GET /accounts/{account_id}/data-security/posture/findings

List all security findings that have been identified as being problematic. This will return a list of findings regardless if they have been ignored or not.

Servers

Path parameters

Name Type Required Description
account_id String Yes

Cloudflare account ID for the user making the request.

Query parameters

Name Type Required Description
vendor String No

Filter by vendor

Valid values:

  • "BITBUCKET"
  • "GOOGLE_CLOUD_PLATFORM"
  • "OPENAI"
  • "BOX"
  • "GITHUB"
  • "JIRA"
  • "MICROSOFT_INTERNAL"
  • "DROPBOX"
  • "ANTHROPIC"
  • "CONFLUENCE"
  • "SLACK"
  • "SERVICENOW"
  • "AWS"
  • "MICROSOFT"
  • "SALESFORCE"
  • "GOOGLE_WORKSPACE"
search String No

A search term.

product String No

Filter by product category of the finding

Valid values:

  • "Cloud"
  • "Saas"
observation String No

Filter by observation type of the finding

Valid values:

  • "Insight"
  • "Activity"
  • "Issue"
severity String No

Filter by severity

Valid values:

  • "High"
  • "Low"
  • "Critical"
  • "Medium"
min_affliction_date String No

Filter to view findings that occurred on or after the affliction date. Can be a date-time in ISO 8601 format or an epoch timestamp.

page Integer No

A page number within the paginated result set.

max_affliction_date String No

Filter to view findings that occurred on or before the affliction date. Can be a date-time in ISO 8601 format or an epoch timestamp.

order String No

Which field to use when ordering the findings.

Valid values:

  • "severity"
  • "instance_count"
  • "latest_affliction_date"
  • "finding.name"
  • "integration.name"
direction String No

Direction to order results.

Valid values:

  • "desc"
  • "asc"
ignored Boolean No

Filter for only the ignored findings. Set to false to only see "active" items

per_page Integer No

Number of results to return per page.

type String No

Filter by type of the finding

Valid values:

  • "Posture"
  • "Content"
cursor String No

A cursor for pagination. Obtained from the result_info.cursor field of a previous response.

integration_id String No

Filter by an integration ID

finding_type_ids String No

A comma separated list of UUIDs identifying the finding type(s).

How to start integrating

  1. Add HTTP Task to your workflow definition.
  2. Search for the API you want to integrate with and click on the name.
    • This loads the API reference documentation and prepares the Http request settings.
  3. Click Test request to test run your request to the API and see the API's response.