Update incident status
Incidents
Update incident status
PUT
Update incident status
Path Parameters
Available options:
Sentinel, DefenderXDR, QRadar, Splunk, CrowdStrike, SentinelOne Body
application/json
v2 request body for updating an incident's status.
New status to apply to the incident.
Available options:
Active, New, Closed Optional comment recorded alongside the status change. Recommended when transitioning to Status.Closed.
Required by Sentinel when closing an incident; ignored by sources that do not surface classifications.
Available options:
BenignPositive, FalsePositive, TruePositive, Undetermined, InformationalExpectedActivity, Unknown, NonIssue, PolicyViolation, QradarFalsePositive, Undefined, Suspicious, null Required by Sentinel when closing an incident; ignored by sources that do not surface classification reasons.
Available options:
InaccurateData, IncorrectAlertLogic, SuspiciousActivity, SuspiciousButExpected, Unknown, Apt, Malware, SecurityPersonnel, SecurityTesting, UnwantedSoftware, Other, MultistagedAttack, CompromisedUser, Phishing, MaliciousUserActivity, NotMalicious, NoEnoughDataToValidate, ConfirmedUserActivity, LineOfBusinessApplication, null When true, also closes the linked service ticket identified by
string UpdateIncidentStatusRequest.TicketId.
Linked service ticket id; required when bool UpdateIncidentStatusRequest.UpdateTicket is true.
Response
No Content