> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ListAlerts

> Lists the alerts that fired for this tenant, most recently triggered
first. The trigger time window is always closed and defaults to the last
hour.



## OpenAPI

````yaml openapi/api_v1_data_openapi3_DOCUMENTATION_ONLY.json POST /api/v1/data/alerts
openapi: 3.0.3
info:
  description: |

    The Data API provides HTTP/JSON REST endpoints for reading and writing data
    to the Chronosphere system.

    Use this link to download the raw Swagger specification:
    <a href="/api/v1/data/swagger.json">/api/v1/data/swagger.json</a>
  title: Data V1 API
  version: v1
servers:
  - url: https://{tenant}.chronosphere.io
    variables:
      tenant:
        default: tenant
        description: tenant ID assigned by the service provider
security:
  - ApiKeyAuth: []
tags:
  - name: DataV1
paths:
  /api/v1/data/alerts:
    post:
      tags:
        - DataV1
      description: |-
        Lists the alerts that fired for this tenant, most recently triggered
        first. The trigger time window is always closed and defaults to the last
        hour.
      operationId: ListAlerts
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/datav1ListAlertsRequest'
        required: true
        x-originalParamName: body
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/datav1ListAlertsResponse'
          description: A successful response.
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/googlerpcStatus'
          description: An unexpected error response.
components:
  schemas:
    datav1ListAlertsRequest:
      properties:
        filter:
          allOf:
            - $ref: '#/components/schemas/datav1AlertsFilter'
          description: >-
            Which alerts to return. An omitted filter, an empty filter and a
            filter

            that sets neither `trigger_time_range` nor `active_time_range` are
            all

            treated alike: the default one hour trigger-time window applies.
            Every

            other unset field places no constraint, so an empty filter returns
            every

            alert in that window.
        page:
          $ref: '#/components/schemas/configv1PageParams'
        sort_order:
          allOf:
            - $ref: '#/components/schemas/ListAlertsRequestSortOrder'
          description: The order alerts are returned in. Defaults to `TRIGGERED_DESC`.
      type: object
    datav1ListAlertsResponse:
      properties:
        alerts:
          description: The alerts on this page, in the requested sort order.
          items:
            $ref: '#/components/schemas/datav1Alert'
          type: array
        page:
          $ref: '#/components/schemas/configv1PageResult'
        total_count:
          description: The number of alerts matching the filter across all pages.
          format: int64
          type: string
      type: object
    googlerpcStatus:
      properties:
        code:
          format: int32
          type: integer
        details:
          items:
            $ref: '#/components/schemas/protobufAny'
          type: array
        message:
          type: string
      type: object
    datav1AlertsFilter:
      description: >-
        The set of alerts to return. Filters of different kinds are combined
        with

        AND: an alert is returned only if it satisfies every filter that is set.


        The search filters (`monitor_slugs`, `monitor_name_contains`,
        `slo_slugs`,

        `slo_name_contains` and `alert_title_contains`) are the one exception.

        They are OR'ed with each other into a single search clause, so an alert

        matches the search as soon as it matches any one of them: setting

        `monitor_slugs` and `alert_title_contains` together returns the alerts

        matching either, not only the alerts matching both. That clause is then

        AND'ed with every filter outside the group, so `severity` combined with
        a

        search term still requires both to hold.


        `notifier_slugs` and `external_connections` form a second such group:
        they

        are OR'ed with each other into one delivery clause, which is then AND'ed
        with

        everything else.
      properties:
        active_time_range:
          allOf:
            - $ref: '#/components/schemas/datav1TimeRange'
          description: >-
            Return only alerts that were firing at some point during this
            window,

            whether or not they were triggered inside it. Defaults and maximum
            span

            are the same as for `trigger_time_range`.


            Mutually exclusive with `trigger_time_range`.
        alert_ids:
          description: Return only the alerts with these IDs.
          items:
            type: string
          type: array
        alert_title_contains:
          description: >-
            Match alerts whose title contains this string, case-insensitively.
