Farsight Feeds

Alerts API

Normalized, filterable feed of event-type items across layers — query and facet endpoints.

The alerts API is a single, normalized event feed unified across every layer that produces discrete events (incidents, advisories, anomalies, escalations). Each item carries a stable shape so the same query and the same UI work regardless of which underlying layer the event came from.

Routes

MethodPathPurpose
GET/alertsQuery alerts with full filter set.
GET/alerts/facetsFacet counts (types, sources, severities, layers) for the current filter.

Filters

All filters compose. Omit to match everything.

ParamTypeNotes
typescsvAlert types (incident, advisory, anomaly, escalation, …).
sourcescsvSource feed ids that produced the alert.
severitycsvOne or more of low, medium, high, critical.
layerscsvRestrict to alerts whose origin layer matches.
qstringFree-text query against title/description.
sinceRFC3339 or duratione.g. 2026-05-01T00:00:00Z, 24h, 7d.
untilRFC3339 or durationInclusive upper bound.
bboxminLon,minLat,maxLon,maxLatSpatial filter (R-tree).
aoistringRestrict to the named AOI (see operator control plane).
limitintDefault 200, max 2000.
offsetintPagination cursor.

Response shape

{
  "total": 4831,
  "alerts": [
    {
      "id": "alr_…",
      "type": "anomaly",
      "severity": "high",
      "layer": "ais",
      "title": "Anchor-drag pattern near subsea cable",
      "ts": "2026-05-27T18:12:04Z",
      "geometry": { "type": "Point", "coordinates": [55.21, 26.07] },
      "props": { /* layer-specific */ }
    }
  ]
}

Facets

GET /alerts/facets returns the same filter dimensions broken down into counts for the current filter set — useful for driving filter UIs:

{
  "types":      { "incident": 1240, "anomaly": 380, "advisory": 91 },
  "severities": { "low": 700, "medium": 800, "high": 211 },
  "layers":     { "ais": 480, "adsb": 220, "natural": 91 },
  "sources":    { /* … */ }
}

Mapping to the UI

The Farsight /farsight/alerts view consumes these two endpoints directly — the filter sidebar reads facets, the result list reads alerts, and the map spatial bound rides the bbox parameter.

Status

Live on the deployed system. Push streaming of new alerts is planned but not yet deployed — poll /alerts?since=… until then.

On this page