Carbon Black Cloud (CBC)-Audit and Remediation API-LiveQuery REST API πŸ—-Live Query Run

Number of APIs: 11

  1. Start Query Run POST {{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs

  2. Get Query Details GET {{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}

  3. Get Query Run Results POST {{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/_search?format=csv&download=true

  4. Scroll All Run Results POST {{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/results/_scroll

  5. Get Live Query Recommendations GET {{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/recommendations

  6. Stop Query Run PUT {{cb_url}}/livequery/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/status

  7. Delete Query Run DELETE {{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}

  8. Get Facets From Live Query Results POST {{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/_facet

  9. Get Device Summary Facets POST {{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/device_summaries/_facet

  10. Get Device Summary From Results POST {{cb_url}}/livequery/v1/orgs/{{cb_org_key}}/runs/{{cb_query_id}}/results/device_summaries/_search