Skip to main content
POST
Create incident comment

Path Parameters

workspaceId
string<uuid>
required
source
enum<string>
required
Available options:
Sentinel,
DefenderXDR,
QRadar,
Splunk,
CrowdStrike,
SentinelOne,
SumoLogic
incidentId
string
required

Body

application/json

v2 request body for creating a comment on an incident.

content
null | string
required

Body of the comment.

extensionId
null | string

Ignored. The source in the route decides where the comment is written; this field is accepted so clients that still send it keep working (PLAT-3611).

Response

Created

Standard v2 API response envelope for single-item responses.

data
object
meta
object
Last modified on October 9, 2026