Demisto Incidents API
The Incidents API from Demisto — 1 operation(s) for incidents.
The Incidents API from Demisto — 1 operation(s) for incidents.
swagger: '2.0'
info:
description: 'This is the public REST API to integrate with the demisto server.
HTTP request can be sent using any HTTP-client.
For an example dedicated client take a look at: https://github.com/demisto/demisto-py.
Requests must include API-key that can be generated in the Demisto web client under ''Settings'' -> ''Integrations'' -> ''API keys''
Optimistic Locking and Versioning\:
When using Demisto REST API, you will need to make sure to work on the latest version of the item (incident, entry, etc.), otherwise, you will get a DB version error (which not allow you to override a newer item).
In addition, you can pass ''version\: -1'' to force data override (make sure that other users data might be lost).
Assume that Alice and Bob both read the same data from Demisto server, then they both changed the data, and then both tried to write the new versions back to the server. Whose changes should be saved? Alice’s? Bob’s?
To solve this, each data item in Demisto has a numeric incremental version.
If Alice saved an item with version 4 and Bob trying to save the same item with version 3, Demisto will rollback Bob request and returns a DB version conflict error.
Bob will need to get the latest item and work on it so Alice work will not get lost.
Example request using ''curl''\:
```
curl ''https://hostname:443/incidents/search'' -H ''content-type: application/json'' -H ''accept: application/json'' -H ''Authorization: <API Key goes here>'' --data-binary ''{"filter":{"query":"-status:closed -category:job","period":{"by":"day","fromValue":7}}}'' --compressed
```'
title: Demisto Apikeys Incidents API
version: 2.0.0
host: hostname:443
schemes:
- https
consumes:
- application/json
- application/xml
produces:
- application/json
security:
- api_key: []
- csrf_token: []
- x-xdr-auth-id: []
tags:
- name: Incidents
paths:
/incidents/search:
post:
description: 'This will search incidents across all indices
You can filter by multiple options'
summary: Search incidents by filter
operationId: searchIncidents
parameters:
- name: filter
in: body
required: true
schema:
$ref: '#/definitions/SearchIncidentsData'
responses:
'200':
description: incidentSearchResponse
schema:
type: object
properties:
data:
type: array
items:
$ref: '#/definitions/Incident'
total:
type: integer
tags:
- Incidents
definitions:
Incident:
description: 'An incident can be manually opened algorithmically or arrive from an external source like SIEM.
If you add fields, make sure to add them to the mapping as well.
If adding a user controlled field, please
make sure to add it to the CopyFrom and getIncidentFieldString (in services package) methods.'
type: object
title: Incident details.
properties:
ShardID:
type: integer
format: int64
account:
description: Account holds the tenant name so that slicing and dicing on the master can leverage bleve
type: string
x-go-name: Account
activated:
description: When was this activated
type: string
format: date-time
x-go-name: Activated
activatingingUserId:
description: The user that activated this investigation
type: string
x-go-name: ActivatingUserID
attachment:
description: Attachments
type: array
items:
$ref: '#/definitions/Attachment'
x-go-name: Attachments
autime:
description: AlmostUniqueTime is an attempt to have a unique sortable ID for an incident
type: integer
format: int64
x-go-name: AlmostUniqueTime
canvases:
description: Canvases of the incident
type: array
items:
type: string
x-go-name: Canvases
category:
description: Category
type: string
x-go-name: Category
closeNotes:
description: Notes for closing the incident
type: string
x-go-name: CloseNotes
closeReason:
description: The reason for closing the incident (select from existing predefined values)
type: string
x-go-name: ArchiveReason
closed:
description: When was this closed
type: string
format: date-time
x-go-name: Closed
closingUserId:
description: The user ID that closed this investigation
type: string
x-go-name: ClosingUserID
created:
description: When was this created
type: string
format: date-time
x-go-name: Created
details:
description: The details of the incident - reason, etc.
type: string
x-go-name: Details
droppedCount:
description: DroppedCount ...
type: integer
format: int64
x-go-name: DroppedCount
dueDate:
description: SLA
type: string
format: date-time
x-go-name: DueDate
hasRole:
description: Internal field to make queries on role faster
type: boolean
x-go-name: HasRole
id:
type: string
x-go-name: ID
investigationId:
description: Investigation that was opened as a result of the incoming event
type: string
x-go-name: Investigation
isPlayground:
description: IsPlayGround
type: boolean
x-go-name: IsPlayGround
labels:
description: Labels related to incident - each label is composed of a type and value
type: array
items:
$ref: '#/definitions/Label'
x-go-name: Labels
lastOpen:
type: string
format: date-time
x-go-name: LastOpen
linkedCount:
description: LinkedCount ...
type: integer
format: int64
x-go-name: LinkedCount
linkedIncidents:
description: LinkedIncidents incidents that were marked as linked by user
type: array
items:
type: string
x-go-name: LinkedIncidents
modified:
type: string
format: date-time
x-go-name: Modified
name:
description: Incident Name - given by user
type: string
x-go-name: Name
notifyTime:
description: Incdicates when last this field was changed with a value that supposed to send a notification
type: string
format: date-time
x-go-name: NotifyTime
occurred:
description: When this incident has really occurred
type: string
format: date-time
x-go-name: Occurred
openDuration:
description: Duration incident was open
type: integer
format: int64
x-go-name: OpenDuration
owner:
description: The user who owns this incident
type: string
x-go-name: OwnerID
parent:
description: Parent
type: string
x-go-name: Parent
phase:
description: Phase
type: string
x-go-name: Phase
playbookId:
description: The associated playbook for this incident
type: string
x-go-name: PlaybookID
previousRoles:
description: PreviousRoleName - do not change this field manually
type: array
items:
type: string
x-go-name: PreviousRoleName
rawCategory:
type: string
x-go-name: RawCategory
rawCloseReason:
description: The reason for closing the incident (select from existing predefined values)
type: string
x-go-name: RawArchiveReason
rawJSON:
type: string
x-go-name: RawJSONData
rawName:
description: Incident RawName
type: string
x-go-name: RawName
rawPhase:
description: RawPhase
type: string
x-go-name: RawPhase
rawType:
description: Incident raw type
type: string
x-go-name: RawType
reason:
description: The reason for the resolve
type: string
x-go-name: Reason
reminder:
description: When if at all to send a reminder
type: string
format: date-time
x-go-name: Reminder
roles:
description: The role assigned to this investigation
type: array
items:
type: string
x-go-name: RoleName
runStatus:
$ref: '#/definitions/RunStatus'
severity:
$ref: '#/definitions/Severity'
sla:
$ref: '#/definitions/SLAState'
sortValues:
type: array
items:
type: string
x-go-name: SortValues
sourceBrand:
description: SourceBrand ...
type: string
x-go-name: SourceBrand
sourceInstance:
description: SourceInstance ...
type: string
x-go-name: SourceInstance
status:
$ref: '#/definitions/IncidentStatus'
type:
description: Incident type
type: string
x-go-name: Type
version:
type: integer
format: int64
x-go-name: Versn
CustomFields:
$ref: '#/definitions/CustomFields'
additionalProperties:
type: object
x-go-package: github.com/demisto/server/domain
IncidentWrapper:
description: IncidentWrapper is an extension of the Incident entity, which includes an additional field of changed-status for the web client
type: object
properties:
ShardID:
type: integer
format: int64
account:
description: Account holds the tenant name so that slicing and dicing on the master can leverage bleve
type: string
x-go-name: Account
activated:
description: When was this activated
type: string
format: date-time
x-go-name: Activated
activatingingUserId:
description: The user that activated this investigation
type: string
x-go-name: ActivatingUserID
attachment:
description: Attachments
type: array
items:
$ref: '#/definitions/Attachment'
x-go-name: Attachments
autime:
description: AlmostUniqueTime is an attempt to have a unique sortable ID for an incident
type: integer
format: int64
x-go-name: AlmostUniqueTime
canvases:
description: Canvases of the incident
type: array
items:
type: string
x-go-name: Canvases
category:
description: Category
type: string
x-go-name: Category
changeStatus:
type: string
x-go-name: ChangeStatus
closeNotes:
description: Notes for closing the incident
type: string
x-go-name: CloseNotes
closeReason:
description: The reason for closing the incident (select from existing predefined values)
type: string
x-go-name: ArchiveReason
closed:
description: When was this closed
type: string
format: date-time
x-go-name: Closed
closingUserId:
description: The user ID that closed this investigation
type: string
x-go-name: ClosingUserID
created:
description: When was this created
type: string
format: date-time
x-go-name: Created
details:
description: The details of the incident - reason, etc.
type: string
x-go-name: Details
droppedCount:
description: DroppedCount ...
type: integer
format: int64
x-go-name: DroppedCount
dueDate:
description: SLA
type: string
format: date-time
x-go-name: DueDate
hasRole:
description: Internal field to make queries on role faster
type: boolean
x-go-name: HasRole
id:
type: string
x-go-name: ID
insights:
type: integer
format: uint64
x-go-name: Insights
investigationId:
description: Investigation that was opened as a result of the incoming event
type: string
x-go-name: Investigation
isPlayground:
description: IsPlayGround
type: boolean
x-go-name: IsPlayGround
labels:
description: Labels related to incident - each label is composed of a type and value
type: array
items:
$ref: '#/definitions/Label'
x-go-name: Labels
lastOpen:
type: string
format: date-time
x-go-name: LastOpen
linkedCount:
description: LinkedCount ...
type: integer
format: int64
x-go-name: LinkedCount
linkedIncidents:
description: LinkedIncidents incidents that were marked as linked by user
type: array
items:
type: string
x-go-name: LinkedIncidents
modified:
type: string
format: date-time
x-go-name: Modified
name:
description: Incident Name - given by user
type: string
x-go-name: Name
notifyTime:
description: Incdicates when last this field was changed with a value that supposed to send a notification
type: string
format: date-time
x-go-name: NotifyTime
occurred:
description: When this incident has really occurred
type: string
format: date-time
x-go-name: Occurred
openDuration:
description: Duration incident was open
type: integer
format: int64
x-go-name: OpenDuration
owner:
description: The user who owns this incident
type: string
x-go-name: OwnerID
parent:
description: Parent
type: string
x-go-name: Parent
phase:
description: Phase
type: string
x-go-name: Phase
playbookId:
description: The associated playbook for this incident
type: string
x-go-name: PlaybookID
previousRoles:
description: PreviousRoleName - do not change this field manually
type: array
items:
type: string
x-go-name: PreviousRoleName
rawCategory:
type: string
x-go-name: RawCategory
rawCloseReason:
description: The reason for closing the incident (select from existing predefined values)
type: string
x-go-name: RawArchiveReason
rawJSON:
type: string
x-go-name: RawJSONData
rawName:
description: Incident RawName
type: string
x-go-name: RawName
rawPhase:
description: RawPhase
type: string
x-go-name: RawPhase
rawType:
description: Incident raw type
type: string
x-go-name: RawType
reason:
description: The reason for the resolve
type: string
x-go-name: Reason
reminder:
description: When if at all to send a reminder
type: string
format: date-time
x-go-name: Reminder
roles:
description: The role assigned to this investigation
type: array
items:
type: string
x-go-name: RoleName
runStatus:
$ref: '#/definitions/RunStatus'
severity:
$ref: '#/definitions/Severity'
sla:
$ref: '#/definitions/SLAState'
sortValues:
type: array
items:
type: string
x-go-name: SortValues
sourceBrand:
description: SourceBrand ...
type: string
x-go-name: SourceBrand
sourceInstance:
description: SourceInstance ...
type: string
x-go-name: SourceInstance
status:
$ref: '#/definitions/IncidentStatus'
type:
description: Incident type
type: string
x-go-name: Type
version:
type: integer
format: int64
x-go-name: Versn
additionalProperties:
type: object
x-go-package: github.com/demisto/server/domain
IncidentStatus:
description: IncidentStatus is the status of the incident
type: number
format: double
x-go-package: github.com/demisto/server/domain
Duration:
description: 'A Duration represents the elapsed time between two instants
as an int64 nanosecond count. The representation limits the
largest representable duration to approximately 290 years.'
type: integer
format: int64
x-go-package: time
Order:
description: Order struct holds a sort field and the direction of sorting
type: object
properties:
asc:
type: boolean
x-go-name: Asc
field:
type: string
x-go-name: Field
fieldType:
type: string
x-go-name: FieldType
x-go-package: github.com/demisto/server/domain
SLAState:
description: SLAState is the incident sla at closure time
type: number
format: double
x-go-package: github.com/demisto/server/domain
CustomFields:
description: 'The keys should be the field''s display name all lower and without spaces. For example: Scan IP -> scanip
To get the actual key name you can also go to Demisto CLI and run /incident_add and look for the key that you would like to update'
type: object
title: CustomFields ...
additionalProperties:
type: object
x-go-package: github.com/demisto/server/domain
SearchIncidentsData:
type: object
title: SearchIncidentsData ...
properties:
filter:
$ref: '#/definitions/IncidentFilter'
userFilter:
type: boolean
x-go-name: FilterByUser
x-go-package: github.com/demisto/server/web
RunStatus:
description: RunStatus of a job
type: string
x-go-package: github.com/demisto/server/domain
Attachment:
type: object
title: Attachment ...
properties:
description:
type: string
x-go-name: Description
name:
type: string
x-go-name: Name
path:
type: string
x-go-name: Path
showMediaFile:
type: boolean
x-go-name: ShowMediaFile
type:
type: string
x-go-name: Type
x-go-package: github.com/demisto/server/domain
Label:
type: object
title: Label ...
