Skip to main content
Triggered when an unauthorized access point is detected on the network. Alert name: ALERT_ROGUE_AP

Payload

{
  "metadata": {
    "alert_name": "ALERT_ROGUE_AP",
    "network_name": "Main Office",
    "timestamp": "2026-01-23T21:40:03Z"
  },
  "data": {
    "rogue_access_points": [
      {
        "mac": "AA:BB:CC:DD:EE:FF",
        "vendor": "TP-Link",
        "connected_switch_label": "Floor 2 Switch",
        "port_number": 24
      }
    ]
  }
}

Fields

FieldTypeDescription
macstringMAC address of the rogue access point
vendorstringVendor identified from the MAC address
connected_switch_labelstringSwitch where the rogue AP is connected
port_numberintegerSwitch port number