Returns the verdict-based action configuration for a specific alert source. Enumerate alert sources via the Integrations API; this endpoint returns the configuration for one of them.
The alert source ID. This property is required.
A successful response.
The verdict-based action configuration for an alert source.
The alert source identifier.
The verdict-to-action mappings, one entry per verdict.
A single mapping from a verdict to its post-triage action.
The verdict. Accepted values: "True Positive - Malicious", "True Positive - Benign", "False Positive".
The post-triage action for this verdict. Accepted values: "open_case", "trigger_workflow", "do_nothing".
The timestamp when the configuration was last updated.
Invalid bearer token. If you receive this message more than once try creating a new Client ID/Client Secret or generating a new bearer token.
You don't have permission to access this resource.