Skip to main content

assignIncident

The assignIncident method enables bulk assignment and reassignment of EDR and XDR incidents to eligible GravityZone users. Assignees can also be removed through the same method.

Important

You must have View and Analyze Data rights and a license that includes access to incidents to use this method.

Parameters

Parameter

Description

Included in request

Type

Value requirements

type

The type of the target incidents.

Mandatory

String

Possible values:

  • incidents: Endpoint incidents from GravityZone Control Center.

  • extendedIncidents: Organization incidents from GravityZone Control Center.

incidentIds

A list containing the internal IDs of the incidents to which a GravityZone user should be assigned.

Each incident ID corresponds to the incident_id parameter from the New Incident and New extended incident event types.

Mandatory

Array of strings

You must have access to all incidents specified in this parameter.

Each ID must be a 24-character hexadecimal string.

The array must contain between 1 and 1000 elements.

Tip

The value of each incident ID can be obtained from GravityZone Control Center as follows:

  1. Log in to GravityZone Control Center.

  2. Go to the Incidents page and locate the incident to which you want to assign a GravityZone user.

  3. Click the incident ID.

    The incident details page opens automatically, and its URL contains the value of the incidentId parameter.

    Example

    In the URL https://cloudgz.gravityzone.bitdefender.com/#!/incidents/view/6a92240ddbb8645d80cea23e, the incidentId is 6a92240ddbb8645d80cea23e.

assigneeId

The ID of the GravityZone user to be assigned to the incidents specified in incidentIds.

When set to null, the current assignee is removed from all incidents specified in incidentIds.

Mandatory

String or null

Must be a 24-character hexadecimal string representing an existing user ID within your company. The specified user must not already be assigned to any of the incidents listed in incidentIds.

These are common parameters, available across all public API methods:

Parameter

Description

Included in request

Type

Value requirements

id

This parameter adds an identifier to the request, linking it to its corresponding response.

The target replies with the same value in the response, allowing easy call tracking.

Mandatory

String

No additional requirements.

method

The name of the method you are using to send the request.

Mandatory

String

Must be a valid method name.

jsonrpc

The version of JSON-RPC used by the request and the response.

Mandatory

String

The only possible value is 2.0.

params

An object containing the configuration of the request.

Mandatory

Object

No additional requirements.

Return value

This method returns a Boolean value indicating whether the user specified by assigneeId was successfully assigned to all incidents referenced in incidentIds.

Important

  • The #DEMO incident cannot be assigned to a user. Attempting to assign it through the API will result in an error.

  • All incident assignment changes are tracked in both the Incident history panel and the User activity page from GravityZone Control Center. Actions performed by MDR analysts are attributed to an MDR Service account.

Example

Request:

{
    "params": {
        "type": "incidents",
        "incidentIds": [
            "6a56324d89d2462496622cda"
        ],
        "assigneeId": "6a56324d89d2462496622cdb"
    },
    "jsonrpc": "2.0",
    "method": "assignIncident",
    "id": "0df7568c-59c1-48e0-a31b-18d83e6d9810"
}

Response:

{
    "id": "0df7568c-59c1-48e0-a31b-18d83e6d9810",
    "jsonrpc": "2.0",
    "result": true
}