            Only

            the title is matched, never the name or slug of the monitor or SLO
            that

            raised the alert. This is one of the OR'ed search filters, so
            setting it

            widens the result set rather than narrowing it: an alert matches the

            search as soon as it matches any one of those filters. See

            `AlertsFilter` for the full list.
          type: string
        external_connections:
          description: >-
            Return only alerts a notification was attempted through one of these

            (external connection, destination identity) pairs for. Failed sends
            match

            too, exactly as for `notifier_slugs`, and setting both OR's the two
            lists

            together.


            The pair is matched whole. `destination_identity` is compared
            exactly, so

            leaving it empty matches only destinations stored without one
            (PagerDuty,

            OpsGenie, webhook) rather than every identity on the connection.
          items:
            $ref: '#/components/schemas/datav1ExternalConnection'
          type: array
        firing_status:
          allOf:
            - $ref: '#/components/schemas/datav1FiringStatus'
          description: >-
            Return only alerts that are currently firing, or only alerts that
            have

            resolved. Unset returns both.
        label_filters:
          description: >-
            Each LabelFilter is one AND clause; the clauses are OR'ed together.
            An

            alert is returned if it satisfies at least one of them.
          items:
            $ref: '#/components/schemas/datav1LabelFilter'
          type: array
        monitor_name_contains:
          description: >-
            Match alerts raised by monitors whose name or slug contains this
            string,

            case-insensitively. This is one of the OR'ed search filters, so
            setting

            it widens the result set rather than narrowing it: an alert matches
            the

            search as soon as it matches any one of those filters. See

            `AlertsFilter` for the full list.
          type: string
        monitor_slugs:
          description: >-
            Match alerts raised by monitors with these slugs. This is one of the

            OR'ed search filters, so setting it widens the result set rather
            than

            narrowing it: an alert matches the search as soon as it matches any
            one

            of those filters. See `AlertsFilter` for the full list.
          items:
            type: string
          type: array
        mute_status:
          allOf:
            - $ref: '#/components/schemas/datav1MuteStatus'
          description: >-
            Return only alerts whose notifications are muted, or only alerts
            whose

            notifications are not muted. Unset returns both.
        notifier_slugs:
          description: >-
            Return only alerts a notification was attempted against one of these

            notifiers for. A send that failed still matches: the question this
            answers

            is "which alerts tried to reach me here", not "which reached me".


            This is OR'ed with `external_connections` rather than AND'ed with
            it:

            setting both returns alerts matching either list, because notifiers
            and

            external connections are two spellings of the same idea. The
            combined

            delivery filter is then AND'ed with every other filter.
          items:
            type: string
          type: array
        severity:
          allOf:
            - $ref: '#/components/schemas/datav1Severity'
          description: Return only alerts of this severity. Unset returns all severities.
        slo_name_contains:
          description: >-
            Match alerts raised by SLOs whose name or slug contains this string,

            case-insensitively. This is one of the OR'ed search filters, so
            setting

            it widens the result set rather than narrowing it: an alert matches
            the

            search as soon as it matches any one of those filters. See

            `AlertsFilter` for the full list.
          type: string
        slo_slugs:
          description: >-
            Match alerts raised by SLOs with these slugs. This is one of the
            OR'ed

            search filters, so setting it widens the result set rather than

            narrowing it: an alert matches the search as soon as it matches any
            one

            of those filters. See `AlertsFilter` for the full list.
          items:
            type: string
          type: array
        source_collection_slugs:
          description: |-
            Return only alerts whose monitor or SLO belongs to one of these
            collections.
          items:
            type: string
          type: array
        source_team_slugs:
          description: >-
            Return only alerts owned by one of these teams. The owning team is

            recorded when the alert triggers, so re-assigning a collection to a

            different team does not change the team on alerts that already
            fired.

