<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Stealthwatch Cloud API V3 Source ID Question in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/stealthwatch-cloud-api-v3-source-id-question/m-p/4527657#M754</link>
    <description>&lt;P&gt;&lt;A href="https://developer.cisco.com/docs/stealthwatch/cloud/#!stealthwatch-cloud-api-version-3" target="_blank" rel="noopener"&gt;https://developer.cisco.com/docs/stealthwatch/cloud/#!stealthwatch-cloud-api-version-3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you pull back an observation, the source id of the object is what?&amp;nbsp; I assumed it was a hostname ID, but that doesn't seem to line up.&amp;nbsp; I said that because it doesn't find the hostname for the IDs I'm feeding it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I feel like I must be missing something.&amp;nbsp; What is that source id?&amp;nbsp; And how do I query to get the actual source information, like the hostname and IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, given this returned observation object ID, what is that source ID 38?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;{&lt;BR /&gt;"id": 9831,&lt;BR /&gt;"time": "2022-01-06T11:25:36Z",&lt;BR /&gt;"creation_time": "2022-01-06T11:25:36Z",&lt;BR /&gt;"source": 38,&lt;BR /&gt;"observation_name": "New External Server",&lt;BR /&gt;"resource_name": "new_external_server_observation_v2",&lt;BR /&gt;"end_time": "2022-01-06T11:25:36Z",&lt;BR /&gt;"external_ip": "91.189.91.39",&lt;BR /&gt;"new_tag": "WebServer",&lt;BR /&gt;"new_ports": "80, 443, 8000, 8080, 8443",&lt;BR /&gt;"bytes_in": 10111562,&lt;BR /&gt;"bytes_out": 392364,&lt;BR /&gt;"external_ip_country_code": "US",&lt;BR /&gt;}&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jan 2022 21:40:30 GMT</pubDate>
    <dc:creator>conard.richardson</dc:creator>
    <dc:date>2022-01-06T21:40:30Z</dc:date>
    <item>
      <title>Stealthwatch Cloud API V3 Source ID Question</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-cloud-api-v3-source-id-question/m-p/4527657#M754</link>
      <description>&lt;P&gt;&lt;A href="https://developer.cisco.com/docs/stealthwatch/cloud/#!stealthwatch-cloud-api-version-3" target="_blank" rel="noopener"&gt;https://developer.cisco.com/docs/stealthwatch/cloud/#!stealthwatch-cloud-api-version-3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you pull back an observation, the source id of the object is what?&amp;nbsp; I assumed it was a hostname ID, but that doesn't seem to line up.&amp;nbsp; I said that because it doesn't find the hostname for the IDs I'm feeding it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I feel like I must be missing something.&amp;nbsp; What is that source id?&amp;nbsp; And how do I query to get the actual source information, like the hostname and IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, given this returned observation object ID, what is that source ID 38?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;{&lt;BR /&gt;"id": 9831,&lt;BR /&gt;"time": "2022-01-06T11:25:36Z",&lt;BR /&gt;"creation_time": "2022-01-06T11:25:36Z",&lt;BR /&gt;"source": 38,&lt;BR /&gt;"observation_name": "New External Server",&lt;BR /&gt;"resource_name": "new_external_server_observation_v2",&lt;BR /&gt;"end_time": "2022-01-06T11:25:36Z",&lt;BR /&gt;"external_ip": "91.189.91.39",&lt;BR /&gt;"new_tag": "WebServer",&lt;BR /&gt;"new_ports": "80, 443, 8000, 8080, 8443",&lt;BR /&gt;"bytes_in": 10111562,&lt;BR /&gt;"bytes_out": 392364,&lt;BR /&gt;"external_ip_country_code": "US",&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 21:40:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-cloud-api-v3-source-id-question/m-p/4527657#M754</guid>
      <dc:creator>conard.richardson</dc:creator>
      <dc:date>2022-01-06T21:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Cloud API V3 Source ID Question</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-cloud-api-v3-source-id-question/m-p/4529854#M755</link>
      <description>&lt;P&gt;Got the answer.&amp;nbsp; Had to reach out through our Cisco partner contacts.&amp;nbsp; For anybody else that might come across this.&amp;nbsp; The documentation is incomplete:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This should be the id of the device that was the source of the device.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can get the device info from &lt;A href="https://%3ctenant-id%3e.obsrvbl.com/v2/#/device/summary/?id=&amp;lt;source" target="_blank"&gt;https://&amp;lt;tenant-id&amp;gt;.obsrvbl.com/v2/#/device/summary/?id=&amp;lt;source&lt;/A&gt;&amp;gt;, where &amp;lt;source&amp;gt; is the device id you get from the observation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This &lt;A href="https://%3ctenant-id%3e.obsrvbl.com/api/v3/sources/devicesource/%3csource" target="_blank"&gt;https://&amp;lt;tenant-id&amp;gt;.obsrvbl.com/api/v3/sources/devicesource/&amp;lt;source&lt;/A&gt;&amp;gt; will provide a rich set of info.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 22:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-cloud-api-v3-source-id-question/m-p/4529854#M755</guid>
      <dc:creator>conard.richardson</dc:creator>
      <dc:date>2022-01-11T22:02:17Z</dc:date>
    </item>
  </channel>
</rss>

