Skip to content
Start here

Filter and list events

client.CloudforceOne.ThreatEvents.List(ctx, params) (*[]ThreatEventListResponse, error)
GET/accounts/{account_id}/cloudforce-one/events

Use datasetId=all or datasetId=* for the legacy all-datasets scope, datasetId=analytics for datasets with isAnalytics=true, or datasetId=operational for datasets with isAnalytics=false (limited to 50). Scope values must be used alone. When datasetId is unspecified, events are listed from the default Cloudforce One Threat Events dataset. To list existing datasets, use the List Datasets endpoint.

Security

API Token

The preferred authorization scheme for interacting with the Cloudflare API. Create a token.

Example:Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY
Accepted Permissions (at least one required)
Cloudforce One WriteCloudforce One Read
ParametersExpand Collapse
params ThreatEventListParams
AccountID param.Field[string]

Path param: Account ID.

Cache param.Field[ThreatEventListParamsCache]Optional

Query param: Cache strategy. ‘from-graph’ serves results from the graph-node KV cache when all requested UUIDs are cached; falls back to normal path on partial/zero hit.

const ThreatEventListParamsCacheFromGraph ThreatEventListParamsCache = "from-graph"
Cursor param.Field[string]Optional

Query param: Cursor for pagination. When provided, filters are embedded in the cursor so you only need to pass cursor and pageSize. Returned in the previous response’s result_info.cursor field. Use cursor-based pagination for deep pagination (beyond 100,000 records) or for optimal performance.

DatasetID param.Field[[]string]Optional

Query param: Dataset UUIDs to query, or one standalone scope value: ‘all’/’*’ for the legacy all-datasets behavior, ‘analytics’ for isAnalytics=true datasets, or ‘operational’ for isAnalytics=false datasets. If not provided, uses the default dataset.

ForceRefresh param.Field[bool]Optional

Query param

Format param.Field[ThreatEventListParamsFormat]Optional

Query param

const ThreatEventListParamsFormatJson ThreatEventListParamsFormat = "json"
const ThreatEventListParamsFormatStix2 ThreatEventListParamsFormat = "stix2"
const ThreatEventListParamsFormatTaxii ThreatEventListParamsFormat = "taxii"
Order param.Field[ThreatEventListParamsOrder]Optional

Query param

const ThreatEventListParamsOrderAsc ThreatEventListParamsOrder = "asc"
const ThreatEventListParamsOrderDesc ThreatEventListParamsOrder = "desc"
OrderBy param.Field[string]Optional

Query param

Page param.Field[float64]Optional

Query param: Page number (1-indexed) for offset-based pagination. Limited to offset of 100,000 records. For deep pagination, use cursor-based pagination instead.

PageSize param.Field[float64]Optional

Query param: Number of results per page. Maximum 25,000.

One of the following:
One of the following:
One of the following:
One of the following:
One of the following:
One of the following:
One of the following:
One of the following:
One of the following:
SearchBranches param.Field[[][]ThreatEventListParamsSearchBranch]Optional

Query param: JSON-encoded. OR branches of structured search filters. Filters within a branch are AND’d, branches are OR’d, and the result is AND’d with search: AND(search) AND OR(AND(branch 1), ...). Max 8 branches of 1-10 conditions each. Not supported for analytics datasets, and indicator filters are not yet supported inside branches. Cursor pages carry the original branches, so do not resend them with cursor.

