> ## Documentation Index
> Fetch the complete documentation index at: https://chainpatrol.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Detection Drift Signals

> Analyze organization detection configs and surface zero-result, noisy-source, and stale-query drift signals.

## Overview

Analyze an organization's detection configs and surface drift signals: zero-result
configs, noisy sources, and stale queries.


## OpenAPI

````yaml POST /detection/drift
openapi: 3.0.3
info:
  title: ChainPatrol External API - OpenAPI 3.0
  description: ChainPatrol External API documentation
  version: 2.0.0
servers:
  - url: https://app.chainpatrol.io/api/v2
security: []
tags:
  - name: asset
  - name: report
externalDocs:
  url: https://chainpatrol.com/docs
paths:
  /detection/drift:
    post:
      tags:
        - detection
      summary: Get detection drift signals
      description: >-
        Analyze organization detection configs and surface zero-result,
        noisy-source, and stale-query drift signals.
      operationId: detectionDrift
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                slug:
                  type: string
                  minLength: 1
                lookbackHours:
                  type: integer
                  minimum: 0
                  exclusiveMinimum: true
                  default: 168
                startDate:
                  type: string
                endDate:
                  type: string
                source:
                  type: string
                  minLength: 1
                configIds:
                  type: array
                  items:
                    type: integer
                    minimum: 0
                    exclusiveMinimum: true
                includeDisabled:
                  type: boolean
                  default: false
                thresholds:
                  type: object
                  properties:
                    zeroResultsMaxHours:
                      type: integer
                      minimum: 0
                      exclusiveMinimum: true
                      default: 72
                    noisyResultsPerDay:
                      type: number
                      minimum: 0
                      exclusiveMinimum: true
                      default: 100
                    noisyAllowedRatioThreshold:
                      type: number
                      minimum: 0
                      maximum: 1
                      default: 0.6
                    staleConfigDays:
                      type: integer
                      minimum: 0
                      exclusiveMinimum: true
                      default: 30
              required:
                - slug
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                  range:
                    type: object
                    properties:
                      startDate:
                        type: string
                      endDate:
                        type: string
                      lookbackHours:
                        type: integer
                        minimum: 0
                        exclusiveMinimum: true
                    required:
                      - startDate
                      - endDate
                      - lookbackHours
                  thresholds:
                    type: object
                    properties:
                      zeroResultsMaxHours:
                        type: integer
                        minimum: 0
                        exclusiveMinimum: true
                        default: 72
                      noisyResultsPerDay:
                        type: number
                        minimum: 0
                        exclusiveMinimum: true
                        default: 100
                      noisyAllowedRatioThreshold:
                        type: number
                        minimum: 0
                        maximum: 1
                        default: 0.6
                      staleConfigDays:
                        type: integer
                        minimum: 0
                        exclusiveMinimum: true
                        default: 30
                    required:
                      - zeroResultsMaxHours
                      - noisyResultsPerDay
                      - noisyAllowedRatioThreshold
                      - staleConfigDays
                  summary:
                    type: object
                    properties:
                      checkedConfigs:
                        type: integer
                        minimum: 0
                      signalCount:
                        type: integer
                        minimum: 0
                      zeroResultsCount:
                        type: integer
                        minimum: 0
                      noisyCount:
                        type: integer
                        minimum: 0
                      staleCount:
                        type: integer
                        minimum: 0
                    required:
                      - checkedConfigs
                      - signalCount
                      - zeroResultsCount
                      - noisyCount
                      - staleCount
                  signals:
                    type: array
                    items:
                      type: object
                      properties:
                        signal:
                          type: string
                          enum:
                            - zero_results_too_long
                            - noisy_source
                            - stale_query
                        configId:
                          type: integer
                          minimum: 0
                          exclusiveMinimum: true
                        source:
                          type: string
                        title:
                          type: string
                          nullable: true
                        status:
                          type: string
                        severity:
                          type: string
                          enum:
                            - low
                            - medium
                            - high
                        details:
                          type: object
                          additionalProperties: {}
                      required:
                        - signal
                        - configId
                        - source
                        - title
                        - status
                        - severity
                        - details
                required:
                  - ok
                  - range
                  - thresholds
                  - summary
                  - signals
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.BAD_REQUEST'
        '401':
          description: Authorization not provided
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.UNAUTHORIZED'
        '403':
          description: Insufficient access
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.FORBIDDEN'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.INTERNAL_SERVER_ERROR'
      security:
        - ApiKey: []
components:
  schemas:
    error.BAD_REQUEST:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Invalid input data
        code:
          type: string
          description: The error code
          example: BAD_REQUEST
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Invalid input data error (400)
      description: The error information
      example:
        code: BAD_REQUEST
        message: Invalid input data
        issues: []
    error.UNAUTHORIZED:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Authorization not provided
        code:
          type: string
          description: The error code
          example: UNAUTHORIZED
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Authorization not provided error (401)
      description: The error information
      example:
        code: UNAUTHORIZED
        message: Authorization not provided
        issues: []
    error.FORBIDDEN:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Insufficient access
        code:
          type: string
          description: The error code
          example: FORBIDDEN
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Insufficient access error (403)
      description: The error information
      example:
        code: FORBIDDEN
        message: Insufficient access
        issues: []
    error.INTERNAL_SERVER_ERROR:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Internal server error
        code:
          type: string
          description: The error code
          example: INTERNAL_SERVER_ERROR
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Internal server error error (500)
      description: The error information
      example:
        code: INTERNAL_SERVER_ERROR
        message: Internal server error
        issues: []
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: X-API-KEY
      description: >-
        Your API key. This is required by most endpoints to access our API
        programatically. Reach out to us at
        [support@chainpatrol.io](mailto:support@chainpatrol.io?subject=Re:%20API%20Key%20for%20SDK&body=Company:%20%0AName:%20%0APurpose:%20)
        to get an API key for your use.

````