Isolate an endpoint
Deprecated
Spaces method and path for this operation:
post /s/{space_id}/api/endpoint/isolate
Refer to Spaces for more information.
Isolate an endpoint from the network.
This URL will return a 308 permanent redirect to POST <kibana host>:<port>/api/endpoint/action/isolate.
Body
Required
-
List of agent types to retrieve. Defaults to
endpoint.Values are
endpoint,sentinel_one,crowdstrike, ormicrosoft_defender_endpoint. -
A list of alerts ids.
At least
1element. Minimum length of each is1. -
Case IDs to be updated (cannot contain empty strings)
At least
1element. Minimum length of each is1. -
Optional comment
-
List of endpoint IDs (cannot contain empty strings)
At least
1element. Minimum length of each is1. -
Optional parameters object
POST
/api/endpoint/isolate
curl \
--request POST 'https://localhost:5601/api/endpoint/isolate' \
--header "Authorization: $API_KEY" \
--header "Content-Type: application/json" \
--data '{"agent_type":"endpoint","alert_ids":["string"],"case_ids":["case-id-1","case-id-2"],"comment":"This is a comment","endpoint_ids":["endpoint-id-1","endpoint-id-2"],"parameters":{}}'