Investigation | Dropzone AI Documentation

List investigations (with optional filtering, sorting, and search)

Returns a paginated list of investigations. By default, only completed investigations (state='success') are returned. Use query parameters to filter by state, outcomes, priorities, date ranges, and more.

Authorizations

Query parameters

Show properties

Show properties

Show properties

Show properties

Show properties

Show properties

Responses

200

Paginated list of investigations

Use next and previous URLs in the response for easy page navigation.

Response body

application/json

{ "count": 1, "next": "https://example.com", "previous": "https://example.com", "results": [ { "alert": { "alert_type": "text", "assets": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "coalesce_key": "text", "create_time": "2026-07-28T03:44:00.113Z", "created_at": "2026-07-28T03:44:00.113Z", "direct_source_label": "text", "entities": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "id": 1, "origin_integration": "text", "origin_ticket_id": "text", "origin_ticket_id_label": "text", "origin_ticket_url": "text", "original_title": "text", "proxy_source_label": "text", "raw_alert_content": "text", "schema_key": "text", "severity": "text", "start_time": "2026-07-28T03:44:00.113Z", "tenant_id": "text", "tenant_integration_key": "text", "tenant_label": "text", "tenant_union": { "created_at": "2026-07-28T03:44:00.113Z", "display_name": "text", "id": 1, "lookup_dict": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "updated_at": "2026-07-28T03:44:00.113Z" }, "title": "text", "updated_at": "2026-07-28T03:44:00.113Z" }, "alert_summary": "text", "attack_surface": "text", "canceled": "CANCEL_MANUAL", "conclusion": "text", "conclusion_summary": "text", "created_at": "2026-07-28T03:44:00.113Z", "custom_outcome": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "error_msg": "text", "exec_summary": "text", "feedback": { "conclusion": "text", "conclusion_summary": "text", "created_at": "2026-07-28T03:44:00.113Z", "findings": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "findings_ranking": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "id": 1, "insight_tags": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "key_findings": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "outcome": "COMPLETED_BREACHED_CONFIRMED", "outcome_note": "text", "priority": "informational", "remediations_done": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "status": "in_review", "updated_at": "2026-07-28T03:44:00.113Z" }, "findings": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "findings_ranking": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "generated_time": "2026-07-28T03:44:00.113Z", "id": 1, "ignored_for_investigation_id": 1, "insight_tags": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "interview_proposals": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "inv_url": "text", "key_findings": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "mitre_tactic": "text", "outcome": "COMPLETED_BREACHED_CONFIRMED", "priority": "informational", "recommended_remediations": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "remediation_action_runs": [ { "entity": "text", "remediation_action": { "name": "text" } } ], "start_time": "2026-07-28T03:44:00.113Z", "status": "not_asked", "updated_at": "2026-07-28T03:44:00.113Z" } ] }

Errors

400

Bad request - invalid input

401

Unauthorized

403

Access denied

500

System error

503

System not ready for requests

Create a new alert investigation

Creates a new alert investigation, returning investigation_id. Returns existing id if alert already exists (unless force_reinvestigation=True). Then use GET /app/api/v1/investigation/{investigation_id} for updates.

Authorizations

Body

Responses

200

Existing investigation found

Response body

application/json

{ "investigation_id": 1 }

201

New investigation created

Errors

400

Bad request - invalid input

401

Unauthorized

403

Access denied

422

Alert skipped due to missing data (e.g., propagation delay)

500

System error

503

System not ready for requests

Get an alert investigation

Returns an alert investigation.

Authorizations

Path parameters

Responses

200

Investigation data object. For progress: investigation.status=

Response body

application/json

{ "alert": { "alert_type": "text", "assets": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "coalesce_key": "text", "create_time": "2026-07-28T03:44:00.113Z", "created_at": "2026-07-28T03:44:00.113Z", "direct_source_label": "text", "enrich_result": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "entities": [ { "type": "text", "value": "text" } ], "handler_version": "v1", "id": 1, "origin_integration": "text", "origin_integration_display_name": "text", "origin_ticket_id": "text", "origin_ticket_id_label": "text", "origin_ticket_url": "text", "original_title": "text", "proxy_source_label": "text", "raw_alert_content": "text", "schema_key": "text", "severity": "text", "start_time": "2026-07-28T03:44:00.113Z", "tenant_id": "text", "tenant_integration_key": "text", "tenant_label": "text", "tenant_union": { "created_at": "2026-07-28T03:44:00.113Z", "display_name": "text", "id": 1, "last_modified_by": { "email": "name@gmail.com", "first_name": "text", "id": 1, "last_name": "text", "oidc_user_id": "text", "role": "admin" }, "lookup_dict": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "updated_at": "2026-07-28T03:44:00.113Z" }, "title": "text", "updated_at": "2026-07-28T03:44:00.113Z" }, "alert_summary": "text", "attack_surface": "text", "backfill": 1, "canceled": "CANCEL_MANUAL", "conclusion": "text", "conclusion_summary": "text", "created_at": "2026-07-28T03:44:00.113Z", "email_screenshot": "text", "error_msg": "text", "exec_summary": "text", "findings": [ { "artifacts": [ "text" ], "evidences": [ { "data": "text", "evidence_type": "text", "tag": "text" } ], "finding": "text", "headline": "text", "outcome": "COMPLETED_BREACHED_CONFIRMED" } ], "findings_ranking": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "generated_time": "2026-07-28T03:44:00.113Z", "id": 1, "ignored_for": 1, "insight_tags": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "interview_proposals": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "inv_url": "text", "is_retried": true, "key_findings": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "mitre_tactic": "text", "outcome": "COMPLETED_BREACHED_CONFIRMED", "priority": "informational", "ready": true, "recommended_remediations": [ "text" ], "related_alert_hypothesis": { "ANY_ADDITIONAL_PROPERTY": "anything" }, "start_time": "2026-07-28T03:44:00.113Z", "status": "not_asked", "updated_at": "2026-07-28T03:44:00.113Z" }

Errors

401

Unauthorized

403

Access denied

404

Resource not found

500

System error

503

System not ready for requests

Last updated 8 months ago