GET /service/api/console/gsm/{gsmKey}/sites/{siteId}/threathistory
?startDate={startDate}
&endDate={endDate}
&returnedInfo={returnedInfo}
&pageSize={pageSize}
&pageNr={pageNr}
Gets threat history information for endpoints on a GSM site.
Request Information
URI Parameters
| Name | Description | Type | Additional Information |
|---|---|---|---|
| gsmKey |
The GSM console keycode. |
string |
Required |
| siteId |
The site identifier. |
string |
Required |
| startDate |
If specified, returns all threat history records after (or at) the given date. If omitted, defaults to 'endDate' minus 24 hours. |
date |
None. |
| endDate |
If specified, returns all threat history records before (or at) the given date. If omitted, defaults to the current date and time. |
date |
None. |
| returnedInfo |
A comma separated list of classes of information to be provided in response data. Currently only the "ExtendedInfo" class is supported as a value. If omitted, general threat record information is returned only. |
string |
None. |
| pageSize |
Specifies the number of records to return. |
integer |
Default value is 50 |
| pageNr |
Specifies the page number. Can be used to retrieve the next batch of records. |
integer |
Default value is 1 |
URI Sample(s)
|
GET
|
https://unityapi.webrootcloudav.com/service/api/console/gsm/3515-3EC8-3018-4DAB-A776/sites/3c5b599c-f244-4c7e-a78b-b3e9f252fac8/threathistory
|
|
GET
|
https://unityapi.webrootcloudav.com/service/api/console/gsm/3515-3EC8-3018-4DAB-A776/sites/3c5b599c-f244-4c7e-a78b-b3e9f252fac8/threathistory?returnedInfo=ExtendedInfo
|
|
GET
|
https://unityapi.webrootcloudav.com/service/api/console/gsm/3515-3EC8-3018-4DAB-A776/sites/3c5b599c-f244-4c7e-a78b-b3e9f252fac8/threathistory?startDate=2018-09-01&endDate=2018-09-30&pageSize=100&pageNr=3
|
Body Parameters
None.
Response Information
Resource Description
Information about matching threat history records.
GetThreatHistoryResponseModel| Name | Description | Type | Additional Information |
|---|---|---|---|
| MoreAvailable |
Value indicating whether more records are available in the queried time window. Increment the page number in the query to obtain additional threat history records. |
boolean |
None. |
| PageNr |
The number of the page that was requested. |
integer |
None. |
| PageSize |
The size of the page that was requested. |
integer |
None. |
| StartDate |
Start date for returned records. Threat history entries after (or at) this date are contained in the response. |
date |
None. |
| EndDate |
End date for returned records. Threat history entries before (or at) this date are contained in the response. |
date |
None. |
| ThreatRecords |
List of threat history records. |
Collection of GetThreatHistoryResponseModel_Record |
None. |
Sample Response
{
"MoreAvailable": false,
"PageNr": 1,
"PageSize": 50,
"StartDate": "2026-03-12T20:12:34.7051057Z",
"EndDate": "2026-06-12T20:12:34.7051057Z",
"ThreatRecords": [
{
"EndpointId": "49159a4c-0ae4-4877-a20c-f11c437b070b",
"MachineId": "9C5ADAE827AB47B496DE2F7F1E6A5ADC:::AB5B185637B44CA79CC7AF17A3E53F43:::AB5B185637B44CA79CC7AF17A3E53F43",
"HostName": "MyComputer1",
