Search
curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"findingId": "<string>",
"pageSize": 123,
"pageToken": "<string>"
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences"
payload = {
"findingId": "<string>",
"pageSize": 123,
"pageToken": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({findingId: '<string>', pageSize: 123, pageToken: '<string>'})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'findingId' => '<string>',
'pageSize' => 123,
'pageToken' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences"
payload := strings.NewReader("{\n \"findingId\": \"<string>\",\n \"pageSize\": 123,\n \"pageToken\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"findingId\": \"<string>\",\n \"pageSize\": 123,\n \"pageToken\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"findingId\": \"<string>\",\n \"pageSize\": 123,\n \"pageToken\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"list": [
{
"deviceId": "<string>",
"firstSeenAt": "2023-11-07T05:31:56Z",
"harnessKind": "<string>",
"lastSeenAt": "2023-11-07T05:31:56Z",
"userId": "<string>"
}
],
"nextPageToken": "<string>"
}Findings
Search
Search returns the ungoverned, enabled observation rows behind one shadow-mcp finding — the same present-set that produced its evidence counts. Authorized as VIEWER — the same role required to read the finding itself.
POST
/
api
/
v1
/
search
/
shadow_mcp_occurrences
Search
curl --request POST \
--url https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"findingId": "<string>",
"pageSize": 123,
"pageToken": "<string>"
}
'import requests
url = "https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences"
payload = {
"findingId": "<string>",
"pageSize": 123,
"pageToken": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({findingId: '<string>', pageSize: 123, pageToken: '<string>'})
};
fetch('https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'findingId' => '<string>',
'pageSize' => 123,
'pageToken' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences"
payload := strings.NewReader("{\n \"findingId\": \"<string>\",\n \"pageSize\": 123,\n \"pageToken\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"findingId\": \"<string>\",\n \"pageSize\": 123,\n \"pageToken\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{tenantDomain}.conductor.one/api/v1/search/shadow_mcp_occurrences")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"findingId\": \"<string>\",\n \"pageSize\": 123,\n \"pageToken\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"list": [
{
"deviceId": "<string>",
"firstSeenAt": "2023-11-07T05:31:56Z",
"harnessKind": "<string>",
"lastSeenAt": "2023-11-07T05:31:56Z",
"userId": "<string>"
}
],
"nextPageToken": "<string>"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
This API uses OAuth2 with the Client Credential flow. Client Credentials must be sent in the BODY, not the headers. For an example of how to implement this, refer to the c1TokenSource.Token() function.
Body
application/json
Was this page helpful?