Skip to main content
Server path: /sophos-central-alerts | Type: Application | PCID required: Yes

Tools


sophos-central-alerts_acknowledge_alert

Take action on an alert Parameters:
ParameterTypeRequiredDefaultDescription
alertIdstringYesAlert ID
actionstringYesAction to perform (e.g., acknowledge)
messagestringNoOptional message for the action

sophos-central-alerts_create_case

Create investigation case Parameters:
ParameterTypeRequiredDefaultDescription
assigneestringNoAssignee ID
initialDetectionIdstringNoInitial detection ID to link
namestringYesCase name
overviewstringNoCase overview
severitystringYesCase severity
statusstringYesCase status
typestringYesCase type

sophos-central-alerts_delete_case

Delete case Parameters:
ParameterTypeRequiredDefaultDescription
caseIdstringYesCase ID

sophos-central-alerts_get_alert

Get alert details Parameters:
ParameterTypeRequiredDefaultDescription
alertIdstringYesAlert ID

sophos-central-alerts_get_case

Get case details Parameters:
ParameterTypeRequiredDefaultDescription
caseIdstringYesCase ID

sophos-central-alerts_get_case_mitre_attack_summary

Get MITRE ATT&CK summary Parameters:
ParameterTypeRequiredDefaultDescription
caseIdstringYesCase ID

sophos-central-alerts_get_who_am_i

Get caller identity and tenant information

sophos-central-alerts_list_alerts

List alerts Parameters:
ParameterTypeRequiredDefaultDescription
pageSizeintegerNoNumber of items per page
pageintegerNoPage number
severitystringNoFilter by severity
categorystringNoFilter by category
productstringNoFilter by product
fromstringNoFilter alerts from this timestamp

sophos-central-alerts_list_case_detections

List case detections Parameters:
ParameterTypeRequiredDefaultDescription
caseIdstringYesCase ID
pageSizeintegerNoItems per page
pageintegerNoPage number

sophos-central-alerts_list_case_impacted_entities

List impacted entities Parameters:
ParameterTypeRequiredDefaultDescription
caseIdstringYesCase ID
pageSizeintegerNoItems per page
pageintegerNoPage number

sophos-central-alerts_list_cases

List investigation cases Parameters:
ParameterTypeRequiredDefaultDescription
pageSizeintegerNoNumber of items per page (1-50)
pageintegerNoPage number

sophos-central-alerts_search_alerts

Search alerts Parameters:
ParameterTypeRequiredDefaultDescription
filterobjectNoFilter criteria as key-value pairs
pageSizeintegerNoNumber of items per page
pageTotalbooleanNoInclude total count
sortstring[]NoSort fields (e.g., [‘-raisedAt’] for descending)

sophos-central-alerts_update_case

Update case Parameters:
ParameterTypeRequiredDefaultDescription
caseIdstringYesCase ID
assigneestringNoUpdated assignee
namestringNoUpdated name
overviewstringNoUpdated overview
severitystringNoUpdated severity
statusstringNoUpdated status