Method: instances.searchEntities

Full name: projects.locations.instances.searchEntities

Identifies the entity type and retrieves relevant data associated with a specified indicator. The API returns a maximum of 1000 entities.

HTTP request

GET https://{endpoint}/v1beta/{instance}:searchEntities

Where {endpoint} is one of the supported service endpoints.

Path parameters

Parameters
instance

string

Required. The ID of the Instance to search entities for. Format: projects/{project}/locations/{location}/instances/{instance}

Query parameters

Parameters
indicator

string

Required. Value of indicator tied to an entity.

Request body

The request body must be empty.

Response body

Response message for search entities.

If successful, the response body contains data with the following structure:

JSON representation
{
  "entities": [
    {
      object (Entity)
    }
  ]
}
Fields
entities[]

object (Entity)

A list of entities.

Authorization scopes

Requires one of the following OAuth scopes:

  • https://www.googleapis.com/auth/cloud-platform
  • https://www.googleapis.com/auth/chronicle
  • https://www.googleapis.com/auth/chronicle.readonly

For more information, see the Authentication Overview.

IAM Permissions

Requires the following IAM permission on the instance resource:

  • chronicle.entities.searchEntities

For more information, see the IAM documentation.