# External alerts via API

**URL:** <https://discuss.elastic.co/t/external-alerts-via-api/257293>\
**Category:** SIEM\
**Created:** [December 2, 2020, 12:45am UTC](https://discuss.elastic.co/t/external-alerts-via-api/257293 "2020-12-02T00:45:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Derick\_Jansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/derick_jansen/32/71407_2.png) [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Post date:** [December 2, 2020, 12:45am UTC](https://discuss.elastic.co/t/external-alerts-via-api/257293/1 "2020-12-02T00:45:37Z")

</div>

Hi

I am using the /detection\_engine/signals/search endpoint to grab detections but this endpoint doesn't include External alerts (eg. Crowdstrike). Is there an endpoint or other method to programmatically collect external alerts?

Cheers!

---

<div class="post-metadata">

**Author:** ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)\
**Post date:** [December 2, 2020, 12:26pm UTC](https://discuss.elastic.co/t/external-alerts-via-api/257293/2 "2020-12-02T12:26:21Z")

</div>

Hi @Derick_Jansen, thanks for the post!

External alerts are defined as log events that have the ECS field:value of `event.kind:alert`

These events have no SIEM/Security app detection rule metadata applied to them, so they are more like raw events.

Here are two possible options if you want to grab these external alert events:

1. Use Elasticsearch API's to access them directly in the indices into which they are ingested.
2. Create and activate a simple detection engine rule to create a detection alert (aka signal) for each external alert that is received. For example, a custom query rule that uses `event.module:crowdstrike AND event.kind:alert`, and then continue to use the API endpoint you're using now.

Note, for option 2, when creating the detection rule, you can use the "rule name override" switch, so that an original alert name from Crowdstrike appears as the rule name in the signal document, like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/3732b92e21db6fb9c1fada0109a8aa40e0e0e6c8.png)

Please let us know if this helps.

Also, I'd be interested to know what you're doing with the detection alerts once you pull them using the API?

Thanks!  
Mike P.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2020, 12:26pm UTC](https://discuss.elastic.co/t/external-alerts-via-api/257293/3 "2020-12-30T12:26:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
