Documentation Index
Fetch the complete documentation index at: https://docs.contraforce.com/llms.txt
Use this file to discover all available pages before exploring further.
Sentinel, DefenderXDR, QRadar, Splunk, CrowdStrike, SentinelOne v2 request body for updating an incident's status.
New status to apply to the incident.
Active, New, Closed Optional comment recorded alongside the status change. Recommended when transitioning to Status.Closed.
Required by Sentinel when closing an incident; ignored by sources that do not surface classifications.
BenignPositive, FalsePositive, TruePositive, Undetermined, InformationalExpectedActivity, Unknown, NonIssue, PolicyViolation, QradarFalsePositive, Undefined, Suspicious, null Required by Sentinel when closing an incident; ignored by sources that do not surface classification reasons.
InaccurateData, IncorrectAlertLogic, SuspiciousActivity, SuspiciousButExpected, Unknown, Apt, Malware, SecurityPersonnel, SecurityTesting, UnwantedSoftware, Other, MultistagedAttack, CompromisedUser, Phishing, MaliciousUserActivity, NotMalicious, NoEnoughDataToValidate, ConfirmedUserActivity, LineOfBusinessApplication, null When true, also closes the linked service ticket identified by
string UpdateIncidentStatusRequest.TicketId.
Linked service ticket id; required when bool UpdateIncidentStatusRequest.UpdateTicket is true.
No Content