Start an Export Events Job
POST {{cb_url}}/jobs/v1/orgs/{{cb_org_key}}/jobs/start/event_export
Used with investigate searches - Processes, Process Events, Observations, Auth Events and Enriched Events - to start a search job.
Permission (.notation name) | Operation(s) |
---|---|
jobs.status | READ |
org.search.events | CREATE |
Request Body
{"api_resource"=>"<choose one: ENRICHED_EVENTS, PROCESSES, PROCESS_EVENTS, AUTH_EVENTS, OBSERVATIONS>", "version"=>"v2", "query"=>{"criteria"=>{}, "exclusions"=>{}, "query"=>"*:*", "time_range"=>{"start"=>"2023-03-26T02:00:00.000Z", "end"=>"2023-03-29T02:06:20.864Z"}, "rows"=>10000, "fields"=>["*"], "sort"=>[{"field"=>"device_timestamp", "order"=>"DESC"}]}}
RESPONSES
status: Created
{"id":5731438,"type":"event_export","job_parameters":{"job_parameters":{"query":{"criteria":{},"exclusions":{},"query":"*:*","time_range":{"start":"2023-03-26T02:00:00.000Z","end":"2023-03-29T02:06:20.864Z"},"rows":10000,"fields":["*"],"sort":[{"field":"device_timestamp","order":"DESC"}]}},"process_guid":null,"api_resource":"OBSERVATIONS","version":"v2","search_id":null},"connector_id":"12345ABCD","org_key":"ABCD1234","status":"CREATED","create_time":"2023-03-29T03:17:02.978Z","last_update_time":"2023-03-29T03:17:02.979Z"}