change_alert_status
Change the status of one or more alerts to Open, In Review, or Completed to manage incident response workflow.
Instructions
Change the status of one or more alerts. status codes: 2=Open, 3=In Review, 5=Completed. (To mark a false positive use mark_alert_false_positive.) server: which configured server to target (default active/default).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| server | No | ||
| status | Yes | ||
| alert_ids | Yes | ||
| observation | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |