In order to get all GCTI (and/or RULE_DETECTION) alerts in one api call. It seems necessary to hit the legacyStreamDetectionAlerts endpoint. https://cloud.google.com/chronicle/docs/reference/rest/v1alpha/projects.locations.instances.legacy/legacyStreamDetectionAlerts I do not see this is currently supported in secops client. \- Mike