# Issue Search

POST /easm/issues/search: Searches issues on your assets by state, severity, type, category, asset and dates.

Source: https://docs.deepinfo.com/reference/easm/issue-search/

Last updated: 2026-09-27

---
`POST https://api.deepinfo.com/v1/easm/issues/search`

Searches issues on your assets by state, severity, type, category, asset and dates.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `page_size` | Optional | Min `25`, max `100`. Default `100`. | `25` |
| `page` | Optional | Min `1`, max `800`. Default `1`. | `1` |

## Request Body

| Parameter | Type | Required | Description |
|---|---|---|---|
| `filters` | object | Optional | See [Filtering](#ref-filtering) below |
| `sort` | array | Optional | List of `{field, order}` |

```json
{}
```

## Filtering

Example body:

```json
{
  "filters": {
    "must": [
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "asset.name",
      "order": "desc"
    }
  ]
}
```

See [Getting Started → Search & Filters](/getting-started/search-and-filters/) for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

### Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators: `eq`, `in`, `startswith`, `endswith`, `wildcard`, `fuzzy`, `contains_any`, `contains_all`, `exists`

| Field | Description |
|---|---|
| `asset.id` | The ID of the asset the issue was found on, a 24-character hexadecimal string; it is the same ID that Asset Search returns for that asset. |
| `asset.name` | The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET. |
| `asset.tags` | Your own tags on the asset the issue was found on, as a list of strings (the asset's `tags` in Asset Search). |
| `asset.domain_asset.id` | The ID of the domain asset the issue's asset belongs to; for a domain it is the asset's own ID. `asset.domain_asset` is null when the asset's domain is not one of your assets. |
| `asset.domain_asset.name` | The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets. |
| `type.id` | The ID of the issue type, a 24-character hexadecimal string. Pass it to Issue Type Detail (`GET /easm/issues/types/{issue_type_id}`), or filter on it to list every asset with that issue type. |
| `type.name` | The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it. |
| `type.category.id` | The ID of the issue type's category, a 24-character hexadecimal string, as listed by Issue Categories (`GET /easm/issues/categories/list`). |
| `type.category.name` | The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`. |

Operators: `eq`, `in`, `exists`

| Field | Description |
|---|---|
| `asset.type` | The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website). |
| `state` | The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set. |
| `severity` | The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology. |
| `type.severity` | The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it. |

Operators: `eq`, `in`, `gte`, `lte`, `exists`

| Field | Description |
|---|---|
| `first_seen_date` | When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`. |
| `last_seen_date` | When the issue was most recently detected on the asset, in ISO 8601 UTC. |
| `last_check_date` | When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`. |

Operators: `eq`, `in`

| Field | Description |
|---|---|
| `id` | The issue's ID, a 24-character hexadecimal string. Pass it to Issue Detail (`GET /easm/issues/{issue_id}`), or filter on it with `in` to select exact issues. |

### Sortable Fields

| Field | Description |
|---|---|
| `asset.name` | The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset `host:port`. The Issue List shows it as ASSET. |
| `asset.type` | The type of the asset the issue was found on: `domain`, `subdomain`, `ip` or `website` (shown as Domain, Subdomain, IP Address and Website). |
| `asset.domain_asset.name` | The name of the domain asset the issue's asset belongs to, such as `acme.example` for `www.acme.example`; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets. |
| `state` | The issue's state: `newly_detected`, `unresolved` and `reappeared` are active states set by the platform; `not_applicable` and `verified_resolved` are inactive states set by the platform, and `ignored`, `risk_accepted`, `marked_as_resolved` and `marked_as_false_positive` are inactive states you set. |
| `severity` | The severity of this issue: `Critical`, `High`, `Medium`, `Low` or `Information`; the Issue List severity tabs filter on it. It usually matches `type.severity` but can be higher, as seen on some issues about vulnerabilities detected on a technology. |
| `type.name` | The name of the issue type, for example `Missing SPF Record` or `SSL/TLS Not Implemented`; the Issue List's SEARCH box matches it. |
| `type.severity` | The severity of the issue type: `Critical`, `High`, `Medium`, `Low` or `Information`. Each issue also has its own `severity`, which usually matches it. |
| `type.category.name` | The name of the issue type's category, such as `DNS`, `SSL/TLS`, `Web Application`, `Domain/Whois`, `Network` or `Database Server`. |
| `first_seen_date` | When the issue was first detected on the asset, in ISO 8601 UTC (for example `2025-06-01T08:00:00Z`). The platform's ACTIVE DAYS runs from this date to `last_seen_date`. |
| `last_seen_date` | When the issue was most recently detected on the asset, in ISO 8601 UTC. |
| `last_check_date` | When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals `last_seen_date`. |

