Search Suggestions for Observations

GET {{cb_url}}/api/investigate/v2/orgs/{{cb_org_key}}/observations/search_suggestions?suggest.q=device_id&suggest.count=2

Returns suggestions for the observations search based on fields in the organizationโ€™s system. Will return field names if the โ€œsuggest.qโ€ parameter does not yet contain a colon and will return no suggestion otherwise.

RBAC Permissions Required

Permission (.notation name)Operation(s)
org.search.eventsREAD, CREATE

API Documentation

Information on Fields

Request Params

KeyDatatypeRequiredDescription
suggest.qstringThe query to generate suggestions for
suggest.countnumberThe number of suggestions to return

RESPONSES

status: OK

{"suggestions":[{"term":"device_id","weight":500,"required_skus_all":[],"required_skus_some":["threathunter","defense"]},{"term":"netconn_remote_device_id","weight":350,"required_skus_all":["xdr"],"required_skus_some":[]}]}