triage_endpoint
Initiate forensics triage on specified agents to collect endpoint data for security analysis. Supports up to 10 concurrent triage actions.
Instructions
Initiate Forensics Triage
Initiate forensics triage for the specified agents.
Maximum of 10 concurrent triage actions at a time.
Specified agents must have Forensics License enabled.
Specified agents must be the same OS, Windows or macOS, but not a mixture of both.
Specified configuration must have type "Online = True".
Required license: Cortex XSIAM Premium or
[POST /public_api/v1/triage_endpoint] · Endpoint Management
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| request_data | Yes |