Perhaps this is a discussion in the API forums? I'm just wondering if this is even possible to perform. Right now Harmony Logs are forwarded to on-prem SIEM. An alert is triggered within the SIEM if a Forensic event is triggered within harmony endpoint. Would it be possible to programmatically retrieve the forensic report that you can download when navigating the web gui for endpoint and downloading the report from the log event?
I've been exploring the API functionality, and have not been remotely successful with it. So before I spend hours trying to make this work, I thought I'd see if any experts were aware if this data is even accessible outside of the harmony portal?
Thanks!