We are working on a SOAR project and are trying to figure out if it is possible either through the API or the Advanced Hunting queries to pull a list of events from the machine timeline when alerts occur.
We have successfully integrated and can query and pull information but I am having trouble finding if this specific use case is an option.
Thanks