> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List organization security finding occurrences

> Pages one finding's occurrences by the status predicates its row counts with, so every count on the finding row can be expanded into the rows behind it. Resolved occurrences list newest resolution first; every other status lists in the finding detail's workload order.



## OpenAPI

````yaml https://platform.ankra.app/openapi.json get /org/security/findings/{finding_id}/occurrences
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
paths:
  /org/security/findings/{finding_id}/occurrences:
    get:
      tags:
        - Security
      summary: List organization security finding occurrences
      description: >-
        Pages one finding's occurrences by the status predicates its row counts
        with, so every count on the finding row can be expanded into the rows
        behind it. Resolved occurrences list newest resolution first; every
        other status lists in the finding detail's workload order.
      operationId: list_security_finding_occurrences
      parameters:
        - in: path
          name: finding_id
          required: true
          schema:
            format: uuid
            type: string
        - in: query
          name: page
          required: false
          schema:
            default: 1
            maximum: 10000
            minimum: 1
            type: integer
        - description: Values above 100 are clamped to 100.
          in: query
          name: page_size
          required: false
          schema:
            default: 50
            minimum: 1
            type: integer
        - description: >-
            Keep only occurrences in one status, using the same predicates the
            finding row's disposition_counts are built from: open is active with
            no disposition, acknowledged and accepted_risk are active with that
            disposition, resolved is the resolved scan state. Omit it to list
            every occurrence, live and resolved.
          in: query
          name: status
          required: false
          schema:
            enum:
              - open
              - acknowledged
              - accepted_risk
              - resolved
            type: string
        - description: Keep only occurrences observed on this cluster.
          in: query
          name: cluster_id
          required: false
          schema:
            format: uuid
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityFindingOccurrenceListResponse'
          description: Successful response
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityDetailError'
          description: Business validation error
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityPermissionDenied'
          description: Permission or CSRF denied
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityDetailError'
          description: Organization-scoped resource not found
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Request validation error
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityDetailError'
          description: Internal server error
components:
  schemas:
    SecurityFindingOccurrenceListResponse:
      properties:
        pagination:
          $ref: '#/components/schemas/SecurityPagination'
        result:
          items:
            $ref: '#/components/schemas/SecurityOccurrence'
          type: array
      required:
        - result
        - pagination
      type: object
    SecurityDetailError:
      properties:
        detail:
          type: string
      required:
        - detail
      type: object
    SecurityPermissionDenied:
      properties:
        detail:
          enum:
            - permission_denied
          type: string
        permission:
          type: string
        scope_type:
          type: string
      required:
        - detail
        - permission
        - scope_type
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    SecurityPagination:
      properties:
        page:
          type: integer
        page_size:
          type: integer
        total_count:
          type: integer
        total_pages:
          type: integer
      required:
        - page
        - page_size
        - total_pages
        - total_count
      type: object
    SecurityOccurrence:
      properties:
        addon_attribution_confidence:
          type: string
        addon_attribution_reason:
          type: string
        addon_slug:
          anyOf:
            - type: string
            - type: 'null'
        cluster_id:
          format: uuid
          type: string
        cluster_name:
          type: string
        container_name:
          anyOf:
            - type: string
            - type: 'null'
        effective_disposition:
          type: string
        effective_policy_id:
          anyOf:
            - format: uuid
              type: string
            - type: 'null'
        first_seen_at:
          format: date-time
          type: string
        fixed_version:
          anyOf:
            - type: string
            - type: 'null'
        id:
          format: uuid
          type: string
        image_digest:
          anyOf:
            - type: string
            - type: 'null'
        image_ref:
          anyOf:
            - type: string
            - type: 'null'
        installed_version:
          anyOf:
            - type: string
            - type: 'null'
        last_evaluated_at:
          format: date-time
          type: string
        last_seen_at:
          format: date-time
          type: string
        report_name:
          type: string
        report_namespace:
          anyOf:
            - type: string
            - type: 'null'
        report_scope:
          type: string
        report_uid:
          anyOf:
            - type: string
            - type: 'null'
        resolved_at:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
        scan_state:
          type: string
        workload_kind:
          anyOf:
            - type: string
            - type: 'null'
        workload_name:
          anyOf:
            - type: string
            - type: 'null'
        workload_namespace:
          anyOf:
            - type: string
            - type: 'null'
        workload_uid:
          anyOf:
            - type: string
            - type: 'null'
      required:
        - id
        - cluster_id
        - cluster_name
        - report_scope
        - report_uid
        - report_name
        - report_namespace
        - workload_uid
        - workload_kind
        - workload_namespace
        - workload_name
        - container_name
        - image_ref
        - image_digest
        - installed_version
        - fixed_version
        - addon_slug
        - addon_attribution_confidence
        - addon_attribution_reason
        - scan_state
        - effective_disposition
        - effective_policy_id
        - first_seen_at
        - last_seen_at
        - last_evaluated_at
        - resolved_at
      type: object
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object

````