curl --request PUT \
--url https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status \
--header 'Content-Type: application/json' \
--data '
{
"comment": "<string>",
"updateTicket": true,
"ticketId": "<string>"
}
'import requests
url = "https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status"
payload = {
"comment": "<string>",
"updateTicket": True,
"ticketId": "<string>"
}
headers = {"Content-Type": "application/json"}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({comment: '<string>', updateTicket: true, ticketId: '<string>'})
};
fetch('https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'comment' => '<string>',
'updateTicket' => true,
'ticketId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status"
payload := strings.NewReader("{\n \"comment\": \"<string>\",\n \"updateTicket\": true,\n \"ticketId\": \"<string>\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status")
.header("Content-Type", "application/json")
.body("{\n \"comment\": \"<string>\",\n \"updateTicket\": true,\n \"ticketId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"comment\": \"<string>\",\n \"updateTicket\": true,\n \"ticketId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}Update incident status
curl --request PUT \
--url https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status \
--header 'Content-Type: application/json' \
--data '
{
"comment": "<string>",
"updateTicket": true,
"ticketId": "<string>"
}
'import requests
url = "https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status"
payload = {
"comment": "<string>",
"updateTicket": True,
"ticketId": "<string>"
}
headers = {"Content-Type": "application/json"}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({comment: '<string>', updateTicket: true, ticketId: '<string>'})
};
fetch('https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'comment' => '<string>',
'updateTicket' => true,
'ticketId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status"
payload := strings.NewReader("{\n \"comment\": \"<string>\",\n \"updateTicket\": true,\n \"ticketId\": \"<string>\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status")
.header("Content-Type", "application/json")
.body("{\n \"comment\": \"<string>\",\n \"updateTicket\": true,\n \"ticketId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/api/v2/workspaces/{workspaceId}/incidents/{source}/{incidentId}/status")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"comment\": \"<string>\",\n \"updateTicket\": true,\n \"ticketId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}Path Parameters
Sentinel, DefenderXDR, QRadar, Splunk, CrowdStrike, SentinelOne, SumoLogic Body
v2 request body for updating an incident's status.
New status to apply to the incident.
Active, New, Closed, OnHold, WaitingOnCustomer Optional comment recorded alongside the status change. Recommended when transitioning to Status.Closed.
Required when status is Closed for sources that support classifications
(Sentinel, DefenderXDR, SentinelOne, CrowdStrike, SumoLogic);
not required for other sources, but recorded in ContraForce when supplied. One of
TruePositive, FalsePositive, BenignPositive, or Undetermined; it
determines which classificationReason values are accepted.
BenignPositive, FalsePositive, TruePositive, Undetermined, null Required whenever classification is set for a source that supports classifications,
and must belong to it:
TruePositive: MultistagedAttack, Malware, MaliciousUserActivity, UnwantedSoftware, Phishing, CompromisedUser, Apt, SuspiciousActivity, Other.
FalsePositive: NotMalicious, NoEnoughDataToValidate, InaccurateData, IncorrectAlertLogic, Other.
BenignPositive: SecurityTesting, ConfirmedUserActivity, LineOfBusinessApplication, SecurityPersonnel, SuspiciousButExpected, Other.
Undetermined: Unknown, Other.
A reason outside the classification's list returns 400 VALIDATION_ERROR.
InaccurateData, IncorrectAlertLogic, SuspiciousActivity, SuspiciousButExpected, Unknown, Apt, Malware, SecurityPersonnel, SecurityTesting, UnwantedSoftware, Other, MultistagedAttack, CompromisedUser, Phishing, MaliciousUserActivity, NotMalicious, NoEnoughDataToValidate, ConfirmedUserActivity, LineOfBusinessApplication, null When true, also closes the linked service ticket identified by
string UpdateIncidentStatusRequest.TicketId.
Linked service ticket id; required when bool UpdateIncidentStatusRequest.UpdateTicket is true.
Response
No Content