Hi Karl,
thanx for answer me,
i haven't investigated more about response body null,
i guess i was trying to use a wrong API for my objective, i mean to decode IP address into network name according with my network hierarchy.
i think to have reached a solution using "siem" API group instead of "functions"
this is working form me:
curl -S -X GET -k -H 'SEC: ********-****-****-****-************' -H 'Range: items=0-49' -H 'Version: 19.0' -H 'Accept: application/json' 'https://siem.puntozeroscarl.it/api/siem/source_addresses?fields=source_ip%2Cnetwork&filter=source_ip%3D%2710.151.103.1%27'
BR
Giancarlo
------------------------------
Giancarlo Cecchetti
------------------------------
Original Message:
Sent: Fri June 16, 2023 09:45 AM
From: Karl Jaeger
Subject: Using networkname() aql function by REST API
Giancarlo
so far so good! You are using API already by GUI via try it out. I am just a bit confused by response body is null.
this should show the syntax needed .
when using curl from CLI on other hosts other dependency may occur depending on from where issuing your command.
tip = try in QRadar CLI first.
pls copy GUI and CLI output for further analysis'.
BR
Karl
------------------------------
[Karl] [Jaeger] [Business Partner]
[QRadar Specialist]
[pro4bizz]
[Karlsruhe] [Germany]
[4972190981722]
------------------------------