Agent tool submit gamebook
Path Parameters
Sentinel, DefenderXDR, QRadar, Splunk, CrowdStrike, SentinelOne Body
Request DTO for the agent's submit-gamebook tool. Allows the agent to queue one or more remediation gamebooks against an incident as it investigates.
Sequential incident number from the source platform. Used in human-readable summaries and gamebook tracking.
Human-readable incident title from the source platform. Used in summaries and audit logs.
How the agent run was triggered. OnQueue (background): subject to per-severity Gamebooks capability gating — submissions are rejected for severities where Gamebooks is not enabled. ManualInvestigateAndRespond (operator-requested): always allowed to submit gamebooks regardless of capability settings.
OnQueue, ManualInvestigateOnly, ManualInvestigateAndRespond Ordered playbook actions to run as part of this gamebook. Each entry binds a playbook from the registered catalog to its target entity. Must contain at least one entry — empty arrays are rejected.
Response
OK
Standard v2 API response envelope for single-item responses.