type ThreatEventListParamsSearchBranchesObject struct{…}
Field ThreatEventListParamsSearchBranchesObjectField
One of the following:
const ThreatEventListParamsSearchBranchesObjectFieldAttacker ThreatEventListParamsSearchBranchesObjectField = "attacker"
const ThreatEventListParamsSearchBranchesObjectFieldAttackerCountry ThreatEventListParamsSearchBranchesObjectField = "attackerCountry"
const ThreatEventListParamsSearchBranchesObjectFieldCategory ThreatEventListParamsSearchBranchesObjectField = "category"
const ThreatEventListParamsSearchBranchesObjectFieldCreatedAt ThreatEventListParamsSearchBranchesObjectField = "createdAt"
const ThreatEventListParamsSearchBranchesObjectFieldDate ThreatEventListParamsSearchBranchesObjectField = "date"
const ThreatEventListParamsSearchBranchesObjectFieldEvent ThreatEventListParamsSearchBranchesObjectField = "event"
const ThreatEventListParamsSearchBranchesObjectFieldIndicator ThreatEventListParamsSearchBranchesObjectField = "indicator"
const ThreatEventListParamsSearchBranchesObjectFieldIndicatorType ThreatEventListParamsSearchBranchesObjectField = "indicatorType"
const ThreatEventListParamsSearchBranchesObjectFieldMitreAttack ThreatEventListParamsSearchBranchesObjectField = "mitreAttack"
const ThreatEventListParamsSearchBranchesObjectFieldMitreCapec ThreatEventListParamsSearchBranchesObjectField = "mitreCapec"
const ThreatEventListParamsSearchBranchesObjectFieldTags ThreatEventListParamsSearchBranchesObjectField = "tags"
const ThreatEventListParamsSearchBranchesObjectFieldTargetCountry ThreatEventListParamsSearchBranchesObjectField = "targetCountry"
const ThreatEventListParamsSearchBranchesObjectFieldTargetIndustry ThreatEventListParamsSearchBranchesObjectField = "targetIndustry"
const ThreatEventListParamsSearchBranchesObjectFieldTLP ThreatEventListParamsSearchBranchesObjectField = "tlp"
const ThreatEventListParamsSearchBranchesObjectFieldUUID ThreatEventListParamsSearchBranchesObjectField = "uuid"
Op ThreatEventListParamsSearchBranchesObjectOp
One of the following:
const ThreatEventListParamsSearchBranchesObjectOpEquals ThreatEventListParamsSearchBranchesObjectOp = "equals"
const ThreatEventListParamsSearchBranchesObjectOpNot ThreatEventListParamsSearchBranchesObjectOp = "not"
const ThreatEventListParamsSearchBranchesObjectOpGt ThreatEventListParamsSearchBranchesObjectOp = "gt"
const ThreatEventListParamsSearchBranchesObjectOpGte ThreatEventListParamsSearchBranchesObjectOp = "gte"
const ThreatEventListParamsSearchBranchesObjectOpLt ThreatEventListParamsSearchBranchesObjectOp = "lt"
const ThreatEventListParamsSearchBranchesObjectOpLte ThreatEventListParamsSearchBranchesObjectOp = "lte"
const ThreatEventListParamsSearchBranchesObjectOpLike ThreatEventListParamsSearchBranchesObjectOp = "like"
const ThreatEventListParamsSearchBranchesObjectOpContains ThreatEventListParamsSearchBranchesObjectOp = "contains"
const ThreatEventListParamsSearchBranchesObjectOpStartsWith ThreatEventListParamsSearchBranchesObjectOp = "startsWith"
const ThreatEventListParamsSearchBranchesObjectOpEndsWith ThreatEventListParamsSearchBranchesObjectOp = "endsWith"
const ThreatEventListParamsSearchBranchesObjectOpFind ThreatEventListParamsSearchBranchesObjectOp = "find"
Value string
maxLength512
minLength1
type ThreatEventListParamsSearchBranchesObject struct{…}
Field ThreatEventListParamsSearchBranchesObjectField
One of the following:
const ThreatEventListParamsSearchBranchesObjectFieldAttacker ThreatEventListParamsSearchBranchesObjectField = "attacker"
const ThreatEventListParamsSearchBranchesObjectFieldAttackerCountry ThreatEventListParamsSearchBranchesObjectField = "attackerCountry"
const ThreatEventListParamsSearchBranchesObjectFieldCategory ThreatEventListParamsSearchBranchesObjectField = "category"
const ThreatEventListParamsSearchBranchesObjectFieldCreatedAt ThreatEventListParamsSearchBranchesObjectField = "createdAt"
const ThreatEventListParamsSearchBranchesObjectFieldDate ThreatEventListParamsSearchBranchesObjectField = "date"
const ThreatEventListParamsSearchBranchesObjectFieldEvent ThreatEventListParamsSearchBranchesObjectField = "event"
