# Query Events

Queries events from the SIEM configured with the token used for authentication.

Operation ID: siem_query_events

Endpoint: GET /v1/siem/events
Security: BearerAuth

## Query parameters:

  - `cursor` (string,null)
    Cursor to use to retrieve the next page of results.

  - `limit` (integer,null)
    Number of Account objects to return in this page. Defaults to 100.

  - `order` (array)
    Select a field to order the results by. Defaults to time. To control the direction of the sorting, append [asc] or [desc] to the field name. For example, name[desc] will sort the results by name in descending order. The ordering defaults to asc if not specified. May be used multiple times to order by multiple fields, and the ordering is applied in the order the fields are specified.

  - `filter` (array)
    Filter results by this query. For more information on filtering, refer to our Filtering Guide. Defaults to no filter. If used more than once, the queries are ANDed together.

  - `meta` (array)
    Add metadata to the response by invoking meta functions. Documentation for meta functions is available. Not all meta functions are available at every endpoint.

  - `passthrough-param` (array)
    Provider-specific query to pass through to the SIEM. This is useful for advanced queries that are not
supported by the API. The keys and values are provider-specific. For example, to perform a specific
query in Rapid7 IDR, you can use the query: "{advanced query}" key-value pair.

  - `include_raw_data` (boolean,null)
    Include the raw data from the SIEM in the response. This is useful for debugging and troubleshooting. Defaults to false.

## Response 200 fields (application/json):

  - `result` (array, required)
    List of events

  - `cursor` (string, required)
    Cursor to use to retrieve the next page of results

  - `status` (string, required)
    Enum: "PENDING", "COMPLETE"

  - `messages` (object)

  - `messages.problems` (array,null)
    Warnings or issues that occurred during processing that did not prevent the request from returning, but may indicate a problem or issue with expected processing behavior.

  - `messages.problems.occurred_at` (string, required)
    The date and time the problem occurred.

  - `messages.problems.status` (integer, required)
    The HTTP status code of the problem. Matches the HTTP response code sent by the server.

  - `messages.problems.instance` (string, required)
    A URI reference that identifies the specific occurrence of the problem. It may or may not yield further information if dereferenced.

  - `messages.problems.message` (string, required)
    A short, display-friendly summary of the problem.

  - `messages.problems.type` (string)
    A URI reference that identifies the type of problem that occurred. When the URI scheme is HTTP(s), it may or may not be possible to deference the URL to a display-friendly description of the problem type.

  - `messages.problems.cause` (array,null)
    A list of the root cause(s) for this problem occurrence. Includes at minimum one root cause, and is otherwise an unordered list of causes.

  - `messages.problems.cause.type` (string, required)
    A URI reference that identifies the type of problem that occurred. When the URI scheme is HTTP(s), it may or may not be possible to deference the URL to a display-friendly description of the problem type.

  - `messages.problems.cause.message` (string, required)
    A short, display-friendly summary of the problem.

  - `messages.problems.cause.detail` (string,null)
    A display-friendly and more detailed explanation of the problem. It may offer additional contextual detail, but may also be just a generic description of the problem.

  - `messages.problems.cause.remediation` (string,null)
    A display-friendly explanation for how to remediate the problem. This field may be omitted in case there are multiple problems, each with its own remediation, or if no remediation is possible.

  - `messages.problems.cause.context` (object)

  - `messages.problems.cause.context.parameter` (object)

  - `messages.problems.cause.context.parameter.id` (string, required)
    If the location of the parameter is body, this value is always a JSON Pointer, otherwise it's the name of the parameter.

  - `messages.problems.cause.context.parameter.location` (string, required)
    Enum: "header", "path", "query", "body"

  - `messages.problems.cause.context.parameter.value` (any,null)
    The given value of the parameter.

  - `messages.problems.cause.context.resources` (array,null)

  - `messages.problems.cause.context.resources.type` (string, required)
    Enum: "account", "bridge", "credential", "integration_point", "integration", "member", "operation", "organization_webhook", "role", "sub_org", "token", "transform"

  - `messages.problems.cause.context.resources.id` (string, required)
    ID of the related resource.

  - `messages.problems.cause.context.resources.rel` (string, required)
    Enum: "affected", "cause"

  - `messages.problems.cause.context.raw_error` (string,null)
    If available this represents the underlying raw error, for example an error response from a Provider.

  - `messages.problems.cause.context.provider_details` (object,null)
    If available this represents the underlying details from the provider. May include the error message, status code, and other details.

  - `messages.problems.detail` (string,null)
    A display-friendly and more detailed explanation of the problem. It may offer additional contextual detail, but may also be just a generic description of the problem.

  - `messages.problems.remediation` (string,null)
    A display-friendly explanation for how to remediate the problem. This field may be omitted in case there are multiple problems, each with its own remediation, or if no remediation is possible.

  - `messages.problems.context` (object)

  - `meta` (object)

  - `meta.stats` (object)

  - `meta.stats.count` (object,null)
    A count of total response times. If present "*" will be all items, or they can be faceted into specific categories.

  - `meta.api` (object)

  - `meta.api.response` (object)

  - `meta.api.response.primary` (object)

  - `meta.api.response.primary.endpoint` (string, required)
    The endpoint URL of the primary API request made to fulfill the response.

  - `meta.api.response.primary.response` (string, required)
    The response from the primary API request.

  - `meta.api.response.list` (object,null)
    All responses from backing API calls, indexed by endpoint URL.

  - `meta.mapping` (object)

  - `meta.mapping.chains` (object)
    The list of mapping chains applied, indexed by operation ID. Each entry contains an array of mapping IDs.