## Response Fields

| Field | Type | Description |
|---|---|---|
| `page` | integer |  |
| `page_size` | integer |  |
| `result_count` | integer |  |
| `results` | array of object |  |
| `results[].id` | string |  |
| `results[].asset` | object |  |
| `results[].state` | string | One of `newly_detected`, `reappeared`, `unresolved`, `marked_as_resolved`, `risk_accepted`, `ignored`, `marked_as_false_positive`, `not_applicable`, `verified_resolved` |
| `results[].severity` | string | One of `Critical`, `High`, `Medium`, `Low`, `Information` |
| `results[].first_seen_date` | string | date-time |
| `results[].last_seen_date` | string | date-time |
| `results[].last_check_date` | string | date-time |
| `results[].type` | object |  |

Paginated. See [Getting Started → Pagination](/getting-started/pagination/).

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `page` | number |
| `page_size` | number |
| `result_count` | number |
| `results` | array<object> |
| `results[].id` | string |
| `results[].asset` | object |
| `results[].asset.id` | string |
| `results[].asset.name` | string |
| `results[].asset.name_unicode` | string |
| `results[].asset.type` | string |
| `results[].asset.tags` | array |
| `results[].asset.domain_asset` | object \| null |
| `results[].asset.domain_asset.id` | string |
| `results[].asset.domain_asset.name` | string |
| `results[].asset.domain_asset.name_unicode` | string |
| `results[].state` | string |
| `results[].severity` | string |
| `results[].first_seen_date` | string |
| `results[].last_seen_date` | string |
| `results[].last_check_date` | string |
| `results[].type` | object |
| `results[].type.id` | string |
| `results[].type.name` | string |
| `results[].type.severity` | string |
| `results[].type.category` | object |
| `results[].type.category.id` | string |
| `results[].type.category.name` | string |

## Examples

### 200 · OK

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/issues/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 21,
  "results": [
    {
      "id": "000000000000000e8a020001",
      "asset": {
        "id": "000000000000000ea4f90001",
        "name": "acme.example",
        "name_unicode": "acme.example",
        "type": "domain",
        "tags": [],
        "domain_asset": {
          "id": "000000000000000e915c0001",
          "name": "acme.example",
          "name_unicode": "acme.example"
        }
      },
      "state": "reappeared",
      "severity": "Critical",
      "first_seen_date": "2025-06-01T08:00:00Z",
      "last_seen_date": "2025-07-31T08:00:00Z",
      "last_check_date": "2025-07-31T08:00:00Z",
      "type": {
        "id": "000000000000000e16fe0001",
        "name": "Expired SSL certificate",
        "severity": "Critical",
        "category": {
          "id": "000000000000000e1c170001",
          "name": "SSL/TLS"
        }
      }
    },
    {
      "id": "000000000000000e8a020002",
      "asset": {
        "id": "000000000000000ea4f90002",
        "name": "fernhill.example",
        "name_unicode": "fernhill.example",
        "type": "domain",
        "tags": [],
        "domain_asset": null
      },
      "state": "reappeared",
      "severity": "High",
      "first_seen_date": "2025-05-25T08:00:00Z",
      "last_seen_date": "2025-07-24T08:00:00Z",
      "last_check_date": "2025-07-24T08:00:00Z",
      "type": {
        "id": "000000000000000e16fe0002",
        "name": "Missing DMARC record",
        "severity": "High",
        "category": {
          "id": "000000000000000e1c170002",
          "name": "DNS"
        }
      }
    }
  ]
}
```

### 400 · Invalid Parameter (invalid page=0)

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/issues/search?page=0' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

`Content-Type: application/json` · `deepinfo-request-id: 00000000-0000-4000-8000-0000356d0001`

```json
{
  "code": 10400,
  "parameters": [
    {
      "param": "page",
      "details": [
        "Ensure this value is greater than or equal to 1."
      ]
    }
  ],
  "solution": "https://docs.deepinfo.com/reference/"
}
```

### Request Template

The request only: a request template has no response.

```bash
curl -X POST 'https://api.deepinfo.com/v1/easm/issues/search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "asset.id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "asset.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "asset.tags",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "asset.domain_asset.id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "asset.domain_asset.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "type.id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "type.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "type.category.id",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "type.category.name",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "asset.type",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "state",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "severity",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "type.severity",
        "type": "eq",
        "value": "<value>"
      },
      {
        "name": "first_seen_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "last_seen_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "last_check_date",
        "type": "eq",
        "value": "<date-time>"
      },
      {
        "name": "id",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "asset.name",
      "order": "desc"
    }
  ]
}'
```
