Skip to content

Update many incident's editable fields, given a list of incident IDs

PATCH
/v1/incidents
object
One of:

PATCH /incidents/:id

object
assigned_to
string | null format: uuid
contained_date
string | null format: date-time
description
string | null
detected_date
string | null format: date-time
occurred_date
string | null format: date-time
responded_date
string | null format: date-time
severity
One of:
null
severity_reasoning
string | null
source
string | null
status
One of:
null
tags
array | null
threat_objectives
array | null

A relational struct that has a threat objective type and its relevancy to a risk.

object
created_date

The time that this relation was mutated

string | null format: date-time
relevance
One of:
null
threat_objective
required

The threat objective type

string
Allowed values: Sabotage Data Disclosure Extortion Customer Targeting Resource Hijacking Fraud
title
string | null
ids
Array<string>
default:
Example
INC-00001
tag_operation
One of:
null

Incidents updated

object
incidents
required
Array<object>

Core incident information for a view

object
comment_count
required
integer format: int64
incident
required

Relationship, core incident information

object
assigned_to
One of:
null
contained_date
string | null format: date-time
created_date
required
string format: date-time
description
required
string
detected_date
required
string format: date-time
id
required
string
Example
INC-00001
occurred_date
string | null format: date-time
opened_by
One of:
null
responded_date
string | null format: date-time
severity
One of:
null
severity_reasoning
string | null
source
string | null
status
required

The status of an incident

string
Allowed values: New In Progress Review Closed
title
required
string
updated_date
required
string format: date-time
risk_associations
required
Array<string>
tags
required
Array<object>
object
content
required
string
creator_id
required
string format: uuid
id
required
string format: uuid
org_id
string | null format: uuid
threat_objectives
required
Array<object>

A relational struct that has a threat objective type and its relevancy to a risk.

object
created_date

The time that this relation was mutated

string | null format: date-time
relevance
One of:
null
threat_objective
required

The threat objective type

string
Allowed values: Sabotage Data Disclosure Extortion Customer Targeting Resource Hijacking Fraud

Empty payload

Not found