Skip to content

removeEvidenceFromCase

MUTATIONremoveEvidenceFromCase

Cases GraphQL API · Mutations

removeEvidenceFromCase will remove evidence from an existing case. The response will include the evidence that the service will attempt to remove from the case. Removing evidence from cases is an asynchronous operation. It will typically finish pretty quickly, but removed detections/events will can remain attached to the case until the async job is fully complete. The processing status, that is found on the case type will reflect the state of the processing job. Once the status is set to 'SUCCESS' the background job is complete and requesting the case will only return evidence that was not removed. Adding, removing or updating evidence (closing a case) while other jobs are processing for a given case will cause the jobs to queue. Jobs will be worked through in the order they were received.

Arguments

Argument Type Description
input RemoveEvidenceFromCaseInput!

Returns

RemoveEvidenceFromCaseResult

Request samples

curl -X POST "https://api.taegis.sophos.com/graphql" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"query\": \"mutation RemoveEvidenceFromCase(\$input: RemoveEvidenceFromCaseInput!) { removeEvidenceFromCase(input: \$input) { caseId detectionIds eventIds assetIds searchQueries } }\",
  \"variables\": {
    \"input\": {
      \"caseId\": \"<caseId>\"
    }
  }
}"

import requests

response = requests.post(
    "https://api.taegis.sophos.com/graphql",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'query': 'mutation RemoveEvidenceFromCase($input: '
             'RemoveEvidenceFromCaseInput!) { removeEvidenceFromCase(input: '
             '$input) { caseId detectionIds eventIds assetIds searchQueries } '
             '}',
    'variables': {'input': {'caseId': '<caseId>'}}},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "query": "mutation RemoveEvidenceFromCase($input: RemoveEvidenceFromCaseInput!) { removeEvidenceFromCase(input: $input) { caseId detectionIds eventIds assetIds searchQueries } }",
  "variables": {
    "input": {
      "caseId": "<caseId>"
    }
  }
}'
Invoke-RestMethod -Method POST -Uri "https://api.taegis.sophos.com/graphql" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api.taegis.sophos.com/graphql", strings.NewReader(`{
  "query": "mutation RemoveEvidenceFromCase($input: RemoveEvidenceFromCaseInput!) { removeEvidenceFromCase(input: $input) { caseId detectionIds eventIds assetIds searchQueries } }",
  "variables": {
    "input": {
      "caseId": "<caseId>"
    }
  }
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api.taegis.sophos.com/graphql", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "query": "mutation RemoveEvidenceFromCase($input: RemoveEvidenceFromCaseInput!) { removeEvidenceFromCase(input: $input) { caseId detectionIds eventIds assetIds searchQueries } }",
  "variables": {
    "input": {
      "caseId": "<caseId>"
    }
  }
}),
});
const data = await response.json();
console.log(data);