Actions56
- Acquisition Actions
- Asset Actions
- Baseline Actions
- Case Actions
- InterACT Actions
- Organization Actions
- Repository Actions
- Task Actions
- Triage Rule Actions
- User Actions
Baseline → Acquire Baseline
AI-generatedOverview
This node operation acquires a baseline for a specified organization and case within the Binalyze AIR system. It allows users to filter endpoints based on various criteria such as endpoint IDs, name, group, IP address, isolation status, issues, management status, online status, platform, policy, tags, and version. This operation is useful for security analysts or IT administrators who need to capture a baseline snapshot of endpoint configurations and statuses for further analysis or comparison.
Use Case Examples
- Acquiring a baseline for all endpoints in a specific organization and case filtered by platform and online status.
- Capturing a baseline excluding certain endpoint IDs and filtering by isolation status to focus on isolated devices.
Properties
| Name | Meaning |
|---|---|
| Organization | The organization to use for baseline acquisition, selectable by list or by ID. |
| Case | The case for baseline acquisition, selectable by list or by ID. |
| Endpoint Filters (Required) | Filters to target specific endpoints for baseline acquisition. At least one filter must be defined. |
Output
JSON
baselineId- The unique identifier of the acquired baseline.status- The status of the baseline acquisition process.details- Additional details or metadata about the acquired baseline.
Dependencies
- Requires an API key credential for authentication with the Binalyze AIR API.
Troubleshooting
- Ensure that the organization ID and case ID are valid and correctly formatted as per the validation rules.
- At least one endpoint filter must be defined; otherwise, the operation will not proceed.
- If the API authentication fails, verify that the API key credential is correctly configured and has the necessary permissions.
- Check network connectivity to the Binalyze AIR API endpoint if requests time out or fail.