get_alerts
Retrieve recent security alerts from Wazuh with optional filtering by severity, agent, rule, and search terms to investigate potential threats.
Instructions
Retrieve recent security alerts from Wazuh with optional filtering
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum number of alerts to return (1-100) | |
| offset | No | Pagination offset | |
| level | No | Minimum rule severity level | |
| agent_id | No | Filter by agent ID | |
| rule_id | No | Filter by specific rule ID | |
| sort | No | Sort field with direction prefix (e.g., '-timestamp') | |
| search | No | Search term for full_log text |