Full name: projects.locations.instances.legacy.legacySearchAssetEvents
Legacy endpoint for getting events for a given asset.
HTTP request
Path parameters
Parameters
instance
string
Required. The name of the parent resource, which is the SecOps instance this request is sent to. Format: projects/{project}/locations/{location}/instances/{instance}
Required. The time range of the events to return [inclusive start time, exclusive end time).
maxResults
integer
The maximum number of events to return. The service may return fewer than this value. If unspecified, at most 10,000 events will be returned. The maximum value is 100,000; values above 100,000 will be coerced to 100,000.
The time used to alias indicator and fetch results of the asset.
Uses RFC 3339, where generated output will always be Z-normalized and uses 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: "2014-10-02T15:01:23Z", "2014-10-02T15:01:23.045123456Z" or "2014-10-02T15:01:23+05:30".
Request body
The request body must be empty.
Response body
Returns searched for events grouped into different categories.
If successful, the response body contains data with the following structure:
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-25 UTC."],[[["\u003cp\u003eThis API endpoint \u003ccode\u003eprojects.locations.instances.legacy.legacySearchAssetEvents\u003c/code\u003e is a legacy method for retrieving events associated with a specified asset within a Chronicle instance.\u003c/p\u003e\n"],["\u003cp\u003eThe request requires an asset indicator, a time range, and an instance path parameter, while it also accepts optional parameters like \u003ccode\u003emaxResults\u003c/code\u003e and \u003ccode\u003ereferenceTime\u003c/code\u003e to further refine the search.\u003c/p\u003e\n"],["\u003cp\u003eThe API response is structured in JSON and includes various categories of events, such as \u003ccode\u003eresults\u003c/code\u003e, \u003ccode\u003ealerts\u003c/code\u003e, \u003ccode\u003eip_network_events\u003c/code\u003e, \u003ccode\u003eedr_events\u003c/code\u003e, and \u003ccode\u003etyped_user_events\u003c/code\u003e, along with lists of file hashes (\u003ccode\u003emd5\u003c/code\u003e, \u003ccode\u003esha1\u003c/code\u003e, \u003ccode\u003esha256\u003c/code\u003e).\u003c/p\u003e\n"],["\u003cp\u003eThe response includes the \u003ccode\u003etotal_records\u003c/code\u003e and \u003ccode\u003etoo_many_results\u003c/code\u003e field, to allow the client to know how many records matched the request, and if there were more results than specified in the \u003ccode\u003emaxResults\u003c/code\u003e parameter.\u003c/p\u003e\n"],["\u003cp\u003eUtilizing this endpoint requires the \u003ccode\u003echronicle.legacies.legacySearchAssetEvents\u003c/code\u003e IAM permission and the \u003ccode\u003ehttps://www.googleapis.com/auth/cloud-platform\u003c/code\u003e OAuth scope.\u003c/p\u003e\n"]]],[],null,["# Method: legacy.legacySearchAssetEvents\n\n- [HTTP request](#body.HTTP_TEMPLATE)\n- [Path parameters](#body.PATH_PARAMETERS)\n- [Query parameters](#body.QUERY_PARAMETERS)\n- [Request body](#body.request_body)\n- [Response body](#body.response_body)\n - [JSON representation](#body.LegacySearchAssetEventsResponse.SCHEMA_REPRESENTATION)\n- [Authorization scopes](#body.aspect)\n- [IAM Permissions](#body.aspect_1)\n- [Try it!](#try-it)\n\n**Full name**: projects.locations.instances.legacy.legacySearchAssetEvents\n\nLegacy endpoint for getting events for a given asset.\n\n### HTTP request\n\nChoose a location: \nafrica-south1 asia-northeast1 asia-south1 asia-southeast1 asia-southeast2 australia-southeast1 europe-west12 europe-west2 europe-west3 europe-west6 europe-west9 me-central1 me-central2 me-west1 northamerica-northeast2 southamerica-east1 us eu \n\n\u003cbr /\u003e\n\n### Path parameters\n\n### Query parameters\n\n### Request body\n\nThe request body must be empty.\n\n### Response body\n\nReturns searched for events grouped into different categories.\n\nIf successful, the response body contains data with the following structure:\n\n### Authorization scopes\n\nRequires the following OAuth scope:\n\n- `https://www.googleapis.com/auth/cloud-platform`\n\nFor more information, see the [Authentication Overview](/docs/authentication#authorization-gcp).\n\n### IAM Permissions\n\nRequires the following [IAM](https://cloud.google.com/iam/docs) permission on the `instance` resource:\n\n- `chronicle.legacies.legacySearchAssetEvents`\n\nFor more information, see the [IAM documentation](https://cloud.google.com/iam/docs)."]]