Skip to main content
Panther Knowledge Base

Can I query Panther’s data lake for alerts using their alert status, or assignee?

QUESTION

Can I query Panther’s data lake for alerts using their alert status, assignee, or any other similar metadata?

ANSWER

You can do this via Panther's API. For API query examples see the Data Lake API documentation

While we store rule matches in the data lake (i.e., log events that matched a rule), the actual alerts and their metadata are stored in DynamoDB. 

 

  • Was this article helpful?