Is there any way to extract "Framework Mapping" from a specific detection/alert using API? I see this information is available in
p_rule_reports for an alert.
The following steps should be taken:
- Use the
mutation IssueDataLakeQueryto issue the SQL query (as explained in the documentation).
- Run a second API call, to retrieve the results using the ID in the
QueryResultobtained from the mutation.