"FileName": "eicar.com",
"PathName": "?:\\users\\user1\\desktop",
"MalwareGroup": "Anti-Malware Testfile",
"FirstSeen": "2026-05-30T20:12:34.7051057Z",
"LastSeen": "2026-06-10T20:12:34.7051057Z",
"ExtendedInfo": {
"DwellTime": 225,
"FileMD5": "53909FBE9B594A1889CA9487A49E2583",
"FileSize": 68,
"UserName": "User1",
"IPAddress": "95.60.206.85",
"Determination": "B",
"FileVendor": "",
"FileProduct": "",
"FileVersion": ""
}
},
{
"EndpointId": "16876318-a506-419e-9cb2-45972b4fcde8",
"MachineId": "9EB0BA4969034C69A05D090C821CC2C0:::EC86656B4A6B40188169F61288A59DE8:::EC86656B4A6B40188169F61288A59DE8",
"HostName": "MyComputer2",
"FileName": "eicar.com",
"PathName": "?:\\users\\user2\\desktop",
"MalwareGroup": "Anti-Malware Testfile",
"FirstSeen": "2026-05-30T20:12:34.7051057Z",
"LastSeen": "2026-06-10T20:12:34.7051057Z",
"ExtendedInfo": {
"DwellTime": 9,
"FileMD5": "FCDBE133064B477E8F051315F820C152",
"FileSize": 68,
"UserName": "User2",
"IPAddress": "95.170.0.120",
"Determination": "B",
"FileVendor": "",
"FileProduct": "",
"FileVersion": ""
}
}
]
}
<GetThreatHistoryResponseModel xmlns:i="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://schemas.datacontract.org/2004/07/Webroot.UnityAPI.ServiceExtension.Console.Models">
<EndDate>2026-06-12T20:12:34.7051057Z</EndDate>
<MoreAvailable>false</MoreAvailable>
<PageNr>1</PageNr>
<PageSize>50</PageSize>
<StartDate>2026-03-12T20:12:34.7051057Z</StartDate>
<ThreatRecords>
<GetThreatHistoryResponseModel_Record>
<EndpointId>49159a4c-0ae4-4877-a20c-f11c437b070b</EndpointId>
<ExtendedInfo>
<Determination>B</Determination>
<DwellTime>225</DwellTime>
<FileMD5>53909FBE9B594A1889CA9487A49E2583</FileMD5>
<FileProduct></FileProduct>
<FileSize>68</FileSize>
<FileVendor></FileVendor>
<FileVersion></FileVersion>
<IPAddress>95.60.206.85</IPAddress>
<UserName>User1</UserName>
</ExtendedInfo>
<FileName>eicar.com</FileName>
<FirstSeen>2026-05-30T20:12:34.7051057Z</FirstSeen>
<HostName>MyComputer1</HostName>
<LastSeen>2026-06-10T20:12:34.7051057Z</LastSeen>
<MachineId>9C5ADAE827AB47B496DE2F7F1E6A5ADC:::AB5B185637B44CA79CC7AF17A3E53F43:::AB5B185637B44CA79CC7AF17A3E53F43</MachineId>
<MalwareGroup>Anti-Malware Testfile</MalwareGroup>
<PathName>?:\users\user1\desktop</PathName>
</GetThreatHistoryResponseModel_Record>
<GetThreatHistoryResponseModel_Record>
<EndpointId>16876318-a506-419e-9cb2-45972b4fcde8</EndpointId>
<ExtendedInfo>
<Determination>B</Determination>
<DwellTime>9</DwellTime>
<FileMD5>FCDBE133064B477E8F051315F820C152</FileMD5>
<FileProduct></FileProduct>
<FileSize>68</FileSize>
<FileVendor></FileVendor>
<FileVersion></FileVersion>
<IPAddress>95.170.0.120</IPAddress>
<UserName>User2</UserName>
</ExtendedInfo>
<FileName>eicar.com</FileName>
<FirstSeen>2026-05-30T20:12:34.7051057Z</FirstSeen>
<HostName>MyComputer2</HostName>
<LastSeen>2026-06-10T20:12:34.7051057Z</LastSeen>
<MachineId>9EB0BA4969034C69A05D090C821CC2C0:::EC86656B4A6B40188169F61288A59DE8:::EC86656B4A6B40188169F61288A59DE8</MachineId>
<MalwareGroup>Anti-Malware Testfile</MalwareGroup>
<PathName>?:\users\user2\desktop</PathName>
</GetThreatHistoryResponseModel_Record>
</ThreatRecords>
</GetThreatHistoryResponseModel>