> For the complete documentation index, see [llms.txt](https://docs.onum.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.onum.com/listeners/listener-integrations/pull-data-from-http-endpoints/pull-data-from-the-greymatter-api.md).

# Pull data from the Greymatter API

## Overview

Get a list of DRP alerts through the [Greymatter API](https://apidocs.myreliaquest.com/) using the **HTTP Pull** Listener.

## HTTP Pull Listener configuration

In Falcon Onum, go to the **Listeners** area and click **New Listener > HTTP Pull**. Give a name to your new Listener and enter the following data:

### Parameters

N/A

### Secrets

You must define these credentials in Onum:

* `greymatter_token` will reference your Greymatter token.

To do it, click **Add element** and enter a **Name** for the secret (in this case, `greymatter_token`). Then, click the **Value** field and select **New secret** to create a new one:

* Give the secret a **Name**.
* Turn off the **Expiration date** option.
* Click **Add new value** and paste the secret corresponding to the value.
* Click **Save**.

You can now select the secret you just created in the **Value** field list.

{% hint style="info" %}
Learn more about secrets in Onum in [this article](/settings/organization-settings/secrets-management.md).
{% endhint %}

### Setup

After entering the required parameters and secrets, you can choose to manually enter the rest of configuration fields, or simply paste the given YAML.

{% tabs %}
{% tab title="Config as YAML" %}
Toggle **ON** the **Config as YAML** option to enable a free text field where you can paste the following YAML:

```yaml
withTemporalWindow: true
temporalWindow:
  duration: 5m
  offset: 5m
  tz: UTC
  format: RFC3339
withAuthentication: false
withEnumerationPhase: false
collectionPhase:
  paginationType: "cursor"
  cursorSelector: ".data.drpAlerts.pageInfo.endCursor"
  initialRequest:
    method: POST
    url: "https://greymatter.myreliaquest.com/graphql"
    headers:
      - name: X-API-KEY
        value: ${secrets.greymatter_token}
      - name: Content-Type
        value: application/json
    bodyType: raw
    bodyRaw: |
      {
        "query":"query drpAlerts ($after: String, $filter: DrpReportTriageItemViewFilterInput, $first: Int!, $orderBy: DRPAlertOrder) {\n    drpAlerts (after: $after, filter: $filter, first: $first, orderBy: $orderBy) {\n        edges {\n            cursor\n            node {\n                active\n                alertFingerprint\n                classification\n                closedSource\n                createdAt\n                domain\n                hosts\n                id\n                migrated\n                rejectedByRuleIds\n                removedAt\n                riskFactorKeys\n                riskType\n                severity\n                shortCode\n                sourceGroup\n                sourceRef\n                sourceUpdated\n                sourceUris\n                subTitle\n                thumbnailUri\n                title\n                updatedAt\n                uri\n            }\n        }\n        pageInfo {\n            endCursor\n            hasNextPage\n            hasPreviousPage\n            startCursor\n        }\n        totalCount\n    }\n}",
        "variables": {
          "after": "T18w",
          "filter": {
            "changed": "PT5M#UTC"
          },
          "first": 1000,
          "orderBy": {
            "direction": "ASC",
            "orderBy": "CREATED_AT"
          }
        }
      }
  nextRequest:
    method: POST
    url: "https://greymatter.myreliaquest.com/graphql"
    headers:
      - name: X-API-KEY
        value: ${secrets.greymatter_token}
      - name: Content-Type
        value: application/json
    bodyType: raw
    bodyRaw: |
      {
        "query": "query drpAlerts ($after: String, $filter: DrpReportTriageItemViewFilterInput, $first: Int!, $orderBy: DRPAlertOrder) {\n    drpAlerts (after: $after, filter: $filter, first: $first, orderBy: $orderBy) {\n        edges {\n            cursor\n            node {\n                active\n                alertFingerprint\n                classification\n                closedSource\n                createdAt\n                domain\n                hosts\n                id\n                migrated\n                rejectedByRuleIds\n                removedAt\n                riskFactorKeys\n                riskType\n                severity\n                shortCode\n                sourceGroup\n                sourceRef\n                sourceUpdated\n                sourceUris\n                subTitle\n                thumbnailUri\n                title\n                updatedAt\n                uri\n            }\n        }\n        pageInfo {\n            endCursor\n            hasNextPage\n            hasPreviousPage\n            startCursor\n        }\n        totalCount\n    }\n}",
        "variables": {
          "after": "${pagination.cursor}",
          "filter": {
            "changed": "PT5M#UTC"
          },
          "first": 1000,
          "orderBy": {
            "direction": "ASC",
            "orderBy": "CREATED_AT"
          }
        }
      }
  output:
    select: ".data.drpAlerts.edges"
    map: "."
    outputMode: element 
```

{% endtab %}

{% tab title="Manually configure" %}
**Temporal Window**

Toggle **ON** to add a temporal window for events. This repeatedly shifts the time window over which data is collected.

