Skip to main content

mnemonic MDR - Argus Managed Defence

This Integration is part of the mnemonic MDR Pack.#

Rapidly detect, analyse and respond to security threats with mnemonic’s leading Managed Detection and Response (MDR) service.

This integration was integrated and tested with version 5.1.1 argus-toolbelt (PyPi).

Configure ArgusManagedDefence in Cortex#

ParameterDescriptionRequired
Fetch incidentsDefines if this integration fetches incidents.False
Incident typeShould be set to Argus Case.False
API URLURL to Argus' API Endpoint.True
API KeyAPI Key of API user in Argus.True
Minimum severity of alerts to fetchArgus Cases with priority lower than this value will be excluded by fetch incidents.True
First fetch timeHow far back should the first run fetch open cases in Argus.False
Maximum number of incidents per fetchMaximum number of cases to be fetched from Argus. 0 means up to system limit (100 000)False
Fetch incidents exclude tagExcludes fetching incidents with the optional tag. May be used to exclude fetching Argus Cases created by XSOAR. Tags in Argus are of key: value pairs. You may exclude with tag key, or key: value pairs by a comma-separated string.False
Incident Mirroring DirectionWhich direction should the integration mirror incidents.False
Mirroring tagNames of tags used to mark incident entries to be mirrored. Comma separated.False
Close Argus CaseIf true, when an incident is closed in XSOAR: close the mirrored Argus CaseFalse
Close XSOAR IncidentIf true, when mirrored Argus Case is closed: also close the XSOAR IncidentFalse
Trust any certificate (not secure)Skip HTTPS certification verification.False
Use system proxy settingsUse system proxy settings.False

Mirroring#

This integration supports in- and outbound mirroring of incidents. Case comments are added as incident notes and case attachments added as files. Tags and events are fetched and placed in context.

Configuration#

You should set the mirroring direction parameter to the appropriate mirroring direction(s). If you are mirroring out, please note that all War Room entries you want added to Argus must be attached with the same tag as configured as the integration parameter Mirroring tag.

Excluding cases / creating Argus Cases from XSOAR#

If you wish to create an Argus Case from an incident you should configure the integration to exclude fetching incidents with and appropriate tag and ensure that the new Argus Case has this tag. This will ensure that this Argus Case is not fetched back by the integration and a new incident created. An example use case could be that you are running an XSOAR incident for a while for internal purposes before you wish to create an Argus Case.

Example#

!argus-create-case subject=<...> description=<...> service=<...> type=<...> tags=<exclude_tag>

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

argus-get-attachment#


Fetch specific attachment metadata

Base Command#

argus-add-attachment Add attachment to case (Max 50 MB, should be an archive)

Input#

Argument NameDescriptionRequired
case_idID of Argus case.Required
file_idID of attachment.Required

Context Output#

PathTypeDescription
Argus.Attachment.responseCodeNumberAPI response metadata, response code of this request
Argus.Attachment.limitNumberAPI response metadata, limit of results this request ran with
Argus.Attachment.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Attachment.countNumberAPI response metadata, total number of results this query has
Argus.Attachment.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Attachment.messages.messageStringAttachment Messages Message
Argus.Attachment.messages.messageTemplateStringAttachment Messages Message Template
Argus.Attachment.messages.typeStringAttachment Messages Type
Argus.Attachment.messages.fieldStringAttachment Messages Field
Argus.Attachment.messages.timestampNumberAttachment Messages Timestamp
Argus.Attachment.data.idStringAttachment ID
Argus.Attachment.data.addedTimestampNumberAttachment Added Timestamp
Argus.Attachment.data.addedByUser.idNumberAttachment Added By User ID
Argus.Attachment.data.addedByUser.customerIDNumberAttachment Added By User Customer ID
Argus.Attachment.data.addedByUser.customer.idNumberAttachment Added By User Customer ID
Argus.Attachment.data.addedByUser.customer.nameStringAttachment Added By User Customer Name
Argus.Attachment.data.addedByUser.customer.shortNameStringAttachment Added By User Customer Short Name
Argus.Attachment.data.addedByUser.customer.domain.idNumberAttachment Added By User Customer Domain ID
Argus.Attachment.data.addedByUser.customer.domain.nameStringAttachment Added By User Customer Domain Name
Argus.Attachment.data.addedByUser.domain.idNumberAttachment Added By User Domain ID
Argus.Attachment.data.addedByUser.domain.nameStringAttachment Added By User Domain Name
Argus.Attachment.data.addedByUser.userNameStringAttachment Added By User User Name
Argus.Attachment.data.addedByUser.nameStringAttachment Added By User Name
Argus.Attachment.data.addedByUser.typeStringAttachment Added By User Type
Argus.Attachment.data.nameStringAttachment Name
Argus.Attachment.data.mimeTypeStringAttachment Mime Type
Argus.Attachment.data.flagsStringAttachment Flags
Argus.Attachment.data.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Attachment.data.originEmailAddressStringAttachment Origin Email Address
Argus.Attachment.data.addedTimeStringAttachment Added Time

Command Example#

!argus-add-attachment case_id=123 file_id=1@1

argus-add-case-tag#


Adds a key, value tag to an Argus case

Base Command#

argus-add-case-tag

Input#

Argument NameDescriptionRequired
case_idCase ID to add tag to.Required
keyKey of tag to add to case.Required
valueValue of tag to add to case.Required

Context Output#

PathTypeDescription
Argus.Tags.responseCodeNumberAPI response metadata, response code of this request
Argus.Tags.limitNumberAPI response metadata, limit of results this request ran with
Argus.Tags.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Tags.countNumberAPI response metadata, total number of results this query has
Argus.Tags.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Tags.messages.messageStringTag Messages Message
Argus.Tags.messages.messageTemplateStringTag Messages Message Template
Argus.Tags.messages.typeStringTag Messages Type
Argus.Tags.messages.fieldStringTag Messages Field
Argus.Tags.messages.timestampNumberTag Messages Timestamp
Argus.Tags.data.idStringTag ID
Argus.Tags.data.keyStringTag Key
Argus.Tags.data.valueStringTag Value
Argus.Tags.data.addedTimestampNumberTag Added Timestamp
Argus.Tags.data.addedByUser.idNumberTag Added By User ID
Argus.Tags.data.addedByUser.customerIDNumberTag Added By User Customer ID
Argus.Tags.data.addedByUser.customer.idNumberTag Added By User Customer ID
Argus.Tags.data.addedByUser.customer.nameStringTag Added By User Customer Name
Argus.Tags.data.addedByUser.customer.shortNameStringTag Added By User Customer Short Name
Argus.Tags.data.addedByUser.customer.domain.idNumberTag Added By User Customer Domain ID
Argus.Tags.data.addedByUser.customer.domain.nameStringTag Added By User Customer Domain Name
Argus.Tags.data.addedByUser.domain.idNumberTag Added By User Domain ID
Argus.Tags.data.addedByUser.domain.nameStringTag Added By User Domain Name
Argus.Tags.data.addedByUser.userNameStringTag Added By User User Name
Argus.Tags.data.addedByUser.nameStringTag Added By User Name
Argus.Tags.data.addedByUser.typeStringTag Added By User Type
Argus.Tags.data.flagsStringTag Flags
Argus.Tags.data.addedTimeStringTag Added Time

Command Example#

!argus-add-case-tag case_id=123 key=foo value=bar

argus-list-case-tags#


List tags attached to an Argus case

Base Command#

argus-list-case-tags

Input#

Argument NameDescriptionRequired
case_idCase ID .Required
limitLimit the amount of fetched tags. (Default 25).Optional
offsetSkip a number of results.Optional

Context Output#

PathTypeDescription
Argus.Tags.responseCodeNumberAPI response metadata, response code of this request
Argus.Tags.limitNumberAPI response metadata, limit of results this request ran with
Argus.Tags.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Tags.countNumberAPI response metadata, total number of results this query has
Argus.Tags.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Tags.messages.messageStringTag Messages Message
Argus.Tags.messages.messageTemplateStringTag Messages Message Template
Argus.Tags.messages.typeStringTag Messages Type
Argus.Tags.messages.fieldStringTag Messages Field
Argus.Tags.messages.timestampNumberTag Messages Timestamp
Argus.Tags.data.idStringTag ID
Argus.Tags.data.keyStringTag Key
Argus.Tags.data.valueStringTag Value
Argus.Tags.data.addedTimestampNumberTag Added Timestamp
Argus.Tags.data.addedByUser.idNumberTag Added By User ID
Argus.Tags.data.addedByUser.customerIDNumberTag Added By User Customer ID
Argus.Tags.data.addedByUser.customer.idNumberTag Added By User Customer ID
Argus.Tags.data.addedByUser.customer.nameStringTag Added By User Customer Name
Argus.Tags.data.addedByUser.customer.shortNameStringTag Added By User Customer Short Name
Argus.Tags.data.addedByUser.customer.domain.idNumberTag Added By User Customer Domain ID
Argus.Tags.data.addedByUser.customer.domain.nameStringTag Added By User Customer Domain Name
Argus.Tags.data.addedByUser.domain.idNumberTag Added By User Domain ID
Argus.Tags.data.addedByUser.domain.nameStringTag Added By User Domain Name
Argus.Tags.data.addedByUser.userNameStringTag Added By User User Name
Argus.Tags.data.addedByUser.nameStringTag Added By User Name
Argus.Tags.data.addedByUser.typeStringTag Added By User Type
Argus.Tags.data.flagsStringTag Flags
Argus.Tags.data.addedTimeStringTag Added Time

Command Example#

!argus-list-case-tags case_id=123

argus-add-comment#


Add comment to an Argus case

Base Command#

argus-add-comment

Input#

Argument NameDescriptionRequired
case_idCase ID.Required
commentThe comment to attach.Required
as_reply_toID of comment this comment will reply to.Optional
internalWhether this comment will be shown to the customer. Possible values are: false, true. Default is false.Optional
origin_email_addressDefine the e-mail address this comment originates from.Optional
associated_attachment_idID of case attachement this comment is related to.Optional

Context Output#

PathTypeDescription
Argus.Comment.responseCodeNumberAPI response metadata, response code of this request
Argus.Comment.limitNumberAPI response metadata, limit of results this request ran with
Argus.Comment.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Comment.countNumberAPI response metadata, total number of results this query has
Argus.Comment.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Comment.messages.messageStringComment Messages Message
Argus.Comment.messages.messageTemplateStringComment Messages Message Template
Argus.Comment.messages.typeStringComment Messages Type
Argus.Comment.messages.fieldStringComment Messages Field
Argus.Comment.messages.timestampNumberComment Messages Timestamp
Argus.Comment.data.idStringComment ID
Argus.Comment.data.addedTimestampNumberComment Added Timestamp
Argus.Comment.data.addedByUser.idNumberComment Added By User ID
Argus.Comment.data.addedByUser.customerIDNumberComment Added By User Customer ID
Argus.Comment.data.addedByUser.customer.idNumberComment Added By User Customer ID
Argus.Comment.data.addedByUser.customer.nameStringComment Added By User Customer Name
Argus.Comment.data.addedByUser.customer.shortNameStringComment Added By User Customer Short Name
Argus.Comment.data.addedByUser.customer.domain.idNumberComment Added By User Customer Domain ID
Argus.Comment.data.addedByUser.customer.domain.nameStringComment Added By User Customer Domain Name
Argus.Comment.data.addedByUser.domain.idNumberComment Added By User Domain ID
Argus.Comment.data.addedByUser.domain.nameStringComment Added By User Domain Name
Argus.Comment.data.addedByUser.userNameStringComment Added By User User Name
Argus.Comment.data.addedByUser.nameStringComment Added By User Name
Argus.Comment.data.addedByUser.typeStringComment Added By User Type
Argus.Comment.data.commentStringComment Comment
Argus.Comment.data.flagsStringComment Flags
Argus.Comment.data.lastUpdatedTimestampNumberComment Last Updated Timestamp
Argus.Comment.data.statusStringComment Status
Argus.Comment.data.priorityStringComment Priority
Argus.Comment.data.originEmailAddressStringComment Origin Email Address
Argus.Comment.data.associatedAttachments.idStringComment Associated Attachments ID
Argus.Comment.data.associatedAttachments.nameStringComment Associated Attachments Name
Argus.Comment.data.references.typeStringComment References Type
Argus.Comment.data.references.commentIDStringComment References Comment ID
Argus.Comment.data.lastUpdatedTimeStringComment Last Updated Time
Argus.Comment.data.addedTimeStringComment Added Time

Command Example#

!argus-add-comment case_id=123 comment="this is a comment"

argus-list-case-comments#


List the comments of an Argus case

Base Command#

argus-list-case-comments

Input#

Argument NameDescriptionRequired
case_idCase ID of Argus case.Required
before_commentLimit to comments before this comment ID (in sort order). Possible values are: .Optional
offsetSkip a number of results (default 0).Optional
limitMaximum number of returned results (default 25).Optional
sort_bySort ordering. Default is ascending. Possible values are: ascending, descending.Optional
after_commentLimit to comments after this comment ID (in sort order).Optional

Context Output#

PathTypeDescription
Argus.Comments.responseCodeNumberAPI response metadata, response code of this request
Argus.Comments.limitNumberAPI response metadata, limit of results this request ran with
Argus.Comments.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Comments.countNumberAPI response metadata, total number of results this query has
Argus.Comments.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Comments.messages.messageStringComment Messages Message
Argus.Comments.messages.messageTemplateStringComment Messages Message Template
Argus.Comments.messages.typeStringComment Messages Type
Argus.Comments.messages.fieldStringComment Messages Field
Argus.Comments.messages.timestampNumberComment Messages Timestamp
Argus.Comments.data.idStringComment ID
Argus.Comments.data.addedTimestampNumberComment Added Timestamp
Argus.Comments.data.addedByUser.idNumberComment Added By User ID
Argus.Comments.data.addedByUser.customerIDNumberComment Added By User Customer ID
Argus.Comments.data.addedByUser.customer.idNumberComment Added By User Customer ID
Argus.Comments.data.addedByUser.customer.nameStringComment Added By User Customer Name
Argus.Comments.data.addedByUser.customer.shortNameStringComment Added By User Customer Short Name
Argus.Comments.data.addedByUser.customer.domain.idNumberComment Added By User Customer Domain ID
Argus.Comments.data.addedByUser.customer.domain.nameStringComment Added By User Customer Domain Name
Argus.Comments.data.addedByUser.domain.idNumberComment Added By User Domain ID
Argus.Comments.data.addedByUser.domain.nameStringComment Added By User Domain Name
Argus.Comments.data.addedByUser.userNameStringComment Added By User User Name
Argus.Comments.data.addedByUser.nameStringComment Added By User Name
Argus.Comments.data.addedByUser.typeStringComment Added By User Type
Argus.Comments.data.commentStringComment Comment
Argus.Comments.data.flagsStringComment Flags
Argus.Comments.data.lastUpdatedTimestampNumberComment Last Updated Timestamp
Argus.Comments.data.statusStringComment Status
Argus.Comments.data.priorityStringComment Priority
Argus.Comments.data.originEmailAddressStringComment Origin Email Address
Argus.Comments.data.associatedAttachments.idStringComment Associated Attachments ID
Argus.Comments.data.associatedAttachments.nameStringComment Associated Attachments Name
Argus.Comments.data.references.typeStringComment References Type
Argus.Comments.data.references.commentIDStringComment References Comment ID
Argus.Comments.data.lastUpdatedTimeStringComment Last Updated Time
Argus.Comments.data.addedTimeStringComment Added Time

Command Example#

!argus_list_case_comments case_id=123

argus-advanced-case-search#


Returns cases matching the defined case search criteria

Base Command#

argus-advanced-case-search

Input#

Argument NameDescriptionRequired
start_timestampStart timestamp. Possible values are: .Optional
end_timestampEnd timestamp.Optional
limitSet this value to set max number of results. By default, no restriction on result set size.Optional
offsetSet this value to skip the first (offset) objects. By default, return result from first object. .Optional
include_deletedSet to true to include deleted objects. By default, exclude deleted objects. Possible values are: true, false. Default is false.Optional
sub_criteriaSet additional criterias which are applied using a logical OR.Optional
excludeOnly relevant for subcriteria. If set to true, objects matching this subcriteria object will be excluded. . Possible values are: true, false.Optional
requiredOnly relevant for subcriteria. If set to true, objects matching this subcriteria are required (AND-ed together with parent criteria). . Possible values are: true, false.Optional
customer_idRestrict search to data belonging to specified customers. .Optional
case_idRestrict search to specific cases (by ID). .Optional
customerRestrict search to specific customers (by ID or shortname). .Optional
case_typeRestrict search to entries of one of these types.Optional
serviceRestrict search to entries of one of these services (by service shortname or ID). .Optional
categoryRestrict search to entries of one of these categories (by category shortname or ID).Optional
statusRestrict search to entries of one of these statuses. .Optional
priorityRestrict search to entries with given priorties.Optional
asset_idRestrict search to cases associated with specified assets (hosts, services or processes).Optional
tagRestrict search to entries matching the given tag criteria. .Optional
workflowRestrict search to entries matching the given workflow criteria. .Optional
fieldRestrict search to entries matching the given field criteria. .Optional
keywordsSearch for keywords.Optional
time_field_strategyDefines which timestamps will be included in the search (default all). .Optional
time_match_strategyDefines how strict to match against different timestamps (all/any) using start and end timestamp (default any).Optional
keyword_field_strategyDefines which fields will be searched by keywords (default all supported fields). .Optional
keyword_match_strategyDefines the MatchStrategy for keywords (default match all keywords). .Optional
userRestrict search to cases associated with these users or user groups (by ID or shortname). .Optional
user_field_strategyDefines which user fields will be searched (default match all user fields). .Optional
user_assignedIf set, limit search to cases where assignedUser field is set/unset. Possible values are: true, false.Optional
tech_assignedIf set, limit search to cases where assignedTech field is set/unset. Possible values are: true, false.Optional
include_workflowsIf true, include list of workflows in result. Default is false (not present). . Possible values are: true, false. Default is false.Optional
include_descriptionIf false, omit description from response. Default is true (description is present). . Possible values are: true, false. Default is true.Optional
access_modeIf set, only match cases which is set to one of these access modes.Optional
explicit_accessIf set, only match cases which have explicit access grants matching the specified criteria.Optional
sort_byList of properties to sort by (prefix with "-" to sort descending).Optional
include_flagsOnly include objects which have includeFlags set. .Optional
exclude_flagsExclude objects which have excludeFlags set. .Optional

