remove_endpoints_from_case
Remove specific endpoints from a case using filters such as asset name, IP address, platform, or tags to streamline incident response and case management.
Instructions
Remove endpoints from a case based on specified filters
Input Schema
Name | Required | Description | Default |
---|---|---|---|
filter | No | Filter object to specify which endpoints to remove | |
id | Yes | ID of the case to remove endpoints from |
Input Schema (JSON Schema)
{
"properties": {
"filter": {
"description": "Filter object to specify which endpoints to remove",
"properties": {
"excludedEndpointIds": {
"description": "Array of endpoint IDs to exclude",
"items": {
"type": "string"
},
"type": "array"
},
"groupFullPath": {
"description": "Filter by full group path",
"type": "string"
},
"groupId": {
"description": "Filter by group ID",
"type": "string"
},
"includedEndpointIds": {
"description": "Array of endpoint IDs to remove",
"items": {
"type": "string"
},
"type": "array"
},
"ipAddress": {
"description": "Filter by IP address",
"type": "string"
},
"isolationStatus": {
"description": "Filter by isolation status (e.g., [\"isolated\"])",
"items": {
"type": "string"
},
"type": "array"
},
"issue": {
"description": "Filter by issue",
"type": "string"
},
"managedStatus": {
"description": "Filter by managed status (e.g., [\"managed\"])",
"items": {
"type": "string"
},
"type": "array"
},
"name": {
"description": "Filter by asset name",
"type": "string"
},
"onlineStatus": {
"description": "Filter by online status (e.g., [\"online\"])",
"items": {
"type": "string"
},
"type": "array"
},
"organizationIds": {
"description": "Organization IDs filter. Defaults to [0]",
"items": {
"oneOf": [
{
"type": "number"
},
{
"type": "string"
}
]
},
"type": "array"
},
"platform": {
"description": "Filter by platform (e.g., [\"windows\"])",
"items": {
"type": "string"
},
"type": "array"
},
"policy": {
"description": "Filter by policy",
"type": "string"
},
"searchTerm": {
"description": "Optional search term",
"type": "string"
},
"tags": {
"description": "Filter by tags",
"items": {
"type": "string"
},
"type": "array"
},
"version": {
"description": "Filter by agent version",
"type": "string"
}
},
"required": [],
"type": "object"
},
"id": {
"description": "ID of the case to remove endpoints from",
"type": "string"
}
},
"required": [
"id"
],
"type": "object"
}