Using this REST API call, you can deassign a label from an incident.
DELETE request URL
https://<epo_server_name:port>/rest/dlp/incidents/detachLabel/{incidentId}?incidentNature={incidentNature}&labelName={labelName}
Where
epo_server_name:portis the server IP address and port number.incidentNature={n}n can be 1, 2, or 3 for incidents of different data vectors (incident nature).labelNamelabel text{incidentId}unique identifier of an incident.
Request Parameters
Parameter name | Description | Required | Values |
|---|---|---|---|
Authorization | User credentials for ePO - On-prem. | Required | |
{incidentId} | Unique identifier of an incident. | Required | Number |
labelName | Label assigned to the incident. | Required | Number |
incidentNature={n} | Incidents generated for data-in-use/motion and data-at-rest can have the same incident IDs. Specify n to differentiate the incident nature. Based on the data vectors, {n} can be:
| Required | Number |
Using these sample API calls, you can deassign testLabel2 from incident 209 generated for data-in-use/motion.
Sample DELETE request URL
https://172.27.108.53:8443/rest/dlp/incidents/detachLabel/209?incidentNature=1&labelName=testLabel2
Sample cURL command
curl -k -G -v -X DELETE "https://172.27.108.53:8443/rest/dlp/incidents/detachLabel/205" --data-urlencode "incidentNature=1" --data-urlencode "labelName=testLabel" -u '<user>:<password>'
Response parameters
The response to this API call returns the list of resolution options that set for the specified incident nature.
Element | Description | Data type | |
|---|---|---|---|
Message | Shows whether the label is deassigned successfully for an incident. | String | |
Sample response
Sucess: label has been detached : testLabel2
Status and error codes
List of HTTP status codes returned for the query.
Code | Description |
|---|---|
200 OK | Returns a successful message for the deassigned label. |
400 Bad Request | Returns a bad request if:
|
404 Not Found | Incorrect ePO - On-prem URL. |
405 Not Allowed | Incident is read only. |
500 Internal Server Error | An error on the server side that failed the request. See the ePO - On-prem |