Actions56
- Acquisition Actions
- Asset Actions
- Baseline Actions
- Case Actions
- InterACT Actions
- Organization Actions
- Repository Actions
- Task Actions
- Triage Rule Actions
- User Actions
Case → Get Endpoints
AI-generatedOverview
This node operation retrieves endpoint information related to a specific case within an organization. It is useful for scenarios where users need to gather detailed data about endpoints involved in a case, such as in incident response or forensic investigations. For example, a security analyst might use this operation to fetch all endpoints associated with a case to analyze their status or activities.
Use Case Examples
- Fetching all endpoints linked to a case to review their current state.
- Retrieving endpoint details to correlate with case activities for investigation.
Properties
| Name | Meaning |
|---|---|
| Organization | The organization to filter cases by, specified by ID, name, or selected from a list. This is required to scope the case endpoints retrieval. |
| Case | The specific case to operate on, identified by ID or selected from a list. This is required to specify which case's endpoints to retrieve. |
Output
JSON
endpoints- List of endpoints associated with the specified case.
Dependencies
- Requires an API key credential for authentication to the AIR platform.
Troubleshooting
- Ensure the organization ID or name is correctly specified and accessible by the API key used.
- Verify the case ID is valid and belongs to the specified organization.
- Common errors include 'Unknown resource' if the resource parameter is incorrect, or authentication errors if the API key is invalid or missing.