View a markdown version of this page

GetFindingMetrics - AWS Security Incident Response

GetFindingMetrics

Returns finding-lifecycle metrics for a membership over a specified date range. This read-only operation provides aggregate counts that describe how security findings progressed through the finding lifecycle, from ingestion through triage, investigation, and escalation, including false-positive, true-positive, and in-progress counts. The metrics are scoped to a single membership and to a day-aligned UTC date range.

Request Syntax

GET /v1/membership/membershipId/finding-metrics?endDate=endDate&startDate=startDate HTTP/1.1

URI Request Parameters

The request uses the following URI parameters.

endDate

The end of the date range to retrieve metrics for. This value is the end of a day-aligned UTC window and is inclusive.

Required: Yes

membershipId

The unique identifier of the membership to retrieve finding-lifecycle metrics for.

Length Constraints: Minimum length of 12. Maximum length of 34.

Pattern: m-[a-z0-9]{10,32}

Required: Yes

startDate

The start of the date range to retrieve metrics for. This value is the beginning of a day-aligned UTC window and is inclusive.

Required: Yes

Request Body

The request does not have a request body.

Response Syntax

HTTP/1.1 200 Content-type: application/json { "findingsEscalated": number, "findingsEscalatedFalsePositive": number, "findingsEscalatedInProgress": number, "findingsIngestedGuardDuty": number, "findingsIngestedSecurityHub": number, "findingsInvestigated": number, "findingsInvestigatedFalsePositive": number, "findingsInvestigatedInProgress": number, "findingsTriaged": number, "findingsTriagedFalsePositive": number, "findingsTruePositive": number }

Response Elements

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

findingsEscalated

The number of findings escalated during the requested date range.

Type: Long

findingsEscalatedFalsePositive

The number of escalated findings that were closed as false positives during the requested date range.

Type: Long

findingsEscalatedInProgress

The number of findings whose escalation was in progress during the requested date range.

Type: Long

findingsIngestedGuardDuty

The number of findings ingested from Amazon GuardDuty during the requested date range.

Type: Long

findingsIngestedSecurityHub

The number of findings ingested from AWS Security Hub during the requested date range.

Type: Long

findingsInvestigated

The number of findings investigated during the requested date range.

Type: Long

findingsInvestigatedFalsePositive

The number of investigated findings that were closed as false positives during the requested date range.

Type: Long

findingsInvestigatedInProgress

The number of findings whose investigation was in progress during the requested date range.

Type: Long

findingsTriaged

The number of findings triaged during the requested date range.

Type: Long

findingsTriagedFalsePositive

The number of triaged findings that were closed as false positives during the requested date range.

Type: Long

findingsTruePositive

The number of findings confirmed as true positives during the requested date range.

Type: Long

Errors

For information about the errors that are common to all actions, see Common Error Types.

AccessDeniedException

message

The ID of the resource which lead to the access denial.

HTTP Status Code: 403

ConflictException

Returned when there is a conflict with the current state of the resource.

For UpdateResolverType, this error may occur when attempting to change an AWS-supported case to Self-managed, which is not supported.

message

The exception message.

resourceId

The ID of the conflicting resource.

resourceType

The type of the conflicting resource.

HTTP Status Code: 409

InternalServerException

message

The exception message.

retryAfterSeconds

The number of seconds after which to retry the request.

HTTP Status Code: 500

InvalidTokenException

message

The exception message.

HTTP Status Code: 423

ResourceNotFoundException

message

The exception message.

HTTP Status Code: 404

SecurityIncidentResponseNotActiveException

message

The exception message.

HTTP Status Code: 400

ServiceQuotaExceededException

message

The exception message.

quotaCode

The code of the quota.

resourceId

The ID of the requested resource which lead to the service quota exception.

resourceType

The type of the requested resource which lead to the service quota exception.

serviceCode

The service code of the quota.

HTTP Status Code: 402

ThrottlingException

message

The exception message.

quotaCode

The quota code of the exception.

retryAfterSeconds

The number of seconds after which to retry the request.

serviceCode

The service code of the exception.

HTTP Status Code: 429

ValidationException

Returned when the request contains invalid parameters.

For UpdateResolverType, this error may occur when attempting an unsupported resolver type transition.

fieldList

The fields which lead to the exception.

message

The exception message.

reason

The reason for the exception.

HTTP Status Code: 400

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: