| Field | Required | Accepted Values |
|---|---|---|
status_progress |
No | 'New', 'In Progress', 'Resolved'. Additional custom statuses may be configured per tenant and case domain. |
resolve_reason |
Required when resolving | 'Resolved - Known Issue', 'Resolved - Duplicate Case', 'Resolved - False Positive', 'Resolved - Other', 'Resolved - True Positive', 'Resolved - Security Testing'. Additional values may be available depending on tenant configuration. Must be provided when status_progress is 'Resolved'. Cannot be provided otherwise. Automatically cleared when status changes away from 'Resolved'. |
resolve_comment |
No | Free-text string. Only applicable when status_progress is 'Resolved'. Cannot be provided otherwise. Automatically cleared when status changes away from 'Resolved'. |
user_severity |
No | 'low', 'medium', 'high', 'critical'. Use an empty string "" to clear. |
assigned_user |
No | Valid Cortex XDR email address. |
notes |
No | Free-text string. |
| Custom fields | No | Pass custom field name as key directly in update_data. Accepted values depend on field configuration. |
Required license: Cortex XSIAM Premium or Cortex XSIAM Enterprise or Cortex XSIAM NG SIEM or Cortex XSIAM Enterprise Plus.
case-id
Integer
required
Numeric ID of the case to update
Numeric ID of the case to update
56
Authorization
String
required
{api_key}
{api_key}
authorization_example
x-xdr-auth-id
String
required
{api_key_id}
{api_key_id}
xXdrAuthId_example
curl -X 'POST'
-H
'Accept: application/json'
-H
'Content-Type: application/json'
-H
'Authorization: authorization_example'
-H
'x-xdr-auth-id: xXdrAuthId_example'
'https://api-yourfqdn/public_api/v1/case/update/{case-id}'
-d
''
import http.client
conn = http.client.HTTPSConnection("api-yourfqdn")
payload = "{\"request_data\":{\"update_data\":{\"status_progress\":\"Resolved\",\"resolve_reason\":\"Resolved - Other\",\"resolve_comment\":\"Resolved via public API.\",\"notes\":\"Investigation complete, no further action needed.\",\"user_severity\":\"high\",\"assigned_user\":\"john_doe@domain.com\",\"property1\":null,\"property2\":null}}}"
headers = {
'Authorization': "SOME_STRING_VALUE",
'x-xdr-auth-id': "SOME_STRING_VALUE",
'content-type': "application/json"
}
conn.request("POST", "/public_api/v1/case/update/%7Bcase-id%7D", payload, headers)
res = conn.getresponse()
data = res.read()
print(data.decode("utf-8"))require 'uri'
require 'net/http'
require 'openssl'
url = URI("https://api-yourfqdn/public_api/v1/case/update/%7Bcase-id%7D")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
http.verify_mode = OpenSSL::SSL::VERIFY_NONE
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'SOME_STRING_VALUE'
request["x-xdr-auth-id"] = 'SOME_STRING_VALUE'
request["content-type"] = 'application/json'
request.body = "{\"request_data\":{\"update_data\":{\"status_progress\":\"Resolved\",\"resolve_reason\":\"Resolved - Other\",\"resolve_comment\":\"Resolved via public API.\",\"notes\":\"Investigation complete, no further action needed.\",\"user_severity\":\"high\",\"assigned_user\":\"john_doe@domain.com\",\"property1\":null,\"property2\":null}}}"
response = http.request(request)
puts response.read_bodyconst data = JSON.stringify({
"request_data": {
"update_data": {
"status_progress": "Resolved",
"resolve_reason": "Resolved - Other",
"resolve_comment": "Resolved via public API.",
"notes": "Investigation complete, no further action needed.",
"user_severity": "high",
"assigned_user": "john_doe@domain.com",
"property1": null,
"property2": null
}
}
});
const xhr = new XMLHttpRequest();
xhr.withCredentials = true;
xhr.addEventListener("readystatechange", function () {
if (this.readyState === this.DONE) {
console.log(this.responseText);
}
});
xhr.open("POST", "https://api-yourfqdn/public_api/v1/case/update/%7Bcase-id%7D");
xhr.setRequestHeader("Authorization", "SOME_STRING_VALUE");
xhr.setRequestHeader("x-xdr-auth-id", "SOME_STRING_VALUE");
xhr.setRequestHeader("content-type", "application/json");
xhr.send(data);HttpResponse<String> response = Unirest.post("https://api-yourfqdn/public_api/v1/case/update/%7Bcase-id%7D")
.header("Authorization", "SOME_STRING_VALUE")
.header("x-xdr-auth-id", "SOME_STRING_VALUE")
.header("content-type", "application/json")
.body("{\"request_data\":{\"update_data\":{\"status_progress\":\"Resolved\",\"resolve_reason\":\"Resolved - Other\",\"resolve_comment\":\"Resolved via public API.\",\"notes\":\"Investigation complete, no further action needed.\",\"user_severity\":\"high\",\"assigned_user\":\"john_doe@domain.com\",\"property1\":null,\"property2\":null}}}")
.asString();import Foundation
let headers = [
"Authorization": "SOME_STRING_VALUE",
"x-xdr-auth-id": "SOME_STRING_VALUE",
"content-type": "application/json"
]
let parameters = ["request_data": ["update_data": [
"status_progress": "Resolved",
"resolve_reason": "Resolved - Other",
"resolve_comment": "Resolved via public API.",
"notes": "Investigation complete, no further action needed.",
"user_severity": "high",
"assigned_user": "john_doe@domain.com",
"property1": ,
"property2":
]]] as [String : Any]
let postData = JSONSerialization.data(withJSONObject: parameters, options: [])
let request = NSMutableURLRequest(url: NSURL(string: "https://api-yourfqdn/public_api/v1/case/update/%7Bcase-id%7D")! as URL,
cachePolicy: .useProtocolCachePolicy,
timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data
let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
if (error != nil) {
print(error)
} else {
let httpResponse = response as? HTTPURLResponse
print(httpResponse)
}
})
dataTask.resume()<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api-yourfqdn/public_api/v1/case/update/%7Bcase-id%7D",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "{\"request_data\":{\"update_data\":{\"status_progress\":\"Resolved\",\"resolve_reason\":\"Resolved - Other\",\"resolve_comment\":\"Resolved via public API.\",\"notes\":\"Investigation complete, no further action needed.\",\"user_severity\":\"high\",\"assigned_user\":\"john_doe@domain.com\",\"property1\":null,\"property2\":null}}}",
CURLOPT_HTTPHEADER => [
"Authorization: SOME_STRING_VALUE",
"content-type: application/json",
"x-xdr-auth-id: SOME_STRING_VALUE"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}CURL *hnd = curl_easy_init();
curl_easy_setopt(hnd, CURLOPT_CUSTOMREQUEST, "POST");
curl_easy_setopt(hnd, CURLOPT_URL, "https://api-yourfqdn/public_api/v1/case/update/%7Bcase-id%7D");
struct curl_slist *headers = NULL;
headers = curl_slist_append(headers, "Authorization: SOME_STRING_VALUE");
headers = curl_slist_append(headers, "x-xdr-auth-id: SOME_STRING_VALUE");
headers = curl_slist_append(headers, "content-type: application/json");
curl_easy_setopt(hnd, CURLOPT_HTTPHEADER, headers);
curl_easy_setopt(hnd, CURLOPT_POSTFIELDS, "{\"request_data\":{\"update_data\":{\"status_progress\":\"Resolved\",\"resolve_reason\":\"Resolved - Other\",\"resolve_comment\":\"Resolved via public API.\",\"notes\":\"Investigation complete, no further action needed.\",\"user_severity\":\"high\",\"assigned_user\":\"john_doe@domain.com\",\"property1\":null,\"property2\":null}}}");
CURLcode ret = curl_easy_perform(hnd);var client = new RestClient("https://api-yourfqdn/public_api/v1/case/update/%7Bcase-id%7D");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "SOME_STRING_VALUE");
request.AddHeader("x-xdr-auth-id", "SOME_STRING_VALUE");
request.AddHeader("content-type", "application/json");
request.AddParameter("application/json", "{\"request_data\":{\"update_data\":{\"status_progress\":\"Resolved\",\"resolve_reason\":\"Resolved - Other\",\"resolve_comment\":\"Resolved via public API.\",\"notes\":\"Investigation complete, no further action needed.\",\"user_severity\":\"high\",\"assigned_user\":\"john_doe@domain.com\",\"property1\":null,\"property2\":null}}}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);request_dataobject
update_dataobject
status_progressstringStatus to set on the case. Built-in values: 'New', 'In Progress', 'Resolved'. Values are case-insensitive. Additional custom statuses may be configured per tenant and case domain. If an invalid status is provided, the API will return an error listing the valid options.
Status to set on the case. Built-in values: 'New', 'In Progress', 'Resolved'. Values are case-insensitive. Additional custom statuses may be configured per tenant and case domain. If an invalid status is provided, the API will return an error listing the valid options.
"Resolved"resolve_reasonstring (Enum)Resolution reason when status_progress is set to 'Resolved'. Required when resolving a case. The built-in values listed below may vary per tenant and case domain; additional custom resolution reasons may also be available. If an invalid value is provided, the API will return an error listing the valid options for that specific case.
Resolution reason when status_progress is set to 'Resolved'. Required when resolving a case. The built-in values listed below may vary per tenant and case domain; additional custom resolution reasons may also be available. If an invalid value is provided, the API will return an error listing the valid options for that specific case.
"Resolved - Other"resolve_commentstringFree-text comment to add when resolving the case. Only applicable when status_progress is set to 'Resolved'.
Free-text comment to add when resolving the case. Only applicable when status_progress is set to 'Resolved'.
"Resolved via public API."notesstringFree-text notes associated with the case. Can be set independently of status changes.
Free-text notes associated with the case. Can be set independently of status changes.
"Investigation complete, no further action needed."user_severitystring (Enum)User-defined severity override (lowercase). Use an empty string to clear the severity. Allowed values: 'low', 'medium', 'high', 'critical'.
User-defined severity override (lowercase). Use an empty string to clear the severity. Allowed values: 'low', 'medium', 'high', 'critical'.
"high"assigned_userstringEmail address of the user to assign the case to. Must be a valid Cortex XDR user email.
Email address of the user to assign the case to. Must be a valid Cortex XDR user email.
"john_doe@domain.com"Additional propertiesobjectCustom field values. Use the custom field name as the property key.
Custom field values. Use the custom field name as the property key.
{
"request_data": {
"update_data": {
"status_progress": "Resolved",
"resolve_reason": "Resolved - Other",
"resolve_comment": "Resolved via public API.",
"notes": "Investigation complete, no further action needed.",
"user_severity": "high",
"assigned_user": "john_doe@domain.com"
}
}
}