Fetch CIS compliance profile results for a specific resource

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

Retrieves all CIS compliance profile results for a specific resource within a custom group, showing each benchmark profile's scan status, pass/fail percentage, and rules breakdown

Request URL

https://{serverurl}/dcapi/scap/compliance/result/profiles/{resourceId}

Scope

DesktopCentralCloud.VulnerabilityMgmt.READCopied!

Header

Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52

Request Parameters

- Path Parameters

resourceIdstringMandatory

Computer/resource ID. Fetch from Get CG Association Details resource listing

- Query Parameters

groupResourceIdlongOptional

Custom group resource ID

filterstringOptional

Rule status filter. Values: all, passed, failed, error, unknown, notApplicable, unscored

appFilterstringOptional

Applicability filter. Values: all, 1 (applicable only)

scanStatusstringOptional

Scan status filter. Values: all, SCAN_COMPLETED, YET_TO_SCAN

platformIdlongOptional

Platform ID for filtering

offsetintegerOptional

Pagination offset

limitintegerOptional

Maximum number of results to return

collectionIdlongOptional

Collection ID of the compliance association

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request GET \
  --url https://appdomains/dcapi/scap/compliance/result/profiles/{resourceId} \
  --header 'Authorization: Zoho-oauthtoken  d92d4xxxxxxxxxxxxx15f52'

Response Parameters

- HTTP code 200

Response Body - application/json
JSON Object
Hide Sub-Attributes
resourceNamestring

Name of the computer

cgNamestring

Custom group name

benchmarksJSON Array

List of benchmark profiles with scan results

Show Sub-Attributes
JSON Object
Show Sub-Attributes
profileIdlong

Profile ID

profileTypestring

Profile type. 1 = XCCDF, 0 = OVAL

titlestring

Benchmark profile title

scapTypestring

SCAP standard type

resultstring

Results summary, e.g., 200/245 Rules Passed or NA

successPercentagestring

Pass percentage (0-100)

- HTTP code 401

Response Body - application/json
JSON Object
Hide Sub-Attributes
errorCodelong

Unauthorized error code: credentials missing, expired, or invalid

errorMsgstring

Authentication failure reason

- HTTP code 429

Response Body - application/json
JSON Object
Hide Sub-Attributes
errorCodelong

Rate limit error code returned when the API call reached threshold

errorMsgstring

Rate limit exceeded message with retry guidance

Possible Response Codes

200HTTP code
401HTTP code
429HTTP code

Sample Response: HTTP 200

Profile scan results for a specific resource

Copied!
  {
    "resourceName": "WIN-SERVER-01",
    "benchmarks": [
      {
        "result": "200/245 Rules Passed",
        "scapType": "XCCDF",
        "profileType": 1,
        "profileId": 50001,
        "title": "CIS Microsoft Windows Server 2019 Benchmark - Level 1",
        "successPercentage": 82
      },
      {
        "result": "NA",
        "scapType": "XCCDF",
        "profileType": 1,
        "profileId": 50002,
        "title": "CIS Microsoft Windows Server 2019 Benchmark - Level 2",
        "successPercentage": 0
      }
    ],
    "cgName": "Production Servers"
  }
                
Show full

Sample Response: HTTP 401

Authentication credentials are missing or invalid

Copied!
  {
    "errorMessage": "Authentication required",
    "errorCode": "UNAUTHORIZED"
  }
                
Show full

Sample Response: HTTP 429

API call threshold exceeded

Copied!
  {
    "errorMessage": "Rate limit exceeded. Retry after some time",
    "errorCode": "TOO_MANY_REQUESTS"
  }
                
Show full

Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes

Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.