Connectors
...
Actions
Update Alert Analyst Verdict
5 min
description updates the analyst's verdict on an alert in sentinelone using specific data and filter criteria endpoint url /web/api/v2 1/cloud detection/alerts/analyst verdict method post inputs json body (object) – required filter (object) – required containerimagename contains (string) free text filter by the endpoint container image name (supports multiple values) limit (number) limit reportedat gte (string) reported at greater or equal than tenant (boolean) indicates a tenant scope request reportedat lte (string) reported at lesser or equal than sourceprocessname contains (string) free text filter by source process name incidentstatus (string) filter threats by a incident status sourceprocesscommandline contains (string) free text filter by source commandline createdat lte (string) created at lesser or equal than k8snamespacelabels contains (string) free text filter by the endpoint kubernetes namespace labels (supports multiple values) k8spod contains (string) free text filter by the endpoint kubernetes pod name (supports multiple values) reportedat gt (string) reported at greater than sourceprocessfilehashsha1 contains (string) free text filter by source sha1 k8snode contains (string) free text filter by the endpoint kubernetes node name (supports multiple values) createdat gt (string) created at greater than origagentuuid contains (string) free text filter by agent uuid sourceprocessfilehashmd5 contains (string) free text filter by source md5 query (string) full text search for all fields ostype (string) included os types containername contains (string) free text filter by the endpoint container name (supports multiple values) analystverdict (string) filter threats by a analyst verdict createdat lt (string) created at lesser than origagentname contains (string) free text filter by agent name rulename contains (string) free text filter by rule name origagentosrevision contains (string) free text filter by agent os revision sourceprocessfilepath contains (string) free text filter by source file path k8scontrollerlabels contains (string) free text filter by the endpoint kubernetes controller labels (supports multiple values) siteids (string) list of site ids to filter by containerlabels contains (string) free text filter by the endpoint container labels (supports multiple values) k8snamespacename contains (string) free text filter by the endpoint kubernetes namespace name (supports multiple values) groupids (string) a list of alert ids accountids (string) list of account ids to filter by machinetype (string) agent machine type k8scontrollername contains (string) free text filter by the endpoint kubernetes controller name (supports multiple values) severity (string) severity k8scluster contains (string) free text filter by the endpoint kubernetes cluster name (supports multiple values) ids (string) a list of alert ids scopes (string) filter results by scope createdat gte (string) created at greater or equal than sourceprocessstoryline contains (string) free text filter by source storyline origagentversion contains (string) free text filter by agent os version reportedat lt (string) reported at lesser than k8spodlabels contains (string) free text filter by the endpoint kubernetes pod labels (supports multiple values) sourceprocessfilehashsha256 contains (string) free text filter by source sha255 data (object) – required analystverdict (string) – required analyst verdict output output parameters status code (number) reason (string) json body (object) data (object) affected (number) response headers header type server string date string content type string transfer encoding string connection string x rqid string access control allow origin string access control allow credentials string vary string strict transport security string x frame options string x content type options string content security policy string cache control string pragma string expires string content encoding string