GetFindingMetrics
Returns finding-lifecycle metrics for a membership over a specified date range. This read-only operation provides aggregate counts that describe how security findings progressed through the finding lifecycle, from ingestion through triage, investigation, and escalation, including false-positive, true-positive, and in-progress counts. The metrics are scoped to a single membership and to a day-aligned UTC date range.
Request Syntax
GET /v1/membership/membershipId/finding-metrics?endDate=endDate&startDate=startDate HTTP/1.1
URI Request Parameters
The request uses the following URI parameters.
- endDate
-
The end of the date range to retrieve metrics for. This value is the end of a day-aligned UTC window and is inclusive.
Required: Yes
- membershipId
-
The unique identifier of the membership to retrieve finding-lifecycle metrics for.
Length Constraints: Minimum length of 12. Maximum length of 34.
Pattern:
m-[a-z0-9]{10,32}Required: Yes
- startDate
-
The start of the date range to retrieve metrics for. This value is the beginning of a day-aligned UTC window and is inclusive.
Required: Yes
Request Body
The request does not have a request body.
Response Syntax
HTTP/1.1 200
Content-type: application/json
{
"findingsEscalated": number,
"findingsEscalatedFalsePositive": number,
"findingsEscalatedInProgress": number,
"findingsIngestedGuardDuty": number,
"findingsIngestedSecurityHub": number,
"findingsInvestigated": number,
"findingsInvestigatedFalsePositive": number,
"findingsInvestigatedInProgress": number,
"findingsTriaged": number,
"findingsTriagedFalsePositive": number,
"findingsTruePositive": number
}
Response Elements
If the action is successful, the service sends back an HTTP 200 response.
The following data is returned in JSON format by the service.
- findingsEscalated
-
The number of findings escalated during the requested date range.
Type: Long
- findingsEscalatedFalsePositive
-
The number of escalated findings that were closed as false positives during the requested date range.
Type: Long
- findingsEscalatedInProgress
-
The number of findings whose escalation was in progress during the requested date range.
Type: Long
- findingsIngestedGuardDuty
-
The number of findings ingested from Amazon GuardDuty during the requested date range.
Type: Long
- findingsIngestedSecurityHub
-
The number of findings ingested from AWS Security Hub during the requested date range.
Type: Long
- findingsInvestigated
-
The number of findings investigated during the requested date range.
Type: Long
- findingsInvestigatedFalsePositive
-
The number of investigated findings that were closed as false positives during the requested date range.
Type: Long
- findingsInvestigatedInProgress
-
The number of findings whose investigation was in progress during the requested date range.
Type: Long
- findingsTriaged
-
The number of findings triaged during the requested date range.
Type: Long
- findingsTriagedFalsePositive
-
The number of triaged findings that were closed as false positives during the requested date range.
Type: Long
- findingsTruePositive
-
The number of findings confirmed as true positives during the requested date range.
Type: Long
Errors
For information about the errors that are common to all actions, see Common Error Types.
- AccessDeniedException
-
- message
-
The ID of the resource which lead to the access denial.
HTTP Status Code: 403
- ConflictException
-
Returned when there is a conflict with the current state of the resource.
For UpdateResolverType, this error may occur when attempting to change an AWS-supported case to Self-managed, which is not supported.
- message
-
The exception message.
- resourceId
-
The ID of the conflicting resource.
- resourceType
-
The type of the conflicting resource.
HTTP Status Code: 409
- InternalServerException
-
- message
-
The exception message.
- retryAfterSeconds
-
The number of seconds after which to retry the request.
HTTP Status Code: 500
- InvalidTokenException
-
- message
-
The exception message.
HTTP Status Code: 423
- ResourceNotFoundException
-
- message
-
The exception message.
HTTP Status Code: 404
- SecurityIncidentResponseNotActiveException
-
- message
-
The exception message.
HTTP Status Code: 400
- ServiceQuotaExceededException
-
- message
-
The exception message.
- quotaCode
-
The code of the quota.
- resourceId
-
The ID of the requested resource which lead to the service quota exception.
- resourceType
-
The type of the requested resource which lead to the service quota exception.
- serviceCode
-
The service code of the quota.
HTTP Status Code: 402
- ThrottlingException
-
- message
-
The exception message.
- quotaCode
-
The quota code of the exception.
- retryAfterSeconds
-
The number of seconds after which to retry the request.
- serviceCode
-
The service code of the exception.
HTTP Status Code: 429
- ValidationException
-
Returned when the request contains invalid parameters.
For UpdateResolverType, this error may occur when attempting an unsupported resolver type transition.
- fieldList
-
The fields which lead to the exception.
- message
-
The exception message.
- reason
-
The reason for the exception.
HTTP Status Code: 400
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: