updateIncidentState
A valid Incident Orchestration license is required for this resource
Update Incident state
Input fields
ID!)
IncidentState!)
Return fields
ID!)
Id
ThreatClassification)
The classification of the incident, calculated by classifications of the threats and severity
Date)
Time when the incident database record was created
IncidentEscalation)
Escalation metadata
Date)
Time when the first threat was reported and the incident was created
Int!)
Count of related threats in the whole hoxhunt network
Boolean)
If incident has sensitive information
ID!)
Id
Date)
Time when the last threat was reported to the incident (can be used to track when a new threat is reported to the incident)
[IncidentNote])
Notes left for an incident
Organization!)
Organization that this incident happened in
ID!)
Organization ID
IncidentPolicy!)
Which incident policy created this incident
String!)
Link that can be used to view the incident in the Hoxhunt Respnse UI
[IncidentRuleMatch!]!)
Incident rules that have matched the incident @filterable @sortable
| Argument | Type | Description |
|---|---|---|
filter |
IncidentRuleMatch_filter
|
|
sort |
[IncidentRuleMatch_sort]
|
ThreatSeverity)
Incident severity
SocClassification)
Soc classification
IncidentState!)
Incident of the state, e.g. RESOLVED
Int!)
Count of related threats
ThreatMetaData)
Metadata about the threats in the incident
[Threat]!)
Threats related to the incident @filterable @paginatable @sortable
| Argument | Type | Description |
|---|---|---|
after |
ID
|
|
before |
ID
|
|
filter |
Threat_filter
|
|
first |
Int
|
|
last |
Int
|
|
search |
String
|
|
skip |
Int
|
|
sort |
[Threat_sort]
|
Date)
Time when the incident database record was last updated (update is not necessarily related to the incident itself)