Spaces method and path for this operation:
post /s/{space_id}/api/detection_engine/attacks/status
Refer to Spaces for more information.
Set the workflow status of one or more attack discovery alerts by IDs, optionally cascading the status to their related detection alerts.
POST
/api/detection_engine/attacks/status
curl \
--request POST 'https://localhost:5601/api/detection_engine/attacks/status' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '"{\n \"ids\": [\n \"80e1383f856e67c1b7f7a1634744fa6d66b6e2ef7aa26d226e57afb5a7b2b4a1\"\n ],\n \"status\": \"acknowledged\"\n}"'
Request examples
By
{
"ids": [
"80e1383f856e67c1b7f7a1634744fa6d66b6e2ef7aa26d226e57afb5a7b2b4a1"
],
"status": "acknowledged"
}
{
"ids": [
"80e1383f856e67c1b7f7a1634744fa6d66b6e2ef7aa26d226e57afb5a7b2b4a1"
],
"reason": "false_positive",
"status": "closed"
}
{
"ids": [
"80e1383f856e67c1b7f7a1634744fa6d66b6e2ef7aa26d226e57afb5a7b2b4a1"
],
"status": "closed",
"update_related_alerts": true
}
Response examples (200)
{
"batches": 1,
"deleted": 0,
"failures": [],
"noops": 0,
"requests_per_second": -1,
"retries": {
"bulk": 0,
"search": 0
},
"throttled_millis": 0,
"throttled_until_millis": 0,
"timed_out": false,
"took": 81,
"total": 1,
"updated": 1,
"version_conflicts": 0
}
Response examples (400)
{
"error": "Bad Request",
"message": "[request body].ids: at least one attack id is required to update status",
"statusCode": 400
}
Response examples (401)
{
"error": "Unauthorized",
"message": "[security_exception\n\tRoot causes:\n\t\tsecurity_exception: unable to authenticate user [elastic] for REST request [/_security/_authenticate]]: unable to authenticate user [elastic] for REST request [/_security/_authenticate]",
"statusCode": 401
}
Response examples (500)
{
"message": "Internal Server Error",
"status_code": 500
}