AIR icon

AIR

Manage Binalyze AIR resources

Baseline → Acquire Baseline

AI-generated

Overview

This node operation acquires a baseline for a specified organization and case within the Binalyze AIR system. It allows users to filter endpoints based on various criteria such as endpoint IDs, name, group, IP address, isolation status, issues, management status, online status, platform, policy, tags, and version. This operation is useful for security analysts or IT administrators who need to capture a baseline snapshot of endpoint configurations and statuses for further analysis or comparison.

Use Case Examples

  1. Acquiring a baseline for all endpoints in a specific organization and case filtered by platform and online status.
  2. Capturing a baseline excluding certain endpoint IDs and filtering by isolation status to focus on isolated devices.

Properties

Name Meaning
Organization The organization to use for baseline acquisition, selectable by list or by ID.
Case The case for baseline acquisition, selectable by list or by ID.
Endpoint Filters (Required) Filters to target specific endpoints for baseline acquisition. At least one filter must be defined.

Output

JSON

  • baselineId - The unique identifier of the acquired baseline.
  • status - The status of the baseline acquisition process.
  • details - Additional details or metadata about the acquired baseline.

Dependencies

  • Requires an API key credential for authentication with the Binalyze AIR API.

Troubleshooting

  • Ensure that the organization ID and case ID are valid and correctly formatted as per the validation rules.
  • At least one endpoint filter must be defined; otherwise, the operation will not proceed.
  • If the API authentication fails, verify that the API key credential is correctly configured and has the necessary permissions.
  • Check network connectivity to the Binalyze AIR API endpoint if requests time out or fail.

Discussion