REST API call to assign label to an incident

Prev Next

Using this REST API call, you can assign a label to an incident.

PUT request URL

https://<epo_server_name:port>/rest/dlp/incidents/attachLabel/{incidentId}?incidentNature={incidentNature}&labelName={labelName}

Where

  • epo_server_name:port is the server IP address and port number.

  • {incidentId} unique identifier of an incident.

  • incidentNature={n} n can be 1, 2, or 3 for incidents of different data vectors (incident nature).

  • labelName label text.

Request Parameters

Parameter name

Description

Required

Values

Authorization

User credentials for ePO - On-prem.

Required

{incidentId}

Unique identifier of an incident.

Required

Number

labelName

Label assigned to the incident.

Required

String

incidentNature={n}

Incidents generated for data-in-use/motion and data-at-rest can have the same incident IDs. Specify n to differentiate the incident nature. Based on the data vectors, {n} can be:

  • 1 = Retrieve incident details generated for data-in-use/motion

  • 2 = Reserved to retrieve data-at-rest - Endpoint Discovery incidents and can be used when support for Endpoint Discovery custom attributes is added into the product

  • 3 = Retrieve incident details generated for data-at-rest - Network

Required

Number

Using these sample API calls, "testLabel" is assigned to incident 209 generated for data-in-use/motion.

Sample PUT request URL

https://172.27.108.53:8443/rest/dlp/incidents/attachLabel/209?incidentNature=1&labelName=testLabel

Sample cURL command

curl -k -G -v -X PUT "https://172.27.108.53:8443/rest/dlp/incidents/attachLabel/209" --data-urlencode "incidentNature=1" --data-urlencode "labelName=testLabel" -u '<user>:<password>'

Response parameters

Element

Description

Data type

Message

Shows whether the label is assigned successfully to the required incident.

String

Sample response

Sucess: label has been attached

Status and error codes

List of HTTP status codes returned for the query.

Code

Description

200 OK

Returns a successful message for the assigned label.

400 Bad Request

Returns a bad request if:

  • labelName is missing.

  • labelName contains invalid characters.

  • incidentNature is missing.

  • incidentNature has a non-numeric value.

  • incidentNature is not either 1 or 3.

404 Not Found

Incorrect ePO - On-prem URL.

405 Not Allowed

Incident is read only.

500 Internal Server Error

An error on the server side that failed the request. See the ePO - On-prem orion.log file for more details about the error.