Druva MSP icon

Druva MSP

Interact with the Druva MSP API

Actions79

Alert Summary → Get Unified Alerts

AI-generated

Overview

The node fetches unified alerts from multiple workloads within the Druva MSP platform, including Endpoints, Enterprise Workloads, Microsoft 365, and Google Workspace. It allows users to filter alerts by date using all dates, specific date ranges, or predefined relative date ranges. Additionally, users can filter alerts by specific customer IDs and control the number of alerts returned. This node is useful for MSPs or administrators who need to aggregate and analyze alerts across various workloads and timeframes for monitoring and reporting purposes.

Use Case Examples

  1. An MSP wants to retrieve all endpoint and Microsoft 365 alerts from the last 30 days to monitor security incidents.
  2. A security analyst needs to fetch alerts for specific customers within a defined date range to investigate potential threats.
  3. An administrator wants to get all unified alerts from enterprise workloads and Google Workspace for the current month to generate a monthly security report.

Properties

Name Meaning
Include Workloads Select which workloads to fetch alerts from, such as Endpoints, Enterprise Workloads, Microsoft 365, and Google Workspace.
Date Selection Method Choose whether to filter alerts by all dates, specific dates, or a relative date range.
Start Date Start of the date range for alert retrieval, required if 'Specific Dates' is selected.
End Date End of the date range for alert retrieval, required if 'Specific Dates' is selected.
Date Range Predefined relative date range for alert retrieval, required if 'Relative Date Range' is selected.
Filter by Customers Whether to restrict alerts to specific customer IDs.
Customer IDs Customers to include in the alert feed, required if filtering by customers is enabled.
Return All Whether to return all alerts or limit the number of alerts returned.
Limit Maximum number of alerts to return across all workloads, used if 'Return All' is false.
Wrap Output Items When enabled, wraps all output items into a single item containing an array to prevent the next node from executing multiple times.
Wrapper Property Name The property name to use for the wrapped array of items in the output, default is 'items'.

Output

JSON

  • alertId - Unique identifier of the alert.
  • alertType - Type or category of the alert.
  • severity - Severity level of the alert.
  • workload - The workload source of the alert (e.g., Endpoints, Microsoft 365).
  • customerId - Identifier of the customer associated with the alert.
  • timestamp - Timestamp when the alert was generated.
  • description - Detailed description of the alert.
  • additionalData - Any additional data related to the alert.

Dependencies

  • Druva MSP API
  • An API key credential for authentication

Troubleshooting

  • Ensure the API key credential is correctly configured and has the necessary permissions to access alert data.
  • If no alerts are returned, verify the selected workloads and date filters to ensure they match available data.
  • When filtering by customers, confirm that valid customer IDs are selected.
  • If the node throws an error about an unimplemented resource, verify that the resource parameter is set to 'alertSummary' and operation to 'getUnifiedAlerts'.
  • Network or API rate limit issues may cause request failures; retry or check API usage limits.

Links

Discussion