WTD: Information on Web Threat Detection API
2 years ago
Originally Published: 2016-10-31
Article Number
000065570
Applies To
RSA Product Set: Web Threat Detection
RSA Product/Service Type: Mitigator
RSA Version/Condition: 5.1
Platform: N/A
Platform (Other): null
O/S Version: null
Product Name: null
Product Description: null
Issue
 Customer questions about the WTD API. 
Resolution
 There are three APIs  for
  1. Forensics
  2. Mitigator 
  3. Login(required for either of above APIs)
Note: Login API has to be used for any access. 

For Data Retrieval use the Forensics API,  so this is historical hourly data messaged in the form of .json reports. 
A. This is for the collection of hourly reports, you need to identify the hour to retrieve the report/file. 
B. 3 types of optional filters: by IP address, called the whitelist; by user name, userlist; and by page, pagelist. 

Mitigator API is used to retrieve  Real time data by accessing the bal.json file (stands for Bad Actor List, the results of triggered alerts) so this is not as comprehensive as the Forensics API 

There is one customer facing document published for our customers from previous version(4.0) and is attached to this article. 
 
Notes
Now after all above is stated, our customers need to be cautioned  that Rabbit MQ solution is being strongly encouraged for streaming data to a third party application, while API is going towards not being supported, and definitely not being updated. (although there has not been a final statement on the continued support of WTD API from our Product Management as of November 2016)

Please create a case with Customer Support if you have further questions.