would like to get the alert evidence using the API endpoint documented here:
https://docs.rapid7.com/insightidr/api/alert-triage/#operation/getAlertEvidences
This endpoint requires an alert_rrn but I only have an alert “id” returned from this endpoint:
/idr/v2/investigations/{identifier}/alerts
documented here: InsightIDR API Documentation
How can I get an alert_rrn given in “id”
jjpaolucci
(jjpaolucci)
October 27, 2025, 11:27am
2
I’m not sure why this hasnt been answered by someone from R7 yet.
The API around investigations and alerts is quite underdeveloped and the documentation is confusing at best.
Maurice
(Maurice Kemmann)
October 31, 2025, 10:19am
4
Thanks for your help! I guess i have no access to your IBM Accounts …?!
anorcross
(anorcross)
October 31, 2025, 12:46pm
5