Update SecObserve Record
secobserve_updateUpdate a SecObserve resource record by changing specified fields. PATCH merges changed fields; PUT replaces and blanks omitted fields for full control.
Instructions
Change fields of an existing SecObserve record.
Defaults to PATCH so omitted fields keep their values; set replace=True only when you intend PUT semantics, which blanks anything you leave out.
To change an observation's severity, status or priority, do NOT use this tool -- use secobserve_assess_observation, which writes an observation log, honours the approval workflow and keeps the audit trail intact.
Args: resource (str): Resource name supporting update. id (int): Primary key of the record. data (dict): Fields to change. replace (bool): False = PATCH (default), True = PUT. response_format (ResponseFormat): "markdown" or "json".
Returns: str: The updated record as markdown or JSON.
Examples: - Use when: "disable general rule 4" -> resource="general_rules", id=4, data={"enabled": False} - Use when: "point product 12 at license policy 3" -> resource="products", id=12, data={"license_policy": 3} - Don't use when: assessing an observation (use secobserve_assess_observation).
Error Handling: Refused when the resource has no update operation or the server is read-only. 400 responses carry the API's field-level validation detail.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | Numeric primary key of the record to update. | |
| data | Yes | Fields to change. | |
| replace | No | False sends PATCH (merge, the safe default). True sends PUT and blanks omitted fields. | |
| resource | Yes | Resource name that supports update. | |
| response_format | No | 'markdown' for reading, 'json' for further processing. | markdown |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |