Exfiltration Prevention APIs | Developer APIs | Nightfall Documentation
Exfiltration Prevention APIs | Developer APIs
event_idthe unique identifier of the exfiltration event to filter onintegration_namethe name of the integration to filter onstatethe state of the event to filter on (active, pending, resolved, expired)event_typethe type of exfiltration event to filter onactor_namethe name of the actor who performed the action to filter onactor_emailthe email of the actor who performed the action to filter onuser_namethe username of the user to filter on (backward compatibility)user_emailthe email of the user to filter on (backward compatibility)notesthe comment or notes associated with the event to filter onrisk_labelthe risk label to filter onrisk_sourcethe risk determination source to filter onpolicy_idthe unique identifier of the policy to filter onpolicy_namethe name of the policy to filter onresource_idthe identifier of the resource to filter onresource_namethe name of the resource to filter onresource_owner_namethe name of the resource owner to filter onresource_owner_emailthe email of the resource owner to filter onresource_content_typethe content type of the resource to filter onendpoint.device_idthe device identifier for endpoint events to filter onendpoint.machine_namethe machine name for endpoint events to filter onendpoint.ai_agent.client_typethe AI agent client (e.g. claude_code, cursor, cowork) to filter onendpoint.ai_agent.client_versionthe AI agent client version to filter onendpoint.ai_agent.trigger_pointthe AI agent event phase (PROMPT, MODEL_RESPONSE, TOOL_REQUEST, TOOL_RESPONSE, SHELL, OTEL_TELEMETRY) to filter onendpoint.ai_agent.session_idthe AI agent session identifier to filter onendpoint.ai_agent.tool_namethe tool invoked by the AI agent to filter onendpoint.ai_agent.server_namethe MCP server that served the tool to filter onendpoint.ai_agent.decisionthe permission decision (allow, deny, ask) to filter onendpoint.ai_agent.tool_use_idthe unique identifier for a specific tool invocation to filter onendpoint.ai_agent.modelthe model used for the request (OTel only, e.g. claude-opus-4-7) to filter onendpoint.ai_agent.error_messagethe error message from a failed AI agent call to filter ongdrive.permissionthe permission setting for Google Drive files to filter ongdrive.shared_internal_emailthe internal emails with which the file is shared to filter ongdrive.shared_external_emailthe external emails with which the file is shared to filter ongdrive.drivethe Google Drive name to filter ongdrive.file_ownerthe owner of the Google Drive file to filter ongdrive.label_namethe label name applied to Google Drive files to filter onsalesforce.report.scopethe scope of the Salesforce report to filter onsalesforce.report.event_sourcethe event source of the Salesforce report to filter onsalesforce.report.source_ipthe source IP address of the Salesforce report to filter onsalesforce.report.session_levelthe session level of the Salesforce report to filter onsalesforce.report.operationthe operation type of the Salesforce report to filter onsalesforce.report.descriptionthe description of the Salesforce report to filter onsalesforce.file.source_ipthe source IP address for Salesforce file events to filter onsalesforce.file.session_levelthe session level for Salesforce file events to filter onlast_actioned_bythe entity that performed the last action on the violation, can be one of NIGHTFALL, ADMIN or END_USER