get_alerts
Retrieve recent security alerts from Wazuh with optional filtering by severity, agent, rule, or search terms to monitor and investigate threats.
Instructions
Retrieve recent security alerts from Wazuh with optional filtering
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum number of alerts to return (1-100) | |
| offset | No | Pagination offset | |
| level | No | Minimum rule severity level | |
| agent_id | No | Filter by agent ID | |
| rule_id | No | Filter by specific rule ID | |
| sort | No | Sort field with direction prefix (e.g., '-timestamp') | |
| search | No | Search term for full_log text |