Forum Discussion
Luizao_f
Dec 01, 2020Brass Contributor
Close MCAS alert via API
Good afternoon people.
I am drawing a flow in the Logic App to close the alert in MCAS.
I have little experience with API and would like to get help.
I was using the API call via the path [
[XXXX....
Luizao_f
Dec 04, 2020Brass Contributor
Pranesh1060
Very good. I tested your process and it worked correctly. Thank you. Show.
My second step is to close open incidents in Defender ATP. Do you have something like that? Are you ending incidents on another technology through the Logic App?
Pranesh1060
Dec 07, 2020Brass Contributor
Luizao_f We do have the connector available which can update the alert directly in MDATP and perform other operations like Run AV scan, Collect packages for investigation etc etc. The action you are looking for is update alert. Maybe you can use the same logic to split and isolate the alert id and then close it.