Context Output#

PathTypeDescription
Argus.Cases.responseCodeNumberAPI response metadata, response code of this request
Argus.Cases.limitNumberAPI response metadata, limit of results this request ran with
Argus.Cases.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Cases.countNumberAPI response metadata, total number of results this query has
Argus.Cases.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Cases.messages.messageStringCase Messages Message
Argus.Cases.messages.messageTemplateStringCase Messages Message Template
Argus.Cases.messages.typeStringCase Messages Type
Argus.Cases.messages.fieldStringCase Messages Field
Argus.Cases.messages.timestampNumberCase Messages Timestamp
Argus.Cases.data.idNumberCase ID
Argus.Cases.data.customer.idNumberCase Customer ID
Argus.Cases.data.customer.nameStringCase Customer Name
Argus.Cases.data.customer.shortNameStringCase Customer Short Name
Argus.Cases.data.customer.domain.idNumberCase Customer Domain ID
Argus.Cases.data.customer.domain.nameStringCase Customer Domain Name
Argus.Cases.data.service.idNumberCase Service ID
Argus.Cases.data.service.nameStringCase Service Name
Argus.Cases.data.service.shortNameStringCase Service Short Name
Argus.Cases.data.service.localizedNameStringCase Service Localized Name
Argus.Cases.data.category.idNumberCase Category ID
Argus.Cases.data.category.nameStringCase Category Name
Argus.Cases.data.category.shortNameStringCase Category Short Name
Argus.Cases.data.category.localizedNameStringCase Category Localized Name
Argus.Cases.data.typeStringCase Type
Argus.Cases.data.initialStatusStringCase Initial Status
Argus.Cases.data.statusStringCase Status
Argus.Cases.data.initialPriorityStringCase Initial Priority
Argus.Cases.data.priorityStringCase Priority
Argus.Cases.data.subjectStringCase Subject
Argus.Cases.data.descriptionStringCase Description
Argus.Cases.data.customerReferenceStringCase Customer Reference
Argus.Cases.data.accessModeStringCase Access Mode
Argus.Cases.data.reporter.idNumberCase Reporter ID
Argus.Cases.data.reporter.customerIDNumberCase Reporter Customer ID
Argus.Cases.data.reporter.customer.idNumberCase Reporter Customer ID
Argus.Cases.data.reporter.customer.nameStringCase Reporter Customer Name
Argus.Cases.data.reporter.customer.shortNameStringCase Reporter Customer Short Name
Argus.Cases.data.reporter.customer.domain.idNumberCase Reporter Customer Domain ID
Argus.Cases.data.reporter.customer.domain.nameStringCase Reporter Customer Domain Name
Argus.Cases.data.reporter.domain.idNumberCase Reporter Domain ID
Argus.Cases.data.reporter.domain.nameStringCase Reporter Domain Name
Argus.Cases.data.reporter.userNameStringCase Reporter User Name
Argus.Cases.data.reporter.nameStringCase Reporter Name
Argus.Cases.data.reporter.typeStringCase Reporter Type
Argus.Cases.data.assignedUser.idNumberCase Assigned User ID
Argus.Cases.data.assignedUser.customerIDNumberCase Assigned User Customer ID
Argus.Cases.data.assignedUser.customer.idNumberCase Assigned User Customer ID
Argus.Cases.data.assignedUser.customer.nameStringCase Assigned User Customer Name
Argus.Cases.data.assignedUser.customer.shortNameStringCase Assigned User Customer Short Name
Argus.Cases.data.assignedUser.customer.domain.idNumberCase Assigned User Customer Domain ID
Argus.Cases.data.assignedUser.customer.domain.nameStringCase Assigned User Customer Domain Name
Argus.Cases.data.assignedUser.domain.idNumberCase Assigned User Domain ID
Argus.Cases.data.assignedUser.domain.nameStringCase Assigned User Domain Name
Argus.Cases.data.assignedUser.userNameStringCase Assigned User User Name
Argus.Cases.data.assignedUser.nameStringCase Assigned User Name
Argus.Cases.data.assignedUser.typeStringCase Assigned User Type
Argus.Cases.data.assignedTech.idNumberCase Assigned Tech ID
Argus.Cases.data.assignedTech.customerIDNumberCase Assigned Tech Customer ID
Argus.Cases.data.assignedTech.customer.idNumberCase Assigned Tech Customer ID
Argus.Cases.data.assignedTech.customer.nameStringCase Assigned Tech Customer Name
Argus.Cases.data.assignedTech.customer.shortNameStringCase Assigned Tech Customer Short Name
Argus.Cases.data.assignedTech.customer.domain.idNumberCase Assigned Tech Customer Domain ID
Argus.Cases.data.assignedTech.customer.domain.nameStringCase Assigned Tech Customer Domain Name
Argus.Cases.data.assignedTech.domain.idNumberCase Assigned Tech Domain ID
Argus.Cases.data.assignedTech.domain.nameStringCase Assigned Tech Domain Name
Argus.Cases.data.assignedTech.userNameStringCase Assigned Tech User Name
Argus.Cases.data.assignedTech.nameStringCase Assigned Tech Name
Argus.Cases.data.assignedTech.typeStringCase Assigned Tech Type
Argus.Cases.data.createdTimestampNumberCase Created Timestamp
Argus.Cases.data.createdByUser.idNumberCase Created By User ID
Argus.Cases.data.createdByUser.customerIDNumberCase Created By User Customer ID
Argus.Cases.data.createdByUser.customer.idNumberCase Created By User Customer ID
Argus.Cases.data.createdByUser.customer.nameStringCase Created By User Customer Name
Argus.Cases.data.createdByUser.customer.shortNameStringCase Created By User Customer Short Name
Argus.Cases.data.createdByUser.customer.domain.idNumberCase Created By User Customer Domain ID
Argus.Cases.data.createdByUser.customer.domain.nameStringCase Created By User Customer Domain Name
Argus.Cases.data.createdByUser.domain.idNumberCase Created By User Domain ID
Argus.Cases.data.createdByUser.domain.nameStringCase Created By User Domain Name
Argus.Cases.data.createdByUser.userNameStringCase Created By User User Name
Argus.Cases.data.createdByUser.nameStringCase Created By User Name
Argus.Cases.data.createdByUser.typeStringCase Created By User Type
Argus.Cases.data.lastUpdatedTimestampNumberCase Last Updated Timestamp
Argus.Cases.data.lastUpdatedByUser.idNumberCase Last Updated By User ID
Argus.Cases.data.lastUpdatedByUser.customerIDNumberCase Last Updated By User Customer ID
Argus.Cases.data.lastUpdatedByUser.customer.idNumberCase Last Updated By User Customer ID
Argus.Cases.data.lastUpdatedByUser.customer.nameStringCase Last Updated By User Customer Name
Argus.Cases.data.lastUpdatedByUser.customer.shortNameStringCase Last Updated By User Customer Short Name
Argus.Cases.data.lastUpdatedByUser.customer.domain.idNumberCase Last Updated By User Customer Domain ID
Argus.Cases.data.lastUpdatedByUser.customer.domain.nameStringCase Last Updated By User Customer Domain Name
Argus.Cases.data.lastUpdatedByUser.domain.idNumberCase Last Updated By User Domain ID
Argus.Cases.data.lastUpdatedByUser.domain.nameStringCase Last Updated By User Domain Name
Argus.Cases.data.lastUpdatedByUser.userNameStringCase Last Updated By User User Name
Argus.Cases.data.lastUpdatedByUser.nameStringCase Last Updated By User Name
Argus.Cases.data.lastUpdatedByUser.typeStringCase Last Updated By User Type
Argus.Cases.data.closedTimestampNumberCase Closed Timestamp
Argus.Cases.data.closedByUser.idNumberCase Closed By User ID
Argus.Cases.data.closedByUser.customerIDNumberCase Closed By User Customer ID
Argus.Cases.data.closedByUser.customer.idNumberCase Closed By User Customer ID
Argus.Cases.data.closedByUser.customer.nameStringCase Closed By User Customer Name
Argus.Cases.data.closedByUser.customer.shortNameStringCase Closed By User Customer Short Name
Argus.Cases.data.closedByUser.customer.domain.idNumberCase Closed By User Customer Domain ID
Argus.Cases.data.closedByUser.customer.domain.nameStringCase Closed By User Customer Domain Name
Argus.Cases.data.closedByUser.domain.idNumberCase Closed By User Domain ID
Argus.Cases.data.closedByUser.domain.nameStringCase Closed By User Domain Name
Argus.Cases.data.closedByUser.userNameStringCase Closed By User User Name
Argus.Cases.data.closedByUser.nameStringCase Closed By User Name
Argus.Cases.data.closedByUser.typeStringCase Closed By User Type
Argus.Cases.data.publishedTimestampNumberCase Published Timestamp
Argus.Cases.data.publishedByUser.idNumberCase Published By User ID
Argus.Cases.data.publishedByUser.customerIDNumberCase Published By User Customer ID
Argus.Cases.data.publishedByUser.customer.idNumberCase Published By User Customer ID
Argus.Cases.data.publishedByUser.customer.nameStringCase Published By User Customer Name
Argus.Cases.data.publishedByUser.customer.shortNameStringCase Published By User Customer Short Name
Argus.Cases.data.publishedByUser.customer.domain.idNumberCase Published By User Customer Domain ID
Argus.Cases.data.publishedByUser.customer.domain.nameStringCase Published By User Customer Domain Name
Argus.Cases.data.publishedByUser.domain.idNumberCase Published By User Domain ID
Argus.Cases.data.publishedByUser.domain.nameStringCase Published By User Domain Name
Argus.Cases.data.publishedByUser.userNameStringCase Published By User User Name
Argus.Cases.data.publishedByUser.nameStringCase Published By User Name
Argus.Cases.data.publishedByUser.typeStringCase Published By User Type
Argus.Cases.data.flagsStringCase Flags
Argus.Cases.data.currentUserAccess.levelStringCase Current User Access Level
Argus.Cases.data.currentUserAccess.roleStringCase Current User Access Role
Argus.Cases.data.workflows.workflowStringCase Workflows Workflow
Argus.Cases.data.workflows.stateStringCase Workflows State
Argus.Cases.data.originEmailAddressStringCase Origin Email Address
Argus.Cases.data.createdTimeStringCase Created Time
Argus.Cases.data.lastUpdatedTimeStringCase Last Updated Time
Argus.Cases.data.closedTimeStringCase Closed Time
Argus.Cases.data.publishedTimeStringCase Published Time

Command Example#

!argus-advanced-case-search

argus-close-case#


Close an Argus case

Base Command#

argus-close-case

Input#

Argument NameDescriptionRequired
case_idCase ID of Argus case.Required
commentAttach a closing comment.Optional

Context Output#

PathTypeDescription
Argus.Case.responseCodeNumberAPI response metadata, response code of this request
Argus.Case.limitNumberAPI response metadata, limit of results this request ran with
Argus.Case.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Case.countNumberAPI response metadata, total number of results this query has
Argus.Case.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Case.messages.messageStringCase Messages Message
Argus.Case.messages.messageTemplateStringCase Messages Message Template
Argus.Case.messages.typeStringCase Messages Type
Argus.Case.messages.fieldStringCase Messages Field
Argus.Case.messages.timestampNumberCase Messages Timestamp
Argus.Case.data.idNumberCase ID
Argus.Case.data.customer.idNumberCase Customer ID
Argus.Case.data.customer.nameStringCase Customer Name
Argus.Case.data.customer.shortNameStringCase Customer Short Name
Argus.Case.data.customer.domain.idNumberCase Customer Domain ID
Argus.Case.data.customer.domain.nameStringCase Customer Domain Name
Argus.Case.data.service.idNumberCase Service ID
Argus.Case.data.service.nameStringCase Service Name
Argus.Case.data.service.shortNameStringCase Service Short Name
Argus.Case.data.service.localizedNameStringCase Service Localized Name
Argus.Case.data.category.idNumberCase Category ID
Argus.Case.data.category.nameStringCase Category Name
Argus.Case.data.category.shortNameStringCase Category Short Name
Argus.Case.data.category.localizedNameStringCase Category Localized Name
Argus.Case.data.typeStringCase Type
Argus.Case.data.initialStatusStringCase Initial Status
Argus.Case.data.statusStringCase Status
Argus.Case.data.initialPriorityStringCase Initial Priority
Argus.Case.data.priorityStringCase Priority
Argus.Case.data.subjectStringCase Subject
Argus.Case.data.descriptionStringCase Description
Argus.Case.data.customerReferenceStringCase Customer Reference
Argus.Case.data.accessModeStringCase Access Mode
Argus.Case.data.reporter.idNumberCase Reporter ID
Argus.Case.data.reporter.customerIDNumberCase Reporter Customer ID
Argus.Case.data.reporter.customer.idNumberCase Reporter Customer ID
Argus.Case.data.reporter.customer.nameStringCase Reporter Customer Name
Argus.Case.data.reporter.customer.shortNameStringCase Reporter Customer Short Name
Argus.Case.data.reporter.customer.domain.idNumberCase Reporter Customer Domain ID
Argus.Case.data.reporter.customer.domain.nameStringCase Reporter Customer Domain Name
Argus.Case.data.reporter.domain.idNumberCase Reporter Domain ID
Argus.Case.data.reporter.domain.nameStringCase Reporter Domain Name
Argus.Case.data.reporter.userNameStringCase Reporter User Name
Argus.Case.data.reporter.nameStringCase Reporter Name
Argus.Case.data.reporter.typeStringCase Reporter Type
Argus.Case.data.assignedUser.idNumberCase Assigned User ID
Argus.Case.data.assignedUser.customerIDNumberCase Assigned User Customer ID
Argus.Case.data.assignedUser.customer.idNumberCase Assigned User Customer ID
Argus.Case.data.assignedUser.customer.nameStringCase Assigned User Customer Name
Argus.Case.data.assignedUser.customer.shortNameStringCase Assigned User Customer Short Name
Argus.Case.data.assignedUser.customer.domain.idNumberCase Assigned User Customer Domain ID
Argus.Case.data.assignedUser.customer.domain.nameStringCase Assigned User Customer Domain Name
Argus.Case.data.assignedUser.domain.idNumberCase Assigned User Domain ID
Argus.Case.data.assignedUser.domain.nameStringCase Assigned User Domain Name
Argus.Case.data.assignedUser.userNameStringCase Assigned User User Name
Argus.Case.data.assignedUser.nameStringCase Assigned User Name
Argus.Case.data.assignedUser.typeStringCase Assigned User Type
Argus.Case.data.assignedTech.idNumberCase Assigned Tech ID
Argus.Case.data.assignedTech.customerIDNumberCase Assigned Tech Customer ID
Argus.Case.data.assignedTech.customer.idNumberCase Assigned Tech Customer ID
Argus.Case.data.assignedTech.customer.nameStringCase Assigned Tech Customer Name
Argus.Case.data.assignedTech.customer.shortNameStringCase Assigned Tech Customer Short Name
Argus.Case.data.assignedTech.customer.domain.idNumberCase Assigned Tech Customer Domain ID
Argus.Case.data.assignedTech.customer.domain.nameStringCase Assigned Tech Customer Domain Name
Argus.Case.data.assignedTech.domain.idNumberCase Assigned Tech Domain ID
Argus.Case.data.assignedTech.domain.nameStringCase Assigned Tech Domain Name
Argus.Case.data.assignedTech.userNameStringCase Assigned Tech User Name
Argus.Case.data.assignedTech.nameStringCase Assigned Tech Name
Argus.Case.data.assignedTech.typeStringCase Assigned Tech Type
Argus.Case.data.createdTimestampNumberCase Created Timestamp
Argus.Case.data.createdByUser.idNumberCase Created By User ID
Argus.Case.data.createdByUser.customerIDNumberCase Created By User Customer ID
Argus.Case.data.createdByUser.customer.idNumberCase Created By User Customer ID
Argus.Case.data.createdByUser.customer.nameStringCase Created By User Customer Name
Argus.Case.data.createdByUser.customer.shortNameStringCase Created By User Customer Short Name
Argus.Case.data.createdByUser.customer.domain.idNumberCase Created By User Customer Domain ID
Argus.Case.data.createdByUser.customer.domain.nameStringCase Created By User Customer Domain Name
Argus.Case.data.createdByUser.domain.idNumberCase Created By User Domain ID
Argus.Case.data.createdByUser.domain.nameStringCase Created By User Domain Name
Argus.Case.data.createdByUser.userNameStringCase Created By User User Name
Argus.Case.data.createdByUser.nameStringCase Created By User Name
Argus.Case.data.createdByUser.typeStringCase Created By User Type
Argus.Case.data.lastUpdatedTimestampNumberCase Last Updated Timestamp
Argus.Case.data.lastUpdatedByUser.idNumberCase Last Updated By User ID
Argus.Case.data.lastUpdatedByUser.customerIDNumberCase Last Updated By User Customer ID
Argus.Case.data.lastUpdatedByUser.customer.idNumberCase Last Updated By User Customer ID
Argus.Case.data.lastUpdatedByUser.customer.nameStringCase Last Updated By User Customer Name
Argus.Case.data.lastUpdatedByUser.customer.shortNameStringCase Last Updated By User Customer Short Name
Argus.Case.data.lastUpdatedByUser.customer.domain.idNumberCase Last Updated By User Customer Domain ID
Argus.Case.data.lastUpdatedByUser.customer.domain.nameStringCase Last Updated By User Customer Domain Name
Argus.Case.data.lastUpdatedByUser.domain.idNumberCase Last Updated By User Domain ID
Argus.Case.data.lastUpdatedByUser.domain.nameStringCase Last Updated By User Domain Name
Argus.Case.data.lastUpdatedByUser.userNameStringCase Last Updated By User User Name
Argus.Case.data.lastUpdatedByUser.nameStringCase Last Updated By User Name
Argus.Case.data.lastUpdatedByUser.typeStringCase Last Updated By User Type
Argus.Case.data.closedTimestampNumberCase Closed Timestamp
Argus.Case.data.closedByUser.idNumberCase Closed By User ID
Argus.Case.data.closedByUser.customerIDNumberCase Closed By User Customer ID
Argus.Case.data.closedByUser.customer.idNumberCase Closed By User Customer ID
Argus.Case.data.closedByUser.customer.nameStringCase Closed By User Customer Name
Argus.Case.data.closedByUser.customer.shortNameStringCase Closed By User Customer Short Name
Argus.Case.data.closedByUser.customer.domain.idNumberCase Closed By User Customer Domain ID
Argus.Case.data.closedByUser.customer.domain.nameStringCase Closed By User Customer Domain Name
Argus.Case.data.closedByUser.domain.idNumberCase Closed By User Domain ID
Argus.Case.data.closedByUser.domain.nameStringCase Closed By User Domain Name
Argus.Case.data.closedByUser.userNameStringCase Closed By User User Name
Argus.Case.data.closedByUser.nameStringCase Closed By User Name
Argus.Case.data.closedByUser.typeStringCase Closed By User Type
Argus.Case.data.publishedTimestampNumberCase Published Timestamp
Argus.Case.data.publishedByUser.idNumberCase Published By User ID
Argus.Case.data.publishedByUser.customerIDNumberCase Published By User Customer ID
Argus.Case.data.publishedByUser.customer.idNumberCase Published By User Customer ID
Argus.Case.data.publishedByUser.customer.nameStringCase Published By User Customer Name
Argus.Case.data.publishedByUser.customer.shortNameStringCase Published By User Customer Short Name
Argus.Case.data.publishedByUser.customer.domain.idNumberCase Published By User Customer Domain ID
Argus.Case.data.publishedByUser.customer.domain.nameStringCase Published By User Customer Domain Name
Argus.Case.data.publishedByUser.domain.idNumberCase Published By User Domain ID
Argus.Case.data.publishedByUser.domain.nameStringCase Published By User Domain Name
Argus.Case.data.publishedByUser.userNameStringCase Published By User User Name
Argus.Case.data.publishedByUser.nameStringCase Published By User Name
Argus.Case.data.publishedByUser.typeStringCase Published By User Type
Argus.Case.data.flagsStringCase Flags
Argus.Case.data.currentUserAccess.levelStringCase Current User Access Level
Argus.Case.data.currentUserAccess.roleStringCase Current User Access Role
Argus.Case.data.workflows.workflowStringCase Workflows Workflow
Argus.Case.data.workflows.stateStringCase Workflows State
Argus.Case.data.originEmailAddressStringCase Origin Email Address
Argus.Case.data.createdTimeStringCase Created Time
Argus.Case.data.lastUpdatedTimeStringCase Last Updated Time
Argus.Case.data.closedTimeStringCase Closed Time
Argus.Case.data.publishedTimeStringCase Published Time

Command Example#

!argus-close-case case_id=123

argus-create-case#


Create Argus case

Base Command#

argus-create-case

Input#

Argument NameDescriptionRequired
customerID or shortname of customer to create case for. Defaults to current users customer.Optional
serviceID of service to create case for. Possible values are: ids, support, administrative, advisory, vulnscan.Required
categoryIf set, assign given category to new case (by category shortname). . Possible values are: network-testing, unauthorized-access, dos, data-leakage, exposed-malicious, malicious-infection, poor-practice, reconnaissance, misconfigured, vpn-down, sensor-malfunctioning, not-receiving-traffic, false-positive, suspected-targeted-attack, duplicate, problem-managed, problem-customer, adware, network-connection-lost, failed-authentication, missing-log-sources, no-threat, phishing, argus-improvement, argus-bug.Optional
typeType of case to create . Possible values are: operationalIncident, change, securityIncident, informational.Required
statusStatus of case to create. If not set, system will select automatically. Creating a new case with status closed is not permitted. . Possible values are: pendingCustomer, pendingSoc, pendingVendor, pendingClose, workingSoc, workingCustomer.Optional
tagsTags to add on case creation. (key,value,key,value, ...).Optional
subjectSubject of case to create.Required
descriptionCase description. May use HTML, which will be sanitized. .Required
customer_referenceCustomer reference for case.Optional
priorityPriority of case to create. (default medium). Possible values are: low, medium, high, critical. Default is medium.Optional
access_modeAccess mode for new case. (default roleBased).Optional
origin_email_addressIf case is created from an email, specify origin email address here.Optional
publishWhether to publish new case. Creating an unpublished case requires special permission. (default true). Possible values are: true, false. Default is true.Optional
default_watchersWhether to enable default watchers for this case. If set to false, default watchers will not be enabled, and will not be notified upon creation of this case. (default true). Possible values are: true, false. Default is true.Optional

Context Output#

PathTypeDescription
Argus.Case.responseCodeNumberAPI response metadata, response code of this request
Argus.Case.limitNumberAPI response metadata, limit of results this request ran with
Argus.Case.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Case.countNumberAPI response metadata, total number of results this query has
Argus.Case.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Case.messages.messageStringCase Messages Message
Argus.Case.messages.messageTemplateStringCase Messages Message Template
Argus.Case.messages.typeStringCase Messages Type
Argus.Case.messages.fieldStringCase Messages Field
Argus.Case.messages.timestampNumberCase Messages Timestamp
Argus.Case.data.idNumberCase ID
Argus.Case.data.customer.idNumberCase Customer ID
Argus.Case.data.customer.nameStringCase Customer Name
Argus.Case.data.customer.shortNameStringCase Customer Short Name
Argus.Case.data.customer.domain.idNumberCase Customer Domain ID
Argus.Case.data.customer.domain.nameStringCase Customer Domain Name
Argus.Case.data.service.idNumberCase Service ID
Argus.Case.data.service.nameStringCase Service Name
Argus.Case.data.service.shortNameStringCase Service Short Name
Argus.Case.data.service.localizedNameStringCase Service Localized Name
Argus.Case.data.category.idNumberCase Category ID
Argus.Case.data.category.nameStringCase Category Name
Argus.Case.data.category.shortNameStringCase Category Short Name
Argus.Case.data.category.localizedNameStringCase Category Localized Name
Argus.Case.data.typeStringCase Type
Argus.Case.data.initialStatusStringCase Initial Status
Argus.Case.data.statusStringCase Status
Argus.Case.data.initialPriorityStringCase Initial Priority
Argus.Case.data.priorityStringCase Priority
Argus.Case.data.subjectStringCase Subject
Argus.Case.data.descriptionStringCase Description
Argus.Case.data.customerReferenceStringCase Customer Reference
Argus.Case.data.accessModeStringCase Access Mode
Argus.Case.data.reporter.idNumberCase Reporter ID
Argus.Case.data.reporter.customerIDNumberCase Reporter Customer ID
Argus.Case.data.reporter.customer.idNumberCase Reporter Customer ID
Argus.Case.data.reporter.customer.nameStringCase Reporter Customer Name
Argus.Case.data.reporter.customer.shortNameStringCase Reporter Customer Short Name
Argus.Case.data.reporter.customer.domain.idNumberCase Reporter Customer Domain ID
Argus.Case.data.reporter.customer.domain.nameStringCase Reporter Customer Domain Name
Argus.Case.data.reporter.domain.idNumberCase Reporter Domain ID
Argus.Case.data.reporter.domain.nameStringCase Reporter Domain Name
Argus.Case.data.reporter.userNameStringCase Reporter User Name
Argus.Case.data.reporter.nameStringCase Reporter Name
Argus.Case.data.reporter.typeStringCase Reporter Type
Argus.Case.data.assignedUser.idNumberCase Assigned User ID
Argus.Case.data.assignedUser.customerIDNumberCase Assigned User Customer ID
Argus.Case.data.assignedUser.customer.idNumberCase Assigned User Customer ID
Argus.Case.data.assignedUser.customer.nameStringCase Assigned User Customer Name
Argus.Case.data.assignedUser.customer.shortNameStringCase Assigned User Customer Short Name
Argus.Case.data.assignedUser.customer.domain.idNumberCase Assigned User Customer Domain ID
Argus.Case.data.assignedUser.customer.domain.nameStringCase Assigned User Customer Domain Name
Argus.Case.data.assignedUser.domain.idNumberCase Assigned User Domain ID
Argus.Case.data.assignedUser.domain.nameStringCase Assigned User Domain Name
Argus.Case.data.assignedUser.userNameStringCase Assigned User User Name
Argus.Case.data.assignedUser.nameStringCase Assigned User Name
Argus.Case.data.assignedUser.typeStringCase Assigned User Type
Argus.Case.data.assignedTech.idNumberCase Assigned Tech ID
Argus.Case.data.assignedTech.customerIDNumberCase Assigned Tech Customer ID
Argus.Case.data.assignedTech.customer.idNumberCase Assigned Tech Customer ID
Argus.Case.data.assignedTech.customer.nameStringCase Assigned Tech Customer Name
Argus.Case.data.assignedTech.customer.shortNameStringCase Assigned Tech Customer Short Name
Argus.Case.data.assignedTech.customer.domain.idNumberCase Assigned Tech Customer Domain ID
Argus.Case.data.assignedTech.customer.domain.nameStringCase Assigned Tech Customer Domain Name
Argus.Case.data.assignedTech.domain.idNumberCase Assigned Tech Domain ID
Argus.Case.data.assignedTech.domain.nameStringCase Assigned Tech Domain Name
Argus.Case.data.assignedTech.userNameStringCase Assigned Tech User Name
Argus.Case.data.assignedTech.nameStringCase Assigned Tech Name
Argus.Case.data.assignedTech.typeStringCase Assigned Tech Type
Argus.Case.data.createdTimestampNumberCase Created Timestamp
Argus.Case.data.createdByUser.idNumberCase Created By User ID
Argus.Case.data.createdByUser.customerIDNumberCase Created By User Customer ID
Argus.Case.data.createdByUser.customer.idNumberCase Created By User Customer ID
Argus.Case.data.createdByUser.customer.nameStringCase Created By User Customer Name
Argus.Case.data.createdByUser.customer.shortNameStringCase Created By User Customer Short Name
Argus.Case.data.createdByUser.customer.domain.idNumberCase Created By User Customer Domain ID
Argus.Case.data.createdByUser.customer.domain.nameStringCase Created By User Customer Domain Name
Argus.Case.data.createdByUser.domain.idNumberCase Created By User Domain ID
Argus.Case.data.createdByUser.domain.nameStringCase Created By User Domain Name
Argus.Case.data.createdByUser.userNameStringCase Created By User User Name
Argus.Case.data.createdByUser.nameStringCase Created By User Name
Argus.Case.data.createdByUser.typeStringCase Created By User Type
Argus.Case.data.lastUpdatedTimestampNumberCase Last Updated Timestamp
Argus.Case.data.lastUpdatedByUser.idNumberCase Last Updated By User ID
Argus.Case.data.lastUpdatedByUser.customerIDNumberCase Last Updated By User Customer ID
Argus.Case.data.lastUpdatedByUser.customer.idNumberCase Last Updated By User Customer ID
Argus.Case.data.lastUpdatedByUser.customer.nameStringCase Last Updated By User Customer Name
Argus.Case.data.lastUpdatedByUser.customer.shortNameStringCase Last Updated By User Customer Short Name
Argus.Case.data.lastUpdatedByUser.customer.domain.idNumberCase Last Updated By User Customer Domain ID
Argus.Case.data.lastUpdatedByUser.customer.domain.nameStringCase Last Updated By User Customer Domain Name
Argus.Case.data.lastUpdatedByUser.domain.idNumberCase Last Updated By User Domain ID
Argus.Case.data.lastUpdatedByUser.domain.nameStringCase Last Updated By User Domain Name
Argus.Case.data.lastUpdatedByUser.userNameStringCase Last Updated By User User Name
Argus.Case.data.lastUpdatedByUser.nameStringCase Last Updated By User Name
Argus.Case.data.lastUpdatedByUser.typeStringCase Last Updated By User Type
Argus.Case.data.closedTimestampNumberCase Closed Timestamp
Argus.Case.data.closedByUser.idNumberCase Closed By User ID
Argus.Case.data.closedByUser.customerIDNumberCase Closed By User Customer ID
Argus.Case.data.closedByUser.customer.idNumberCase Closed By User Customer ID
Argus.Case.data.closedByUser.customer.nameStringCase Closed By User Customer Name
Argus.Case.data.closedByUser.customer.shortNameStringCase Closed By User Customer Short Name
Argus.Case.data.closedByUser.customer.domain.idNumberCase Closed By User Customer Domain ID
Argus.Case.data.closedByUser.customer.domain.nameStringCase Closed By User Customer Domain Name
Argus.Case.data.closedByUser.domain.idNumberCase Closed By User Domain ID
Argus.Case.data.closedByUser.domain.nameStringCase Closed By User Domain Name
Argus.Case.data.closedByUser.userNameStringCase Closed By User User Name
Argus.Case.data.closedByUser.nameStringCase Closed By User Name
Argus.Case.data.closedByUser.typeStringCase Closed By User Type
Argus.Case.data.publishedTimestampNumberCase Published Timestamp
Argus.Case.data.publishedByUser.idNumberCase Published By User ID
Argus.Case.data.publishedByUser.customerIDNumberCase Published By User Customer ID
Argus.Case.data.publishedByUser.customer.idNumberCase Published By User Customer ID
Argus.Case.data.publishedByUser.customer.nameStringCase Published By User Customer Name
Argus.Case.data.publishedByUser.customer.shortNameStringCase Published By User Customer Short Name
Argus.Case.data.publishedByUser.customer.domain.idNumberCase Published By User Customer Domain ID
Argus.Case.data.publishedByUser.customer.domain.nameStringCase Published By User Customer Domain Name
Argus.Case.data.publishedByUser.domain.idNumberCase Published By User Domain ID
Argus.Case.data.publishedByUser.domain.nameStringCase Published By User Domain Name
Argus.Case.data.publishedByUser.userNameStringCase Published By User User Name
Argus.Case.data.publishedByUser.nameStringCase Published By User Name
Argus.Case.data.publishedByUser.typeStringCase Published By User Type
Argus.Case.data.flagsStringCase Flags
Argus.Case.data.currentUserAccess.levelStringCase Current User Access Level
Argus.Case.data.currentUserAccess.roleStringCase Current User Access Role
Argus.Case.data.workflows.workflowStringCase Workflows Workflow
Argus.Case.data.workflows.stateStringCase Workflows State
Argus.Case.data.originEmailAddressStringCase Origin Email Address
Argus.Case.data.createdTimeStringCase Created Time
Argus.Case.data.lastUpdatedTimeStringCase Last Updated Time
Argus.Case.data.closedTimeStringCase Closed Time
Argus.Case.data.publishedTimeStringCase Published Time

!argus-create-case subject="test case title" description="test case details" service=administrative type=informational

argus-delete-case#


Mark existing case as deleted

Base Command#

argus-delete-case

Input#

Argument NameDescriptionRequired
case_idID of Argus case to mark as deleted.Required

Context Output#

PathTypeDescription
Argus.Case.responseCodeNumberAPI response metadata, response code of this request
Argus.Case.limitNumberAPI response metadata, limit of results this request ran with
Argus.Case.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Case.countNumberAPI response metadata, total number of results this query has
Argus.Case.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Case.messages.messageStringCase Messages Message
Argus.Case.messages.messageTemplateStringCase Messages Message Template
Argus.Case.messages.typeStringCase Messages Type
Argus.Case.messages.fieldStringCase Messages Field
Argus.Case.messages.timestampNumberCase Messages Timestamp
Argus.Case.data.idNumberCase ID
Argus.Case.data.customer.idNumberCase Customer ID
Argus.Case.data.customer.nameStringCase Customer Name
Argus.Case.data.customer.shortNameStringCase Customer Short Name
Argus.Case.data.customer.domain.idNumberCase Customer Domain ID
Argus.Case.data.customer.domain.nameStringCase Customer Domain Name
Argus.Case.data.service.idNumberCase Service ID
Argus.Case.data.service.nameStringCase Service Name
Argus.Case.data.service.shortNameStringCase Service Short Name
Argus.Case.data.service.localizedNameStringCase Service Localized Name
Argus.Case.data.category.idNumberCase Category ID
Argus.Case.data.category.nameStringCase Category Name
Argus.Case.data.category.shortNameStringCase Category Short Name
Argus.Case.data.category.localizedNameStringCase Category Localized Name
Argus.Case.data.typeStringCase Type
Argus.Case.data.initialStatusStringCase Initial Status
Argus.Case.data.statusStringCase Status
Argus.Case.data.initialPriorityStringCase Initial Priority
Argus.Case.data.priorityStringCase Priority
Argus.Case.data.subjectStringCase Subject
Argus.Case.data.descriptionStringCase Description
Argus.Case.data.customerReferenceStringCase Customer Reference
Argus.Case.data.accessModeStringCase Access Mode
Argus.Case.data.reporter.idNumberCase Reporter ID
Argus.Case.data.reporter.customerIDNumberCase Reporter Customer ID
Argus.Case.data.reporter.customer.idNumberCase Reporter Customer ID
Argus.Case.data.reporter.customer.nameStringCase Reporter Customer Name
Argus.Case.data.reporter.customer.shortNameStringCase Reporter Customer Short Name
Argus.Case.data.reporter.customer.domain.idNumberCase Reporter Customer Domain ID
Argus.Case.data.reporter.customer.domain.nameStringCase Reporter Customer Domain Name
Argus.Case.data.reporter.domain.idNumberCase Reporter Domain ID
Argus.Case.data.reporter.domain.nameStringCase Reporter Domain Name
Argus.Case.data.reporter.userNameStringCase Reporter User Name
Argus.Case.data.reporter.nameStringCase Reporter Name
Argus.Case.data.reporter.typeStringCase Reporter Type
Argus.Case.data.assignedUser.idNumberCase Assigned User ID
Argus.Case.data.assignedUser.customerIDNumberCase Assigned User Customer ID
Argus.Case.data.assignedUser.customer.idNumberCase Assigned User Customer ID
Argus.Case.data.assignedUser.customer.nameStringCase Assigned User Customer Name
Argus.Case.data.assignedUser.customer.shortNameStringCase Assigned User Customer Short Name
Argus.Case.data.assignedUser.customer.domain.idNumberCase Assigned User Customer Domain ID
Argus.Case.data.assignedUser.customer.domain.nameStringCase Assigned User Customer Domain Name
Argus.Case.data.assignedUser.domain.idNumberCase Assigned User Domain ID
Argus.Case.data.assignedUser.domain.nameStringCase Assigned User Domain Name
Argus.Case.data.assignedUser.userNameStringCase Assigned User User Name
Argus.Case.data.assignedUser.nameStringCase Assigned User Name
Argus.Case.data.assignedUser.typeStringCase Assigned User Type
Argus.Case.data.assignedTech.idNumberCase Assigned Tech ID
Argus.Case.data.assignedTech.customerIDNumberCase Assigned Tech Customer ID
Argus.Case.data.assignedTech.customer.idNumberCase Assigned Tech Customer ID
Argus.Case.data.assignedTech.customer.nameStringCase Assigned Tech Customer Name
Argus.Case.data.assignedTech.customer.shortNameStringCase Assigned Tech Customer Short Name
Argus.Case.data.assignedTech.customer.domain.idNumberCase Assigned Tech Customer Domain ID
Argus.Case.data.assignedTech.customer.domain.nameStringCase Assigned Tech Customer Domain Name
Argus.Case.data.assignedTech.domain.idNumberCase Assigned Tech Domain ID
Argus.Case.data.assignedTech.domain.nameStringCase Assigned Tech Domain Name
Argus.Case.data.assignedTech.userNameStringCase Assigned Tech User Name
Argus.Case.data.assignedTech.nameStringCase Assigned Tech Name
Argus.Case.data.assignedTech.typeStringCase Assigned Tech Type
Argus.Case.data.createdTimestampNumberCase Created Timestamp
Argus.Case.data.createdByUser.idNumberCase Created By User ID
Argus.Case.data.createdByUser.customerIDNumberCase Created By User Customer ID
Argus.Case.data.createdByUser.customer.idNumberCase Created By User Customer ID
Argus.Case.data.createdByUser.customer.nameStringCase Created By User Customer Name
Argus.Case.data.createdByUser.customer.shortNameStringCase Created By User Customer Short Name
Argus.Case.data.createdByUser.customer.domain.idNumberCase Created By User Customer Domain ID
Argus.Case.data.createdByUser.customer.domain.nameStringCase Created By User Customer Domain Name
Argus.Case.data.createdByUser.domain.idNumberCase Created By User Domain ID
Argus.Case.data.createdByUser.domain.nameStringCase Created By User Domain Name
Argus.Case.data.createdByUser.userNameStringCase Created By User User Name
Argus.Case.data.createdByUser.nameStringCase Created By User Name
Argus.Case.data.createdByUser.typeStringCase Created By User Type
Argus.Case.data.lastUpdatedTimestampNumberCase Last Updated Timestamp
Argus.Case.data.lastUpdatedByUser.idNumberCase Last Updated By User ID
Argus.Case.data.lastUpdatedByUser.customerIDNumberCase Last Updated By User Customer ID
Argus.Case.data.lastUpdatedByUser.customer.idNumberCase Last Updated By User Customer ID
Argus.Case.data.lastUpdatedByUser.customer.nameStringCase Last Updated By User Customer Name
Argus.Case.data.lastUpdatedByUser.customer.shortNameStringCase Last Updated By User Customer Short Name
Argus.Case.data.lastUpdatedByUser.customer.domain.idNumberCase Last Updated By User Customer Domain ID
Argus.Case.data.lastUpdatedByUser.customer.domain.nameStringCase Last Updated By User Customer Domain Name
Argus.Case.data.lastUpdatedByUser.domain.idNumberCase Last Updated By User Domain ID
Argus.Case.data.lastUpdatedByUser.domain.nameStringCase Last Updated By User Domain Name
Argus.Case.data.lastUpdatedByUser.userNameStringCase Last Updated By User User Name
Argus.Case.data.lastUpdatedByUser.nameStringCase Last Updated By User Name
Argus.Case.data.lastUpdatedByUser.typeStringCase Last Updated By User Type
Argus.Case.data.closedTimestampNumberCase Closed Timestamp
Argus.Case.data.closedByUser.idNumberCase Closed By User ID
Argus.Case.data.closedByUser.customerIDNumberCase Closed By User Customer ID
Argus.Case.data.closedByUser.customer.idNumberCase Closed By User Customer ID
Argus.Case.data.closedByUser.customer.nameStringCase Closed By User Customer Name
Argus.Case.data.closedByUser.customer.shortNameStringCase Closed By User Customer Short Name
Argus.Case.data.closedByUser.customer.domain.idNumberCase Closed By User Customer Domain ID
Argus.Case.data.closedByUser.customer.domain.nameStringCase Closed By User Customer Domain Name
Argus.Case.data.closedByUser.domain.idNumberCase Closed By User Domain ID
Argus.Case.data.closedByUser.domain.nameStringCase Closed By User Domain Name
Argus.Case.data.closedByUser.userNameStringCase Closed By User User Name
Argus.Case.data.closedByUser.nameStringCase Closed By User Name
Argus.Case.data.closedByUser.typeStringCase Closed By User Type
Argus.Case.data.publishedTimestampNumberCase Published Timestamp
Argus.Case.data.publishedByUser.idNumberCase Published By User ID
Argus.Case.data.publishedByUser.customerIDNumberCase Published By User Customer ID
Argus.Case.data.publishedByUser.customer.idNumberCase Published By User Customer ID
Argus.Case.data.publishedByUser.customer.nameStringCase Published By User Customer Name
Argus.Case.data.publishedByUser.customer.shortNameStringCase Published By User Customer Short Name
Argus.Case.data.publishedByUser.customer.domain.idNumberCase Published By User Customer Domain ID
Argus.Case.data.publishedByUser.customer.domain.nameStringCase Published By User Customer Domain Name
Argus.Case.data.publishedByUser.domain.idNumberCase Published By User Domain ID
Argus.Case.data.publishedByUser.domain.nameStringCase Published By User Domain Name
Argus.Case.data.publishedByUser.userNameStringCase Published By User User Name
Argus.Case.data.publishedByUser.nameStringCase Published By User Name
Argus.Case.data.publishedByUser.typeStringCase Published By User Type
Argus.Case.data.flagsStringCase Flags
Argus.Case.data.currentUserAccess.levelStringCase Current User Access Level
Argus.Case.data.currentUserAccess.roleStringCase Current User Access Role
Argus.Case.data.workflows.workflowStringCase Workflows Workflow
Argus.Case.data.workflows.stateStringCase Workflows State
Argus.Case.data.originEmailAddressStringCase Origin Email Address
Argus.Case.data.createdTimeStringCase Created Time
Argus.Case.data.lastUpdatedTimeStringCase Last Updated Time
Argus.Case.data.closedTimeStringCase Closed Time
Argus.Case.data.publishedTimeStringCase Published Time

Command Example#

!argus-delete-case case_id=123

argus-delete-comment#


Mark existing comment as deleted

Base Command#

argus-delete-comment

Input#

Argument NameDescriptionRequired
case_idID of Argus case where comment exists.Required
comment_idID of comment to mark as deleted.Required

Context Output#

PathTypeDescription
Argus.Comment.responseCodeNumberAPI response metadata, response code of this request
Argus.Comment.limitNumberAPI response metadata, limit of results this request ran with
Argus.Comment.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Comment.countNumberAPI response metadata, total number of results this query has
Argus.Comment.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Comment.messages.messageStringComment Messages Message
Argus.Comment.messages.messageTemplateStringComment Messages Message Template
Argus.Comment.messages.typeStringComment Messages Type
Argus.Comment.messages.fieldStringComment Messages Field
Argus.Comment.messages.timestampNumberComment Messages Timestamp
Argus.Comment.data.idStringComment ID
Argus.Comment.data.addedTimestampNumberComment Added Timestamp
Argus.Comment.data.addedByUser.idNumberComment Added By User ID
Argus.Comment.data.addedByUser.customerIDNumberComment Added By User Customer ID
Argus.Comment.data.addedByUser.customer.idNumberComment Added By User Customer ID
Argus.Comment.data.addedByUser.customer.nameStringComment Added By User Customer Name
Argus.Comment.data.addedByUser.customer.shortNameStringComment Added By User Customer Short Name
Argus.Comment.data.addedByUser.customer.domain.idNumberComment Added By User Customer Domain ID
Argus.Comment.data.addedByUser.customer.domain.nameStringComment Added By User Customer Domain Name
Argus.Comment.data.addedByUser.domain.idNumberComment Added By User Domain ID
Argus.Comment.data.addedByUser.domain.nameStringComment Added By User Domain Name
Argus.Comment.data.addedByUser.userNameStringComment Added By User User Name
Argus.Comment.data.addedByUser.nameStringComment Added By User Name
Argus.Comment.data.addedByUser.typeStringComment Added By User Type
Argus.Comment.data.commentStringComment Comment
Argus.Comment.data.flagsStringComment Flags
Argus.Comment.data.lastUpdatedTimestampNumberComment Last Updated Timestamp
Argus.Comment.data.statusStringComment Status
Argus.Comment.data.priorityStringComment Priority
Argus.Comment.data.originEmailAddressStringComment Origin Email Address
Argus.Comment.data.associatedAttachments.idStringComment Associated Attachments ID
Argus.Comment.data.associatedAttachments.nameStringComment Associated Attachments Name
Argus.Comment.data.references.typeStringComment References Type
Argus.Comment.data.references.commentIDStringComment References Comment ID
Argus.Comment.data.lastUpdatedTimeStringComment Last Updated Time
Argus.Comment.data.addedTimeStringComment Added Time

Command Example#

!argus-delete-comment case_id=123 comment_id=123456

argus-edit-comment#


Edit existing comment

Base Command#

argus-edit-comment

Input#

Argument NameDescriptionRequired
case_idID of Argus case where comment exists.Required
comment_idID of comment to edit.Required
commentComment text which will replace the current text.Required

Context Output#

PathTypeDescription
Argus.Comment.responseCodeNumberAPI response metadata, response code of this request
Argus.Comment.limitNumberAPI response metadata, limit of results this request ran with
Argus.Comment.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Comment.countNumberAPI response metadata, total number of results this query has
Argus.Comment.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Comment.messages.messageStringComment Messages Message
Argus.Comment.messages.messageTemplateStringComment Messages Message Template
Argus.Comment.messages.typeStringComment Messages Type
Argus.Comment.messages.fieldStringComment Messages Field
Argus.Comment.messages.timestampNumberComment Messages Timestamp
Argus.Comment.data.idStringComment ID
Argus.Comment.data.addedTimestampNumberComment Added Timestamp
Argus.Comment.data.addedByUser.idNumberComment Added By User ID
Argus.Comment.data.addedByUser.customerIDNumberComment Added By User Customer ID
Argus.Comment.data.addedByUser.customer.idNumberComment Added By User Customer ID
Argus.Comment.data.addedByUser.customer.nameStringComment Added By User Customer Name
Argus.Comment.data.addedByUser.customer.shortNameStringComment Added By User Customer Short Name
Argus.Comment.data.addedByUser.customer.domain.idNumberComment Added By User Customer Domain ID
Argus.Comment.data.addedByUser.customer.domain.nameStringComment Added By User Customer Domain Name
Argus.Comment.data.addedByUser.domain.idNumberComment Added By User Domain ID
Argus.Comment.data.addedByUser.domain.nameStringComment Added By User Domain Name
Argus.Comment.data.addedByUser.userNameStringComment Added By User User Name
Argus.Comment.data.addedByUser.nameStringComment Added By User Name
Argus.Comment.data.addedByUser.typeStringComment Added By User Type
Argus.Comment.data.commentStringComment Comment
Argus.Comment.data.flagsStringComment Flags
Argus.Comment.data.lastUpdatedTimestampNumberComment Last Updated Timestamp
Argus.Comment.data.statusStringComment Status
Argus.Comment.data.priorityStringComment Priority
Argus.Comment.data.originEmailAddressStringComment Origin Email Address
Argus.Comment.data.associatedAttachments.idStringComment Associated Attachments ID
Argus.Comment.data.associatedAttachments.nameStringComment Associated Attachments Name
Argus.Comment.data.references.typeStringComment References Type
Argus.Comment.data.references.commentIDStringComment References Comment ID
Argus.Comment.data.lastUpdatedTimeStringComment Last Updated Time
Argus.Comment.data.addedTimeStringComment Added Time

Command Example#

!argus-edit-comment case_id=123 comment_id=123456 comment="comment content"

argus-get-case-metadata-by-id#


Returns the basic case descriptor for the case identified by ID

Base Command#

argus-get-case-metadata-by-id

Input#

Argument NameDescriptionRequired
case_idID of Argus case.Required
skip_redirectIf true, skip automatic redirect (for merged cases). Possible values are: true, false.Optional

Context Output#

PathTypeDescription
Argus.Case.responseCodeNumberAPI response metadata, response code of this request
Argus.Case.limitNumberAPI response metadata, limit of results this request ran with
Argus.Case.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Case.countNumberAPI response metadata, total number of results this query has
Argus.Case.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Case.messages.messageStringCase Messages Message
Argus.Case.messages.messageTemplateStringCase Messages Message Template
Argus.Case.messages.typeStringCase Messages Type
Argus.Case.messages.fieldStringCase Messages Field
Argus.Case.messages.timestampNumberCase Messages Timestamp
Argus.Case.data.idNumberCase ID
Argus.Case.data.customer.idNumberCase Customer ID
Argus.Case.data.customer.nameStringCase Customer Name
Argus.Case.data.customer.shortNameStringCase Customer Short Name
Argus.Case.data.customer.domain.idNumberCase Customer Domain ID
Argus.Case.data.customer.domain.nameStringCase Customer Domain Name
Argus.Case.data.service.idNumberCase Service ID
Argus.Case.data.service.nameStringCase Service Name
Argus.Case.data.service.shortNameStringCase Service Short Name
Argus.Case.data.service.localizedNameStringCase Service Localized Name
Argus.Case.data.category.idNumberCase Category ID
Argus.Case.data.category.nameStringCase Category Name
Argus.Case.data.category.shortNameStringCase Category Short Name
Argus.Case.data.category.localizedNameStringCase Category Localized Name
Argus.Case.data.typeStringCase Type
Argus.Case.data.initialStatusStringCase Initial Status
Argus.Case.data.statusStringCase Status
Argus.Case.data.initialPriorityStringCase Initial Priority
Argus.Case.data.priorityStringCase Priority
Argus.Case.data.subjectStringCase Subject
Argus.Case.data.descriptionStringCase Description
Argus.Case.data.customerReferenceStringCase Customer Reference
Argus.Case.data.accessModeStringCase Access Mode
Argus.Case.data.reporter.idNumberCase Reporter ID
Argus.Case.data.reporter.customerIDNumberCase Reporter Customer ID
Argus.Case.data.reporter.customer.idNumberCase Reporter Customer ID
Argus.Case.data.reporter.customer.nameStringCase Reporter Customer Name
Argus.Case.data.reporter.customer.shortNameStringCase Reporter Customer Short Name
Argus.Case.data.reporter.customer.domain.idNumberCase Reporter Customer Domain ID
Argus.Case.data.reporter.customer.domain.nameStringCase Reporter Customer Domain Name
Argus.Case.data.reporter.domain.idNumberCase Reporter Domain ID
Argus.Case.data.reporter.domain.nameStringCase Reporter Domain Name
Argus.Case.data.reporter.userNameStringCase Reporter User Name
Argus.Case.data.reporter.nameStringCase Reporter Name
Argus.Case.data.reporter.typeStringCase Reporter Type
Argus.Case.data.assignedUser.idNumberCase Assigned User ID
Argus.Case.data.assignedUser.customerIDNumberCase Assigned User Customer ID
Argus.Case.data.assignedUser.customer.idNumberCase Assigned User Customer ID
Argus.Case.data.assignedUser.customer.nameStringCase Assigned User Customer Name
Argus.Case.data.assignedUser.customer.shortNameStringCase Assigned User Customer Short Name
Argus.Case.data.assignedUser.customer.domain.idNumberCase Assigned User Customer Domain ID
Argus.Case.data.assignedUser.customer.domain.nameStringCase Assigned User Customer Domain Name
Argus.Case.data.assignedUser.domain.idNumberCase Assigned User Domain ID
Argus.Case.data.assignedUser.domain.nameStringCase Assigned User Domain Name
Argus.Case.data.assignedUser.userNameStringCase Assigned User User Name
Argus.Case.data.assignedUser.nameStringCase Assigned User Name
Argus.Case.data.assignedUser.typeStringCase Assigned User Type
Argus.Case.data.assignedTech.idNumberCase Assigned Tech ID
Argus.Case.data.assignedTech.customerIDNumberCase Assigned Tech Customer ID
Argus.Case.data.assignedTech.customer.idNumberCase Assigned Tech Customer ID
Argus.Case.data.assignedTech.customer.nameStringCase Assigned Tech Customer Name
Argus.Case.data.assignedTech.customer.shortNameStringCase Assigned Tech Customer Short Name
Argus.Case.data.assignedTech.customer.domain.idNumberCase Assigned Tech Customer Domain ID
Argus.Case.data.assignedTech.customer.domain.nameStringCase Assigned Tech Customer Domain Name
Argus.Case.data.assignedTech.domain.idNumberCase Assigned Tech Domain ID
Argus.Case.data.assignedTech.domain.nameStringCase Assigned Tech Domain Name
Argus.Case.data.assignedTech.userNameStringCase Assigned Tech User Name
Argus.Case.data.assignedTech.nameStringCase Assigned Tech Name
Argus.Case.data.assignedTech.typeStringCase Assigned Tech Type
Argus.Case.data.createdTimestampNumberCase Created Timestamp
Argus.Case.data.createdByUser.idNumberCase Created By User ID
Argus.Case.data.createdByUser.customerIDNumberCase Created By User Customer ID
Argus.Case.data.createdByUser.customer.idNumberCase Created By User Customer ID
Argus.Case.data.createdByUser.customer.nameStringCase Created By User Customer Name
Argus.Case.data.createdByUser.customer.shortNameStringCase Created By User Customer Short Name
Argus.Case.data.createdByUser.customer.domain.idNumberCase Created By User Customer Domain ID
Argus.Case.data.createdByUser.customer.domain.nameStringCase Created By User Customer Domain Name
Argus.Case.data.createdByUser.domain.idNumberCase Created By User Domain ID
Argus.Case.data.createdByUser.domain.nameStringCase Created By User Domain Name
Argus.Case.data.createdByUser.userNameStringCase Created By User User Name
Argus.Case.data.createdByUser.nameStringCase Created By User Name
Argus.Case.data.createdByUser.typeStringCase Created By User Type
Argus.Case.data.lastUpdatedTimestampNumberCase Last Updated Timestamp
Argus.Case.data.lastUpdatedByUser.idNumberCase Last Updated By User ID
Argus.Case.data.lastUpdatedByUser.customerIDNumberCase Last Updated By User Customer ID
Argus.Case.data.lastUpdatedByUser.customer.idNumberCase Last Updated By User Customer ID
Argus.Case.data.lastUpdatedByUser.customer.nameStringCase Last Updated By User Customer Name
Argus.Case.data.lastUpdatedByUser.customer.shortNameStringCase Last Updated By User Customer Short Name
Argus.Case.data.lastUpdatedByUser.customer.domain.idNumberCase Last Updated By User Customer Domain ID
Argus.Case.data.lastUpdatedByUser.customer.domain.nameStringCase Last Updated By User Customer Domain Name
Argus.Case.data.lastUpdatedByUser.domain.idNumberCase Last Updated By User Domain ID
Argus.Case.data.lastUpdatedByUser.domain.nameStringCase Last Updated By User Domain Name
Argus.Case.data.lastUpdatedByUser.userNameStringCase Last Updated By User User Name
Argus.Case.data.lastUpdatedByUser.nameStringCase Last Updated By User Name
Argus.Case.data.lastUpdatedByUser.typeStringCase Last Updated By User Type
Argus.Case.data.closedTimestampNumberCase Closed Timestamp
Argus.Case.data.closedByUser.idNumberCase Closed By User ID
Argus.Case.data.closedByUser.customerIDNumberCase Closed By User Customer ID
Argus.Case.data.closedByUser.customer.idNumberCase Closed By User Customer ID
Argus.Case.data.closedByUser.customer.nameStringCase Closed By User Customer Name
Argus.Case.data.closedByUser.customer.shortNameStringCase Closed By User Customer Short Name
Argus.Case.data.closedByUser.customer.domain.idNumberCase Closed By User Customer Domain ID
Argus.Case.data.closedByUser.customer.domain.nameStringCase Closed By User Customer Domain Name
Argus.Case.data.closedByUser.domain.idNumberCase Closed By User Domain ID
Argus.Case.data.closedByUser.domain.nameStringCase Closed By User Domain Name
Argus.Case.data.closedByUser.userNameStringCase Closed By User User Name
Argus.Case.data.closedByUser.nameStringCase Closed By User Name
Argus.Case.data.closedByUser.typeStringCase Closed By User Type
Argus.Case.data.publishedTimestampNumberCase Published Timestamp
Argus.Case.data.publishedByUser.idNumberCase Published By User ID
Argus.Case.data.publishedByUser.customerIDNumberCase Published By User Customer ID
Argus.Case.data.publishedByUser.customer.idNumberCase Published By User Customer ID
Argus.Case.data.publishedByUser.customer.nameStringCase Published By User Customer Name
Argus.Case.data.publishedByUser.customer.shortNameStringCase Published By User Customer Short Name
Argus.Case.data.publishedByUser.customer.domain.idNumberCase Published By User Customer Domain ID
Argus.Case.data.publishedByUser.customer.domain.nameStringCase Published By User Customer Domain Name
Argus.Case.data.publishedByUser.domain.idNumberCase Published By User Domain ID
Argus.Case.data.publishedByUser.domain.nameStringCase Published By User Domain Name
Argus.Case.data.publishedByUser.userNameStringCase Published By User User Name
Argus.Case.data.publishedByUser.nameStringCase Published By User Name
Argus.Case.data.publishedByUser.typeStringCase Published By User Type
Argus.Case.data.flagsStringCase Flags
Argus.Case.data.currentUserAccess.levelStringCase Current User Access Level
Argus.Case.data.currentUserAccess.roleStringCase Current User Access Role
Argus.Case.data.workflows.workflowStringCase Workflows Workflow
Argus.Case.data.workflows.stateStringCase Workflows State
Argus.Case.data.originEmailAddressStringCase Origin Email Address
Argus.Case.data.createdTimeStringCase Created Time
Argus.Case.data.lastUpdatedTimeStringCase Last Updated Time
Argus.Case.data.closedTimeStringCase Closed Time
Argus.Case.data.publishedTimeStringCase Published Time

Command Example#

!argus-get-case_metadata_by_id case_id=123

argus-list-case-attachments#


List attachments for an existing case

Base Command#

argus-list-case-attachments

Input#

Argument NameDescriptionRequired
case_idID of Argus case.Required
limitMaximum number of returned results.Optional
offsetSkip a number of results.Optional

Context Output#

PathTypeDescription
Argus.Attachments.responseCodeNumberAPI response metadata, response code of this request
Argus.Attachments.limitNumberAPI response metadata, limit of results this request ran with
Argus.Attachments.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Attachments.countNumberAPI response metadata, total number of results this query has
Argus.Attachments.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Attachments.messages.messageStringAttachment Messages Message
Argus.Attachments.messages.messageTemplateStringAttachment Messages Message Template
Argus.Attachments.messages.typeStringAttachment Messages Type
Argus.Attachments.messages.fieldStringAttachment Messages Field
Argus.Attachments.messages.timestampNumberAttachment Messages Timestamp
Argus.Attachments.data.idStringAttachment ID
Argus.Attachments.data.addedTimestampNumberAttachment Added Timestamp
Argus.Attachments.data.addedByUser.idNumberAttachment Added By User ID
Argus.Attachments.data.addedByUser.customerIDNumberAttachment Added By User Customer ID
Argus.Attachments.data.addedByUser.customer.idNumberAttachment Added By User Customer ID
Argus.Attachments.data.addedByUser.customer.nameStringAttachment Added By User Customer Name
Argus.Attachments.data.addedByUser.customer.shortNameStringAttachment Added By User Customer Short Name
Argus.Attachments.data.addedByUser.customer.domain.idNumberAttachment Added By User Customer Domain ID
Argus.Attachments.data.addedByUser.customer.domain.nameStringAttachment Added By User Customer Domain Name
Argus.Attachments.data.addedByUser.domain.idNumberAttachment Added By User Domain ID
Argus.Attachments.data.addedByUser.domain.nameStringAttachment Added By User Domain Name
Argus.Attachments.data.addedByUser.userNameStringAttachment Added By User User Name
Argus.Attachments.data.addedByUser.nameStringAttachment Added By User Name
Argus.Attachments.data.addedByUser.typeStringAttachment Added By User Type
Argus.Attachments.data.nameStringAttachment Name
Argus.Attachments.data.mimeTypeStringAttachment Mime Type
Argus.Attachments.data.flagsStringAttachment Flags
Argus.Attachments.data.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Attachments.data.originEmailAddressStringAttachment Origin Email Address
Argus.Attachments.data.addedTimeStringAttachment Added Time

Command Example#

!argus-list-case-attachments case_id=123

argus-remove-case-tag-by-id#


Remove existing tag by tag ID

Base Command#

argus-remove-case-tag-by-id

Input#

Argument NameDescriptionRequired
case_idID of Argus case.Required
tag_idID of tag to remove.Required

Context Output#

PathTypeDescription
Argus.Tags.responseCodeNumberAPI response metadata, response code of this request
Argus.Tags.limitNumberAPI response metadata, limit of results this request ran with
Argus.Tags.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Tags.countNumberAPI response metadata, total number of results this query has
Argus.Tags.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Tags.messages.messageStringTag Messages Message
Argus.Tags.messages.messageTemplateStringTag Messages Message Template
Argus.Tags.messages.typeStringTag Messages Type
Argus.Tags.messages.fieldStringTag Messages Field
Argus.Tags.messages.timestampNumberTag Messages Timestamp
Argus.Tags.data.idStringTag ID
Argus.Tags.data.keyStringTag Key
Argus.Tags.data.valueStringTag Value
Argus.Tags.data.addedTimestampNumberTag Added Timestamp
Argus.Tags.data.addedByUser.idNumberTag Added By User ID
Argus.Tags.data.addedByUser.customerIDNumberTag Added By User Customer ID
Argus.Tags.data.addedByUser.customer.idNumberTag Added By User Customer ID
Argus.Tags.data.addedByUser.customer.nameStringTag Added By User Customer Name
Argus.Tags.data.addedByUser.customer.shortNameStringTag Added By User Customer Short Name
Argus.Tags.data.addedByUser.customer.domain.idNumberTag Added By User Customer Domain ID
Argus.Tags.data.addedByUser.customer.domain.nameStringTag Added By User Customer Domain Name
Argus.Tags.data.addedByUser.domain.idNumberTag Added By User Domain ID
Argus.Tags.data.addedByUser.domain.nameStringTag Added By User Domain Name
Argus.Tags.data.addedByUser.userNameStringTag Added By User User Name
Argus.Tags.data.addedByUser.nameStringTag Added By User Name
Argus.Tags.data.addedByUser.typeStringTag Added By User Type
Argus.Tags.data.flagsStringTag Flags
Argus.Tags.data.addedTimeStringTag Added Time

Command Example#

!argus-remove-case-tag-by-id case_id=123 tag_id=123456

argus-remove-case-tag-by-key-value#


Remove existing tag with key, value matching

Base Command#

argus-remove-case-tag-by-key-value

Input#

Argument NameDescriptionRequired
case_idID of Argus case.Required
keyKey of tag to remove.Required
valueValue of tag to remove.Required

Context Output#

PathTypeDescription
Argus.Tags.responseCodeNumberAPI response metadata, response code of this request
Argus.Tags.limitNumberAPI response metadata, limit of results this request ran with
Argus.Tags.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Tags.countNumberAPI response metadata, total number of results this query has
Argus.Tags.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Tags.messages.messageStringTag Messages Message
Argus.Tags.messages.messageTemplateStringTag Messages Message Template
Argus.Tags.messages.typeStringTag Messages Type
Argus.Tags.messages.fieldStringTag Messages Field
Argus.Tags.messages.timestampNumberTag Messages Timestamp
Argus.Tags.data.idStringTag ID
Argus.Tags.data.keyStringTag Key
Argus.Tags.data.valueStringTag Value
Argus.Tags.data.addedTimestampNumberTag Added Timestamp
Argus.Tags.data.addedByUser.idNumberTag Added By User ID
Argus.Tags.data.addedByUser.customerIDNumberTag Added By User Customer ID
Argus.Tags.data.addedByUser.customer.idNumberTag Added By User Customer ID
Argus.Tags.data.addedByUser.customer.nameStringTag Added By User Customer Name
Argus.Tags.data.addedByUser.customer.shortNameStringTag Added By User Customer Short Name
Argus.Tags.data.addedByUser.customer.domain.idNumberTag Added By User Customer Domain ID
Argus.Tags.data.addedByUser.customer.domain.nameStringTag Added By User Customer Domain Name
Argus.Tags.data.addedByUser.domain.idNumberTag Added By User Domain ID
Argus.Tags.data.addedByUser.domain.nameStringTag Added By User Domain Name
Argus.Tags.data.addedByUser.userNameStringTag Added By User User Name
Argus.Tags.data.addedByUser.nameStringTag Added By User Name
Argus.Tags.data.addedByUser.typeStringTag Added By User Type
Argus.Tags.data.flagsStringTag Flags
Argus.Tags.data.addedTimeStringTag Added Time

Command Example#

!argus-remove-case-tag-by-key-value case_id=123 key=foo value=bar

argus-update-case#


Request changes to basic fields of an existing case.

Base Command#

argus-update-case

Input#

Argument NameDescriptionRequired
case_idID of Argus case to update.Required
subjectIf set, change subject of case.Optional
descriptionIf set, change description of case. May use HTML, will be sanitized. .Optional
statusIf set, change status of case . Possible values are: pendingCustomer, pendingSoc, pendingVendor, pendingClose, workingSoc, workingCustomer.Optional
priorityIf set, change priority of case. . Possible values are: low, medium, high, critical.Optional
categoryIf set, assign given category to specified category (by category shortname). Set value to empty string to unset category. . Possible values are: network-testing, unauthorized-access, dos, data-leakage, exposed-malicious, malicious-infection, poor-practice, reconnaissance, misconfigured, vpn-down, sensor-malfunctioning, not-receiving-traffic, false-positive, suspected-targeted-attack, duplicate, problem-managed, problem-customer, adware, network-connection-lost, failed-authentication, missing-log-sources, no-threat, phishing, argus-improvement, argus-bug.Optional
reporterIf set, set given user as reporter for case (by ID or shortname). Shortname will be resolved in the current users domain. .Optional
assigned_userIf set, assign given user to case (by ID or shortname). Shortname will be resolved in the current users domain. If blank, this will unset assignedUser. .Optional
assigned_techIf set, assign given technical user (solution engineer) to case (by ID or shortname). Shortname will be resolved in the current users domain. If blank, this will unset assignedTech.Optional
customer_referenceIf set, change customer reference for case. .Optional
commentIf set, add comment to case. May use HTML, will be sanitized. .Optional
origin_email_addressIf update is made from an email, specify origin email address here.Optional
has_eventsf set, update the hasEvents flag for this case, signalling that this case may have events associated to it. . Possible values are: true, false.Optional
internal_commentIf true, add comment as internal. (default false). Possible values are: true, false. Default is false.Optional

Context Output#

PathTypeDescription
Argus.Case.responseCodeNumberAPI response metadata, response code of this request
Argus.Case.limitNumberAPI response metadata, limit of results this request ran with
Argus.Case.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Case.countNumberAPI response metadata, total number of results this query has
Argus.Case.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Case.messages.messageStringCase Messages Message
Argus.Case.messages.messageTemplateStringCase Messages Message Template
Argus.Case.messages.typeStringCase Messages Type
Argus.Case.messages.fieldStringCase Messages Field
Argus.Case.messages.timestampNumberCase Messages Timestamp
Argus.Case.data.idNumberCase ID
Argus.Case.data.customer.idNumberCase Customer ID
Argus.Case.data.customer.nameStringCase Customer Name
Argus.Case.data.customer.shortNameStringCase Customer Short Name
Argus.Case.data.customer.domain.idNumberCase Customer Domain ID
Argus.Case.data.customer.domain.nameStringCase Customer Domain Name
Argus.Case.data.service.idNumberCase Service ID
Argus.Case.data.service.nameStringCase Service Name
Argus.Case.data.service.shortNameStringCase Service Short Name
Argus.Case.data.service.localizedNameStringCase Service Localized Name
Argus.Case.data.category.idNumberCase Category ID
Argus.Case.data.category.nameStringCase Category Name
Argus.Case.data.category.shortNameStringCase Category Short Name
Argus.Case.data.category.localizedNameStringCase Category Localized Name
Argus.Case.data.typeStringCase Type
Argus.Case.data.initialStatusStringCase Initial Status
Argus.Case.data.statusStringCase Status
Argus.Case.data.initialPriorityStringCase Initial Priority
Argus.Case.data.priorityStringCase Priority
Argus.Case.data.subjectStringCase Subject
Argus.Case.data.descriptionStringCase Description
Argus.Case.data.customerReferenceStringCase Customer Reference
Argus.Case.data.accessModeStringCase Access Mode
Argus.Case.data.reporter.idNumberCase Reporter ID
Argus.Case.data.reporter.customerIDNumberCase Reporter Customer ID
Argus.Case.data.reporter.customer.idNumberCase Reporter Customer ID
Argus.Case.data.reporter.customer.nameStringCase Reporter Customer Name
Argus.Case.data.reporter.customer.shortNameStringCase Reporter Customer Short Name
Argus.Case.data.reporter.customer.domain.idNumberCase Reporter Customer Domain ID
Argus.Case.data.reporter.customer.domain.nameStringCase Reporter Customer Domain Name
Argus.Case.data.reporter.domain.idNumberCase Reporter Domain ID
Argus.Case.data.reporter.domain.nameStringCase Reporter Domain Name
Argus.Case.data.reporter.userNameStringCase Reporter User Name
Argus.Case.data.reporter.nameStringCase Reporter Name
Argus.Case.data.reporter.typeStringCase Reporter Type
Argus.Case.data.assignedUser.idNumberCase Assigned User ID
Argus.Case.data.assignedUser.customerIDNumberCase Assigned User Customer ID
Argus.Case.data.assignedUser.customer.idNumberCase Assigned User Customer ID
Argus.Case.data.assignedUser.customer.nameStringCase Assigned User Customer Name
Argus.Case.data.assignedUser.customer.shortNameStringCase Assigned User Customer Short Name
Argus.Case.data.assignedUser.customer.domain.idNumberCase Assigned User Customer Domain ID
Argus.Case.data.assignedUser.customer.domain.nameStringCase Assigned User Customer Domain Name
Argus.Case.data.assignedUser.domain.idNumberCase Assigned User Domain ID
Argus.Case.data.assignedUser.domain.nameStringCase Assigned User Domain Name
Argus.Case.data.assignedUser.userNameStringCase Assigned User User Name
Argus.Case.data.assignedUser.nameStringCase Assigned User Name
Argus.Case.data.assignedUser.typeStringCase Assigned User Type
Argus.Case.data.assignedTech.idNumberCase Assigned Tech ID
Argus.Case.data.assignedTech.customerIDNumberCase Assigned Tech Customer ID
Argus.Case.data.assignedTech.customer.idNumberCase Assigned Tech Customer ID
Argus.Case.data.assignedTech.customer.nameStringCase Assigned Tech Customer Name
Argus.Case.data.assignedTech.customer.shortNameStringCase Assigned Tech Customer Short Name
Argus.Case.data.assignedTech.customer.domain.idNumberCase Assigned Tech Customer Domain ID
Argus.Case.data.assignedTech.customer.domain.nameStringCase Assigned Tech Customer Domain Name
Argus.Case.data.assignedTech.domain.idNumberCase Assigned Tech Domain ID
Argus.Case.data.assignedTech.domain.nameStringCase Assigned Tech Domain Name
Argus.Case.data.assignedTech.userNameStringCase Assigned Tech User Name
Argus.Case.data.assignedTech.nameStringCase Assigned Tech Name
Argus.Case.data.assignedTech.typeStringCase Assigned Tech Type
Argus.Case.data.createdTimestampNumberCase Created Timestamp
Argus.Case.data.createdByUser.idNumberCase Created By User ID
Argus.Case.data.createdByUser.customerIDNumberCase Created By User Customer ID
Argus.Case.data.createdByUser.customer.idNumberCase Created By User Customer ID
Argus.Case.data.createdByUser.customer.nameStringCase Created By User Customer Name
Argus.Case.data.createdByUser.customer.shortNameStringCase Created By User Customer Short Name
Argus.Case.data.createdByUser.customer.domain.idNumberCase Created By User Customer Domain ID
Argus.Case.data.createdByUser.customer.domain.nameStringCase Created By User Customer Domain Name
Argus.Case.data.createdByUser.domain.idNumberCase Created By User Domain ID
Argus.Case.data.createdByUser.domain.nameStringCase Created By User Domain Name
Argus.Case.data.createdByUser.userNameStringCase Created By User User Name
Argus.Case.data.createdByUser.nameStringCase Created By User Name
Argus.Case.data.createdByUser.typeStringCase Created By User Type
Argus.Case.data.lastUpdatedTimestampNumberCase Last Updated Timestamp
Argus.Case.data.lastUpdatedByUser.idNumberCase Last Updated By User ID
Argus.Case.data.lastUpdatedByUser.customerIDNumberCase Last Updated By User Customer ID
Argus.Case.data.lastUpdatedByUser.customer.idNumberCase Last Updated By User Customer ID
Argus.Case.data.lastUpdatedByUser.customer.nameStringCase Last Updated By User Customer Name
Argus.Case.data.lastUpdatedByUser.customer.shortNameStringCase Last Updated By User Customer Short Name
Argus.Case.data.lastUpdatedByUser.customer.domain.idNumberCase Last Updated By User Customer Domain ID
Argus.Case.data.lastUpdatedByUser.customer.domain.nameStringCase Last Updated By User Customer Domain Name
Argus.Case.data.lastUpdatedByUser.domain.idNumberCase Last Updated By User Domain ID
Argus.Case.data.lastUpdatedByUser.domain.nameStringCase Last Updated By User Domain Name
Argus.Case.data.lastUpdatedByUser.userNameStringCase Last Updated By User User Name
Argus.Case.data.lastUpdatedByUser.nameStringCase Last Updated By User Name
Argus.Case.data.lastUpdatedByUser.typeStringCase Last Updated By User Type
Argus.Case.data.closedTimestampNumberCase Closed Timestamp
Argus.Case.data.closedByUser.idNumberCase Closed By User ID
Argus.Case.data.closedByUser.customerIDNumberCase Closed By User Customer ID
Argus.Case.data.closedByUser.customer.idNumberCase Closed By User Customer ID
Argus.Case.data.closedByUser.customer.nameStringCase Closed By User Customer Name
Argus.Case.data.closedByUser.customer.shortNameStringCase Closed By User Customer Short Name
Argus.Case.data.closedByUser.customer.domain.idNumberCase Closed By User Customer Domain ID
Argus.Case.data.closedByUser.customer.domain.nameStringCase Closed By User Customer Domain Name
Argus.Case.data.closedByUser.domain.idNumberCase Closed By User Domain ID
Argus.Case.data.closedByUser.domain.nameStringCase Closed By User Domain Name
Argus.Case.data.closedByUser.userNameStringCase Closed By User User Name
Argus.Case.data.closedByUser.nameStringCase Closed By User Name
Argus.Case.data.closedByUser.typeStringCase Closed By User Type
Argus.Case.data.publishedTimestampNumberCase Published Timestamp
Argus.Case.data.publishedByUser.idNumberCase Published By User ID
Argus.Case.data.publishedByUser.customerIDNumberCase Published By User Customer ID
Argus.Case.data.publishedByUser.customer.idNumberCase Published By User Customer ID
Argus.Case.data.publishedByUser.customer.nameStringCase Published By User Customer Name
Argus.Case.data.publishedByUser.customer.shortNameStringCase Published By User Customer Short Name
Argus.Case.data.publishedByUser.customer.domain.idNumberCase Published By User Customer Domain ID
Argus.Case.data.publishedByUser.customer.domain.nameStringCase Published By User Customer Domain Name
Argus.Case.data.publishedByUser.domain.idNumberCase Published By User Domain ID
Argus.Case.data.publishedByUser.domain.nameStringCase Published By User Domain Name
Argus.Case.data.publishedByUser.userNameStringCase Published By User User Name
Argus.Case.data.publishedByUser.nameStringCase Published By User Name
Argus.Case.data.publishedByUser.typeStringCase Published By User Type
Argus.Case.data.flagsStringCase Flags
Argus.Case.data.currentUserAccess.levelStringCase Current User Access Level
Argus.Case.data.currentUserAccess.roleStringCase Current User Access Role
Argus.Case.data.workflows.workflowStringCase Workflows Workflow
Argus.Case.data.workflows.stateStringCase Workflows State
Argus.Case.data.originEmailAddressStringCase Origin Email Address
Argus.Case.data.createdTimeStringCase Created Time
Argus.Case.data.lastUpdatedTimeStringCase Last Updated Time
Argus.Case.data.closedTimeStringCase Closed Time
Argus.Case.data.publishedTimeStringCase Published Time

Command Example#

!argus-update-case case_id=123

argus-get-attachment#


Fetch specific attachment metadata

Base Command#

argus-get-attachment

Input#

Argument NameDescriptionRequired
case_idID of Argus case.Required
attachment_idID of attachement.Required

Context Output#

PathTypeDescription
Argus.Attachment.responseCodeNumberAPI response metadata, response code of this request
Argus.Attachment.limitNumberAPI response metadata, limit of results this request ran with
Argus.Attachment.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Attachment.countNumberAPI response metadata, total number of results this query has
Argus.Attachment.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Attachment.messages.messageStringAttachment Messages Message
Argus.Attachment.messages.messageTemplateStringAttachment Messages Message Template
Argus.Attachment.messages.typeStringAttachment Messages Type
Argus.Attachment.messages.fieldStringAttachment Messages Field
Argus.Attachment.messages.timestampNumberAttachment Messages Timestamp
Argus.Attachment.data.idStringAttachment ID
Argus.Attachment.data.addedTimestampNumberAttachment Added Timestamp
Argus.Attachment.data.addedByUser.idNumberAttachment Added By User ID
Argus.Attachment.data.addedByUser.customerIDNumberAttachment Added By User Customer ID
Argus.Attachment.data.addedByUser.customer.idNumberAttachment Added By User Customer ID
Argus.Attachment.data.addedByUser.customer.nameStringAttachment Added By User Customer Name
Argus.Attachment.data.addedByUser.customer.shortNameStringAttachment Added By User Customer Short Name
Argus.Attachment.data.addedByUser.customer.domain.idNumberAttachment Added By User Customer Domain ID
Argus.Attachment.data.addedByUser.customer.domain.nameStringAttachment Added By User Customer Domain Name
Argus.Attachment.data.addedByUser.domain.idNumberAttachment Added By User Domain ID
Argus.Attachment.data.addedByUser.domain.nameStringAttachment Added By User Domain Name
Argus.Attachment.data.addedByUser.userNameStringAttachment Added By User User Name
Argus.Attachment.data.addedByUser.nameStringAttachment Added By User Name
Argus.Attachment.data.addedByUser.typeStringAttachment Added By User Type
Argus.Attachment.data.nameStringAttachment Name
Argus.Attachment.data.mimeTypeStringAttachment Mime Type
Argus.Attachment.data.flagsStringAttachment Flags
Argus.Attachment.data.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Attachment.data.originEmailAddressStringAttachment Origin Email Address
Argus.Attachment.data.addedTimeStringAttachment Added Time

Command Example#

!argus-get-attachment case_id=123 attachment_id=123456

argus-download-attachment#


Download specific attachment contents.

Base Command#

argus-download-attachment

Input#

Argument NameDescriptionRequired
case_idID of Argus case.Required
attachment_idID of attachment to download. .Required
file_nameFilename of attachment, will otherwise be the ID.Optional

Context Output#

PathTypeDescription
File.SizeNumberThe size of the file.
File.SHA1StringThe SHA1 hash of the file.
File.SHA256StringThe SHA256 hash of the file.
File.NameStringThe name of the file.
File.SSDeepStringThe SSDeep hash of the file.
File.EntryIDStringThe entry ID of the file.
File.InfoStringFile information.
File.TypeStringThe file type.
File.MD5StringThe MD5 hash of the file.
File.ExtensionStringThe file extension.

Command Example#

!argus-download-attachment case_id=123 attachment_id=123456

argus-get-events-for-case#


Fetch events associated with specified case.

Base Command#

argus-get-events-for-case

Input#

Argument NameDescriptionRequired
case_idID of Argus case.Required
limitMaximum number of returned results (default 25).Optional
offsetSkip a number of results.Optional

Context Output#

PathTypeDescription
Argus.Events.responseCodeNumberAPI response metadata, response code of this request
Argus.Events.limitNumberAPI response metadata, limit of results this request ran with
Argus.Events.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Events.countNumberAPI response metadata, total number of results this query has
Argus.Events.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Events.messages.messageStringEvent Messages Message
Argus.Events.messages.messageTemplateStringEvent Messages Message Template
Argus.Events.messages.typeStringEvent Messages Type
Argus.Events.messages.fieldStringEvent Messages Field
Argus.Events.messages.timestampNumberEvent Messages Timestamp
Argus.Events.data.customerInfo.idNumberEvent Customer Info ID
Argus.Events.data.customerInfo.nameStringEvent Customer Info Name
Argus.Events.data.customerInfo.shortNameStringEvent Customer Info Short Name
Argus.Events.data.customerInfo.domain.idNumberEvent Customer Info Domain ID
Argus.Events.data.customerInfo.domain.nameStringEvent Customer Info Domain Name
Argus.Events.data.properties.additionalProp1StringEvent Properties Additional Prop 1
Argus.Events.data.properties.additionalProp2StringEvent Properties Additional Prop 2
Argus.Events.data.properties.additionalProp3StringEvent Properties Additional Prop 3
Argus.Events.data.comments.timestampNumberEvent Comments Timestamp
Argus.Events.data.comments.user.idNumberEvent Comments User ID
Argus.Events.data.comments.user.customerIDNumberEvent Comments User Customer ID
Argus.Events.data.comments.user.customer.idNumberEvent Comments User Customer ID
Argus.Events.data.comments.user.customer.nameStringEvent Comments User Customer Name
Argus.Events.data.comments.user.customer.shortNameStringEvent Comments User Customer Short Name
Argus.Events.data.comments.user.customer.domain.idNumberEvent Comments User Customer Domain ID
Argus.Events.data.comments.user.customer.domain.nameStringEvent Comments User Customer Domain Name
Argus.Events.data.comments.user.domain.idNumberEvent Comments User Domain ID
Argus.Events.data.comments.user.domain.nameStringEvent Comments User Domain Name
Argus.Events.data.comments.user.userNameStringEvent Comments User User Name
Argus.Events.data.comments.user.nameStringEvent Comments User Name
Argus.Events.data.comments.user.typeStringEvent Comments User Type
Argus.Events.data.comments.commentStringEvent Comments Comment
Argus.Events.data.associatedCase.idNumberEvent Associated Case ID
Argus.Events.data.associatedCase.subjectStringEvent Associated Case Subject
Argus.Events.data.associatedCase.categoryIDNumberEvent Associated Case Category ID
Argus.Events.data.associatedCase.categoryNameStringEvent Associated Case Category Name
Argus.Events.data.associatedCase.serviceStringEvent Associated Case Service
Argus.Events.data.associatedCase.statusStringEvent Associated Case Status
Argus.Events.data.associatedCase.priorityStringEvent Associated Case Priority
Argus.Events.data.location.shortNameStringEvent Location Short Name
Argus.Events.data.location.nameStringEvent Location Name
Argus.Events.data.location.timeZoneStringEvent Location Time Zone
Argus.Events.data.location.idNumberEvent Location ID
Argus.Events.data.attackInfo.alarmIDNumberEvent Attack Info Alarm ID
Argus.Events.data.attackInfo.alarmDescriptionStringEvent Attack Info Alarm Description
Argus.Events.data.attackInfo.attackCategoryIDNumberEvent Attack Info Attack Category ID
Argus.Events.data.attackInfo.attackCategoryNameStringEvent Attack Info Attack Category Name
Argus.Events.data.attackInfo.signatureStringEvent Attack Info Signature
Argus.Events.data.domain.fqdnStringEvent Domain Fqdn
Argus.Events.data.uriStringEvent Uri
Argus.Events.data.countNumberAPI response metadata, total number of results this query has
Argus.Events.data.source.portNumberEvent Source Port
Argus.Events.data.source.geoLocation.countryCodeStringEvent Source Geo Location Country Code
Argus.Events.data.source.geoLocation.countryNameStringEvent Source Geo Location Country Name
Argus.Events.data.source.geoLocation.locationNameStringEvent Source Geo Location Location Name
Argus.Events.data.source.geoLocation.latitudeNumberEvent Source Geo Location Latitude
Argus.Events.data.source.geoLocation.longitudeNumberEvent Source Geo Location Longitude
Argus.Events.data.source.networkAddress.ipv6BooleanEvent Source Network Address Ipv 6
Argus.Events.data.source.networkAddress.publicBooleanEvent Source Network Address Public
Argus.Events.data.source.networkAddress.maskBitsNumberEvent Source Network Address Mask Bits
Argus.Events.data.source.networkAddress.multicastBooleanEvent Source Network Address Multicast
Argus.Events.data.source.networkAddress.hostBooleanEvent Source Network Address Host
Argus.Events.data.source.networkAddress.addressStringEvent Source Network Address Address
Argus.Events.data.destination.portNumberEvent Destination Port
Argus.Events.data.destination.geoLocation.countryCodeStringEvent Destination Geo Location Country Code
Argus.Events.data.destination.geoLocation.countryNameStringEvent Destination Geo Location Country Name
Argus.Events.data.destination.geoLocation.locationNameStringEvent Destination Geo Location Location Name
Argus.Events.data.destination.geoLocation.latitudeNumberEvent Destination Geo Location Latitude
Argus.Events.data.destination.geoLocation.longitudeNumberEvent Destination Geo Location Longitude
Argus.Events.data.destination.networkAddress.ipv6BooleanEvent Destination Network Address Ipv 6
Argus.Events.data.destination.networkAddress.publicBooleanEvent Destination Network Address Public
Argus.Events.data.destination.networkAddress.maskBitsNumberEvent Destination Network Address Mask Bits
Argus.Events.data.destination.networkAddress.multicastBooleanEvent Destination Network Address Multicast
Argus.Events.data.destination.networkAddress.hostBooleanEvent Destination Network Address Host
Argus.Events.data.destination.networkAddress.addressStringEvent Destination Network Address Address
Argus.Events.data.protocolStringEvent Protocol
Argus.Events.data.timestampNumberEvent Timestamp
Argus.Events.data.startTimestampNumberEvent Start Timestamp
Argus.Events.data.endTimestampNumberEvent End Timestamp
Argus.Events.data.lastUpdatedTimestampNumberEvent Last Updated Timestamp
Argus.Events.data.flagsStringEvent Flags
Argus.Events.data.detailedEventIDSStringEvent Detailed Event IDS
Argus.Events.data.severityStringEvent Severity
Argus.Events.data.idStringEvent ID

Command Example#

!argus_get_events_for_case case_id=123

argus-list-aggregated-events#


List aggregated events

Base Command#

argus-list-aggregated-events

Input#

Argument NameDescriptionRequired
customer_idLimit to customerID.Optional
signatureLimit to signature.Optional
ipLimit to ip/network.Optional
start_timestampLimit to events after this timestamp (default is last 24 hours).Optional
end_timestampLimit to events before this timestamp. Defaults to now.Optional
limitLimit results (default 25).Optional
offsetSkip a number of results.Optional

Context Output#

PathTypeDescription
Argus.Events.responseCodeNumberAPI response metadata, response code of this request
Argus.Events.limitNumberAPI response metadata, limit of results this request ran with
Argus.Events.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Events.countNumberAPI response metadata, total number of results this query has
Argus.Events.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Events.messages.messageStringEvent Messages Message
Argus.Events.messages.messageTemplateStringEvent Messages Message Template
Argus.Events.messages.typeStringEvent Messages Type
Argus.Events.messages.fieldStringEvent Messages Field
Argus.Events.messages.timestampNumberEvent Messages Timestamp
Argus.Events.data.customerInfo.idNumberEvent Customer Info ID
Argus.Events.data.customerInfo.nameStringEvent Customer Info Name
Argus.Events.data.customerInfo.shortNameStringEvent Customer Info Short Name
Argus.Events.data.customerInfo.domain.idNumberEvent Customer Info Domain ID
Argus.Events.data.customerInfo.domain.nameStringEvent Customer Info Domain Name
Argus.Events.data.properties.additionalProp1StringEvent Properties Additional Prop 1
Argus.Events.data.properties.additionalProp2StringEvent Properties Additional Prop 2
Argus.Events.data.properties.additionalProp3StringEvent Properties Additional Prop 3
Argus.Events.data.comments.timestampNumberEvent Comments Timestamp
Argus.Events.data.comments.user.idNumberEvent Comments User ID
Argus.Events.data.comments.user.customerIDNumberEvent Comments User Customer ID
Argus.Events.data.comments.user.customer.idNumberEvent Comments User Customer ID
Argus.Events.data.comments.user.customer.nameStringEvent Comments User Customer Name
Argus.Events.data.comments.user.customer.shortNameStringEvent Comments User Customer Short Name
Argus.Events.data.comments.user.customer.domain.idNumberEvent Comments User Customer Domain ID
Argus.Events.data.comments.user.customer.domain.nameStringEvent Comments User Customer Domain Name
Argus.Events.data.comments.user.domain.idNumberEvent Comments User Domain ID
Argus.Events.data.comments.user.domain.nameStringEvent Comments User Domain Name
Argus.Events.data.comments.user.userNameStringEvent Comments User User Name
Argus.Events.data.comments.user.nameStringEvent Comments User Name
Argus.Events.data.comments.user.typeStringEvent Comments User Type
Argus.Events.data.comments.commentStringEvent Comments Comment
Argus.Events.data.associatedCase.idNumberEvent Associated Case ID
Argus.Events.data.associatedCase.subjectStringEvent Associated Case Subject
Argus.Events.data.associatedCase.categoryIDNumberEvent Associated Case Category ID
Argus.Events.data.associatedCase.categoryNameStringEvent Associated Case Category Name
Argus.Events.data.associatedCase.serviceStringEvent Associated Case Service
Argus.Events.data.associatedCase.statusStringEvent Associated Case Status
Argus.Events.data.associatedCase.priorityStringEvent Associated Case Priority
Argus.Events.data.location.shortNameStringEvent Location Short Name
Argus.Events.data.location.nameStringEvent Location Name
Argus.Events.data.location.timeZoneStringEvent Location Time Zone
Argus.Events.data.location.idNumberEvent Location ID
Argus.Events.data.attackInfo.alarmIDNumberEvent Attack Info Alarm ID
Argus.Events.data.attackInfo.alarmDescriptionStringEvent Attack Info Alarm Description
Argus.Events.data.attackInfo.attackCategoryIDNumberEvent Attack Info Attack Category ID
Argus.Events.data.attackInfo.attackCategoryNameStringEvent Attack Info Attack Category Name
Argus.Events.data.attackInfo.signatureStringEvent Attack Info Signature
Argus.Events.data.domain.fqdnStringEvent Domain Fqdn
Argus.Events.data.uriStringEvent Uri
Argus.Events.data.countNumberAPI response metadata, total number of results this query has
Argus.Events.data.source.portNumberEvent Source Port
Argus.Events.data.source.geoLocation.countryCodeStringEvent Source Geo Location Country Code
Argus.Events.data.source.geoLocation.countryNameStringEvent Source Geo Location Country Name
Argus.Events.data.source.geoLocation.locationNameStringEvent Source Geo Location Location Name
Argus.Events.data.source.geoLocation.latitudeNumberEvent Source Geo Location Latitude
Argus.Events.data.source.geoLocation.longitudeNumberEvent Source Geo Location Longitude
Argus.Events.data.source.networkAddress.ipv6BooleanEvent Source Network Address Ipv 6
Argus.Events.data.source.networkAddress.publicBooleanEvent Source Network Address Public
Argus.Events.data.source.networkAddress.maskBitsNumberEvent Source Network Address Mask Bits
Argus.Events.data.source.networkAddress.multicastBooleanEvent Source Network Address Multicast
Argus.Events.data.source.networkAddress.hostBooleanEvent Source Network Address Host
Argus.Events.data.source.networkAddress.addressStringEvent Source Network Address Address
Argus.Events.data.destination.portNumberEvent Destination Port
Argus.Events.data.destination.geoLocation.countryCodeStringEvent Destination Geo Location Country Code
Argus.Events.data.destination.geoLocation.countryNameStringEvent Destination Geo Location Country Name
Argus.Events.data.destination.geoLocation.locationNameStringEvent Destination Geo Location Location Name
Argus.Events.data.destination.geoLocation.latitudeNumberEvent Destination Geo Location Latitude
Argus.Events.data.destination.geoLocation.longitudeNumberEvent Destination Geo Location Longitude
Argus.Events.data.destination.networkAddress.ipv6BooleanEvent Destination Network Address Ipv 6
Argus.Events.data.destination.networkAddress.publicBooleanEvent Destination Network Address Public
Argus.Events.data.destination.networkAddress.maskBitsNumberEvent Destination Network Address Mask Bits
Argus.Events.data.destination.networkAddress.multicastBooleanEvent Destination Network Address Multicast
Argus.Events.data.destination.networkAddress.hostBooleanEvent Destination Network Address Host
Argus.Events.data.destination.networkAddress.addressStringEvent Destination Network Address Address
Argus.Events.data.protocolStringEvent Protocol
Argus.Events.data.timestampNumberEvent Timestamp
Argus.Events.data.startTimestampNumberEvent Start Timestamp
Argus.Events.data.endTimestampNumberEvent End Timestamp
Argus.Events.data.lastUpdatedTimestampNumberEvent Last Updated Timestamp
Argus.Events.data.flagsStringEvent Flags
Argus.Events.data.detailedEventIDSStringEvent Detailed Event IDS
Argus.Events.data.severityStringEvent Severity
Argus.Events.data.idStringEvent ID

Command Example#

!argus_list_aggregated_events

argus-find-aggregated-events#


Search for aggregated events (OSB! advanced method: look in API doc)

Base Command#

argus-find-aggregated-events

Input#

Argument NameDescriptionRequired
skip_future_eventsSkip future events. Possible values are: true, false.Optional
excludeExclude parameter. Possible values are: true, false.Optional
event_identifier(as list).Optional
location_id(as list).Optional
severity(as list).Optional
customer(as list).Optional
alarm_id(as list).Optional
attack_category_id(as list).Optional
source_geo_country(as list).Optional
destination_geo_country(as list).Optional
geo_country(as list).Optional
properties(as dict: key,value).Optional
exact_match_propertiesExact matching flag. Possible values are: true, false.Optional
sub_criteria(as list).Optional
signature(as list).Optional
last_updated_timestampLast updated timestamp.Optional
index_start_timeIndex start time.Optional
index_end_timeIndex end time.Optional
destination_ip(as list).Optional
source_ip(as list).Optional
ip(as list).Optional
destination_port(as list).Optional
source_port(as list).Optional
port(as lst).Optional
min_severityMinimum severity.Optional
max_severityMaximum severity.Optional
limitLimit results (default 25).Optional
offsetSkip number of results.Optional
include_deletedInclude deleted events. Possible values are: true, false.Optional
min_countMinimum count.Optional
associated_case_id(as list).Optional
source_ip_min_bitsSource IP minimum bits.Optional
destination_ip_min_bitsDestination IP minimum bits.Optional
start_timestampStart timestamp.Optional
end_timestampEnd timestamp.Optional
sort_byOrder results by these properties (prefix with - to sort descending) (as list).Optional
include_flagsSearch objects with these flags set (as list).Optional
exclude_flagsExclude objects with these flags set (as list).Optional

Context Output#

PathTypeDescription
Argus.Events.responseCodeNumberAPI response metadata, response code of this request
Argus.Events.limitNumberAPI response metadata, limit of results this request ran with
Argus.Events.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Events.countNumberAPI response metadata, total number of results this query has
Argus.Events.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Events.messages.messageStringEvent Messages Message
Argus.Events.messages.messageTemplateStringEvent Messages Message Template
Argus.Events.messages.typeStringEvent Messages Type
Argus.Events.messages.fieldStringEvent Messages Field
Argus.Events.messages.timestampNumberEvent Messages Timestamp
Argus.Events.data.customerInfo.idNumberEvent Customer Info ID
Argus.Events.data.customerInfo.nameStringEvent Customer Info Name
Argus.Events.data.customerInfo.shortNameStringEvent Customer Info Short Name
Argus.Events.data.customerInfo.domain.idNumberEvent Customer Info Domain ID
Argus.Events.data.customerInfo.domain.nameStringEvent Customer Info Domain Name
Argus.Events.data.properties.additionalProp1StringEvent Properties Additional Prop 1
Argus.Events.data.properties.additionalProp2StringEvent Properties Additional Prop 2
Argus.Events.data.properties.additionalProp3StringEvent Properties Additional Prop 3
Argus.Events.data.comments.timestampNumberEvent Comments Timestamp
Argus.Events.data.comments.user.idNumberEvent Comments User ID
Argus.Events.data.comments.user.customerIDNumberEvent Comments User Customer ID
Argus.Events.data.comments.user.customer.idNumberEvent Comments User Customer ID
Argus.Events.data.comments.user.customer.nameStringEvent Comments User Customer Name
Argus.Events.data.comments.user.customer.shortNameStringEvent Comments User Customer Short Name
Argus.Events.data.comments.user.customer.domain.idNumberEvent Comments User Customer Domain ID
Argus.Events.data.comments.user.customer.domain.nameStringEvent Comments User Customer Domain Name
Argus.Events.data.comments.user.domain.idNumberEvent Comments User Domain ID
Argus.Events.data.comments.user.domain.nameStringEvent Comments User Domain Name
Argus.Events.data.comments.user.userNameStringEvent Comments User User Name
Argus.Events.data.comments.user.nameStringEvent Comments User Name
Argus.Events.data.comments.user.typeStringEvent Comments User Type
Argus.Events.data.comments.commentStringEvent Comments Comment
Argus.Events.data.associatedCase.idNumberEvent Associated Case ID
Argus.Events.data.associatedCase.subjectStringEvent Associated Case Subject
Argus.Events.data.associatedCase.categoryIDNumberEvent Associated Case Category ID
Argus.Events.data.associatedCase.categoryNameStringEvent Associated Case Category Name
Argus.Events.data.associatedCase.serviceStringEvent Associated Case Service
Argus.Events.data.associatedCase.statusStringEvent Associated Case Status
Argus.Events.data.associatedCase.priorityStringEvent Associated Case Priority
Argus.Events.data.location.shortNameStringEvent Location Short Name
Argus.Events.data.location.nameStringEvent Location Name
Argus.Events.data.location.timeZoneStringEvent Location Time Zone
Argus.Events.data.location.idNumberEvent Location ID
Argus.Events.data.attackInfo.alarmIDNumberEvent Attack Info Alarm ID
Argus.Events.data.attackInfo.alarmDescriptionStringEvent Attack Info Alarm Description
Argus.Events.data.attackInfo.attackCategoryIDNumberEvent Attack Info Attack Category ID
Argus.Events.data.attackInfo.attackCategoryNameStringEvent Attack Info Attack Category Name
Argus.Events.data.attackInfo.signatureStringEvent Attack Info Signature
Argus.Events.data.domain.fqdnStringEvent Domain Fqdn
Argus.Events.data.uriStringEvent Uri
Argus.Events.data.countNumberAPI response metadata, total number of results this query has
Argus.Events.data.source.portNumberEvent Source Port
Argus.Events.data.source.geoLocation.countryCodeStringEvent Source Geo Location Country Code
Argus.Events.data.source.geoLocation.countryNameStringEvent Source Geo Location Country Name
Argus.Events.data.source.geoLocation.locationNameStringEvent Source Geo Location Location Name
Argus.Events.data.source.geoLocation.latitudeNumberEvent Source Geo Location Latitude
Argus.Events.data.source.geoLocation.longitudeNumberEvent Source Geo Location Longitude
Argus.Events.data.source.networkAddress.ipv6BooleanEvent Source Network Address Ipv 6
Argus.Events.data.source.networkAddress.publicBooleanEvent Source Network Address Public
Argus.Events.data.source.networkAddress.maskBitsNumberEvent Source Network Address Mask Bits
Argus.Events.data.source.networkAddress.multicastBooleanEvent Source Network Address Multicast
Argus.Events.data.source.networkAddress.hostBooleanEvent Source Network Address Host
Argus.Events.data.source.networkAddress.addressStringEvent Source Network Address Address
Argus.Events.data.destination.portNumberEvent Destination Port
Argus.Events.data.destination.geoLocation.countryCodeStringEvent Destination Geo Location Country Code
Argus.Events.data.destination.geoLocation.countryNameStringEvent Destination Geo Location Country Name
Argus.Events.data.destination.geoLocation.locationNameStringEvent Destination Geo Location Location Name
Argus.Events.data.destination.geoLocation.latitudeNumberEvent Destination Geo Location Latitude
Argus.Events.data.destination.geoLocation.longitudeNumberEvent Destination Geo Location Longitude
Argus.Events.data.destination.networkAddress.ipv6BooleanEvent Destination Network Address Ipv 6
Argus.Events.data.destination.networkAddress.publicBooleanEvent Destination Network Address Public
Argus.Events.data.destination.networkAddress.maskBitsNumberEvent Destination Network Address Mask Bits
Argus.Events.data.destination.networkAddress.multicastBooleanEvent Destination Network Address Multicast
Argus.Events.data.destination.networkAddress.hostBooleanEvent Destination Network Address Host
Argus.Events.data.destination.networkAddress.addressStringEvent Destination Network Address Address
Argus.Events.data.protocolStringEvent Protocol
Argus.Events.data.timestampNumberEvent Timestamp
Argus.Events.data.startTimestampNumberEvent Start Timestamp
Argus.Events.data.endTimestampNumberEvent End Timestamp
Argus.Events.data.lastUpdatedTimestampNumberEvent Last Updated Timestamp
Argus.Events.data.flagsStringEvent Flags
Argus.Events.data.detailedEventIDSStringEvent Detailed Event IDS
Argus.Events.data.severityStringEvent Severity
Argus.Events.data.idStringEvent ID

Command Example#

!argus-find-aggregated-events

argus-get-payload#


Fetch specified event payload

Base Command#

argus-get-payload

Input#

Argument NameDescriptionRequired
typeEvent type. Possible values are: NIDS, AGGR, AGGRATTACK.Required
timestampTimestamp of event.Required
customer_idID of customer.Required
event_idID of related event.Required

Context Output#

PathTypeDescription
Argus.Payload.responseCodeNumberAPI response metadata, response code of this request
Argus.Payload.limitNumberAPI response metadata, limit of results this request ran with
Argus.Payload.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Payload.countNumberAPI response metadata, total number of results this query has
Argus.Payload.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Payload.messages.messageStringPayload Messages Message
Argus.Payload.messages.messageTemplateStringPayload Messages Message Template
Argus.Payload.messages.typeStringPayload Messages Type
Argus.Payload.messages.fieldStringPayload Messages Field
Argus.Payload.messages.timestampNumberPayload Messages Timestamp
Argus.Payload.data.idStringPayload ID
Argus.Payload.data.typeStringPayload Type
Argus.Payload.data.payloadStringPayload Payload

Command Example#

!argus-get-payload customer_id=123 event_id=123456 timestamp=123456789 type=NIDS

argus-get-pcap#


Fetch specified event payload as PCAP.

Base Command#

argus-get-pcap

Input#

Argument NameDescriptionRequired
typeEvent type. Possible values are: NIDS, AGGR, AGGRATTACK.Required
timestampTimestamp of event.Required
customer_idID of customer.Required
event_idID of related event.Required

Context Output#

There is no context output for this command.

Command Example#

!argus-get-pcap customer_id=123 event_id=123456 timestamp=123456789 type=NIDS

argus-get-event#


Fetch specified event.

Base Command#

argus-get-event

Input#

Argument NameDescriptionRequired
typeType of event. Possible values are: NIDS, AGGR, AGGRATTACK.Required
timestampTimestamp of event.Required
customer_idCustomer ID related to event.Required
event_idID of event.Required

Context Output#

PathTypeDescription
Argus.Event.responseCodeNumberAPI response metadata, response code of this request
Argus.Event.limitNumberAPI response metadata, limit of results this request ran with
Argus.Event.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.Event.countNumberAPI response metadata, total number of results this query has
Argus.Event.sizeNumberAPI response metadata, the number of results returned in this request
Argus.Event.messages.messageStringEvent Messages Message
Argus.Event.messages.messageTemplateStringEvent Messages Message Template
Argus.Event.messages.typeStringEvent Messages Type
Argus.Event.messages.fieldStringEvent Messages Field
Argus.Event.messages.timestampNumberEvent Messages Timestamp
Argus.Event.data.timestampNumberEvent Timestamp
Argus.Event.data.flagsNumberEvent Flags
Argus.Event.data.customerIDNumberEvent Customer ID
Argus.Event.data.aggregationKeyStringEvent Aggregation Key
Argus.Event.data.sourceTypeStringEvent Source Type
Argus.Event.data.customerInfo.idNumberEvent Customer Info ID
Argus.Event.data.customerInfo.nameStringEvent Customer Info Name
Argus.Event.data.customerInfo.shortNameStringEvent Customer Info Short Name
Argus.Event.data.customerInfo.domain.idNumberEvent Customer Info Domain ID
Argus.Event.data.customerInfo.domain.nameStringEvent Customer Info Domain Name
Argus.Event.data.updateBooleanEvent Update
Argus.Event.data.aggregatedBooleanEvent Aggregated
Argus.Event.data.encodedFlagsStringEvent Encoded Flags

Command Example#

!argus-get-event customer_id=123 event_id=123456 timestamp=123456789 type=NIDS

argus-list-nids-events#


Simple search for NIDS events.

Base Command#

argus-list-nids-events

Input#

Argument NameDescriptionRequired
customer_idLimit to customerID.Optional
signatureLimit to signature.Optional
ipLimit to ip/network.Optional
start_timestampLimit to events after this timestamp (default is last 24 hours).Optional
end_timestampLimit to events before this timestamp (default: now).Optional
limitLimit results (default: 25).Optional
offsetSkip a number of results.Optional

Context Output#

PathTypeDescription
Argus.NIDS.responseCodeNumberAPI response metadata, response code of this request
Argus.NIDS.limitNumberAPI response metadata, limit of results this request ran with
Argus.NIDS.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.NIDS.countNumberAPI response metadata, total number of results this query has
Argus.NIDS.sizeNumberAPI response metadata, the number of results returned in this request
Argus.NIDS.messages.messageStringNIDS Messages Message
Argus.NIDS.messages.messageTemplateStringNIDS Messages Message Template
Argus.NIDS.messages.typeStringNIDS Messages Type
Argus.NIDS.messages.fieldStringNIDS Messages Field
Argus.NIDS.messages.timestampNumberNIDS Messages Timestamp
Argus.NIDS.data.customerInfo.idNumberNIDS Customer Info ID
Argus.NIDS.data.customerInfo.nameStringNIDS Customer Info Name
Argus.NIDS.data.customerInfo.shortNameStringNIDS Customer Info Short Name
Argus.NIDS.data.customerInfo.domain.idNumberNIDS Customer Info Domain ID
Argus.NIDS.data.customerInfo.domain.nameStringNIDS Customer Info Domain Name
Argus.NIDS.data.properties.additionalProp1StringNIDS Properties Additional Prop 1
Argus.NIDS.data.properties.additionalProp2StringNIDS Properties Additional Prop 2
Argus.NIDS.data.properties.additionalProp3StringNIDS Properties Additional Prop 3
Argus.NIDS.data.comments.timestampNumberNIDS Comments Timestamp
Argus.NIDS.data.comments.user.idNumberNIDS Comments User ID
Argus.NIDS.data.comments.user.customerIDNumberNIDS Comments User Customer ID
Argus.NIDS.data.comments.user.customer.idNumberNIDS Comments User Customer ID
Argus.NIDS.data.comments.user.customer.nameStringNIDS Comments User Customer Name
Argus.NIDS.data.comments.user.customer.shortNameStringNIDS Comments User Customer Short Name
Argus.NIDS.data.comments.user.customer.domain.idNumberNIDS Comments User Customer Domain ID
Argus.NIDS.data.comments.user.customer.domain.nameStringNIDS Comments User Customer Domain Name
Argus.NIDS.data.comments.user.domain.idNumberNIDS Comments User Domain ID
Argus.NIDS.data.comments.user.domain.nameStringNIDS Comments User Domain Name
Argus.NIDS.data.comments.user.userNameStringNIDS Comments User User Name
Argus.NIDS.data.comments.user.nameStringNIDS Comments User Name
Argus.NIDS.data.comments.user.typeStringNIDS Comments User Type
Argus.NIDS.data.comments.commentStringNIDS Comments Comment
Argus.NIDS.data.sensor.sensorIDNumberNIDS Sensor Sensor ID
Argus.NIDS.data.sensor.hostNameStringNIDS Sensor Host Name
Argus.NIDS.data.sensor.hostIpAddress.hostBooleanNIDS Sensor Host Ip Address Host
Argus.NIDS.data.sensor.hostIpAddress.ipv6BooleanNIDS Sensor Host Ip Address Ipv 6
Argus.NIDS.data.sensor.hostIpAddress.publicBooleanNIDS Sensor Host Ip Address Public
Argus.NIDS.data.sensor.hostIpAddress.maskBitsNumberNIDS Sensor Host Ip Address Mask Bits
Argus.NIDS.data.sensor.hostIpAddress.multicastBooleanNIDS Sensor Host Ip Address Multicast
Argus.NIDS.data.sensor.hostIpAddress.addressStringNIDS Sensor Host Ip Address Address
Argus.NIDS.data.sensor.hostIpStringStringNIDS Sensor Host Ip String
Argus.NIDS.data.location.shortNameStringNIDS Location Short Name
Argus.NIDS.data.location.nameStringNIDS Location Name
Argus.NIDS.data.location.timeZoneStringNIDS Location Time Zone
Argus.NIDS.data.location.idNumberNIDS Location ID
Argus.NIDS.data.attackInfo.alarmIDNumberNIDS Attack Info Alarm ID
Argus.NIDS.data.attackInfo.alarmDescriptionStringNIDS Attack Info Alarm Description
Argus.NIDS.data.attackInfo.attackCategoryIDNumberNIDS Attack Info Attack Category ID
Argus.NIDS.data.attackInfo.attackCategoryNameStringNIDS Attack Info Attack Category Name
Argus.NIDS.data.attackInfo.signatureStringNIDS Attack Info Signature
Argus.NIDS.data.countNumberAPI response metadata, total number of results this query has
Argus.NIDS.data.engineTimestampNumberNIDS Engine Timestamp
Argus.NIDS.data.protocolIDNumberNIDS Protocol ID
Argus.NIDS.data.domain.fqdnStringNIDS Domain Fqdn
Argus.NIDS.data.uriStringNIDS Uri
Argus.NIDS.data.source.portNumberNIDS Source Port
Argus.NIDS.data.source.geoLocation.countryCodeStringNIDS Source Geo Location Country Code
Argus.NIDS.data.source.geoLocation.countryNameStringNIDS Source Geo Location Country Name
Argus.NIDS.data.source.geoLocation.locationNameStringNIDS Source Geo Location Location Name
Argus.NIDS.data.source.geoLocation.latitudeNumberNIDS Source Geo Location Latitude
Argus.NIDS.data.source.geoLocation.longitudeNumberNIDS Source Geo Location Longitude
Argus.NIDS.data.source.networkAddress.ipv6BooleanNIDS Source Network Address Ipv 6
Argus.NIDS.data.source.networkAddress.publicBooleanNIDS Source Network Address Public
Argus.NIDS.data.source.networkAddress.maskBitsNumberNIDS Source Network Address Mask Bits
Argus.NIDS.data.source.networkAddress.multicastBooleanNIDS Source Network Address Multicast
Argus.NIDS.data.source.networkAddress.hostBooleanNIDS Source Network Address Host
Argus.NIDS.data.source.networkAddress.addressStringNIDS Source Network Address Address
Argus.NIDS.data.destination.portNumberNIDS Destination Port
Argus.NIDS.data.destination.geoLocation.countryCodeStringNIDS Destination Geo Location Country Code
Argus.NIDS.data.destination.geoLocation.countryNameStringNIDS Destination Geo Location Country Name
Argus.NIDS.data.destination.geoLocation.locationNameStringNIDS Destination Geo Location Location Name
Argus.NIDS.data.destination.geoLocation.latitudeNumberNIDS Destination Geo Location Latitude
Argus.NIDS.data.destination.geoLocation.longitudeNumberNIDS Destination Geo Location Longitude
Argus.NIDS.data.destination.networkAddress.ipv6BooleanNIDS Destination Network Address Ipv 6
Argus.NIDS.data.destination.networkAddress.publicBooleanNIDS Destination Network Address Public
Argus.NIDS.data.destination.networkAddress.maskBitsNumberNIDS Destination Network Address Mask Bits
Argus.NIDS.data.destination.networkAddress.multicastBooleanNIDS Destination Network Address Multicast
Argus.NIDS.data.destination.networkAddress.hostBooleanNIDS Destination Network Address Host
Argus.NIDS.data.destination.networkAddress.addressStringNIDS Destination Network Address Address
Argus.NIDS.data.timestampNumberNIDS Timestamp
Argus.NIDS.data.severityStringNIDS Severity
Argus.NIDS.data.flagsStringNIDS Flags
Argus.NIDS.data.idStringNIDS ID

Command Example#

!argus-list-nids-events

argus-find-nids-events#


Search for NIDS events.

