The event request uses the HTTP GET method to retrieve Multi-Vector Virtual Execution (MVX) correlated Intrusion Prevention System (IPS) event data from the Network Security appliance managed by your Central Management System appliance. The responses to your event request can be formatted in either JSON or XML.
Note
You must have an IPS-enabled appliance to be able to retrieve IPS event data.
The following flow chart shows how to issue a basic event request:

Responses are limited to 200 events. This limit cannot be changed. If there are more entries than 200, only 200 entries will be returned.
By default, requests are limited to a 12-hour duration. You can specify the duration using the duration option.