const ThreatEventListParamsSearchBranchesObjectFieldIndicator ThreatEventListParamsSearchBranchesObjectField = "indicator"
const ThreatEventListParamsSearchBranchesObjectFieldIndicatorType ThreatEventListParamsSearchBranchesObjectField = "indicatorType"
const ThreatEventListParamsSearchBranchesObjectFieldMitreAttack ThreatEventListParamsSearchBranchesObjectField = "mitreAttack"
const ThreatEventListParamsSearchBranchesObjectFieldMitreCapec ThreatEventListParamsSearchBranchesObjectField = "mitreCapec"
const ThreatEventListParamsSearchBranchesObjectFieldTags ThreatEventListParamsSearchBranchesObjectField = "tags"
const ThreatEventListParamsSearchBranchesObjectFieldTargetCountry ThreatEventListParamsSearchBranchesObjectField = "targetCountry"
const ThreatEventListParamsSearchBranchesObjectFieldTargetIndustry ThreatEventListParamsSearchBranchesObjectField = "targetIndustry"
const ThreatEventListParamsSearchBranchesObjectFieldTLP ThreatEventListParamsSearchBranchesObjectField = "tlp"
const ThreatEventListParamsSearchBranchesObjectFieldUUID ThreatEventListParamsSearchBranchesObjectField = "uuid"
Op ThreatEventListParamsSearchBranchesObjectOp
Value []string
type ThreatEventListParamsSearchBranchesObject struct{…}
Field ThreatEventListParamsSearchBranchesObjectField
Op ThreatEventListParamsSearchBranchesObjectOp
One of the following:
const ThreatEventListParamsSearchBranchesObjectOpEquals ThreatEventListParamsSearchBranchesObjectOp = "equals"
const ThreatEventListParamsSearchBranchesObjectOpNot ThreatEventListParamsSearchBranchesObjectOp = "not"
const ThreatEventListParamsSearchBranchesObjectOpGt ThreatEventListParamsSearchBranchesObjectOp = "gt"
const ThreatEventListParamsSearchBranchesObjectOpGte ThreatEventListParamsSearchBranchesObjectOp = "gte"
const ThreatEventListParamsSearchBranchesObjectOpLt ThreatEventListParamsSearchBranchesObjectOp = "lt"
const ThreatEventListParamsSearchBranchesObjectOpLte ThreatEventListParamsSearchBranchesObjectOp = "lte"
Value ThreatEventListParamsSearchBranchesObjectValueUnion
One of the following:
UnionFloat
UnionString
type ThreatEventListParamsSearchBranchesObject struct{…}
Field ThreatEventListParamsSearchBranchesObjectField
Op ThreatEventListParamsSearchBranchesObjectOp
Value []ThreatEventListParamsSearchBranchesObjectValueUnion
One of the following:
UnionFloat
UnionString
type ThreatEventListParamsSearchBranchesObject struct{…}
Field ThreatEventListParamsSearchBranchesObjectField
Op ThreatEventListParamsSearchBranchesObjectOp
One of the following:
const ThreatEventListParamsSearchBranchesObjectOpEquals ThreatEventListParamsSearchBranchesObjectOp = "equals"
const ThreatEventListParamsSearchBranchesObjectOpNot ThreatEventListParamsSearchBranchesObjectOp = "not"
const ThreatEventListParamsSearchBranchesObjectOpGt ThreatEventListParamsSearchBranchesObjectOp = "gt"
const ThreatEventListParamsSearchBranchesObjectOpGte ThreatEventListParamsSearchBranchesObjectOp = "gte"
const ThreatEventListParamsSearchBranchesObjectOpLt ThreatEventListParamsSearchBranchesObjectOp = "lt"
const ThreatEventListParamsSearchBranchesObjectOpLte ThreatEventListParamsSearchBranchesObjectOp = "lte"
Value unknown
One of the following:
unknown
type ThreatEventListParamsSearchBranchesObject struct{…}
Field ThreatEventListParamsSearchBranchesObjectField
Op ThreatEventListParamsSearchBranchesObjectOp
Value []unknown
One of the following:
unknown
ReturnsExpand Collapse
type ThreatEventListResponse []ThreatEventListResponse
Attacker string
AttackerCountry string
AttackerCountryAlpha3 string
Category string
DatasetID string
Date string
Event string
HasChildren bool
Indicator string
IndicatorType string
IndicatorTypeID float64
KillChain float64
MitreAttack []string
MitreCapec []string
NumReferenced float64
NumReferences float64
RawID string
Referenced []string
ReferencedIDs []float64
References []string
ReferencesIDs []float64
Tags []string
TargetCountry string
TargetCountryAlpha3 string
TargetIndustry string
TLP string
UUID string
Insight stringOptional
ReleasabilityID stringOptional