Base Command#

argus-find-nids-events

Input#

Argument NameDescriptionRequired
skip_future_eventsSkip future evnts. Possible values are: true, false.Optional
excludeExclude. Possible values are: true, false.Optional
event_identifier(as comma-separated list).Optional
location_id(as comma-separated list).Optional
severity(as comma-separated list).Optional
customer(as comma-separated list).Optional
alarm_id(as comma-separated list).Optional
attack_category_id(as comma-separated list).Optional
source_geo_country(as comma-separated list).Optional
destination_geo_country(as comma-separated list).Optional
geo_country(as comma-separated list).Optional
propertiesAs [key,value,key,value, ...] l.Optional
exact_match_propertiesUse exact matching. Possible values are: true, false.Optional
sensor_id(as comma-separated list).Optional
sub_criteria(as comma-separated list).Optional
signature(as comma-separated list).Optional
last_updated_timestampLast updated timestamp.Optional
index_start_timeIndex start time.Optional
index_end_timeIndex end time.Optional
destination_ip(as comma-separated list).Optional
source_ip(as comma-separated list).Optional
ip(as comma-separated list).Optional
destination_port(as comma-separated list).Optional
source_port(as comma-separated list).Optional
portsource_port.Optional
min_severityMinimum severity.Optional
max_severityMaximum severity.Optional
limitLimit number of results (default 25).Optional
offsetSkip a number of results.Optional
include_deletedInclide deleted events. Possible values are: true, false.Optional
start_timestampSearch objects from this timestamp (default: -24hours).Optional
end_timestampSearch objects until this timestamp (default: now).Optional
sort_byOrder results by these properties (prefix with - to sort descending) (as comma-separated list).Optional
include_flags(as comma-separated list).Optional
exclude_flags(as comma-separated list).Optional

Context Output#

PathTypeDescription
Argus.NIDS.responseCodeNumberAPI response metadata, response code of this request
Argus.NIDS.limitNumberAPI response metadata, limit of results this request ran with
Argus.NIDS.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.NIDS.countNumberAPI response metadata, total number of results this query has
Argus.NIDS.sizeNumberAPI response metadata, the number of results returned in this request
Argus.NIDS.messages.messageStringNIDS Messages Message
Argus.NIDS.messages.messageTemplateStringNIDS Messages Message Template
Argus.NIDS.messages.typeStringNIDS Messages Type
Argus.NIDS.messages.fieldStringNIDS Messages Field
Argus.NIDS.messages.timestampNumberNIDS Messages Timestamp
Argus.NIDS.data.customerInfo.idNumberNIDS Customer Info ID
Argus.NIDS.data.customerInfo.nameStringNIDS Customer Info Name
Argus.NIDS.data.customerInfo.shortNameStringNIDS Customer Info Short Name
Argus.NIDS.data.customerInfo.domain.idNumberNIDS Customer Info Domain ID
Argus.NIDS.data.customerInfo.domain.nameStringNIDS Customer Info Domain Name
Argus.NIDS.data.properties.additionalProp1StringNIDS Properties Additional Prop 1
Argus.NIDS.data.properties.additionalProp2StringNIDS Properties Additional Prop 2
Argus.NIDS.data.properties.additionalProp3StringNIDS Properties Additional Prop 3
Argus.NIDS.data.comments.timestampNumberNIDS Comments Timestamp
Argus.NIDS.data.comments.user.idNumberNIDS Comments User ID
Argus.NIDS.data.comments.user.customerIDNumberNIDS Comments User Customer ID
Argus.NIDS.data.comments.user.customer.idNumberNIDS Comments User Customer ID
Argus.NIDS.data.comments.user.customer.nameStringNIDS Comments User Customer Name
Argus.NIDS.data.comments.user.customer.shortNameStringNIDS Comments User Customer Short Name
Argus.NIDS.data.comments.user.customer.domain.idNumberNIDS Comments User Customer Domain ID
Argus.NIDS.data.comments.user.customer.domain.nameStringNIDS Comments User Customer Domain Name
Argus.NIDS.data.comments.user.domain.idNumberNIDS Comments User Domain ID
Argus.NIDS.data.comments.user.domain.nameStringNIDS Comments User Domain Name
Argus.NIDS.data.comments.user.userNameStringNIDS Comments User User Name
Argus.NIDS.data.comments.user.nameStringNIDS Comments User Name
Argus.NIDS.data.comments.user.typeStringNIDS Comments User Type
Argus.NIDS.data.comments.commentStringNIDS Comments Comment
Argus.NIDS.data.sensor.sensorIDNumberNIDS Sensor Sensor ID
Argus.NIDS.data.sensor.hostNameStringNIDS Sensor Host Name
Argus.NIDS.data.sensor.hostIpAddress.hostBooleanNIDS Sensor Host Ip Address Host
Argus.NIDS.data.sensor.hostIpAddress.ipv6BooleanNIDS Sensor Host Ip Address Ipv 6
Argus.NIDS.data.sensor.hostIpAddress.publicBooleanNIDS Sensor Host Ip Address Public
Argus.NIDS.data.sensor.hostIpAddress.maskBitsNumberNIDS Sensor Host Ip Address Mask Bits
Argus.NIDS.data.sensor.hostIpAddress.multicastBooleanNIDS Sensor Host Ip Address Multicast
Argus.NIDS.data.sensor.hostIpAddress.addressStringNIDS Sensor Host Ip Address Address
Argus.NIDS.data.sensor.hostIpStringStringNIDS Sensor Host Ip String
Argus.NIDS.data.location.shortNameStringNIDS Location Short Name
Argus.NIDS.data.location.nameStringNIDS Location Name
Argus.NIDS.data.location.timeZoneStringNIDS Location Time Zone
Argus.NIDS.data.location.idNumberNIDS Location ID
Argus.NIDS.data.attackInfo.alarmIDNumberNIDS Attack Info Alarm ID
Argus.NIDS.data.attackInfo.alarmDescriptionStringNIDS Attack Info Alarm Description
Argus.NIDS.data.attackInfo.attackCategoryIDNumberNIDS Attack Info Attack Category ID
Argus.NIDS.data.attackInfo.attackCategoryNameStringNIDS Attack Info Attack Category Name
Argus.NIDS.data.attackInfo.signatureStringNIDS Attack Info Signature
Argus.NIDS.data.countNumberAPI response metadata, total number of results this query has
Argus.NIDS.data.engineTimestampNumberNIDS Engine Timestamp
Argus.NIDS.data.protocolIDNumberNIDS Protocol ID
Argus.NIDS.data.domain.fqdnStringNIDS Domain Fqdn
Argus.NIDS.data.uriStringNIDS Uri
Argus.NIDS.data.source.portNumberNIDS Source Port
Argus.NIDS.data.source.geoLocation.countryCodeStringNIDS Source Geo Location Country Code
Argus.NIDS.data.source.geoLocation.countryNameStringNIDS Source Geo Location Country Name
Argus.NIDS.data.source.geoLocation.locationNameStringNIDS Source Geo Location Location Name
Argus.NIDS.data.source.geoLocation.latitudeNumberNIDS Source Geo Location Latitude
Argus.NIDS.data.source.geoLocation.longitudeNumberNIDS Source Geo Location Longitude
Argus.NIDS.data.source.networkAddress.ipv6BooleanNIDS Source Network Address Ipv 6
Argus.NIDS.data.source.networkAddress.publicBooleanNIDS Source Network Address Public
Argus.NIDS.data.source.networkAddress.maskBitsNumberNIDS Source Network Address Mask Bits
Argus.NIDS.data.source.networkAddress.multicastBooleanNIDS Source Network Address Multicast
Argus.NIDS.data.source.networkAddress.hostBooleanNIDS Source Network Address Host
Argus.NIDS.data.source.networkAddress.addressStringNIDS Source Network Address Address
Argus.NIDS.data.destination.portNumberNIDS Destination Port
Argus.NIDS.data.destination.geoLocation.countryCodeStringNIDS Destination Geo Location Country Code
Argus.NIDS.data.destination.geoLocation.countryNameStringNIDS Destination Geo Location Country Name
Argus.NIDS.data.destination.geoLocation.locationNameStringNIDS Destination Geo Location Location Name
Argus.NIDS.data.destination.geoLocation.latitudeNumberNIDS Destination Geo Location Latitude
Argus.NIDS.data.destination.geoLocation.longitudeNumberNIDS Destination Geo Location Longitude
Argus.NIDS.data.destination.networkAddress.ipv6BooleanNIDS Destination Network Address Ipv 6
Argus.NIDS.data.destination.networkAddress.publicBooleanNIDS Destination Network Address Public
Argus.NIDS.data.destination.networkAddress.maskBitsNumberNIDS Destination Network Address Mask Bits
Argus.NIDS.data.destination.networkAddress.multicastBooleanNIDS Destination Network Address Multicast
Argus.NIDS.data.destination.networkAddress.hostBooleanNIDS Destination Network Address Host
Argus.NIDS.data.destination.networkAddress.addressStringNIDS Destination Network Address Address
Argus.NIDS.data.timestampNumberNIDS Timestamp
Argus.NIDS.data.severityStringNIDS Severity
Argus.NIDS.data.flagsStringNIDS Flags
Argus.NIDS.data.idStringNIDS ID

Command Example#

!argus-find-nids-events

argus-pdns-search-records#


Search against PassiveDNS with criteria and return matching records.

Base Command#

argus-pdns-search-records

Input#

Argument NameDescriptionRequired
queryLookup query.Required
aggregate_resultWhether aggregate results (default true) . Possible values are: true, false.Optional
include_anonymous_resultsWhether include anonymous results (default true) . Possible values are: true, false.Optional
rr_classLookup with specified record classes (as comma-separated list).Optional
rr_typeLookup with specified record types (as comma-separated list).Optional
customer_idLookup for specified customer IDs (as comma-separated list).Optional
tlpLookup with specified TLPs, public usage only TLP white allowed (as comma-separated list). Possible values are: white, green, amber, red.Optional
limitMax number of results to be returned, default unset means default limit 25 will be used, 0 means unlimited.Optional
offsetNumber of results to be skipped first (default 0).Optional

Context Output#

PathTypeDescription
Argus.PDNS.responseCodeNumberAPI response metadata, response code of this request
Argus.PDNS.limitNumberAPI response metadata, limit of results this request ran with
Argus.PDNS.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.PDNS.countNumberAPI response metadata, total number of results this query has
Argus.PDNS.sizeNumberAPI response metadata, the number of results returned in this request
Argus.PDNS.messages.messageStringPDNS Messages Message
Argus.PDNS.messages.messageTemplateStringPDNS Messages Message Template
Argus.PDNS.messages.typeStringPDNS Messages Type
Argus.PDNS.messages.fieldStringPDNS Messages Field
Argus.PDNS.messages.timestampNumberPDNS Messages Timestamp
Argus.PDNS.data.createdTimestampNumberPDNS Created Timestamp
Argus.PDNS.data.lastUpdatedTimestampNumberPDNS Last Updated Timestamp
Argus.PDNS.data.timesNumberPDNS Times
Argus.PDNS.data.tlpStringPDNS Tlp
Argus.PDNS.data.queryStringPDNS Query
Argus.PDNS.data.answerStringPDNS Answer
Argus.PDNS.data.minTtlNumberPDNS Min Ttl
Argus.PDNS.data.maxTtlNumberPDNS Max Ttl
Argus.PDNS.data.customer.idNumberPDNS Customer ID
Argus.PDNS.data.customer.nameStringPDNS Customer Name
Argus.PDNS.data.customer.shortNameStringPDNS Customer Short Name
Argus.PDNS.data.customer.domain.idNumberPDNS Customer Domain ID
Argus.PDNS.data.customer.domain.nameStringPDNS Customer Domain Name
Argus.PDNS.data.lastSeenTimestampNumberPDNS Last Seen Timestamp
Argus.PDNS.data.firstSeenTimestampNumberPDNS First Seen Timestamp
Argus.PDNS.data.rrclassStringPDNS Rrclass
Argus.PDNS.data.rrtypeStringPDNS Rrtype

Command Example#

!argus-pdns-search-records query=mnemonic.no

argus-fetch-observations-for-domain#


Look up reputation observations for the given domain

Base Command#

argus-fetch-observations-for-domain

Input#

Argument NameDescriptionRequired
fqdnDomain to fetch observations for.Required

Context Output#

PathTypeDescription
Argus.ObservationsDomain.responseCodeNumberAPI response metadata, response code of this request
Argus.ObservationsDomain.limitNumberAPI response metadata, limit of results this request ran with
Argus.ObservationsDomain.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.ObservationsDomain.countNumberAPI response metadata, total number of results this query has
Argus.ObservationsDomain.sizeNumberAPI response metadata, the number of results returned in this request
Argus.ObservationsDomain.messages.messageStringObservations Domain Messages Message
Argus.ObservationsDomain.messages.messageTemplateStringObservations Domain Messages Message Template
Argus.ObservationsDomain.messages.typeStringObservations Domain Messages Type
Argus.ObservationsDomain.messages.fieldStringObservations Domain Messages Field
Argus.ObservationsDomain.messages.timestampNumberObservations Domain Messages Timestamp
Argus.ObservationsDomain.data.domainName.fqdnStringObservations Domain Domain Name Fqdn
Argus.ObservationsDomain.data.reasonStringObservations Domain Reason
Argus.ObservationsDomain.data.overrideBooleanObservations Domain Override
Argus.ObservationsDomain.data.valueNumberObservations Domain Value

Command Example#

!argus-fetch-observations-for-domain fqdn=mnemonic.no

argus-fetch-observations-for-ip#


Look up reputation observations for the given IP

Base Command#

argus-fetch-observations-for-ip

Input#

Argument NameDescriptionRequired
ipIP address to fetch observations for.Required

Context Output#

PathTypeDescription
Argus.ObservationsIP.responseCodeNumberAPI response metadata, response code of this request
Argus.ObservationsIP.limitNumberAPI response metadata, limit of results this request ran with
Argus.ObservationsIP.offsetNumberAPI response metadata, the offset into the result-set of this query
Argus.ObservationsIP.countNumberAPI response metadata, total number of results this query has
Argus.ObservationsIP.sizeNumberAPI response metadata, the number of results returned in this request
Argus.ObservationsIP.messages.messageStringObservations IP Messages Message
Argus.ObservationsIP.messages.messageTemplateStringObservations IP Messages Message Template
Argus.ObservationsIP.messages.typeStringObservations IP Messages Type
Argus.ObservationsIP.messages.fieldStringObservations IP Messages Field
Argus.ObservationsIP.messages.timestampNumberObservations IP Messages Timestamp
Argus.ObservationsIP.data.idNumberObservations IP ID
Argus.ObservationsIP.data.lastModifiedNumberObservations IP Last Modified
Argus.ObservationsIP.data.source.idNumberObservations IP Source ID
Argus.ObservationsIP.data.source.aliasStringObservations IP Source Alias
Argus.ObservationsIP.data.source.nameStringObservations IP Source Name
Argus.ObservationsIP.data.role.idNumberObservations IP Role ID
Argus.ObservationsIP.data.role.aliasStringObservations IP Role Alias
Argus.ObservationsIP.data.role.nameStringObservations IP Role Name
Argus.ObservationsIP.data.firstSeenNumberObservations IP First Seen
Argus.ObservationsIP.data.lastSeenNumberObservations IP Last Seen
Argus.ObservationsIP.data.numObservationsNumberObservations IP Num Observations
Argus.ObservationsIP.data.stateNumberObservations IP State
Argus.ObservationsIP.data.commentStringObservations IP Comment
Argus.ObservationsIP.data.address.hostBooleanObservations IP Address Host
Argus.ObservationsIP.data.address.ipv6BooleanObservations IP Address Ipv 6
Argus.ObservationsIP.data.address.maskBitsNumberObservations IP Address Mask Bits
Argus.ObservationsIP.data.address.multicastBooleanObservations IP Address Multicast
Argus.ObservationsIP.data.address.publicBooleanObservations IP Address Public
Argus.ObservationsIP.data.address.addressStringObservations IP Address Address

Command Example#

!argus-fetch-observations-for-ip ip=94.127.56.170

get-remote-data#


Get remote data from a remote incident. This method does not update the current incident, and should be used for debugging purposes.

Base Command#

get-remote-data

Input#

Argument NameDescriptionRequired
idArgus Case ID.Optional
lastUpdateTime or timestamp case was last updated.Optional

Context Output#

There is no context output for this command.

Command Example#

!get-remote-data case_id=123

update-remote-system#


Updates the remote system with incident changes.

Base Command#

update-remote-system

Input#

Argument NameDescriptionRequired

Context Output#

There is no context output for this command.

Command Example#

!update-remote-system

argus-download-attachment-by-filename#


Downloads case attachment by best-effort search of filename.

Base Command#

argus-download-attachment-by-filename

Input#

Argument NameDescriptionRequired
case_idCase ID.Required
file_nameFilename.Required

Context Output#

PathTypeDescription
File.SizeNumberThe size of the file.
File.SHA1StringThe SHA1 hash of the file.
File.SHA256StringThe SHA256 hash of the file.
File.NameStringThe name of the file.
File.SSDeepStringThe SSDeep hash of the file.
File.EntryIDStringThe entry ID of the file.
File.InfoStringFile information.
File.TypeStringThe file type.
File.MD5StringThe MD5 hash of the file.
File.ExtensionStringThe file extension.

Command Example#

!argus-download-attachment-by-filename case_id=123 file_name=file.name

argus-print-case-comments#


Print case comments as notes

Base Command#

argus-print-case-comments

Input#

Argument NameDescriptionRequired
case_idCase ID.Required

Context Output#

There is no context output for this command.

Command Example#

!argus_print_case_comments case_id=123

argus-print-case-metadata-by-id#


Print case metadata as HTML. Does not add to context.

Base Command#

argus-print-case-metadata-by-id

Input#

Argument NameDescriptionRequired
case_idCase ID.Required
skip_redirectIf true, skip automatic redirect (for merged cases).Optional

Context Output#

There is no context output for this command.

Command Example#

!argus-print-case_metadata_by_id case_id=123

argus-download-case-attachments#


Download all attachments related to Argus Case.

Base Command#

argus-download-case-attachments

Input#

Argument NameDescriptionRequired
case_idCase ID.Required

Context Output#

There is no context output for this command.

Command Example#

!argus-download-case-attachments case_id=123