Skip to main content
PUT
Update incident status

Path Parameters

workspaceId
string<uuid>
required
source
enum<string>
required
Available options:
Sentinel,
DefenderXDR,
QRadar,
Splunk,
CrowdStrike,
SentinelOne,
SumoLogic
incidentId
string
required

Body

application/json

v2 request body for updating an incident's status.

status
enum<string>
required

New status to apply to the incident.

Available options:
Active,
New,
Closed,
OnHold,
WaitingOnCustomer
comment
null | string

Optional comment recorded alongside the status change. Recommended when transitioning to Status.Closed.

classification
null | any

Required when status is Closed for sources that support classifications (Sentinel, DefenderXDR, SentinelOne, CrowdStrike, SumoLogic); not required for other sources, but recorded in ContraForce when supplied. One of TruePositive, FalsePositive, BenignPositive, or Undetermined; it determines which classificationReason values are accepted.

Available options:
BenignPositive,
FalsePositive,
TruePositive,
Undetermined,
null
classificationReason
null | any

Required whenever classification is set for a source that supports classifications, and must belong to it: TruePositive: MultistagedAttack, Malware, MaliciousUserActivity, UnwantedSoftware, Phishing, CompromisedUser, Apt, SuspiciousActivity, Other. FalsePositive: NotMalicious, NoEnoughDataToValidate, InaccurateData, IncorrectAlertLogic, Other. BenignPositive: SecurityTesting, ConfirmedUserActivity, LineOfBusinessApplication, SecurityPersonnel, SuspiciousButExpected, Other. Undetermined: Unknown, Other. A reason outside the classification's list returns 400 VALIDATION_ERROR.

Available options:
InaccurateData,
IncorrectAlertLogic,
SuspiciousActivity,
SuspiciousButExpected,
Unknown,
Apt,
Malware,
SecurityPersonnel,
SecurityTesting,
UnwantedSoftware,
Other,
MultistagedAttack,
CompromisedUser,
Phishing,
MaliciousUserActivity,
NotMalicious,
NoEnoughDataToValidate,
ConfirmedUserActivity,
LineOfBusinessApplication,
null
updateTicket
boolean

When true, also closes the linked service ticket identified by string UpdateIncidentStatusRequest.TicketId.

ticketId
null | string

Linked service ticket id; required when bool UpdateIncidentStatusRequest.UpdateTicket is true.

Response

No Content

Last modified on October 9, 2026