# Getting SIEM alerts through API

**URL:** <https://discuss.elastic.co/t/getting-siem-alerts-through-api/321603>\
**Category:** SIEM\
**Created:** [December 19, 2022, 9:01pm UTC](https://discuss.elastic.co/t/getting-siem-alerts-through-api/321603 "2022-12-19T21:01:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![reg\_reginald](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@reg\_reginald](https://discuss.elastic.co/u/reg_reginald)\
**Post date:** [December 19, 2022, 9:01pm UTC](https://discuss.elastic.co/t/getting-siem-alerts-through-api/321603/1 "2022-12-19T21:01:00Z")

</div>

Hello,

Is it possible to get alerts from Kibana SIEM through an api?

it seems like

`<kibana host>:<port>/api/detection_engine/signals`

could be a way but there's no example with individual alerts, just an aggregation.

Failing that, I guess the following could be used?

> **[Search API | Elasticsearch Guide \[8.5\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-search.html)**

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 20, 2022, 1:59am UTC](https://discuss.elastic.co/t/getting-siem-alerts-through-api/321603/2 "2022-12-20T01:59:50Z")

</div>

Have you tried the signals search API? [Signals endpoint | Elastic Security Solution [8.5] | Elastic](https://www.elastic.co/guide/en/security/current/signals-api-overview.html)

---

<div class="post-metadata">

**Author:** ![reg\_reginald](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@reg\_reginald](https://discuss.elastic.co/u/reg_reginald)\
**Post date:** [December 20, 2022, 11:11pm UTC](https://discuss.elastic.co/t/getting-siem-alerts-through-api/321603/3 "2022-12-20T23:11:48Z")

</div>

I hadn't .

Thanks for pointing me in that direction because it's exactly what I'm after.

Do you know if

1\ signals have a unique identifier ?  
2\ how that api endpoint handles pagination (if the results are too much for one response)?

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [December 21, 2022, 12:06am UTC](https://discuss.elastic.co/t/getting-siem-alerts-through-api/321603/4 "2022-12-21T00:06:12Z")

</div>

> 1\ signals have a unique identifier ?

I believe the document `_id` or `kibana.alert.uuid` represents the signal ID.

> 2\ how that api endpoint handles pagination (if the results are too much for one response)?

The signal search API is just an Elasticsearch query DSL targeting security alerts indices. You can refer to [Paginate search results | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/paginate-search-results.html) on how to paginate your search results.

---

<div class="post-metadata">

**Author:** ![reg\_reginald](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@reg\_reginald](https://discuss.elastic.co/u/reg_reginald)\
**Post date:** [December 21, 2022, 7:13pm UTC](https://discuss.elastic.co/t/getting-siem-alerts-through-api/321603/5 "2022-12-21T19:13:21Z")

</div>

Thanks again Hendry. Really appreciate the accurate responses!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2023, 7:14pm UTC](https://discuss.elastic.co/t/getting-siem-alerts-through-api/321603/6 "2023-01-18T19:14:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
