Skip to main content
Question

Fetch Alerts By Entity (via UDM and REST API)

  • June 9, 2026
  • 1 reply
  • 10 views

soaruser
Forum|alt.badge.img+3

Hi,

Could anyone help me to fetch alert detections (custom as well as curated) of a specific entity from case using UDM Search Query and REST API?

So that I can display it on the case overview.

 

 

1 reply

cmorris
Staff
Forum|alt.badge.img+13
  • Staff
  • June 9, 2026

The Search API now supports querying the Detection dataset, so I do not believe you need to build anything custom here, you can work with a query and the Execute UDM Query action. You’ll likely want to tweak the query (fields returned as well as placeholder for the host or some other entity), but as an example:
 

Results: