Skip to content

Update exclusion

PATCH/settings/exclusions/isolation/{exclusionId}

Endpoint API · Isolation Exclusions

Updates an Isolation exclusion by ID.

Required permissionendpoint-state:update

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
exclusionId path string (uuid) Yes Exclusion ID.

Request body

Content type: application/json

Request body fields

localPortsarray of integer
Local protected ports.
Each item must be ≥ 1 and ≤ 65535.
remotePortsarray of integer
Remote protected ports.
Each item must be ≥ 1 and ≤ 65535.
directionstring
IP traffic direction.
Must be one of: inbound, outbound, both.
remoteAddressesarray of string
Remote addresses to exempt from isolation restrictions.
Must contain at most 1 item.
commentstring
Comment given to the exclusion at the time of creation.

Request samples

curl -X PATCH "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/isolation/<exclusionId>" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"localPorts\": [
    65535
  ],
  \"remotePorts\": [
    65535
  ],
  \"direction\": \"inbound\",
  \"remoteAddresses\": [
    \"http://10.50.100.100\"
  ],
  \"comment\": \"Item is a Malware\"
}"

import requests

response = requests.patch(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/isolation/<exclusionId>",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'localPorts': [65535],
    'remotePorts': [65535],
    'direction': 'inbound',
    'remoteAddresses': ['http://10.50.100.100'],
    'comment': 'Item is a Malware'},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "localPorts": [
    65535
  ],
  "remotePorts": [
    65535
  ],
  "direction": "inbound",
  "remoteAddresses": [
    "http://10.50.100.100"
  ],
  "comment": "Item is a Malware"
}'
Invoke-RestMethod -Method PATCH -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/isolation/<exclusionId>" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("PATCH", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/isolation/<exclusionId>", strings.NewReader(`{
  "localPorts": [
    65535
  ],
  "remotePorts": [
    65535
  ],
  "direction": "inbound",
  "remoteAddresses": [
    "http://10.50.100.100"
  ],
  "comment": "Item is a Malware"
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/isolation/<exclusionId>", {
  method: "PATCH",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "localPorts": [
    65535
  ],
  "remotePorts": [
    65535
  ],
  "direction": "inbound",
  "remoteAddresses": [
    "http://10.50.100.100"
  ],
  "comment": "Item is a Malware"
}),
});
const data = await response.json();
console.log(data);

Responses

200 — Updated Isolation exclusion.

Response fields

idstring (uuid)required
Exclusion ID.
typestringrequired
Exclusion type. This is always isolation.
Must be one of: isolation.
localPortsarray of integer
Local allowed ports.
Each item must be ≥ 1 and ≤ 65535.
remotePortsarray of integer
Remote allowed ports.
Each item must be ≥ 1 and ≤ 65535.
directionstringrequired
IP traffic direction.
Must be one of: inbound, outbound, both.
remoteAddressesarray of string
Remote addresses to exempt from isolation restrictions.
commentstringrequired
Exclusion comment.

Errors

Status Meaning
404 Can't find Isolation exclusion.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "id": "00000000-0000-0000-0000-000000000000",
  "type": "isolation",
  "localPorts": [
    0
  ],
  "remotePorts": [
    0
  ],
  "direction": "inbound",
  "remoteAddresses": [
    "string"
  ],
  "comment": "string"
}

See the guide for a narrative walkthrough of this API.