Filter and list events

package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/cloudforce_one"
  "github.com/cloudflare/cloudflare-go/option"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  threatEvents, err := client.CloudforceOne.ThreatEvents.List(context.TODO(), cloudforce_one.ThreatEventListParams{
    AccountID: cloudflare.F("account_id"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", threatEvents)
}
[
  {
    "attacker": "Flying Yeti",
    "attackerCountry": "CN",
    "attackerCountryAlpha3": "CHN",
    "category": "Domain Resolution",
    "datasetId": "dataset-example-id",
    "date": "2022-04-01T00:00:00Z",
    "event": "An attacker registered the domain domain.com",
    "hasChildren": true,
    "indicator": "domain.com",
    "indicatorType": "domain",
    "indicatorTypeId": 5,
    "killChain": 0,
    "mitreAttack": [
      " "
    ],
    "mitreCapec": [
      " "
    ],
    "numReferenced": 0,
    "numReferences": 0,
    "rawId": "453gw34w3",
    "referenced": [
      " "
    ],
    "referencedIds": [
      0
    ],
    "references": [
      " "
    ],
    "referencesIds": [
      0
    ],
    "tags": [
      "malware"
    ],
    "targetCountry": "US",
    "targetCountryAlpha3": "USA",
    "targetIndustry": "Agriculture",
    "tlp": "amber",
    "uuid": "12345678-1234-1234-1234-1234567890ab",
    "insight": "insight",
    "releasabilityId": "releasabilityId"
  }
]
Returns Examples
[
  {
    "attacker": "Flying Yeti",
    "attackerCountry": "CN",
    "attackerCountryAlpha3": "CHN",
    "category": "Domain Resolution",
    "datasetId": "dataset-example-id",
    "date": "2022-04-01T00:00:00Z",
    "event": "An attacker registered the domain domain.com",
    "hasChildren": true,
    "indicator": "domain.com",
    "indicatorType": "domain",
    "indicatorTypeId": 5,
    "killChain": 0,
    "mitreAttack": [
      " "
    ],
    "mitreCapec": [
      " "
    ],
    "numReferenced": 0,
    "numReferences": 0,
    "rawId": "453gw34w3",
    "referenced": [
      " "
    ],
    "referencedIds": [
      0
    ],
    "references": [
      " "
    ],
    "referencesIds": [
      0
    ],
    "tags": [
      "malware"
    ],
    "targetCountry": "US",
    "targetCountryAlpha3": "USA",
    "targetIndustry": "Agriculture",
    "tlp": "amber",
    "uuid": "12345678-1234-1234-1234-1234567890ab",
    "insight": "insight",
    "releasabilityId": "releasabilityId"
  }
]