How to update an alert using PUT method

%3CLINGO-SUB%20id%3D%22lingo-sub-1322149%22%20slang%3D%22en-US%22%3EHow%20to%20update%20an%20alert%20using%20PUT%20method%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1322149%22%20slang%3D%22en-US%22%3E%3CP%3EHi!%3C%2FP%3E%3CP%3EDo%20you%20know%20if%20it%20is%20possible%20to%20update%20a%20Sentinel%20Alert%20using%20a%20PUT%20httpRequest%3F%3C%2FP%3E%3CP%3EI%20have%20tried%2C%20but%20I%20get%20this%20message%3A%26nbsp%3B%3C%2FP%3E%3CDIV%3E%3CDIV%3E%3CEM%3E%3CFONT%20size%3D%222%22%3E%7B%3C%2FFONT%3E%3C%2FEM%3E%3C%2FDIV%3E%3CDIV%3E%3CEM%3E%3CFONT%20size%3D%222%22%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%22error%22%3A%26nbsp%3B%7B%3C%2FFONT%3E%3C%2FEM%3E%3C%2FDIV%3E%3CDIV%3E%3CEM%3E%3CFONT%20size%3D%222%22%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%22code%22%3A%26nbsp%3B%22Conflict%22%2C%3C%2FFONT%3E%3C%2FEM%3E%3C%2FDIV%3E%3CDIV%3E%3CEM%3E%3CFONT%20size%3D%222%22%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%22message%22%3A%26nbsp%3B%22Newer%26nbsp%3Binstance%26nbsp%3Bof%26nbsp%3Brule%26nbsp%3B'ruleId'%26nbsp%3Bexists%26nbsp%3Bfor%26nbsp%3Bworkspace%26nbsp%3B'workspaceId'%26nbsp%3B(Etag%26nbsp%3Bdoes%26nbsp%3Bnot%26nbsp%3Bmatch).%26nbsp%3BData%26nbsp%3Bwas%26nbsp%3Bnot%26nbsp%3Bsaved.%22%3C%2FFONT%3E%3C%2FEM%3E%3C%2FDIV%3E%3CDIV%3E%3CEM%3E%3CFONT%20size%3D%222%22%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%7D%3C%2FFONT%3E%3C%2FEM%3E%3C%2FDIV%3E%3CDIV%3E%3CEM%3E%3CFONT%20size%3D%222%22%3E%7D%3C%2FFONT%3E%3C%2FEM%3E%3C%2FDIV%3E%3CDIV%3EThank%20you!%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1322624%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20update%20an%20alert%20using%20PUT%20method%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1322624%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F629571%22%20target%3D%22_blank%22%3E%40ingwarr23%3C%2FA%3E%26nbsp%3BI%20would%20say%20no%20as%20that%20would%20allow%20bad%20guys%20to%20potentially%20edit%20the%20information%20in%20an%20alert%20to%20make%20it%20seem%20benign.%26nbsp%3B%20%26nbsp%3BYou%20can%20always%20update%20the%20Incident%20that%20the%20alert%20may%20have%20generated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20you%20state%20what%20it%20is%20you%20are%20trying%20to%20update%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi!

Do you know if it is possible to update a Sentinel Alert using a PUT httpRequest?

I have tried, but I get this message: 

{
    "error": {
        "code": "Conflict",
        "message": "Newer instance of rule 'ruleId' exists for workspace 'workspaceId' (Etag does not match). Data was not saved."
    }
}
Thank you!
1 Reply

@ingwarr23 I would say no as that would allow bad guys to potentially edit the information in an alert to make it seem benign.   You can always update the Incident that the alert may have generated.

 

Can you state what it is you are trying to update?