            Alerts that triggered before this API recorded an owning team match
            no

            team.
          items:
            type: string
          type: array
        source_type:
          allOf:
            - $ref: '#/components/schemas/datav1SourceType'
          description: >-
            Return only alerts raised by this kind of source. Unset returns
            both.
        trigger_time_range:
          allOf:
            - $ref: '#/components/schemas/datav1TimeRange'
          description: >-
            Return only alerts that were triggered inside this window. The
            window is

            always closed: if `end` is not set it defaults to now, and if
            `start` is

            not set it defaults to one hour before `end`. Leaving the whole
            field

            unset is the same as setting it with neither bound, so the last hour
            is

            the window unless `active_time_range` is set instead. Requests whose

            window is wider than the maximum supported span are rejected rather
            than

            truncated, so a response is never a silently partial answer.


            Mutually exclusive with `active_time_range`.
      type: object
    configv1PageParams:
      properties:
        max_size:
          description: >-
            Sets the preferred number of items to return per page. If set to
            `0`, the

            server will use its default value. Regardless of the value
            specified, clients

            must never assume how many items will be returned.
          format: int64
          type: integer
        token:
          description: >-
            An opaque page token that identifies which page the client should
            request.

            An empty value indicates the first page.
          type: string
      type: object
    ListAlertsRequestSortOrder:
      description: The order alerts are returned in, by the time they triggered.
      enum:
        - TRIGGERED_DESC
        - TRIGGERED_ASC
      type: string
    datav1Alert:
      description: >-
        A single alert instance: one signal crossing one monitor or SLO
        threshold,

        from the moment it triggered until it resolved.
      properties:
        alert_id:
          description: Unique identifier for the alert.
          type: string
        alert_title:
          description: The title of the alert, as rendered when it fired.
          type: string
        collection_slug:
          description: The slug of the collection the monitor or SLO belongs to.
          type: string
        external_connections:
          description: >-
            The (external connection, destination identity) pairs a notification
            was

            attempted through for this alert, including sends that failed. Empty
            for an

            alert that was never notified.
          items:
            $ref: '#/components/schemas/datav1ExternalConnection'
          type: array
        firing_status:
          allOf:
            - $ref: '#/components/schemas/datav1FiringStatus'
          description: Whether the alert is still firing or has resolved.
        monitor_labels:
          additionalProperties:
            type: string
          description: The labels of the monitor or SLO that raised the alert.
          type: object
        monitor_name:
          description: >-
            The name of the monitor that raised the alert. Empty for an SLO
            alert.
          type: string
        monitor_slug:
          description: >-
            The slug of the monitor that raised the alert. Empty for an SLO
            alert.
          type: string
        mute_status:
          allOf:
            - $ref: '#/components/schemas/datav1MuteStatus'
          description: >-
            Whether notifications for the alert are currently muted. A resolved
            alert

            is always reported as `NOT_MUTED`.
        notification_policy_slug:
          description: The slug of the notification policy the alert was routed through.
          type: string
        notifier_slugs:
          description: >-
            The notifiers a notification was attempted against for this alert,

            including sends that failed. Empty for an alert that was never
            notified.
          items:
            type: string
          type: array
        resolved_at:
          description: >-
            When the alert stopped firing. Unset while the alert is still
            firing.
          format: date-time
          type: string
        severity:
          allOf:
            - $ref: '#/components/schemas/datav1Severity'
          description: The severity the alert fired at.
        signal:
          additionalProperties:
            type: string
          description: The labels of the signal that fired.
          type: object
        slo_name:
          description: >-
            The name of the SLO that raised the alert. Empty for a monitor
            alert.
          type: string
        slo_slug:
          description: >-
            The slug of the SLO that raised the alert. Empty for a monitor
            alert.
          type: string
        triggered_at:
          description: When the alert started firing.
          format: date-time
          type: string
      type: object
    configv1PageResult:
      properties:
        next_token:
          description: |-
            An opaque page token that identifies the next page of items that the
            client should request. An empty value indicates that there are no
            more items to return.
          type: string
      type: object
    protobufAny:
      additionalProperties: {}
      properties:
        '@type':
          type: string
      type: object
    datav1TimeRange:
      description: |-
        A closed time interval. Both bounds are required unless the field
        documents a default for the one that is missing.
      properties:
        end:
          description: The inclusive end of the interval.
          format: date-time
          type: string
        start:
          description: The inclusive start of the interval.
