List organization security finding occurrences (bearer twin)
Pages one finding’s occurrences by the status predicates its row counts with, so every count on the finding row can be expanded into the rows behind it. Resolved occurrences list newest resolution first; every other status lists in the finding detail’s workload order.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Query Parameters
1 <= x <= 10000Values above 100 are clamped to 100.
x >= 1Keep only occurrences in one status, using the same predicates the finding row's disposition_counts are built from: open is active with no disposition, acknowledged and accepted_risk are active with that disposition, resolved is the resolved scan state. Omit it to list every occurrence, live and resolved.
open, acknowledged, accepted_risk, resolved Keep only occurrences observed on this cluster.