* **Duration**<mark style="color:$primary;">**\***</mark> - `5m`
* **Offset**<mark style="color:$primary;">**\***</mark> - `5m`
* **Format**<mark style="color:$primary;">**\***</mark> - `RFC3339`

**Collection Phase**&#x20;

* **Pagination Type**<mark style="color:red;">**\***</mark> - `Cursor`
* **Cursor Selector**<mark style="color:red;">**\***</mark> - `.data.drpAlerts.pageInfo.endCursor`
* **Initial Request**&#x20;
  * **Response Type**<mark style="color:$primary;">**\***</mark> - `JSON`
  * **Method**<mark style="color:red;">**\***</mark> - `POST`
  * **URL**<mark style="color:red;">**\***</mark> - `https://greymatter.myreliaquest.com/graphql`
  * **Headers**
    * **Name** - `x-api-key`
    * **Value** - `${secrets.greymatter_token}`
    * **Name** - `Content-Type`
    * **Value** - `application/json`
  * **Body Type**<mark style="color:$primary;">**\***</mark> - `Raw`
  * **Body Content**<mark style="color:$primary;">**\***</mark>

```
{
  "query":"query drpAlerts ($after: String, $filter: DrpReportTriageItemViewFilterInput, $first: Int!, $orderBy: DRPAlertOrder) {\n    drpAlerts (after: $after, filter: $filter, first: $first, orderBy: $orderBy) {\n        edges {\n            cursor\n            node {\n                active\n                alertFingerprint\n                classification\n                closedSource\n                createdAt\n                domain\n                hosts\n                id\n                migrated\n                rejectedByRuleIds\n                removedAt\n                riskFactorKeys\n                riskType\n                severity\n                shortCode\n                sourceGroup\n                sourceRef\n                sourceUpdated\n                sourceUris\n                subTitle\n                thumbnailUri\n                title\n                updatedAt\n                uri\n            }\n        }\n        pageInfo {\n            endCursor\n            hasNextPage\n            hasPreviousPage\n            startCursor\n        }\n        totalCount\n    }\n}",
  "variables": {
    "after": "T18w",
    "filter": {
      "changed": "PT5M#UTC"
    },
    "first": 1000,
    "orderBy": {
      "direction": "ASC",
      "orderBy": "CREATED_AT"
    }
  }
}
```

* **Next Request**&#x20;
  * **Response Type**<mark style="color:$primary;">**\***</mark> - `JSON`
  * **Method**<mark style="color:red;">**\***</mark> - `POST`
  * **URL**<mark style="color:red;">**\***</mark> - `https://greymatter.myreliaquest.com/graphql`
  * **Headers**
    * **Name** - `x-api-key`
    * **Value** - `${secrets.greymatter_token}`
    * **Name** - `Content-Type`
    * **Value** - `application/json`
  * **Body Type**<mark style="color:$primary;">**\***</mark> - `Raw`
  * **Body Content**<mark style="color:$primary;">**\***</mark>

```
{
  "query": "query drpAlerts ($after: String, $filter: DrpReportTriageItemViewFilterInput, $first: Int!, $orderBy: DRPAlertOrder) {\n    drpAlerts (after: $after, filter: $filter, first: $first, orderBy: $orderBy) {\n        edges {\n            cursor\n            node {\n                active\n                alertFingerprint\n                classification\n                closedSource\n                createdAt\n                domain\n                hosts\n                id\n                migrated\n                rejectedByRuleIds\n                removedAt\n                riskFactorKeys\n                riskType\n                severity\n                shortCode\n                sourceGroup\n                sourceRef\n                sourceUpdated\n                sourceUris\n                subTitle\n                thumbnailUri\n                title\n                updatedAt\n                uri\n            }\n        }\n        pageInfo {\n            endCursor\n            hasNextPage\n            hasPreviousPage\n            startCursor\n        }\n        totalCount\n    }\n}",
  "variables": {
    "after": "${pagination.cursor}",
    "filter": {
      "changed": "PT5M#UTC"
    },
    "first": 1000,
    "orderBy": {
      "direction": "ASC",
      "orderBy": "CREATED_AT"
    }
  }
}
```

* **Output**&#x20;
  * **Select**<mark style="color:$primary;">**\***</mark> - `.data.drpAlerts.edges`
  * **Map** - `.`
  * **Output Mode**<mark style="color:$primary;">**\***</mark> - `element`
    {% endtab %}
    {% endtabs %}

When you're done, click **Create labels** to move on to the next step and define the required [Labels](https://docs.onum.com/the-workspace/listeners/labels) if needed.
