Skip to content

Update exclusion

PATCH/settings/exclusions/scanning/{exclusionId}

Endpoint API · Scanning Exclusions

Update a scanning exclusion by ID.

Required permissionendpoint-state:update

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.
exclusionId path string (uuid) Yes Exclusion ID.

Request body

Content type: application/json

Request body fields

valuestring
Exclusion value to be updated. Behavioral and Detected Exploit exclusions do not support updating this value.
scanModestring
Default value of scan mode is "onDemandAndOnAccess" for exclusions of type path, posixPath and virtualPath, "onAccess" for process, web, pua, amsi. Behavioral and Detected Exploits (exploitMitigation) type exclusions do not support a scan mode.
Must be one of: onDemand, onAccess, onDemandAndOnAccess.
commentstring
Comment indicating why the exclusion was created.
Must be at most 100 characters long.

Request samples

curl -X PATCH "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/scanning/<exclusionId>" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"value\": \"Exclusion value\",
  \"scanMode\": \"onDemand\",
  \"comment\": \"Item is a Malware.\"
}"

import requests

response = requests.patch(
    "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/scanning/<exclusionId>",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'value': 'Exclusion value',
    'scanMode': 'onDemand',
    'comment': 'Item is a Malware.'},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "value": "Exclusion value",
  "scanMode": "onDemand",
  "comment": "Item is a Malware."
}'
Invoke-RestMethod -Method PATCH -Uri "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/scanning/<exclusionId>" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("PATCH", "https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/scanning/<exclusionId>", strings.NewReader(`{
  "value": "Exclusion value",
  "scanMode": "onDemand",
  "comment": "Item is a Malware."
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/endpoint/v1/settings/exclusions/scanning/<exclusionId>", {
  method: "PATCH",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "value": "Exclusion value",
  "scanMode": "onDemand",
  "comment": "Item is a Malware."
}),
});
const data = await response.json();
console.log(data);

Responses

200 — Updated exclusion.

Response fields

idstring (uuid)required
Unique ID for the scanning exclusion setting.
valuestringrequired
Exclusion value.
typestringrequired
Scanning exclusion type.
Must be one of: path, posixPath, virtualPath, process, web, pua, detectedExploit, amsi, behavioral, journalHashingProcess, journalHashingPath.
scanModestringrequired
Default value of scan mode is "onDemandAndOnAccess" for exclusions of type path, posixPath and virtualPath, "onAccess" for process, web, pua, amsi. Behavioral and Detected Exploits (exploitMitigation) type exclusions do not support a scan mode.
Must be one of: onDemand, onAccess, onDemandAndOnAccess.
descriptionstring
Exclusion description added by the system.
commentstring
Comment indicating why the exclusion was created.
lockedByManagingAccountbooleanrequired
Whether a partner manages the exclusion. 'true' means that only the partner can change or delete it.

Errors

Status Meaning
403 Forbidden. This may be due to scanning exclusions being managed at Partner/Enterprise level.
404 Can't find exclusion.
500 Unexpected error.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "id": "00000000-0000-0000-0000-000000000000",
  "value": "string",
  "type": "path",
  "scanMode": "onDemand",
  "description": "string",
  "comment": "string",
  "lockedByManagingAccount": true
}

See the guide for a narrative walkthrough of this API.