removeEvidenceFromCase¶
MUTATIONremoveEvidenceFromCase
Cases GraphQL API · Mutations
removeEvidenceFromCase will remove evidence from an existing case. The response will include the evidence that the service will attempt to remove from the case. Removing evidence from cases is an asynchronous operation. It will typically finish pretty quickly, but removed detections/events will can remain attached to the case until the async job is fully complete. The processing status, that is found on the case type will reflect the state of the processing job. Once the status is set to 'SUCCESS' the background job is complete and requesting the case will only return evidence that was not removed. Adding, removing or updating evidence (closing a case) while other jobs are processing for a given case will cause the jobs to queue. Jobs will be worked through in the order they were received.
Request samples¶
curl -X POST "https://api.taegis.sophos.com/graphql" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
\"query\": \"mutation RemoveEvidenceFromCase(\$input: RemoveEvidenceFromCaseInput!) { removeEvidenceFromCase(input: \$input) { caseId detectionIds eventIds assetIds searchQueries } }\",
\"variables\": {
\"input\": {
\"caseId\": \"<caseId>\"
}
}
}"
import requests
response = requests.post(
"https://api.taegis.sophos.com/graphql",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
json={ 'query': 'mutation RemoveEvidenceFromCase($input: '
'RemoveEvidenceFromCaseInput!) { removeEvidenceFromCase(input: '
'$input) { caseId detectionIds eventIds assetIds searchQueries } '
'}',
'variables': {'input': {'caseId': '<caseId>'}}},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
"Content-Type" = "application/json"
}
$body = '{
"query": "mutation RemoveEvidenceFromCase($input: RemoveEvidenceFromCaseInput!) { removeEvidenceFromCase(input: $input) { caseId detectionIds eventIds assetIds searchQueries } }",
"variables": {
"input": {
"caseId": "<caseId>"
}
}
}'
Invoke-RestMethod -Method POST -Uri "https://api.taegis.sophos.com/graphql" -Headers $headers -Body $body -ContentType "application/json"
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
req, err := http.NewRequest("POST", "https://api.taegis.sophos.com/graphql", strings.NewReader(`{
"query": "mutation RemoveEvidenceFromCase($input: RemoveEvidenceFromCaseInput!) { removeEvidenceFromCase(input: $input) { caseId detectionIds eventIds assetIds searchQueries } }",
"variables": {
"input": {
"caseId": "<caseId>"
}
}
}`))
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api.taegis.sophos.com/graphql", {
method: "POST",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
body: JSON.stringify({
"query": "mutation RemoveEvidenceFromCase($input: RemoveEvidenceFromCaseInput!) { removeEvidenceFromCase(input: $input) { caseId detectionIds eventIds assetIds searchQueries } }",
"variables": {
"input": {
"caseId": "<caseId>"
}
}
}),
});
const data = await response.json();
console.log(data);