---
title: Get recently updated entity context
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: Docs > API Reference > Security Monitoring
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Get recently updated entity context{% #get-recently-updated-entity-context %}
Copy pageCopied
{% tab title="v2" %}
**Note**: This endpoint is in Preview and is subject to change. If you have any feedback, contact [Datadog support](https://docs.datadoghq.com/help/).
| Datadog site      | API endpoint                                                                                 |
| ----------------- | -------------------------------------------------------------------------------------------- |
| ap1.datadoghq.com | GET https://api.ap1.datadoghq.com/api/v2/security_monitoring/entity_context/recently_updated |
| ap2.datadoghq.com | GET https://api.ap2.datadoghq.com/api/v2/security_monitoring/entity_context/recently_updated |
| app.datadoghq.eu  | GET https://api.datadoghq.eu/api/v2/security_monitoring/entity_context/recently_updated      |
| app.ddog-gov.com  | GET https://api.ddog-gov.com/api/v2/security_monitoring/entity_context/recently_updated      |
| us2.ddog-gov.com  | GET https://api.us2.ddog-gov.com/api/v2/security_monitoring/entity_context/recently_updated  |
| uk1.datadoghq.com | GET https://api.uk1.datadoghq.com/api/v2/security_monitoring/entity_context/recently_updated |
| app.datadoghq.com | GET https://api.datadoghq.com/api/v2/security_monitoring/entity_context/recently_updated     |
| us3.datadoghq.com | GET https://api.us3.datadoghq.com/api/v2/security_monitoring/entity_context/recently_updated |
| us5.datadoghq.com | GET https://api.us5.datadoghq.com/api/v2/security_monitoring/entity_context/recently_updated |

### Overview

Get the entities with the most recent updates in the Cloud SIEM entity context store. Entities are ranked by the time of their most recent revision in the requested time range, and the top `limit` entities are returned in that order. This endpoint is not paginated. This endpoint requires the `siem_entities_read` permission.

OAuth apps require the `siem_entities_read` authorization [scope](https://docs.datadoghq.com/api/latest/scopes.md#security-monitoring) to access this endpoint.



### Arguments

#### Query Strings

| Name        | Type    | Description                                                                                                                                                                                                      |
| ----------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| query       | string  | A free-text query (for example, an email address or principal ID) used to filter the entities returned.                                                                                                          |
| entity_type | enum    | The type of entity to retrieve. Only `siem_entity_identity` is currently supported. Defaults to `siem_entity_identity`. Allowed enum values: `siem_entity_identity`                                              |
| from        | string  | The start of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now-7d`). Defaults to `now-7d`.                                                                                  |
| to          | string  | The end of the time range to query, as an RFC3339 timestamp or a relative time (for example, `now`). Defaults to `now`. Entities are ranked by their most recent revision within `[from, to]`.                   |
| limit       | integer | The number of entities to return. Must be between 1 and 100.                                                                                                                                                     |
| revisions   | enum    | Which revisions to return for each entity: `latest` returns only the latest revision of each entity as of `to`, and `all` returns every revision in the requested time range. Allowed enum values: `latest, all` |

### Response

{% tab title="200" %}
OK
{% tab title="Model" %}
Response from the recently updated entities endpoint, containing the entities with the most recent updates in the requested time range, ordered from most to least recently updated.

| Parent field | Field                           | Type      | Description                                                                                                                                                                                    |
| ------------ | ------------------------------- | --------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|              | data [*required*]          | [object]  | The list of entities with the most recent updates, ordered from most to least recently updated.                                                                                                |
| data         | attributes [*required*]    | object    | The attributes of an entity context entry, grouping all the historical revisions of the entity.                                                                                                |
| attributes   | revisions [*required*]     | [object]  | The historical revisions of the entity, ordered chronologically.                                                                                                                               |
| revisions    | attributes [*required*]    | object    | The set of attributes recorded for the entity at this revision. The keys depend on the kind of entity.                                                                                         |
| revisions    | first_seen_at [*required*] | date-time | The first time the entity was observed at this revision.                                                                                                                                       |
| revisions    | last_seen_at [*required*]  | date-time | The last time the entity was observed at this revision.                                                                                                                                        |
| data         | id [*required*]            | string    | The unique identifier of the entity.                                                                                                                                                           |
| data         | type [*required*]          | string    | The type of the entity. Reflects the underlying entity kind from the entity context store (for example, `siem_entity_identity` for identities). Defaults to `entity` when the kind is unknown. |

{% /tab %}

{% tab title="Example" %}

```json
{
  "data": [
    {
      "attributes": {
        "revisions": [
          {
            "attributes": {
              "accounts": [
                "linked-account-123"
              ],
              "display_name": "Test User",
              "email": "user@example.com",
              "principal_id": "user@example.com"
            },
            "first_seen_at": "2026-04-01T00:00:00Z",
            "last_seen_at": "2026-05-01T00:00:00Z"
          }
        ]
      },
      "id": "user@example.com",
      "type": "siem_entity_identity"
    }
  ]
}
```

{% /tab %}

{% /tab %}

{% tab title="400" %}
Bad Request
{% tab title="Model" %}
API error response.

| Field                    | Type     | Description       |
| ------------------------ | -------- | ----------------- |
| errors [*required*] | [string] | A list of errors. |

{% /tab %}

{% tab title="Example" %}

```json
{
  "errors": [
    "Bad Request"
  ]
}
```

{% /tab %}

{% /tab %}

{% tab title="403" %}
Not Authorized
{% tab title="Model" %}
API error response.

| Field                    | Type     | Description       |
| ------------------------ | -------- | ----------------- |
| errors [*required*] | [string] | A list of errors. |

{% /tab %}

{% tab title="Example" %}

```json
{
  "errors": [
    "Bad Request"
  ]
}
```

{% /tab %}

{% /tab %}

{% tab title="429" %}
Too many requests
{% tab title="Model" %}
API error response.

| Field                    | Type     | Description       |
| ------------------------ | -------- | ----------------- |
| errors [*required*] | [string] | A list of errors. |

{% /tab %}

{% tab title="Example" %}

```json
{
  "errors": [
    "Bad Request"
  ]
}
```

{% /tab %}

{% /tab %}

### Code Example

##### 
                  \# Use a Personal Access Token or Service Access Token export DD_BEARER_TOKEN="<PERSONAL_ACCESS_TOKEN OR SERVICE_ACCESS_TOKEN>"  \# Curl command curl -X GET "https://api.datadoghq.com/api/v2/security_monitoring/entity_context/recently_updated" \
-H "Accept: application/json" \
-H "Authorization: Bearer ${DD_BEARER_TOKEN}" 
                
{% /tab %}
