assignIncident
The assignIncident method enables bulk assignment and reassignment of EDR and XDR incidents to eligible GravityZone users. Assignees can also be removed through the same method.
Important
You must have View and Analyze Data rights and a license that includes access to incidents to use this method.
Parameters
Parameter | Description | Included in request | Type | Value requirements |
|---|---|---|---|---|
| The type of the target incidents. | Mandatory | String | Possible values:
|
| A list containing the internal IDs of the incidents to which a GravityZone user should be assigned. Each incident ID corresponds to the | Mandatory | Array of strings | You must have access to all incidents specified in this parameter. Each ID must be a 24-character hexadecimal string. The array must contain between 1 and 1000 elements. TipThe value of each incident ID can be obtained from GravityZone Control Center as follows:
|
| The ID of the GravityZone user to be assigned to the incidents specified in When set to | Mandatory | String or | Must be a 24-character hexadecimal string representing an existing user ID within your company. The specified user must not already be assigned to any of the incidents listed in |
These are common parameters, available across all public API methods:
Parameter | Description | Included in request | Type | Value requirements |
|---|---|---|---|---|
| This parameter adds an identifier to the request, linking it to its corresponding response. The target replies with the same value in the response, allowing easy call tracking. | Mandatory | String | No additional requirements. |
| The name of the method you are using to send the request. | Mandatory | String | Must be a valid method name. |
| The version of JSON-RPC used by the request and the response. | Mandatory | String | The only possible value is |
| An object containing the configuration of the request. | Mandatory | Object | No additional requirements. |
Return value
This method returns a Boolean value indicating whether the user specified by assigneeId was successfully assigned to all incidents referenced in incidentIds.
Important
The #DEMO incident cannot be assigned to a user. Attempting to assign it through the API will result in an error.
All incident assignment changes are tracked in both the Incident history panel and the User activity page from GravityZone Control Center. Actions performed by MDR analysts are attributed to an MDR Service account.
Example
Request:
{
"params": {
"type": "incidents",
"incidentIds": [
"6a56324d89d2462496622cda"
],
"assigneeId": "6a56324d89d2462496622cdb"
},
"jsonrpc": "2.0",
"method": "assignIncident",
"id": "0df7568c-59c1-48e0-a31b-18d83e6d9810"
}Response:
{
"id": "0df7568c-59c1-48e0-a31b-18d83e6d9810",
"jsonrpc": "2.0",
"result": true
}