sophos_get_detections_group_results
Retrieve grouped detection results from a completed query, providing counts, detection rules, MITRE ATT&CK tags, and device information for each group of similar detections.
Instructions
Get results of a completed detection-groups query. Each item represents a group of similar detections with a count, detection rule, MITRE ATT&CK tags, and device info.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| page | No | Page number (1-based, default 1) | |
| run_id | Yes | Detection-groups query run ID | |
| page_size | No | Number of results per page (default 50, max 2000) | |
| tenant_id | Yes | Tenant UUID |