properties:
type:
type: string
x-go-name: Type
value:
type: string
x-go-name: Value
x-go-package: github.com/demisto/server/domain
IncidentFilter:
type: object
title: IncidentFilter allows for very simple filtering.
properties:
Cache:
description: Cache of join functions
type: object
additionalProperties:
type: array
items:
type: string
andOp:
type: boolean
x-go-name: AndOp
category:
type: array
items:
type: string
x-go-name: Category
details:
type: string
x-go-name: Details
files:
type: array
items:
type: string
x-go-name: Files
firstIncidentInPage:
$ref: '#/definitions/IncidentWrapper'
fromActivatedDate:
type: string
format: date-time
x-go-name: FromActivatedDate
fromClosedDate:
type: string
format: date-time
x-go-name: FromClosedDate
fromDate:
type: string
format: date-time
x-go-name: FromDate
fromDateLicense:
type: string
format: date-time
x-go-name: FromDateLicenseVal
fromDueDate:
type: string
format: date-time
x-go-name: FromDueDate
fromReminder:
type: string
format: date-time
x-go-name: FromReminder
id:
type: array
items:
type: string
x-go-name: ID
includeTmp:
type: boolean
x-go-name: IncludeTmp
investigation:
type: array
items:
type: string
x-go-name: Investigation
lastIncidentInPage:
$ref: '#/definitions/IncidentWrapper'
level:
type: array
items:
$ref: '#/definitions/Severity'
x-go-name: Level
name:
type: array
items:
type: string
x-go-name: Name
nextPage:
type: boolean
x-go-name: NextPage
notCategory:
type: array
items:
type: string
x-go-name: NotCategory
notInvestigation:
type: array
items:
type: string
x-go-name: NotInvestigation
notStatus:
type: array
items:
$ref: '#/definitions/IncidentStatus'
x-go-name: NotStatus
page:
description: 0-based page
type: integer
format: int64
x-go-name: Page
parent:
type: array
items:
type: string
x-go-name: Parent
period:
$ref: '#/definitions/Period'
query:
type: string
x-go-name: Query
reason:
type: array
items:
type: string
x-go-name: Reason
searchAfter:
description: Efficient next page, pass max sort value from previous page
type: array
items:
type: string
x-go-name: SearchAfter
searchBefore:
description: Efficient prev page, pass min sort value from next page
type: array
items:
type: string
x-go-name: SearchBefore
sequentialPagesSearch:
type: boolean
x-go-name: SequentialPagesSearch
size:
description: Size is limited to 1000, if not passed it defaults to 0, and no results will return
type: integer
format: int64
x-go-name: Size
sort:
description: The sort order
type: array
items:
$ref: '#/definitions/Order'
x-go-name: Sort
status:
type: array
items:
$ref: '#/definitions/IncidentStatus'
x-go-name: Status
systems:
type: array
items:
type: string
x-go-name: Systems
timeFrame:
$ref: '#/definitions/Duration'
toActivatedDate:
type: string
format: date-time
x-go-name: ToActivatedDate
toClosedDate:
type: string
format: date-time
x-go-name: ToClosedDate
toDate:
type: string
format: date-time
x-go-name: ToDate
toDueDate:
type: string
format: date-time
x-go-name: ToDueDate
toReminder:
type: string
format: date-time
x-go-name: ToReminder
totalOnly:
type: boolean
x-go-name: TotalOnly
type:
type: array
items:
type: string
x-go-name: Type
urls:
type: array
items:
type: string
x-go-name: Urls
users:
type: array
items:
type: string
x-go-name: Users
x-go-package: github.com/demisto/server/repo/entities
Period:
type: object
title: Period holds the 'Period' query, such as last 3 days, last 6 hours, between 6 days from now until 3 days from now.
properties:
by:
description: By is used for legacty, and if exists it will override ByTo and ByFrom
type: string
x-go-name: By
byFrom:
type: string
x-go-name: ByFrom
byTo:
type: string
x-go-name: ByTo
field:
type: string
x-go-name: Field
fromValue:
type: string
format: duration
x-go-name: FromValue
toValue:
type: string
format: duration
x-go-name: ToValue
x-go-package: github.com/demisto/server/domain
Severity:
description: Severity is the incident severity
type: number
format: double
x-go-package: github.com/demisto/server/domain
securityDefinitions:
api_key:
type: apiKey
name: Authorization
in: header
csrf_token:
type: apiKey
name: X-XSRF-TOKEN
in: header
x-xdr-auth-id:
type: apiKey
name: x-xdr-auth-id
in: header