          format: date-time
          type: string
      type: object
    datav1ExternalConnection:
      description: >-
        An (external connection, destination identity) pair a notification was
        sent

        through. Used both to filter alerts and to report what an alert was
        notified

        through.
      properties:
        destination_identity:
          description: >-
            Identity within the connection, such as a Slack channel or an email

            address. Empty for connection types that have none (PagerDuty,
            OpsGenie,

            webhook).
          type: string
        slug:
          description: Slug of the external connection. Required when used as a filter.
          type: string
      type: object
    datav1FiringStatus:
      description: Whether an alert is currently firing or has resolved.
      enum:
        - RESOLVED
        - FIRING
      type: string
    datav1LabelFilter:
      description: A set of label matchers evaluated together as a single AND clause.
      properties:
        label_matchers:
          description: |-
            The matchers that make up this clause. An alert must satisfy all of
            them. A filter with no matchers is ignored rather than matching
            everything.
          items:
            $ref: '#/components/schemas/LabelFilterLabelMatcher'
          type: array
        match_strategy:
          allOf:
            - $ref: '#/components/schemas/LabelFilterMatchStrategy'
          description: >-
            How closely an alert's labels must correspond to `label_matchers`.

            Defaults to `SUBSET_MATCH` when unset, whether or not
            `label_matchers`

            is populated. Applied per target: a filter that only names monitor

            labels places no constraint on the alert's signal labels under
            either

            strategy.
      type: object
    datav1MuteStatus:
      description: Whether notifications for an alert are currently muted.
      enum:
        - MUTED
        - NOT_MUTED
      type: string
    datav1Severity:
      description: The severity an alert fired at.
      enum:
        - WARN
        - CRITICAL
      type: string
    datav1SourceType:
      description: Whether an alert was raised by a monitor or by an SLO.
      enum:
        - MONITOR
        - SLO
      type: string
    LabelFilterLabelMatcher:
      description: One matcher, and which of the alert's two label sets it applies to.
      properties:
        filter_target:
          allOf:
            - $ref: '#/components/schemas/LabelMatcherFilterTarget'
          description: Which of the alert's label sets this matcher applies to. Required.
        matcher:
          allOf:
            - $ref: '#/components/schemas/commonPromQLMatcher'
          description: The label name, value and comparison to apply.
      type: object
    LabelFilterMatchStrategy:
      description: |-
        How closely an alert's labels must correspond to the matchers.

         - SUBSET_MATCH: EQUAL matchers require the labels to contain all the given labels, but
        the alert may carry more. NOT_EQUAL excludes an alert when the labels
        match any matcher.
         - EXACT_MATCH: EQUAL matchers require exactly the provided labels, no more or less.
        NOT_EQUAL excludes an alert only when every NOT_EQUAL matcher applies.
      enum:
        - SUBSET_MATCH
        - EXACT_MATCH
      type: string
    LabelMatcherFilterTarget:
      description: |-
        The label set a matcher reads. An alert carries the labels of the
        signal that fired (`SIGNAL`) and the labels of the monitor or SLO
        that raised it (`MONITOR`); the two are matched independently.
      enum:
        - MONITOR
        - SIGNAL
      type: string
    commonPromQLMatcher:
      properties:
        name:
          description: Prometheus label name for the matcher
          type: string
        type:
          allOf:
            - $ref: '#/components/schemas/commonPromQLMatcherType'
          description: The type of match to be performed
        value:
          description: Prometheus label value for the matcher
          type: string
      type: object
    commonPromQLMatcherType:
      enum:
        - MatchEqual
        - MatchRegexp
        - MatchNotEqual
        - MatchNotRegexp
      type: string
  securitySchemes:
    ApiKeyAuth:
      description: Chronosphere API token
      in: header
      name: API-Token
      type: apiKey

````

## Related topics

- [Alert details](/investigate/alerts/alert-details.md)
- [Manage service level objectives](/investigate/alerts/manage-slos.md)
- [Monitor details](/investigate/alerts/monitors/monitor-details.md)
- [ListNotificationPolicies](/tooling/api-info/definition/operations/ListNotificationPolicies.md)
- [ListMonitors](/tooling/api-info/definition/operations/ListMonitors.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.