After some experimentation I found that the endpoint will return all data if passed the following general JSON object after it's converted to a query string: { "page_number": 1, "min_time": "2018-01-01T00:00:00.000000Z", "max_time": "2038-01-01T00:00:00.000000Z", "count": 10000, "artifact": { "count": 10000, "min_time": "2018-01-01T00:00:00.000000Z", "max_time": "2038-01-01T00:00:00.000000Z", }, "event": { "count": 10000, "min_time": "2018-01-01T00:00:00.000000Z", "max_time": "2038-01-01T00:00:00.000000Z", }, "playbook": { "count": 10000, "min_time": "2018-01-01T00:00:00.000000Z", "max_time": "2038-01-01T00:00:00.000000Z", }, "action": { "count": 10000, "min_time": "2018-01-01T00:00:00.000000Z", "max_time": "2038-01-01T00:00:00.000000Z", } } For example: /rest/container/<container ID>/timeline?query_params={"page_number":1,"min_time":"2018-01-01T00:00:00.000000Z","max_time":"2038-01-01T00:00:00.000000Z","count":10000,"artifact":{"count":10000,"min_time":"2018-01-01T00:00:00.000000Z","max_time":"2038-01-01T00:00:00.000000Z"},"event":{"count":10000,"min_time":"2018-01-01T00:00:00.000000Z","max_time":"2038-01-01T00:00:00.000000Z"},"playbook":{"count":10000,"min_time":"2018-01-01T00:00:00.000000Z","max_time":"2038-01-01T00:00:00.000000Z"},"action":{"count":10000,"min_time":"2018-01-01T00:00:00.000000Z","max_time":"2038-01-01T00:00:00.000000Z"}}
... View more