Issue Search
https://api.deepinfo.com/v1/easm/issues/searchSearches issues on your assets by state, severity, type, category, asset and dates.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
page_ | Optional | Min 25, max 100. Default 100.Example 25 |
page | Optional | Min 1, max 800. Default 1.Example 1 |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "state",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "asset.name",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith wildcard fuzzy contains_ contains_ exists
| Field | Description |
|---|---|
asset. | The ID of the asset the issue was found on, a 24-character hexadecimal string; it is the same ID that Asset Search returns for that asset. |
asset. | The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset host:port. The Issue List shows it as ASSET. |
asset. | Your own tags on the asset the issue was found on, as a list of strings (the asset's tags in Asset Search). |
asset. | The ID of the domain asset the issue's asset belongs to; for a domain it is the asset's own ID. asset.domain_asset is null when the asset's domain is not one of your assets. |
asset. | The name of the domain asset the issue's asset belongs to, such as acme.example for www.acme.example; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets. |
type. | The ID of the issue type, a 24-character hexadecimal string. Pass it to Issue Type Detail (GET /easm/issues/types/{issue_type_id}), or filter on it to list every asset with that issue type. |
type. | The name of the issue type, for example Missing SPF Record or SSL/TLS Not Implemented; the Issue List's SEARCH box matches it. |
type. | The ID of the issue type's category, a 24-character hexadecimal string, as listed by Issue Categories (GET /easm/issues/categories/list). |
type. | The name of the issue type's category, such as DNS, SSL/TLS, Web Application, Domain/Whois, Network or Database Server. |
Operators eq in exists
| Field | Description |
|---|---|
asset. | The type of the asset the issue was found on: domain, subdomain, ip or website (shown as Domain, Subdomain, IP Address and Website). |
state | The issue's state: newly_detected, unresolved and reappeared are active states set by the platform; not_applicable and verified_resolved are inactive states set by the platform, and ignored, risk_accepted, marked_as_resolved and marked_as_false_positive are inactive states you set. |
severity | The severity of this issue: Critical, High, Medium, Low or Information; the Issue List severity tabs filter on it. It usually matches type.severity but can be higher, as seen on some issues about vulnerabilities detected on a technology. |
type. | The severity of the issue type: Critical, High, Medium, Low or Information. Each issue also has its own severity, which usually matches it. |
Operators eq in gte lte exists
| Field | Description |
|---|---|
first_ | When the issue was first detected on the asset, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z). The platform's ACTIVE DAYS runs from this date to last_seen_date. |
last_ | When the issue was most recently detected on the asset, in ISO 8601 UTC. |
last_ | When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals last_seen_date. |
Operators eq in
| Field | Description |
|---|---|
id | The issue's ID, a 24-character hexadecimal string. Pass it to Issue Detail (GET /easm/issues/{issue_id}), or filter on it with in to select exact issues. |
Sortable Fields
| Field | Description |
|---|---|
asset. | The name of the asset the issue was found on: a domain, subdomain or IP address, or for a website asset host:port. The Issue List shows it as ASSET. |
asset. | The type of the asset the issue was found on: domain, subdomain, ip or website (shown as Domain, Subdomain, IP Address and Website). |
asset. | The name of the domain asset the issue's asset belongs to, such as acme.example for www.acme.example; for a domain it is the asset's own name. Null when the asset's domain is not one of your assets. |
state | The issue's state: newly_detected, unresolved and reappeared are active states set by the platform; not_applicable and verified_resolved are inactive states set by the platform, and ignored, risk_accepted, marked_as_resolved and marked_as_false_positive are inactive states you set. |
severity | The severity of this issue: Critical, High, Medium, Low or Information; the Issue List severity tabs filter on it. It usually matches type.severity but can be higher, as seen on some issues about vulnerabilities detected on a technology. |
type. | The name of the issue type, for example Missing SPF Record or SSL/TLS Not Implemented; the Issue List's SEARCH box matches it. |
type. | The severity of the issue type: Critical, High, Medium, Low or Information. Each issue also has its own severity, which usually matches it. |
type. | The name of the issue type's category, such as DNS, SSL/TLS, Web Application, Domain/Whois, Network or Database Server. |
first_ | When the issue was first detected on the asset, in ISO 8601 UTC (for example 2025-06-01T08:00:00Z). The platform's ACTIVE DAYS runs from this date to last_seen_date. |
last_ | When the issue was most recently detected on the asset, in ISO 8601 UTC. |
last_ | When the asset was last checked for this issue, in ISO 8601 UTC; while the issue is still found it equals last_seen_date. |
Response Fields
| Field | Type | Description |
|---|---|---|
page | integer | |
page_ | integer | |
result_ | integer | |
results | array of object | |
results[]. | string | |
results[]. | object | |
results[]. | string | One of newly_detected, reappeared, unresolved, marked_, risk_accepted, ignored, marked_, not_applicable, verified_resolved |
results[]. | string | One of Critical, High, Medium, Low, Information |
results[]. | string | date-time |
results[]. | string | date-time |
results[]. | string | date-time |
results[]. | object |
Paginated. See Getting Started → Pagination.
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
page | number | 1 |
page_size | number | 25 |
result_count | number | 21 |
results | array< | |
results[]. | string | "000000000000000e8a020001" |
results[]. | object | |
results[]. | string | "000000000000000ea4f90001" |
results[]. | string | "acme.example" |
results[]. | string | "acme.example" |
results[]. | string | "domain" |
results[]. | array | |
results[]. | object | null | |
results[]. | string | "000000000000000e915c0001" |
results[]. | string | "acme.example" |
results[]. | string | "acme.example" |
results[]. | string | "reappeared" |
results[]. | string | "Critical" |
results[]. | string | "2025-06-01T08:00:00Z" |
results[]. | string | "2025-07-31T08:00:00Z" |
results[]. | string | "2025-07-31T08:00:00Z" |
results[]. | object | |
results[]. | string | "000000000000000e16fe0001" |
results[]. | string | "Expired SSL certificate" |
results[]. | string | "Critical" |
results[]. | object | |
results[]. | string | "000000000000000e1c170001" |
results[]. | string | "SSL/TLS" |
Examples
Selecting one loads it into the request and response panels.