GetInvestigation
This API is currently available as a preview. This feature is available in the following AWS Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Paris), Europe (Stockholm), and Asia Pacific (Tokyo).
Retrieves the results and status of a specific GuardDuty investigation.
An administrator account can retrieve any investigation within the organization. Member accounts can only retrieve investigations that belong to them.
Request Syntax
GET /detector/DetectorId/investigation/InvestigationId HTTP/1.1
URI Request Parameters
The request uses the following URI parameters.
- DetectorId
-
The unique ID of the GuardDuty detector associated with the investigation.
To find the
detectorIdin the current Region, see the Settings page in the GuardDuty console, or run the ListDetectors API.Length Constraints: Minimum length of 1. Maximum length of 300.
Required: Yes
- InvestigationId
-
The unique identifier of the investigation to retrieve.
Length Constraints: Minimum length of 1. Maximum length of 64.
Pattern:
[a-fA-F0-9\-]+Required: Yes
Request Body
The request does not have a request body.
Response Syntax
HTTP/1.1 200
Content-type: application/json
{
"investigation": {
"cloud": {
"account": "string",
"provider": "string",
"region": "string"
},
"confidence": "string",
"endTime": number,
"error": "string",
"investigationId": "string",
"metadata": {
"product": {
"feature": "string",
"name": "string"
},
"version": "string"
},
"risk": "string",
"riskLevel": "string",
"startTime": number,
"status": "string",
"summary": "string",
"triggeredBy": "string",
"triggerPrompt": "string"
}
}
Response Elements
If the action is successful, the service sends back an HTTP 200 response.
The following data is returned in JSON format by the service.
- investigation
-
The details and results of the requested investigation.
Type: Investigation object
Errors
For information about the errors that are common to all actions, see Common Error Types.
- AccessDeniedException
-
An access denied exception object.
- Message
-
The error message.
- Type
-
The error type.
HTTP Status Code: 403
- BadRequestException
-
A bad request exception object.
- Message
-
The error message.
- Type
-
The error type.
HTTP Status Code: 400
- InternalServerErrorException
-
An internal server error exception object.
- Message
-
The error message.
- Type
-
The error type.
HTTP Status Code: 500
- ResourceNotFoundException
-
The requested resource can't be found.
- Message
-
The error message.
- Type
-
The error type.
HTTP Status Code: 404
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: